The Computer Fraud and Abuse Act was written to punish hacking, but it is charged far more broadly than that. Federal prosecutors have used it against employees who took files on the way out the door, against people who logged into accounts they were not supposed to, and against conduct that amounts to little more than breaking a written rule. The statute’s key terms are genuinely contested — and a computer fraud lawyer should test, from the start, whether what happened is actually a federal crime.
Elizabeth Franklin-Best, P.C. is a federal criminal defense and appellate firm, and we take on Computer Fraud and Abuse Act cases nationwide. Elizabeth Franklin-Best limits her practice to federal courts and agencies, and she holds Best Lawyers in America recognition as a 2026 “Best Lawyer” in Appellate Practice. The CFAA turns on questions of authorization and intent, and we defend it by holding the government to the narrowed meaning the Supreme Court has given the statute.
This guide explains what the CFAA is, the offenses it defines, what prosecutors must prove, the penalties involved, and how a defense is built. It is general legal information, not legal advice. If you are under investigation or charged, we offer a paid, one-hour initial consultation to review your situation. This guide sits within our white-collar crime defense practice.
Table of Contents

Quick Answer
| Question | Answer |
|---|---|
| What is the CFAA? | The Computer Fraud and Abuse Act, 18 U.S.C. § 1030 — the principal federal statute against unauthorized computer access, hacking, and computer-based fraud. |
| What conduct does it cover? | Accessing a protected computer without authorization or exceeding authorized access — to obtain information, commit fraud, or cause damage. |
| What did Van Buren change? | The Supreme Court held that exceeding authorized access means entering off-limits areas of a computer — not misusing information you were allowed to access. |
| What penalties can apply? | From a misdemeanor up to 10 years or more in prison, depending on the offense, the intent, and the harm. |
| What does an initial consultation cost? | It is a paid consultation — one hour with us, working through your access facts and exposure. |
Key Takeaways
- The CFAA is far broader than hacking — it is charged against insiders, former employees, and ordinary account misuse, not just outside intruders.
- The statute turns on two phrases: accessing a computer “without authorization” and “exceeding authorized access.”
- The Supreme Court narrowed “exceeds authorized access” — it covers entering off-limits files or systems, not misusing data you were entitled to see.
- After that decision, violating a workplace computer-use policy or a website’s terms of service is not, by itself, a federal crime.
- “Protected computer” is defined so broadly that nearly every internet-connected device qualifies.
- CFAA penalties range from a misdemeanor to 10 years or more, depending on the intent behind the access and the damage caused.
What Is the Computer Fraud and Abuse Act?
The Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, is the central federal computer-crime statute. It was enacted in the 1980s to punish hacking — the unauthorized intrusion into computer systems — and it still reaches that conduct. But over the decades it has been amended and stretched, and prosecutors now use it against a wide range of behavior: a departing employee who downloads company files, a person who logs into another’s email or cloud account, an insider who pulls records from a database, or a scheme that uses a computer to defraud.
That breadth is the heart of CFAA litigation. The statute applies to any “protected computer,” a term defined so expansively that virtually every internet-connected device — every laptop, phone, and server — falls within it. With the “computer” element almost always satisfied, the real fight in a CFAA case is over authorization: whether the defendant was permitted to do what they did, and whether the law actually criminalizes it.
The Section 1030 Offenses
Section 1030 is not a single crime but a set of related offenses. The provisions charged most often include:
- Obtaining information — accessing a protected computer without authorization, or exceeding authorized access, to obtain information.
- Computer fraud — accessing a protected computer with intent to defraud and obtaining something of value.
- Damage — knowingly transmitting code or commands, or intentionally accessing a computer, and causing damage — impairing the integrity or availability of data, programs, or systems.
- Trafficking and extortion — trafficking in passwords, and threats to damage a computer or to release data obtained from one.
Each provision has its own elements, its own intent requirement, and its own penalty range. CFAA charges are also frequently paired with other offenses — wire fraud when a computer is used to carry out a scheme, or trade secret theft when the information taken is proprietary. Identifying exactly which subsection the government has charged, and whether its specific requirements are met, is where a CFAA defense begins.
Without Authorization and Exceeds Authorized Access
The CFAA distinguishes between two ways of crossing the line. Accessing a computer without authorization describes the classic outside intruder — someone with no right to be in the system at all. Exceeding authorized access describes an insider — someone who is allowed into a system but goes somewhere within it they are not permitted to go. For years, the meaning of that second phrase was the most litigated question in computer-crime law.
In 2021, the Supreme Court resolved much of it. In Van Buren v. United States, 593 U.S. 374 (2021), the Court adopted a “gates-up-or-down” approach: a person exceeds authorized access only by obtaining information from areas of a computer — files, folders, or databases — that are off-limits to them. The statute does not reach a person who is entitled to access information but does so for an improper reason. That distinction is decisive. After Van Buren, breaking an employer’s acceptable-use policy, or violating a website’s terms of service, by misusing information you were allowed to see is not, standing alone, a federal crime. The case sharply narrowed the CFAA, and it is the first thing a defense examines in any “exceeds authorized access” prosecution.
Applied insight. Many CFAA charges filed before 2021 — and some still filed today — rest on the theory that a defendant misused access they actually had. After Van Buren, that theory often fails. The decisive question is not why a person accessed information, but whether they were entitled to reach it at all.
Penalties Under the CFAA
CFAA penalties vary widely, because the statute scales punishment to the conduct. The least serious offense — simply obtaining information — can be a misdemeanor carrying up to a year. But the same conduct becomes a felony, with up to five years, when it is done for commercial advantage or private financial gain, in furtherance of another crime, or where the information’s value exceeds a statutory threshold. Computer fraud under the statute carries up to five years, and a prior conviction raises that to ten.
The damage provisions are the most serious. Knowingly transmitting code or commands and intentionally causing damage can carry up to ten years, and the exposure climbs further — and can reach twenty years — for repeat offenders and for conduct that causes serious harm. Convictions also carry fines and, frequently, restitution measured by the victim’s loss, including the cost of investigating and repairing the intrusion. Because the loss figure drives both the charge and the sentence, scrutinizing how that figure is calculated is essential work, and our federal sentencing practice addresses it in detail.
Applied insight. In CFAA cases, the alleged “loss” is often a moving target — incident-response billing, internal IT time, and estimated lost revenue can be stacked to clear a statutory threshold or inflate a sentence. Disciplined scrutiny of how loss is measured frequently changes both the level of the charge and the exposure at sentencing.
How CFAA Sentences Are Calculated
Most CFAA convictions are sentenced under U.S. Sentencing Guidelines § 2B1.1 — the same fraud-and-theft guideline that governs wire fraud — which means the offense level is driven overwhelmingly by the loss figure. The statute defines “loss” generously for the government: 18 U.S.C. § 1030(e)(11) sweeps in the reasonable cost of responding to the offense, assessing the damage, and restoring systems, plus revenue lost because of an interruption of service. Incident-response invoices and internal IT hours can therefore turn a modest intrusion into a six-figure loss on paper.
Two recent changes matter for the defense. Since November 1, 2024, the Sentencing Commission’s Amendment 827 moved the intended-loss rule into the text of § 2B1.1 itself, so the government may again rely on what a defendant allegedly intended rather than what actually happened — a point worth contesting on the facts. And because the Guidelines are advisory under United States v. Booker, 543 U.S. 220 (2005), a defense that dismantles the loss narrative at sentencing can matter as much as one aimed at the verdict. Each disputed dollar of loss has to be proved, traced, and causally connected to the access charged.
Defending a CFAA Case
The strongest CFAA defenses focus on authorization. After Van Buren, a central argument is that the defendant was entitled to access the information at issue — that any wrongdoing was a misuse of permitted access, not an intrusion into off-limits areas, and so falls outside the statute. Where the government’s theory rests on a violated computer-use policy or a terms-of-service breach, that theory is now vulnerable. The scope of a person’s authorization — what their credentials actually permitted — becomes the decisive factual question.
Other defenses target intent and harm. The fraud provision requires an intent to defraud; the damage provisions require knowing or intentional conduct — not mistake, not authorized testing, not ordinary use that happened to cause a problem. The intent element has real teeth on the access counts too: in Conlan Abu v. Dickson, 107 F.4th 508 (6th Cir. 2024), the Sixth Circuit held that intentionally exceeding authorized access requires that the insider purposefully entered an area of the computer and knew it was forbidden — deliberate access without notice that it was off-limits is not enough. A defense may also show that the alleged loss does not meet the statutory threshold, or that the government has inflated it. We examine the access logs, the credentials, the policies, and the loss calculation, and we measure the charge against the narrowed statute the Supreme Court has defined. Outcomes are never something an honest lawyer guarantees, and we will not — our commitment is to test, rigorously, whether the conduct is a CFAA crime at all.
What Changed in CFAA Enforcement (2021–2026)
Van Buren answered the central question but expressly left one open: whether the “gates” that define authorized access must be technological, or whether contracts and written policies can erect them too. In May 2022, the Department of Justice largely resolved that question as a matter of charging policy. Under Justice Manual § 9-48.000, prosecutors may bring an “exceeds authorized access” charge only where the computer is divided into areas through code or configuration — not merely through terms of service, contracts, or employee policies — and only where the defendant knowingly crossed into an area that was unconditionally off-limits. The policy also requires consultation with the Criminal Division’s Computer Crime and Intellectual Property Section before charging.
The same policy created an express carve-out for security researchers: prosecutors should decline charges where the evidence shows the defendant’s conduct was, and was intended as, good-faith security research — testing or investigating a system to correct a vulnerability, carried out to avoid harm and to promote the security of the affected devices or services. Research conducted to extort an owner does not qualify. A charging policy is not a statutory defense, and it creates no enforceable rights, but it gives the defense a powerful benchmark when charged conduct looks like the kind of case the Department has said it will not bring.
The circuits have continued to read the statute the way Van Buren pointed. In NRA Group, LLC v. Durenleau, 153 F.4th 1333 (3d Cir. 2025), the Third Circuit held that, absent evidence of code-based hacking, the CFAA does not reach claims built on a current employee’s breach of workplace computer-use policies — adopting the same gates-based view of authorization that the Fourth and Ninth Circuits had already taken. The practical line is now reasonably clear across much of the country: crossing a technological barrier — a password, an access control, a configuration that walls off part of a system — can be unauthorized access, while merely violating a policy about how permitted access is used generally is not. Identifying which side of that line the government’s theory falls on is the first move in any modern CFAA defense.
Data scraping has followed its own track. In hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022), the Ninth Circuit reasoned that the CFAA’s “without authorization” clause likely does not reach the scraping of websites that are open to the public, because authorization is beside the point where no gate exists at all. The decision arose in a civil preliminary-injunction posture, so its holding is provisional by nature — but its logic, combined with the 2022 charging policy, has made pure public-data scraping an unattractive criminal theory. Password-protected areas, circumvented technical blocks, and access continued after an unambiguous cease-and-desist remain a very different matter.
Why Work With Elizabeth Franklin-Best, P.C.
CFAA defense rewards appellate-grade statutory work, because the statute’s reach is still being defined case by case. Elizabeth Franklin-Best holds admission to the United States Supreme Court and all twelve federal circuit courts of appeals, and pro hac vice admission lets her appear in district courts nationwide. The firm carries a Chambers USA 2026 ranking for Litigation: White-Collar Crime & Government Investigations — a practice category that includes exactly these computer-access and data-theft prosecutions.
That recognition rests on a substantial federal record. Our principal attorney has handled more than 330 federal matters — over 190 in the United States district courts and more than 120 in the courts of appeals, with cert-stage work at the Supreme Court — including in excess of 100 federal appeals across all twelve circuits, and she is the author of Reversing Your Criminal Conviction. Past results never guarantee a future outcome, but in a statute as unsettled as the CFAA, that appellate fluency is what lets us argue the narrowed law to a trial court and preserve every issue for review.
The CFAA’s meaning has been actively reshaped by the courts within the last five years, and a defense is only as good as its grasp of those moving limits. We pair that doctrinal work with a granular factual investigation — access logs, credential scopes, system architecture, and the loss math — because CFAA cases are won where the law and the forensics meet. You can find the rest of our white-collar crime defense practice, including related data-theft and fraud charges, through the main practice guide.
Talk With a Computer Fraud Lawyer
If you are under investigation for unauthorized computer access, or have been charged under the CFAA, the question of whether your conduct fits the statute is genuinely open — and worth fighting. Our paid, one-hour initial consultation is where that fight starts: we will look at what was accessed, what your credentials permitted, how the government is counting loss, and what a defense built on the narrowed statute would look like.
Frequently Asked Questions
What is the Computer Fraud and Abuse Act?
The Computer Fraud and Abuse Act, 18 U.S.C. Section 1030, is the principal federal computer-crime statute. It criminalizes accessing a protected computer without authorization or exceeding authorized access to obtain information, commit fraud, or cause damage.
What is a protected computer?
A protected computer is defined very broadly under the CFAA. It includes essentially any computer used in or affecting interstate or foreign commerce — which, in practice, means nearly every internet-connected device, from a phone to a server.
What is the difference between without authorization and exceeds authorized access?
Accessing a computer without authorization describes an outside intruder with no right to be in the system. Exceeding authorized access describes an insider who is allowed into a system but reaches files or areas within it that are off-limits to them.
Does violating a website’s terms of service violate the CFAA?
Generally no, not by itself. After the Supreme Court’s decision in Van Buren, misusing information you were allowed to access — including by breaking a terms-of-service rule or a workplace policy — is not, standing alone, a federal CFAA crime.
What did the Van Buren decision change?
In Van Buren v. United States, the Supreme Court held that exceeding authorized access means entering off-limits areas of a computer, not misusing information you were entitled to access. The decision sharply narrowed how broadly the CFAA can be charged.
Is the CFAA only about hacking?
No. Although the CFAA was written to address hacking, prosecutors use it much more broadly — against departing employees, account misuse, and computer-based fraud schemes. The breadth of its use is a frequent point of contest.
What must the government prove in a CFAA case?
It depends on the subsection, but the government generally must prove access to a protected computer, that the access was without authorization or exceeded authorized access, the required intent, and — for some offenses — resulting damage or loss.
What penalties does a CFAA conviction carry?
Penalties range from a misdemeanor of up to one year to felonies carrying five, ten, or more years, depending on the offense, the intent behind the access, and the damage caused. Convictions also bring fines and often restitution.
Can I be charged for accessing my employer’s computer?
Possibly, but the scope of your authorization matters. After Van Buren, accessing files you were permitted to access is generally not a CFAA crime, even for an improper purpose. Reaching areas your credentials did not permit is a different question.
Is the CFAA a felony?
It can be either. Some CFAA offenses are misdemeanors, but most prosecutions involve felony provisions — particularly where the access was for financial gain, in furtherance of another crime, or caused damage.
What are the defenses to a CFAA charge?
Defenses include that the access was authorized, that any wrongdoing was a misuse of permitted access rather than an intrusion, the lack of the required intent, that the loss does not meet the statutory threshold, and that the loss has been inflated.
How much does an initial consultation cost?
Our initial consultation is a paid, one-hour session. You will leave with a clearer view of whether the charged conduct actually fits the CFAA, how the loss figure was built, and which defense paths are worth pursuing.
Is web scraping illegal under the CFAA?
Scraping data from pages open to the general public is likely not access without authorization under the CFAA — the Ninth Circuit reasoned in the hiQ Labs case that no gate exists to cross. Scraping behind passwords, around technical blocks, or after a cease-and-desist letter is a riskier question, and other laws can still apply.
Can security researchers be charged under the CFAA?
The Justice Department’s 2022 charging policy directs prosecutors to decline CFAA charges where the conduct was, and was intended as, good-faith security research carried out to avoid harm and to promote security. The policy is not a statutory defense, though, so researchers can still face investigation and should document their good faith carefully.
Is hacking a federal crime?
Yes. Breaking into a computer system without authorization is prosecuted federally under the CFAA, and the same conduct often draws wire fraud, identity theft, or trade secret charges. Penalties scale with the intent behind the intrusion and the harm it causes.
Can I be charged under the CFAA for logging into someone else’s email or social media account?
Accessing another person’s email, cloud storage, or social media account without permission can be charged under the CFAA, because you have no authorization to enter that account at all — the classic gates-down scenario. Cases like these often add wiretap, stored-communications, or identity-theft counts. The defense usually turns on whether access was truly unauthorized, what was obtained, and how any claimed loss is measured.
What is the statute of limitations for a CFAA charge?
Most federal CFAA prosecutions are governed by the general five-year statute of limitations for non-capital federal offenses under 18 U.S.C. Section 3282. The clock generally runs from the date of the unlawful access, though the analysis can be fact-specific where conduct is alleged to continue. The civil CFAA limitations period is separate and shorter, so the timing question should always be reviewed by counsel.

