Washington Computer Crime Laws Explained

A practical guide to Washington’s cybercrime statutes, key offenses, penalties, and how state law interacts with federal computer crime enforcement.

By Medha deb
Created on

Washington State has enacted detailed computer crime laws to address modern online misconduct, from unauthorized access and data theft to cyber harassment and disruption of online services. These statutes, often referred to collectively as the Washington Cybercrime Act, operate alongside federal laws such as the Computer Fraud and Abuse Act (CFAA). This guide explains the main Washington offenses, how they are classified, typical penalties, and how they connect with broader federal cybercrime enforcement.

Why Computer Crime Laws Matter in Washington

Computers and networks are now central to business, government, and personal life. As a result, crimes involving electronic systems can cause substantial financial loss, privacy invasions, and threats to safety. Washington’s legislature created specific cybercrime offenses to ensure that:

  • Unauthorized system access is clearly criminalized, even when no physical property is touched.
  • Damage to data or services is treated similarly to traditional property damage.[10]
  • Theft of electronic information can be punished as a serious felony.
  • Online harassment through electronic communication is explicitly addressed.

At the same time, federal law gives prosecutors tools to address multi-state or international cyber schemes, including hacking, password trafficking, and extortion using computers.

Major Categories of Computer Crimes in Washington

Washington’s cybercrime framework focuses on several key categories of misconduct.

  • Computer trespass – unauthorized access to computer systems or networks.
  • Electronic data tampering – altering, corrupting, or damaging data without authorization.
  • Electronic data service interference – disrupting access to data networks or online services.
  • Electronic data theft – obtaining electronic data to defraud, extort, or gain money or property.
  • Cyber harassment – using electronic communications to threaten, intimidate, or harass.

Each offense has specific elements and penalties, which vary depending on the seriousness of the conduct and whether critical systems or large losses are involved.

Computer Trespass: Unauthorized Access to Systems

Computer trespass is Washington’s central offense for unauthorized access to computers or networks. It is divided into first and second degree, depending on the circumstances and harm.

Key Elements of Computer Trespass

While statutory language is technical, the basic idea is that a person commits computer trespass when they:

  • Intentionally gain access to a computer system, network, or data; and
  • Do so without authorization or beyond any permission they have; and
  • Access areas or data they are not allowed to use.

First-degree trespass typically involves more sensitive targets or significant harm, such as access to a government system or a system handling large amounts of monetary value. Second-degree trespass applies to other forms of unauthorized access.

Penalties for Computer Trespass

Offense Typical Classification Examples of Consequences
Computer trespass in the first degree Often treated as a felony when serious harm or protected systems are involved. Possible state prison term, fines, and restitution for losses.
Computer trespass in the second degree Gross misdemeanor. Potential local jail time and fines, plus restitution.

These state charges may be accompanied by federal charges if, for example, the conduct involves interstate systems or significant financial loss, under the CFAA’s unauthorized access provisions.

Electronic Data Tampering and Service Interference

Beyond mere access, Washington law punishes tampering with data and interfering with data services when done maliciously and without authorization.

Electronic Data Tampering

Electronic data tampering occurs when someone intentionally and without authorization alters, corrupts, or deletes electronic data or programs. Examples include:

  • Intentionally deleting another business’s records from their system.
  • Altering stored information to conceal fraud.
  • Injecting malicious code that changes or damages files.

Washington law distinguishes between first and second degree tampering, with more serious classifications when the conduct targets government systems or causes substantial monetary loss.

Electronic Data Service Interference

Electronic data service interference covers unauthorized acts that interrupt or suspend access to a data network or service. This may include:

  • Sending commands that disable or overload an online service.
  • Disrupting the functioning of a data network that serves customers.
  • Attacks resembling denial-of-service, if they fit statutory elements.[10]

More serious charges may apply if the interference affects government networks or critical services, or if the financial loss is significant.[10]

Electronic Data Theft: Stealing Information and Value

Electronic data theft is one of the more serious computer crime offenses under Washington law, reflecting the high value of digital information in modern commerce.

Elements of Electronic Data Theft

Under Washington statutes, a person commits electronic data theft when they:

  • Intentionally obtain electronic data without authorization; and
  • Lack reasonable grounds to believe they are authorized; and
  • Act with the intent to:
  • Devise or execute a scheme to defraud, deceive, extort, or commit another state-law crime; or
  • Wrongfully control, gain access to, or obtain money, property, or additional electronic data.

Because this offense focuses on both unauthorized access and fraudulent intent, it often overlaps conceptually with federal fraud-related computer crimes, including provisions of the CFAA and access device fraud statutes.

Penalty Level

Washington classifies electronic data theft as a class C felony. Consequences can include state prison time, substantial fines, and orders to pay restitution to victims. The exact sentence depends on the offender’s history, the scale of loss, and whether other crimes (such as traditional theft or identity theft) are also charged.

Cyber Harassment: Online Threats and Intimidation

To respond to harassment and threats conducted through electronic means, Washington law includes a specific cyber harassment offense. This covers electronic communications that are intended to intimidate or harass under defined conditions.

What Counts as Cyber Harassment?

Under Washington’s cyber harassment statute, a person may be guilty if they:

  • Make an electronic communication to another person or a third party; and
  • Do so with the intent to harass or intimidate; and
  • Under circumstances not constituting telephone harassment; and
  • The communication includes one or more of the following:
  • Lewd, lascivious, or obscene words, images, or language.
  • Anonymous or repeated messages.
  • Threats of bodily injury, now or in the future.
  • Threats to damage the property of the person or others.

Certain aggravated forms, especially those involving threats of harm or property damage, can result in more serious charges.

Relation to Broader Cybercrime Definitions

Federal law has recently defined cybercrime against individuals to include online harassment, threats, stalking, and coercion using computers. Washington’s cyber harassment statute fits within this broader landscape, allowing state-level enforcement where the victim and offender are connected to Washington, and federal tools may be used for multi-jurisdictional cases.

Washington Law and Federal Computer Crime Statutes

Washington’s computer crime laws do not operate in isolation. Many incidents can potentially be prosecuted under both state and federal statutes, especially where online activity crosses state lines or involves federal interests.

The Computer Fraud and Abuse Act (CFAA)

The federal Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, is a cornerstone of U.S. cybercrime enforcement. It generally prohibits:

  • Intentionally accessing a computer without authorization or exceeding authorized access to obtain information or value.
  • Causing damage to protected computers through knowing transmission of harmful code or commands.
  • Trafficking in passwords or similar access information.
  • Extortion that involves threats related to computers or data.

Federal sentencing provisions allow for substantial prison terms for serious offenses, particularly those involving national security information or large-scale fraud. Department of Justice guidance also clarifies when prosecutors will bring CFAA charges, focusing on clearly unauthorized access rather than simple misuse of legitimately obtained information.

Parallel and Overlapping Enforcement

In practice, the same conduct may violate both Washington’s Cybercrime Act and federal statutes. For example:

  • A Washington resident who accesses a company’s system without permission to steal data may face electronic data theft charges under state law and CFAA charges federally.
  • A coordinated attack that disrupts online services could lead to electronic data service interference prosecutions in Washington, and federal charges for damaging protected computers or fraud, depending on the facts.[10]
  • Cyber harassment cases that involve interstate threats or stalking might be addressed under both state cyber harassment statutes and federal laws targeting cybercrime against individuals.

Which jurisdiction takes the lead depends on factors like the scale of harm, locations of victims and systems, and priorities of state and federal authorities.

Reporting and Handling Internet Crime in Washington

Victims of computer-based crimes in Washington have several avenues to report incidents and seek help. The Attorney General’s office discusses internet crime generally and encourages use of coordinated reporting mechanisms.

Typical Steps When a Cybercrime Occurs

  • Document the activity – Save emails, logs, screenshots, and any relevant messages before systems are cleaned or changed.
  • Notify local law enforcement – Many cybercrime investigations begin with a report to local police, who can coordinate with state or federal agencies.
  • Use national reporting channels – Federal resources such as the Internet Crime Complaint Center (IC3) collect and route complaints to appropriate agencies.
  • Seek legal advice – Because statutes are complex and penalties can be serious, both victims and those under investigation often consult criminal law attorneys familiar with Washington’s cybercrime provisions.

Law enforcement agencies may combine technical investigation (such as tracing IP addresses and analyzing logs) with traditional criminal procedures to build cases under state or federal statutes.

Common Questions About Washington Computer Crime Laws

Is every unauthorized login a felony in Washington?

Not necessarily. Washington distinguishes between degrees of computer trespass and related offenses. Less serious unauthorized access may be charged as a gross misdemeanor (second-degree computer trespass), while conduct involving sensitive systems, large losses, or additional crimes can rise to felony-level offenses, such as electronic data theft or first-degree trespass.

How does “without authorization” differ under state and federal law?

Both Washington law and the CFAA use concepts of unauthorized access, but federal guidance emphasizes that prosecutors must show the defendant knowingly accessed a computer area they were not allowed to use at the time, rather than simply misusing data they were allowed to obtain. Washington’s statutes similarly focus on intentional access without authorization or exceeding the scope of any permission granted.

Can online harassment be prosecuted even if no physical harm occurs?

Yes. Cyber harassment statutes focus on the intent to harass or intimidate and the content of electronic communications, including threats and repeated contacts. Physical injury is not required for charges to be filed, although threats of bodily harm or property damage can lead to more serious consequences.

Do Washington’s computer crime laws cover business data and trade secrets?

Washington’s electronic data theft and data tampering provisions can apply when someone wrongfully obtains or alters business information, especially with intent to defraud or gain money or property. Depending on the circumstances, other laws related to trade secrets, fraud, or theft may also be involved, and federal statutes may apply if interstate commerce or protected computers are affected.

Are denial-of-service or ransomware attacks covered?

Washington’s statutes addressing electronic data service interference and data tampering can apply to conduct that interrupts access to networks or corrupts data.[10] Separately, many states have explicit statutes addressing denial-of-service attacks and ransomware, and federal laws such as the CFAA and fraud statutes provide additional tools for prosecutors in serious cases.[10]

References

  1. Chapter 9A.90 RCW – Washington Cybercrime Act — Washington State Legislature. 2024-01-01. https://app.leg.wa.gov/rcw/default.aspx?cite=9A.90&full=true
  2. Chapter 9A.90. Washington Cybercrime Act – Selected Statutes — WomensLaw.org. 2023-02-15. https://www.womenslaw.org/laws/wa/statutes/chapter-9a90-washington-cybercrime-act
  3. Computer Fraud and Abuse Act (CFAA) — National Association of Criminal Defense Lawyers. 2022-08-10. https://www.nacdl.org/Landing/ComputerFraudandAbuseAct
  4. 9-48.000 – Computer Fraud and Abuse Act — U.S. Department of Justice, Justice Manual. 2022-05-19. https://www.justice.gov/jm/jm-9-48000-computer-fraud
  5. Cybercrimes — National Association of Attorneys General. 2023-07-01. https://www.naag.org/issues/cyber-and-technology/cybercrimes/
  6. Computer Crime Statutes — National Conference of State Legislatures. 2022-06-15. https://www.ncsl.org/technology-and-communication/computer-crime-statutes
  7. Internet Crime – Washington State — Office of the Attorney General, Washington State. 2023-03-20. https://www.atg.wa.gov/internet-crime
Medha Deb is an editor with a master's degree in Applied Linguistics from the University of Hyderabad. She believes that her qualification has helped her develop a deep understanding of language and its application in various contexts.

Read full bio of medha deb