Skip to content

Generated Source Mirror

This page is generated from the source Markdown file so it can be viewed inside the MkDocs site.

📝 Page Status: Draft — sourced but not yet reviewed

  • Status: draft
  • Sources: 3
  • Relationships: 4
  • Research debt items: 4

Computer Fraud and Abuse Act (18 U.S.C. § 1030)

Summary

The Computer Fraud and Abuse Act (CFAA) is the primary U.S. federal criminal statute addressing unauthorized computer access. Originally enacted in 1984 and substantially expanded in 1986, it has been amended multiple times and remains controversial for its broad language and potential for prosecutorial overreach.

Official Sources

Legislative History

Year Action Significance
1984 Original enactment (Comprehensive Crime Control Act) Created 18 U.S.C. § 1030 targeting unauthorized access to government and financial computers
1986 Computer Fraud and Abuse Act Major expansion: added computer vandalism, unauthorized access offenses, broadened scope beyond federal computers
1989 Amendment Technical corrections
1994 Amendment Added civil cause of action, expanded to cover interstate computer crime
1996 National Information Infrastructure Protection Act Expanded "protected computer" definition, increased penalties
2001 USA PATRIOT Act Expanded scope for terrorism-related offenses, increased penalties, broadened definitions
2002 Cyber Security Enhancement Act Increased maximum penalties
2008 Identity Theft Enforcement and Restitution Act Further expanded scope and penalties

Key Provisions

  • § 1030(a)(1): Unauthorized access to classified information via computer
  • § 1030(a)(2): Obtaining information from protected computers without authorization or exceeding authorized access
  • § 1030(a)(3): Unauthorized access to government computers
  • § 1030(a)(4): Computer fraud (accessing to defraud and obtain value)
  • § 1030(a)(5): Causing damage to protected computers (malware, DoS)
  • § 1030(a)(6): Trafficking in passwords
  • § 1030(a)(7): Extortion involving computers

Proposed Reforms

Aaron's Law (not enacted)

Introduced by Rep. Zoe Lofgren and Sen. Ron Wyden (with Sen. Rand Paul), Aaron's Law would: - Delete the vague phrase "exceeds authorized access" - Clarify the definition of "access without authorization" - Prevent stacking of charges for the same underlying conduct - Distinguish common internet activity from harmful cyberattacks

Named after Aaron Swartz, who faced up to 35 years under the CFAA for downloading academic articles.

Interpreting Cases

  • Van Buren v. United States (2021): Supreme Court narrowed "exceeds authorized access" to a gates-up-or-down inquiry — does not cover policy-violating use of systems one is authorized to access.
  • United States v. Nosal (9th Cir.): Addressed employee access violations.
  • hiQ Labs v. LinkedIn (9th Cir.): Addressed whether scraping public data violates the CFAA.

Criticism

The CFAA has been widely criticized for: - Vague definitions that criminalize common internet behavior - Enabling prosecutorial overreach (stacking charges for exponentially higher penalties) - Chilling security research by making vulnerability testing legally risky - Being used to threaten terms-of-service violations as federal crimes - The case of Aaron Swartz highlighted these concerns and inspired reform efforts

Relevance to Open Source and Software Companies

The CFAA directly affects: - Security researchers conducting vulnerability testing - Developers building web scrapers or API clients - Companies with terms of service that users might technically "exceed" - Open source contributors accessing codebases - The Van Buren decision (2021) significantly narrowed the statute's scope, providing more certainty for developers

Relationships

Sources

Research Debt

  • Add hiQ Labs v. LinkedIn and United States v. Nosal case pages.
  • Document the Aaron Swartz case in detail.
  • Add CRS Report on CFAA as a source.
  • Review per-fact footnote-to-source mapping; multiple sources are cited on this page.

Document metadata

  • Enactment date: 1984
  • Last verified: 2026-06-25