Understanding Oregon Computer Crime Laws
A practical guide to Oregon’s computer crime statutes, penalties, and key legal concepts for digital-age conduct.
Oregon has a dedicated computer crime statute that targets unauthorized and fraudulent use of computers, networks, and digital data. The law is designed to protect individuals, businesses, and public entities from hacking, data destruction, and computer-based fraud while recognizing that not every rule violation or minor misuse of a work computer rises to the level of a criminal offense.
Overview of Oregon Computer Crime Statute
Oregon primarily addresses computer-related offenses under ORS 164.377, the state’s core computer crime provision. This law supplements traditional theft and fraud statutes by focusing on how computers and networks are used to commit or facilitate those offenses.
The statute applies broadly to any computer, computer system, or computer network. In practice, that includes devices such as desktop and laptop computers, servers, cloud systems, and many internet-connected platforms.
Key Legal Foundations
- Code sections: Oregon computer crimes are primarily governed by ORS 164.377, often considered alongside related theft provisions in ORS Chapter 164.
- Mental state: The required mental state for computer crime is generally knowingly—meaning the conduct is not accidental or inadvertent.
- Relationship to other crimes: Computer-based conduct can also implicate offenses such as theft, fraud, unlawful distribution of cable equipment, and telecommunications service theft when those acts are carried out through digital means.
Main Categories of Computer Crime in Oregon
ORS 164.377 identifies three principal categories of computer-related criminal conduct. These categories distinguish between fraudulent use of computers, damage to computer systems or data, and unauthorized access to computer resources.
1. Computer Use for Fraud, Theft, or Services
The first category covers using computers or networks to commit fraud or obtain money, property, or services through deception.
- Fraud schemes executed via email, websites, or online platforms.
- Obtaining money or property using false pretenses or misrepresentations online.
- Theft that involves proprietary information or intimate images obtained through computer systems.
Under Oregon law, a person commits computer crime in this category if they knowingly access or use a computer or network to devise or execute such schemes.
2. Unauthorized Alteration, Damage, or Destruction
The second category focuses on the integrity of computer systems and data. It aims to penalize actions that impair or destroy digital resources without authorization.
- Altering software or data in a way that changes functionality or records without permission.
- Damaging systems or networks through malware, deletion of files, or disruption of services.
- Destroying digital information such as customer databases, intellectual property, or operational records.
This category captures conduct commonly associated with malicious hacking, sabotage, or destructive insider behavior.
3. Unauthorized Use or Access
The third category addresses unauthorized access itself, even where no further damage or fraud occurs.
- Using a computer or network without authorization, such as accessing systems beyond granted permissions.
- Attempting to access protected systems without consent or proper credentials.
- Accessing software, programs, or data that the user has no legal right to view or use.
This category is often referred to as computer trespass and is intended to deter hacking and other intrusions into systems where a person lacks authorization.
Felony vs. Misdemeanor Computer Crimes
Oregon’s computer crime statute differentiates offenses based on the nature of the conduct and, in some cases, the systems involved. The law sets out varying levels of punishment, primarily through classification as a Class C felony or a Class A misdemeanor.
Offense Classifications
| Type of Conduct | Typical Classification | General Penalty Range |
|---|---|---|
| Fraud, theft, or services via computer (ORS 164.377(2)) | Class C felony | Up to approximately 5 years of imprisonment, plus fines (actual sentence depends on guidelines). |
| Unauthorized alteration, damage, or destruction (ORS 164.377(3)) | Class C felony | Similar felony-level penalties, often including possible probation and jail time. |
| Unauthorized use or access (ORS 164.377(4)) | Class A misdemeanor in most cases | Up to about 1 year of imprisonment for a Class A misdemeanor, plus potential fines. |
| Computer crimes involving Oregon State Lottery systems | Class C felony even for access-based offenses | Felony penalties due to heightened protection of lottery systems. |
Misdemeanor Computer-Related Offenses
Beyond the core computer crime statute, Oregon treats certain computer-related activities as misdemeanors, particularly when they involve lower-value theft or unauthorized use of services.
- Misdemeanor computer access: Unauthorized access alone is usually a Class A misdemeanor, unless special circumstances apply.
- Theft of services: When computer systems or communication services are obtained without payment, the offense can be charged as a misdemeanor if the value of services is relatively low.
- Unlawful distribution of cable television equipment: Oregon separately criminalizes certain unauthorized cable devices as a Class B misdemeanor.
What “Knowingly” Means in Computer Crime Cases
One central element in Oregon computer crime prosecutions is the requirement that the defendant act knowingly. This mental state helps distinguish deliberate misconduct from accidental or technical errors.
Elements of the “Knowingly” Standard
Under Oregon law, acting knowingly generally means that the person is aware of their conduct and the circumstances that make that conduct criminal.
- The person is aware they are accessing or using a computer or network.
- The person understands they are doing so without authorization or with intent to defraud, steal, or damage.
- Mistakes or inadvertent clicks, absent further evidence of intent, typically do not satisfy this standard.
Courts look at context, behavior patterns, and supporting evidence—such as communications, system logs, or financial records—to determine whether the mental state requirement is met.
Unauthorised Access vs. Policy Violations
One important clarification in Oregon law is the distinction between unauthorized access as defined in the statute and violations of internal company policies or rules. This distinction was highlighted by the Oregon Supreme Court and has practical implications for employees and employers.
Internal Rules vs. Criminal Conduct
The Oregon Supreme Court has explained that simply violating an employer’s computer-use policy—such as checking personal email on a work computer contrary to company rules—does not automatically amount to computer crime.
- Policy violations may lead to disciplinary action, termination, or civil consequences.
- Computer crime requires unauthorized access or use in a manner akin to hacking or intruding into systems without permission.
- Criminal conduct typically involves bypassing security measures, misusing passwords, or accessing data the individual is clearly not allowed to see.
The court emphasized that the statute was intended for significant intrusions and misuse, not routine internal rule violations. This guidance helps prevent over-criminalization of everyday workplace behavior.
Related Digital Offenses in Oregon
Computer crime in Oregon intersects with broader categories of digital and communication offenses. While ORS 164.377 is central, related statutes and legal doctrines can also apply to conduct involving technology.
Telecommunications and Service Theft
Oregon law treats the unauthorized use of communication systems—such as computer networks, telephone systems, or cable television services—without payment as evidence of intent to avoid payment. This can form the basis for theft-related charges when individuals or businesses obtain digital services without compensating providers.
Cable Television and Network Devices
The state also criminalizes the unlawful distribution of devices designed to receive cable television signals without authorization. Such offenses, although focused on cable systems, share a technological component with computer crime and reflect similar concerns about unauthorized access to digital services.
National Context: Computer Crime Statutes
Oregon’s statute fits within a broader national landscape of computer crime laws aiming to address hacking, unauthorized access, malware, denial-of-service attacks, and ransomware. States and the federal government, including through the Computer Fraud and Abuse Act (CFAA), have enacted overlapping frameworks to protect digital infrastructure and data.
Practical Implications for Individuals and Businesses
Understanding Oregon computer crime laws is important for everyday users and organizations that rely on digital systems. The statute affects how businesses structure network access, how employees use work devices, and how individuals interact with online platforms.
For Individuals
- Avoid accessing accounts, systems, or data that you are not authorized to use, even if you possess credentials from another person.
- Do not alter or delete data on shared or employer-owned systems without clear permission.
- Be cautious about participating in online schemes that promise quick financial gain, particularly where you are asked to use computers to move funds or manipulate records.
For Employers and Organizations
- Implement clear, written computer-use policies that outline permissible and impermissible activities on company systems.
- Use access controls and authentication measures so that authorization boundaries are easy to identify and enforce.
- Log user activity and maintain backups, both for security purposes and to assist in any investigation of potential computer crime.
- Train employees on cybersecurity best practices and on the legal significance of unauthorized access or data manipulation.
Frequently Asked Questions (FAQs)
Is simply breaking a workplace computer rule a crime in Oregon?
No. Violating an employer’s computer-use policy, by itself, is not normally computer crime under Oregon law. The Oregon Supreme Court has clarified that such conduct may result in internal discipline but does not automatically meet the legal standard for unauthorized access or use.
When does accessing a computer become a felony?
Accessing a computer becomes a felony when it is done knowingly and used to execute fraud, obtain money or property by deception, commit theft (including theft of proprietary information), or when unauthorized alteration, damage, or destruction of systems or data occurs. These acts are generally classified as Class C felonies.
What if I only access a system without causing harm?
Unauthorized access or use without further damage or fraud is typically treated as a Class A misdemeanor, assuming no special circumstances such as involvement of Oregon State Lottery systems. However, even misdemeanor charges can carry significant consequences, including potential jail time and fines.
Does Oregon’s computer crime law apply to mobile devices and cloud systems?
The statute covers computers, computer systems, and networks, which in practice can include smartphones, tablets, servers, and cloud environments when they function as part of a computer system or network. The key question is whether the device or service fits within the statutory definition of computer-related infrastructure.
How can I find the exact language of Oregon’s computer crime statute?
The full text of ORS 164.377 and related theft provisions is available through the Oregon Legislature’s official website under Chapter 164 of the Oregon Revised Statutes. Consulting the official statute is recommended for precise wording and any updates.
References
- Oregon Computer Crimes Laws — FindLaw. 2023-06-01. https://www.findlaw.com/state/oregon-law/oregon-computer-crimes-laws.html
- Oregon Revised Statutes Chapter 164 (including ORS 164.377) — Oregon Legislature. 2024-01-01. https://www.oregonlegislature.gov/bills_laws/ors/ors164.HTML
- ORS 164.377 Computer Crime Analysis — OregonCrimes.com. 2022-09-15. https://www.oregoncrimes.com/oregon_computer_crime_law.html
- Victory! Oregon Supreme Court Agrees that Violating a Company Rule is Not Computer Crime — Electronic Frontier Foundation. 2016-08-30. https://www.eff.org/deeplinks/2016/08/victory-oregon-supreme-court-agrees-violating-company-rule-not-computer-crime
- Computer Crime Statutes — National Conference of State Legislatures (NCSL). 2022-05-10. https://www.ncsl.org/technology-and-communication/computer-crime-statutes
- Civil Rights and Computer Fraud and Abuse Act Overview — Thompson Law LLC. 2021-11-01. https://www.thompsonlawllc.com/legal-services/cyber-crimes-and-computer-offenses/
Read full bio of Sneha Tete





