Federal Computer Fraud & Abuse Act

A dispute over computer access can take on a very different character once federal investigators become involved. What may have started with an employee account, shared credentials, downloaded business files, a compromised password, or alleged interference with a computer system can lead to examination of devices, login histories, server records, financial transactions, and communications. The legal question is not simply whether someone used a computer in a way another person or business opposed, but whether the conduct satisfies the requirements of a federal computer crime.

Scrivner Law Firm defends people facing federal criminal allegations in Taney County and throughout Southwest Missouri. Attorney Dayrell Scrivner brings decades of legal experience, including two decades as a prosecutor, to evaluating how federal investigators obtained and interpreted digital evidence, what access the accused person actually had, and whether the facts support the intent and conduct alleged by the government.

The principal federal statute in these cases is the Computer Fraud and Abuse Act, primarily codified at 18 U.S.C. § 1030. The CFAA addresses several different forms of conduct rather than one general offense of “hacking,” including unauthorized access to obtain information, computer-related fraud, intentional or reckless damage, certain trafficking in passwords or access credentials, and computer-related extortion. Identifying the particular subsection at issue is therefore an important first step in determining what federal prosecutors must prove.

The Federal Case Often Turns on Access Before It Turns on Technology

The central issue in many CFAA prosecutions is not whether a computer was used. The more difficult issue is whether the accused person accessed the relevant computer or information without authorization, or exceeded access that had actually been granted.

Under 18 U.S.C. § 1030(e), a “protected computer” includes computers used by or for the federal government or a financial institution, as well as computers used in or affecting interstate or foreign commerce or communication. Because internet-connected computers ordinarily operate through interstate communications, the federal definition can reach far beyond government systems and major corporate networks.

That broad federal nexus does not eliminate the government’s burden on authorization. Password possession, prior employment, shared accounts, administrator rights, remote-access software, vendor relationships, and informal workplace practices can create factual disputes over what access was permitted at the time of the alleged conduct.

A defense should therefore identify who granted access, what restrictions existed, whether access had been revoked, what the accused knew about those restrictions, and which files, folders, accounts, databases, or systems were allegedly off-limits.

Section 1030 Covers Several Different Types of Computer Conduct

A CFAA charge should be analyzed by subsection rather than by the general label “computer fraud.”

18 U.S.C. § 1030(a)(2) addresses intentionally accessing a computer without authorization or exceeding authorized access and thereby obtaining certain financial information, information from a federal department or agency, or information from a protected computer.

18 U.S.C. § 1030(a)(3) applies to certain unauthorized access to nonpublic computers used by or for the United States government.

18 U.S.C. § 1030(a)(4) combines computer access with fraud. It applies when a person knowingly and with intent to defraud accesses a protected computer without authorization or exceeds authorized access, furthers an intended fraud through that conduct, and obtains something of value, subject to a limited statutory exception.

18 U.S.C. § 1030(a)(5) addresses computer damage. The statute distinguishes among knowingly transmitting a program, information, code, or command that intentionally causes unauthorized damage; unauthorized access that recklessly causes damage; and unauthorized access that causes damage and loss.

18 U.S.C. § 1030(a)(6) concerns trafficking in passwords or similar access information with intent to defraud when the statutory federal-commerce or government-computer requirements are met.

18 U.S.C. § 1030(a)(7) addresses certain interstate or foreign communications made with intent to extort money or another thing of value through threats involving computer damage, unauthorized acquisition of information, impairment of confidentiality, or demands connected to damage caused to facilitate extortion.

Section 1030(b) separately makes attempts and conspiracies punishable. The government therefore does not always need to claim that the intended computer offense was completed.

One of the most important limits on the CFAA comes from the United States Supreme Court’s decision in Van Buren v. United States. The Court rejected a reading that would turn ordinary misuse of information into a CFAA offense merely because a person accessed information for an improper reason.

Under Van Buren, a person who has authorization to use a computer “exceeds authorized access” when the person uses that access to obtain or alter information located in areas of the computer that are off-limits to that person. The focus is on whether the person was entitled to obtain or alter the information through the access used, not simply on whether an employer, website, or organization disapproved of the person’s purpose.

This distinction can be crucial for employees, contractors, business partners, account holders, IT personnel, and others who had legitimate credentials. Violating a workplace rule, confidentiality policy, or permitted-use policy is not automatically the same as accessing a prohibited part of a computer system.

Digital Evidence Must Connect the Accused to the Alleged Access

Federal computer investigations can generate extensive technical evidence. Investigators may examine IP addresses, login histories, authentication records, cloud records, device identifiers, timestamps, deleted files, messages, financial transfers, server logs, password-reset records, and forensic images of seized devices.

A login or IP address does not necessarily resolve who performed the act. Shared devices, credentials, remote administration, automated processes, compromised accounts, and multi-user networks can complicate attribution.

The sequence of events also matters. Access may have been authorized and later revoked. A user may have entered a general system but not a restricted directory. A program may also have caused an interruption without proof that the user intended damage.

A CFAA defense may therefore require the legal theory and forensic evidence to be tested together rather than treating technical conclusions as self-proving.

Damage, Loss, and Financial Purpose Can Change the Exposure

The CFAA defines “damage” as impairment to the integrity or availability of data, a program, a system, or information. It separately defines “loss” to include reasonable costs of responding to an offense, assessing damage, restoring data or systems, and certain revenue losses or consequential damages caused by interruption of service.

Those definitions can matter when prosecutors rely on § 1030(a)(5) or seek enhanced felony treatment. The statute considers circumstances including whether loss reaches $5,000 in a one-year period, medical care was affected, physical injury occurred, public health or safety was threatened, certain government computers were affected, or damage reached at least ten protected computers.

Loss calculations should not automatically be accepted at face value. A company may include incident-response expenses, consultant fees, employee time, restoration work, security improvements, or claimed business interruption. The defense can examine whether those amounts were actually caused by the alleged offense and fit the statutory definition.

Financial purpose also matters under § 1030(a)(2). An offense that otherwise carries misdemeanor exposure can become a felony when, among other circumstances, it is committed for commercial advantage or private financial gain, in furtherance of another criminal or tortious act, or when the value of the information obtained exceeds $5,000.

A CFAA Count May Be Only One Part of a Federal Indictment

Computer allegations frequently overlap with other federal statutes. Depending on the facts, prosecutors may consider 18 U.S.C. § 1343 for wire fraud, 18 U.S.C. § 1029 for access-device fraud, 18 U.S.C. §§ 1028 or 1028A for identity-related offenses, or 18 U.S.C. § 1832 for theft of trade secrets.

An allegation that someone entered an account without authorization may be paired with a claim that the access was used to divert money, obtain credentials, steal proprietary data, impersonate another person, or assist a larger fraud scheme.

That makes count-by-count analysis important. The government must prove the elements of each charged offense, and a weakness affecting one theory may not operate the same way against another. Search warrants, device seizures, subpoenas, cooperating witnesses, and the admissibility of digital records may also affect several counts at once.

Missouri Computer-Tampering Laws Can Apply to Similar Conduct

Federal jurisdiction does not necessarily exclude Missouri law. Conduct investigated under the CFAA may also fit state computer statutes.

RSMo 569.095 addresses tampering with computer data. Among other acts, it applies to certain unauthorized modification, destruction, taking, or disclosure of data or programs; taking or disclosing passwords and other access information; intentionally examining information about another person through unauthorized access; and receiving, retaining, using, or disclosing data known or believed to have been obtained in violation of the statute. The offense is generally a class A misdemeanor, but it can become a class E felony when committed to carry out a scheme to defraud or obtain property valued at $750 or more.

RSMo 569.097 addresses tampering with computer equipment, including certain unauthorized damage, destruction, modification, or taking of computers, systems, networks, equipment, or data-storage devices. The classification can increase when the conduct is connected to a fraud scheme or when damage reaches statutory thresholds.

RSMo 569.099 addresses tampering with computer users. It covers certain knowing unauthorized access to a computer, computer system, or network, as well as denying computer services to an authorized user. It is generally a class A misdemeanor and can become a class E felony when committed to execute a fraud scheme or obtain property valued at $750 or more.

Missouri also permits certain civil claims for computer tampering under RSMo 537.525.

Penalties Depend on the Particular CFAA Theory

There is no single sentence for a CFAA conviction. Federal punishment depends on the subsection, criminal history, purpose of the access, value involved, degree of damage or loss, number and type of affected computers, and whether injury or other aggravating harm occurred.

Some first offenses under § 1030 can be misdemeanors carrying up to one year of imprisonment. Other provisions authorize felony sentences of up to five or ten years. Repeat offenses and serious damage cases can carry greater statutory maximums. Conduct under § 1030(a)(5) that knowingly or recklessly causes serious bodily injury can expose a defendant to up to twenty years, while conduct resulting in death can carry punishment up to life imprisonment when the statutory requirements are satisfied.

A federal conviction may also involve fines, restitution, forfeiture issues, supervised release, and collateral consequences affecting employment, professional licensing, security-sensitive work, business relationships, and future access to computer systems.

Building a Defense Around the Government’s Actual Theory

A strong defense does not begin with a generic argument that no “hacking” occurred. It begins with the precise subsection charged and the digital path the government says proves the offense.

Authorization records may show that the accused had broader access than investigators assumed. System architecture may show that allegedly restricted information was available through ordinary permissions. Forensic evidence may fail to identify who used a device or account. The government may be unable to prove fraudulent intent, intentional damage, knowledge of a restriction, or the required connection between the accused person and a transmission or command. Claimed loss may include expenses that do not qualify under the statute. Evidence may also be challenged when obtained through an unlawful search or when the government cannot establish the necessary foundation for technical records.

Because federal cases often develop before an indictment, statements during an interview, consent to search a device, preservation of business records, and communications with employers or alleged victims can affect the case before formal charges appear.

Speak With Scrivner Law Firm About a Federal Computer Crime Investigation

A federal computer crime investigation can develop quickly once agents begin obtaining account records, examining devices, reviewing server activity, or interviewing people connected to the alleged access. Whether the investigation involves unauthorized access, computer fraud, data theft, system damage, or another alleged violation of the Computer Fraud and Abuse Act, getting defense counsel involved early can provide an opportunity to evaluate the government’s theory, preserve relevant evidence, and address important questions about authorization, intent, and who was responsible for the activity.

Attorney Dayrell Scrivner brings experience as both a former prosecutor and criminal defense lawyer to federal criminal cases. If you have received a target letter or subpoena, have been contacted by federal investigators, or have been charged under 18 U.S.C. § 1030, contact Scrivner Law Firm through the online contact form to discuss the allegations, the potential consequences, and the options available for your defense.

CLIENT REVIEWS

Scrivner Law is amazing. They helped and answered every single question my wife and I had. They gave us advise on other cases as well. They are always so very easy to get...

Nicholas Missouri

Dayrell is easy to connect with and you can tell that he enjoys what he does! He seems truly invested in his clients and helped me understand soo many things. When you...

Casey Missouri

Very happy with all the help that Scrivner Law firm did for our case.Super nice. Explained all the steps of our case until it was finished.While we were on vacation we...

S S Missouri

OUR ADDRESS

Please note that our law firm's address is for mail correspondence only. We do not accept in-office visits to this location. To schedule an appointment or consult with an attorney, please contact us via phone or email. Our contact information is readily available on our website. We look forward to hearing from you and strive to supply efficient and accessible legal services to our clients.

Branson Office
1440 State Hwy 248
Ste Q, #451

Branson, MO 65616

Phone: (417) 699-0074 Fax: (417) 429-2159

CONTACT US

Fill out the contact form or call us at (417) 699-0074 
to schedule your consultation.

LEAVE US A MESSAGE