Concept Page
Computer Fraud and Abuse Act 1986
The Computer Fraud and Abuse Act 1986 is a US law prohibiting unauthorized access to computers. It is significant in combating cybercrime. The law led to the conviction of hacker Kevin Mitnick.
The Computer Fraud and Abuse Act (CFAA), enacted on 26 October 1986 as Title 18, U.S.C. § 1030, is the United Statesâ primary federal statute criminalising unauthorised access to computer systems. Drafted in the wake of the 1983 âMorris wormâ incident, the law uniquely blends traditional concepts of trespass with the nascent digital environment, giving prosecutors a tool to pursue a wide spectrum of cyberâoffencesâfrom simple password cracking to largeâscale data exfiltration. Its breadth and the severity of its penaltiesâup to five yearsâ imprisonment for a firstâtime violation and up to ten years for offenses involving national security or financial institutionsâhave made the CFAA a cornerstone of American cyberâlaw enforcement and a frequent subject of scholarly debate. ## Origins / Historical Background The CFAA originated as an amendment to the 1979 Computer Fraud and Abuse Act, itself part of the broader Electronic Communications Privacy Act of 1986. Lawmakers responded to the rapid diffusion of personal computers and the 1988 âMorris wormâ that crippled roughly oneâthird of the nationâs ARPANETâconnected machines, prompting Congress to codify âunauthorised accessâ as a federal crime. The original text defined a âprotected computerâ as any computer used in or affecting interstate or foreign commerce, a definition later expanded in the 1994 and 1996 amendments to include any computer used by the federal government and, eventually, virtually every device connected to the Internet. ## Key Provisions Section 1030(a)(2) criminalises intentional access without authorizationâor exceeding authorised accessâto obtain information from any protected computer. Subsection (a)(4) targets fraud and related activity in connection with a protected computer, imposing penalties of up to ten years when the offense involves a financial institution or the United States government. The act also creates civil liability under 18 U.S.C. § 1030(g), allowing victims to sue for actual damages and injunctive relief. Penalties are calibrated by the nature of the target: violations involving a âprotected computerâ used in interstate commerce carry a maximum fine of $250,000 per count, while those affecting national security can trigger fines of up to $1 million. ## Enforcement Mechanism The Department of Justice, primarily through the Computer Crime and Intellectual Property Section (CCIPS), coordinates prosecutions, while the Federal Bureau of Investigation and the U.S. Secret Service conduct investigations and digital forensics. A typical case begins with a subpoena to the targetâs ISP for IP logs, followed by a forensic image of the suspectâs device to establish the âwithout authorizationâ element. Prosecutors must demonstrate that the defendant knowingly accessed a protected computer and either obtained information, caused damage exceeding $5,000, or transmitted a program that caused damage, as stipulated in 18 U.S.C. § 1030(a)(5). Convictions often hinge on the âexceeds authorised accessâ clause, a point of contention that has generated extensive appellate litigation. ## Notable Cases and Legal Evolution The 1995 conviction of Kevin Mitnick, who was sentenced to five years for hacking into corporate networks, marked the CFAAâs first highâprofile application and cemented its reputation as a deterrent. In 2009, United States v. Lori Drew invoked the act to pursue a civil claim against a teenager who created a fake MySpace profile, illustrating the statuteâs reach into online harassment. The 2013 prosecution of Aaron Swartz for massâdownloading academic articles sparked a public outcry over perceived overreach, leading to the 2015 âAaronâs Lawâ proposal that sought to narrow the âexceeds authorised accessâ language. The Supreme Courtâs 2021 decision in Van Buren v. United States clarified that the CFAA does not punish a user for violating a websiteâs terms of service, narrowing the scope of âexceeds authorised accessâ and prompting renewed calls for reform. ## Current Status, Controversies, and Reform Efforts As of 2024, the Department of Justice reports roughly 1,200 CFAA prosecutions annually, with a steady increase in cases involving ransomware and supplyâchain attacks on critical infrastructure. Criticsâincluding the Electronic Frontier Foundation and several congressional membersâargue that the actâs vague language enables selective prosecution and stifles legitimate security research. Legislative initiatives such as the âSAFE Computing Actâ (introduced in 2023) propose to replace the âexceeds authorised accessâ test with a clearer âunauthorised accessâ standard and to establish safeâharbor provisions for vulnerability disclosure. Meanwhile, the act remains a pivotal tool for agencies combating stateâsponsored cyberâespionage, as evidenced by the 2022 indictment