
The Computer Fraud and Abuse Act can turn routine computer use into federal criminal charges if you're not careful. Accessing a work computer after termination, sharing login credentials, or downloading files without explicit permission may trigger federal prosecution. In fact, many LA residents face CFAA charges without realizing their actions violated federal law. These charges carry serious penalties, including prison time, substantial fines, and lasting impacts on your career. Understanding what constitutes a CFAA violation, how federal prosecutors build their cases, and available defense strategies is essential for protecting your rights and future.
Congress passed this federal statute in 1986 as an amendment to existing computer fraud legislation that proved insufficient for addressing emerging cybersecurity threats. The Computer Fraud and Abuse Act serves as the primary tool federal prosecutors use when charging cybercrimes, though the word "hacking" never appears in its provisions. Instead, the law criminalizes several categories of conduct involving unauthorized access to computers.
The statute underwent significant expansion since its original passage. Congress added a civil cause of action in 1994, allowing private parties to seek compensatory damages and injunctive relief for CFAA violations. Further amendments in 1996 introduced computer extortion provisions and felony enhancements. The USA Patriot Act expanded the definition of protected computers in 2001 to include those located outside the United States. The most recent expansion came in 2008, broadening extortion provisions to cover threats involving data theft and disclosure.
The law criminalizes seven distinct types of conduct under 18 U.S.C. § 1030(a). These provisions target unauthorized access to protected computers, obtaining information from financial institutions or government agencies, computer fraud schemes, causing damage to computer systems, password trafficking, and extortion attempts. Both the commission of these acts and conspiracy or attempts to commit them face prosecution.
California maintains its own computer crime statutes under Penal Code Section 502, which addresses similar conduct at the state level. The key distinction lies in jurisdiction. Federal prosecutors handle CFAA cases when they involve protected computers or interstate commerce elements. State prosecutors pursue violations that remain within California's borders without federal interest.
The CFAA's grounding in the commerce power means federal jurisdiction extends far beyond what the statute's original intent suggested. This creates overlap with state laws, allowing both federal and state charges for the same conduct in some situations. Federal cases typically involve more severe penalties and resources compared to state prosecutions.
Federal jurisdiction triggers when conduct targets "protected computers." The statute defines these as computers exclusively used by financial institutions or the United States Government, or those used in or affecting interstate or foreign commerce. Courts, including the Supreme Court, interpret "affecting interstate or foreign commerce" to include any computer connected to the internet.
This broad interpretation means most modern computing devices fall under CFAA protection. Laptops, desktops, smartphones, and even Internet of Things devices like smart appliances and fitness trackers qualify as protected computers. Web servers storing website data also meet this definition. One court concluded that social media platform servers holding member data constitute protected computers.
The statute's expansive reach creates a situation where virtually any internet-connected device triggers federal jurisdiction. This explains why routine activities like accessing a former employer's system or violating website terms of service can result in federal charges. The commerce power foundation allows federal prosecutors to claim jurisdiction over conduct that might seem purely local in nature.
Certain CFAA provisions employ different jurisdictional approaches. Section 1030(a)(7), which addresses extortion threats, requires proof that the defendant transmitted the threat in interstate or foreign commerce rather than focusing solely on whether the targeted computer affects commerce. Threats crossing state borders satisfy this requirement.
One mistake shouldn't define your future
contact our defense team.



Federal prosecutors charge CFAA violations across several distinct categories, each targeting specific forms of computer-related misconduct. Understanding these prosecuted offenses reveals how broad the statute's reach extends into both obvious cybercrimes and seemingly routine digital activities.
Section 1030(a)(2) criminalizes intentionally accessing a computer without authorization or exceeding authorized access to obtain information. This provision applies to financial records, government data, and information from any protected computer. Prosecutors use this section frequently because it covers such varied conduct. Accessing a competitor's database without permission violates this provision. So does an employee viewing files outside their job responsibilities.
The penalty structure depends on the circumstances. Basic violations carry a maximum one-year prison sentence. However, prosecutors can pursue enhanced penalties up to ten years when the offense involves commercial advantage, private financial gain, or information valued over $5,000.
Password trafficking under Section 1030(a)(6) prohibits knowingly trafficking in passwords or similar information that allows unauthorized computer access. The statute defines trafficking broadly to include selling, distributing, or otherwise making passwords available to unauthorized individuals. This provision targets those who facilitate access for others rather than the end users themselves.
The offense requires proof that such trafficking affects interstate or foreign commerce or involves government computers. First-time offenders face up to one year imprisonment, while repeat violations carry penalties up to ten years.
Section 1030(a)(4) addresses accessing protected computers with intent to defraud and obtaining anything of value. Prosecutors must prove the defendant knowingly accessed the system without authorization or exceeded authorized access to further fraud. Ransomware attacks frequently fall under this provision when attackers encrypt systems and demand payment.
Extortion charges under Section 1030(a)(7) cover threats to damage protected computers or obtain information without authorization. The 2008 amendments expanded this section beyond explicit damage threats to include threats involving data theft, public disclosure of stolen data, or refusing to repair damage already caused. These provisions carry five to ten years imprisonment.
Section 1030(a)(5) establishes three levels of damage offenses based on mental state. Intentionally causing damage by knowingly transmitting code carries one to ten years, or up to twenty years for repeat offenses. This covers deliberate virus transmission and malware deployment. Recklessly causing damage through intentional access results in one to five years imprisonment. Even negligently causing damage by intentional access qualifies as a federal offense with up to one year imprisonment.
Ransomware prosecutions rely heavily on these damage provisions. Federal prosecutors charged defendants who deployed ransomware against hospitals and municipalities under Section 1030(a)(5), alleging they intentionally transmitted malicious code causing system damage.
The Supreme Court's 2021 decision in Van Buren v. United States fundamentally changed how prosecutors approach information theft cases. The Court held that exceeding authorized access occurs only when someone accesses computer areas to which their authorization does not extend, not when they misuse information they're authorized to access. An individual accesses files, folders, or databases beyond their permitted areas violates the statute. Using authorized information for improper purposes does not.
This narrow interpretation prevents prosecutors from charging employees who access information within their authorization but use it improperly. A departing employee downloading trade secrets they could legitimately access no longer faces CFAA liability under the exceeding authorized access theory.
CFAA violations create both civil and criminal exposure, with penalties structured around the specific conduct, data value involved, and whether the actions caused measurable damage. Federal judges impose sentences based on complex guidelines that consider offense characteristics and criminal history, though these recommendations are not binding.
Basic trespassing violations carry relatively modest sentences. Accessing government computers without authorization results in up to one year imprisonment for first offenses. Password trafficking violations follow similar sentencing patterns with maximum one-year terms. Negligently causing damage through intentional access also falls within this one-year range.
More serious offenses trigger substantially longer terms. Accessing computers to defraud and obtain value carries up to five years imprisonment. Computer extortion schemes result in the same five-year maximum. National security information theft can lead to ten years imprisonment even for first-time offenders.
Intentional damage provisions vary based on harm severity. Knowingly transmitting harmful code like viruses carries one to ten years depending on circumstances. Recklessly damaging systems through intentional access results in one to five years. These ranges expand significantly when violations affect critical infrastructure, financial institutions, or government systems.
Subsequent offenses typically double the maximum sentence. A second conviction for password trafficking increases penalties from one year to ten years. By the same token, repeat offenses involving national security information jump from ten to twenty years. Computer extortion cases escalate from five years to ten years for second convictions.
The statute authorizes substantial financial penalties beyond imprisonment. Courts impose fines under general federal sentencing provisions, which can reach $250,000 for individuals. Organizations face even higher fines, potentially reaching $500,000. Moreover, judges order restitution to compensate victims for actual losses, including investigation costs and damage assessment expenses.
Civil liability adds another layer of financial exposure. Victims who suffer damage or loss can file lawsuits seeking compensatory damages and injunctive relief. Regulatory consequences prove significant when violations affect financial institutions, healthcare systems, or government networks.
Federal convictions appear on background checks conducted by commercial screening companies and government agencies. Records from federal court cases become part of national databases that employers access during hiring processes. Healthcare, education, childcare, financial services, and government positions maintain the strictest screening practices.
Professional licensing boards review federal convictions independently using fingerprint-based systems connected to federal databases. Nurses, teachers, electricians, and real estate agents face discipline, application denials, or conditional licensing based on their criminal history. Boards evaluate the offense type, timing, patterns of conduct, and relevance to professional duties when making decisions.
Federal prosecutors rely on sophisticated investigative techniques when building Computer Fraud and Abuse Act cases. These investigations demand technical expertise, inter-agency coordination, and careful adherence to prosecutorial policies that govern charging decisions.
Computer fraud prosecutions depend heavily on digital evidence including server logs, email records, network traffic data, and forensic analysis of storage devices. Digital forensics experts examine server logs, network traffic, malware samples, and compromised data to reconstruct how violations occurred. This evidence is often highly technical and requires expert testimony to explain to judges and juries.
Server and network logs document access times, IP addresses, and user identifiers to establish unauthorized access patterns. Email communications may demonstrate intent, authorization discussions, or knowledge of system access restrictions. Forensic analysis identifies malware, unauthorized software, or evidence of system manipulation. System configuration records establish security settings and authorization protocols in effect during alleged offenses.
Chain of custody issues, improper search procedures, or violations of Fourth Amendment protections may render digital evidence inadmissible. Qualified digital forensics experts can challenge the government's technical conclusions and identify alternative explanations for digital evidence. Defense investigation must also examine whether the government properly obtained and preserved digital evidence according to established protocols.
The National Cyber Investigative Joint Task Force coordinates federal CFAA investigations through a network of over 30 partnering agencies from across law enforcement, the intelligence community, and the Department of Defense. Victims of CFAA violations often work with the FBI, the Secret Service, and private cybersecurity firms to investigate breaches and implement remedial measures.
Cases under the CFAA are often complex, and analysis of whether a particular investigation or prosecution is consistent with charging policy requires a nuanced understanding of technology, the sensitivity of information involved, tools for lawful evidence gathering, national and international coordination issues, and victim concerns. Prosecutors must confer with the Computer Crime and Intellectual Property Section of the Criminal Division prior to charging under the CFAA.
Defending against Computer Fraud and Abuse Act charges requires examining authorization boundaries, intent elements, and technical evidence. Defense attorneys challenge prosecutorial interpretations and leverage recent legal developments that narrow the statute's application.
The Department of Justice clarified its charging policy to require computational restrictions rather than contractual limitations when proving "exceeds authorized access". Prosecutors must demonstrate that protected computers are divided through computer code or configuration, not merely through employment policies or terms of service agreements. This policy shift prevents charges based solely on workplace rule violations or website terms breaches.
The Supreme Court's Van Buren decision confirmed that using systems for improper purposes does not automatically constitute exceeding authorization when legitimate access exists. Courts struggled for years with how to handle authorized users who misuse information. Defense teams focus on reconstructing system behavior and identifying ambiguous permissions that contradict investigative assumptions.
Authorization defenses examine whether defendants believed they had legitimate access based on employment agreements, usage policies, and workplace practices. System permissions that did not technically restrict accessed files or areas support authorization claims. Defense attorneys analyze credential issuance patterns, sharing practices, and communication histories to demonstrate good-faith beliefs about access rights.
The CFAA generally requires intentional conduct. Accidental access or actions resulting from misunderstandings about permission boundaries may not satisfy intent requirements. Prosecutors must prove defendants knew facts making their access unauthorized. The attorney for the government should decline prosecution if evidence shows the defendant's conduct consisted of good-faith security research.
Expert witnesses critically evaluate prosecution evidence by questioning digital forensics methodology, chain of custody, and data integrity. Defense experts decode system behavior to identify cases where automated processes mimic unauthorized access. These specialists interpret financial data and technical evidence, offering alternative explanations that challenge prosecution narratives.
Over 90 percent of criminal cases resolve through plea bargaining rather than trial. Defendants typically receive lighter sentences by accepting pleas compared to trial convictions. Federal plea agreements involve charge bargaining and sentencing agreements, with Rule 11(c)(1)(C) pleas allowing binding sentence arrangements.
The Computer Fraud and Abuse Act affects far more than traditional hackers. Seemingly routine activities like accessing work systems after termination or sharing login credentials can trigger federal prosecution with severe consequences. Given these points, understanding where authorization boundaries lie and what constitutes a violation is critical for LA residents in our increasingly digital world.
Recent court decisions have narrowed some prosecutorial theories, particularly around exceeding authorized access. Nonetheless, federal prosecutors continue pursuing CFAA cases aggressively. Strong defense strategies exist, but they require technical expertise and knowledge of recent legal developments.
When facing CFAA charges, experienced legal representation makes the difference between conviction and successful defense of your rights and future.


Don't face
the prosecutor alone
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed sed augue mauris. Integer placerat et massa in pharetra. Cras diam mi, tincidunt nec erat in, mollis sagittis sapien. Quisque ultrices id diam quis dapibus. Nullam ac erat ac justo convallis fringilla nec ut purus. Vivamus volutpat orci et lacus tempus fringilla. Morbi sed erat vel nisi blandit placerat eget eget sapien.
Nulla eget tristique leo. Proin dignissim tellus nec risus congue fringilla. Donec interdum purus sem, a finibus ante efficitur ornare. Quisque ullamcorper pharetra lacus, vitae pharetra magna pretium vel. Donec aliquet purus sed pellentesque mollis. Pellentesque vestibulum eget massa in facilisis. Phasellus eu risus non metus consectetur facilisis. Interdum et malesuada fames ac ante ipsum primis in faucibus. In vitae fermentum enim, in vulputate diam. Aliquam malesuada urna suscipit, elementum sapien ac, posuere nisl.
Integer malesuada leo quis erat imperdiet aliquet. Aliquam ut eros vulputate, pharetra nulla quis, bibendum justo. Suspendisse justo leo, efficitur vel ex nec, fermentum condimentum dui. Suspendisse ut massa sit amet ligula mattis viverra. Sed sed turpis ligula. In vulputate, enim sit amet laoreet blandit, elit nisl fermentum odio, nec convallis libero dolor nec tellus. Donec rutrum nibh non nibh tincidunt, non iaculis diam dignissim. Sed nec massa pellentesque, gravida sem id, lobortis nisi. Integer turpis metus, sagittis vitae metus vel, feugiat congue nibh.
Vestibulum sed arcu eleifend ipsum eleifend semper nec sed est. Nam dapibus massa ut scelerisque egestas. Integer at elit faucibus elit molestie luctus. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Curabitur nulla neque, rhoncus sit amet ultricies ac, sagittis ac nibh. Praesent mattis ultricies nisi vitae efficitur. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nunc ullamcorper non est vitae faucibus. Duis pellentesque magna fermentum leo molestie, et dapibus diam dictum. Vivamus eu purus ullamcorper, consequat diam quis, blandit eros. Cras ultrices finibus metus, eget tempor sem euismod quis. Interdum et malesuada fames ac ante ipsum primis in faucibus.
Class aptent taciti sociosqu ad litora torquent per conubia nostra, per inceptos himenaeos. Fusce hendrerit arcu vel nisi bibendum, nec accumsan nunc sollicitudin. Mauris eu pretium ante, at rhoncus metus. Nunc dignissim turpis vel libero commodo imperdiet. Vestibulum ante ipsum primis in faucibus orci luctus et ultrices posuere cubilia curae; Donec gravida arcu eu turpis lobortis, vitae bibendum lectus egestas. Phasellus gravida eleifend ligula, eu sagittis diam rhoncus ut. Suspendisse fringilla ipsum eu purus tincidunt ornare. Vestibulum tincidunt enim eu ante mattis interdum. Integer molestie, est quis tincidunt dapibus, ex diam ultrices enim, nec vestibulum lectus orci non elit. Etiam vestibulum justo erat, ut vulputate urna dapibus vitae. Fusce ultrices lacus ac eros scelerisque, non malesuada neque ultrices. In pretium mi sed eros pharetra, eu molestie felis consectetur.
This page was reviewed and approved by William S. Kroger, a leading criminal defense attorney in Los Angeles. Mr. Kroger has decades of experience defending clients in both state and federal courts. He is recognized for his strong trial skills and dedication to protecting the rights of the accused. Throughout his career, he has successfully represented clients facing a wide range of serious criminal charges. His personalized defense strategies are designed to achieve the best possible outcome in every case. Clients trust Mr. Kroger for his knowledge, commitment, and proven results.
He is also an active member of respected legal organizations, including the American Bar Association and the National Association for Criminal Defense Lawyers. With his expertise and reputation, William S. Kroger is regarded as one of California’s top defense lawyers.