The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. §1030, is the primary federal statute used to prosecute computer crimes. Originally enacted in 1986 to address hacking of government and financial institution computers, the CFAA has been amended repeatedly and now covers a broad range of conduct involving unauthorized access to computers and networks. Federal prosecutors in the Northern District of Texas use the CFAA to prosecute cases ranging from large-scale data breaches and ransomware attacks to insider threats, corporate espionage, and even disputes over computer access between employers and former employees.

At Deandra Grant Law, Attorney James Lee Bright leads our defense in federal computer crime cases. Lee’s 25+ years of federal experience include handling cases involving complex technical evidence and multi-agency investigations.

Key CFAA ProvisionsHow Federal Computer Crime Charges Work Under the CFAA

  • 1030(a)(2) — Unauthorized Access to Obtain Information. Covers intentionally accessing a computer without authorization or exceeding authorized access and obtaining information from any protected computer. Misdemeanor for first offense; felony for aggravating factors. Maximum 5 years (first offense) to 10 years (subsequent).
  • 1030(a)(4) — Computer Fraud. Covers knowingly accessing a protected computer without authorization with intent to defraud and obtaining anything of value. Maximum 5 years (first offense), 10 years (subsequent).
  • 1030(a)(5) — Damaging a Computer. Covers knowingly causing the transmission of code or commands that intentionally cause damage to a protected computer. Covers malware, ransomware, DDoS attacks, and data destruction. Maximum 10 years (first offense), 20 years (subsequent).
  • 1030(a)(6) — Trafficking in Passwords. Covers trafficking in passwords or similar access information affecting interstate commerce or government computers. Maximum 10 years.
  • 1030(a)(7) — Extortion Involving Computers. Covers threatening to damage a computer or obtain/release information to extort something of value. Maximum 5 years. Used in ransomware cases.

The “Authorization” Question

The central legal issue in most CFAA cases is what constitutes “authorization” and when a person “exceeds authorized access.” The Supreme Court addressed this question in Van Buren v. United States (2021), holding that a person “exceeds authorized access” only when they access areas of a computer system they are not entitled to access — not when they access permitted areas for improper purposes. This decision narrowed the CFAA significantly and provides an important defense in cases where the defendant had some legitimate access to the computer system.

Lee evaluates every CFAA case against the Van Buren framework to determine whether the government’s theory of unauthorized access is legally valid or overreaches beyond what the statute actually prohibits.

How We Challenge the Government’s Evidence

Attribution

The government must prove that the defendant was the person who accessed the computer system. In cases involving remote access, this requires linking IP addresses, login credentials, and device identifiers to the specific defendant. Our forensic team evaluates whether this attribution is supported by reliable technical evidence or relies on assumptions that can be challenged.

Digital Forensic Methodology

We evaluate whether the government’s forensic examiners followed accepted protocols for evidence collection, preservation, and analysis. Were devices properly write-blocked? Were forensic images verified? Were logs and artifacts properly interpreted? Were alternative explanations (shared accounts, compromised credentials, malware) adequately investigated?

Damage and Loss Calculations

CFAA sentencing is heavily influenced by the amount of loss or damage. The government often inflates loss figures by including incident response costs, system remediation, and business interruption losses. Lee works with technical experts to independently assess the actual damage caused and challenge inflated calculations.

Intent

Most CFAA offenses require proof of specific intent — intent to defraud, intent to cause damage, or knowing conduct. Accidental access, authorized testing, security research, and good-faith disputes about the scope of access all raise intent defenses that Lee evaluates in every case.

Contact Deandra Grant Law

If you are under investigation or have been charged with a federal offense, contact Deandra Grant Law for a free, confidential consultation with Attorney James Lee Bright. Lee has more than 25 years of federal trial experience and is admitted to practice in all four federal districts in Texas, the District of Columbia, the Fifth Circuit Court of Appeals, and the United States Supreme Court.

Call us at (214) 225-7117 or schedule a free consultation at texasdwisite.com/schedule-consultation/. Se habla español: (972) 347-8833.

The defense is ready.

Firm Accolades

blue-seal-293-61-bbb-91827042

Better Business Bureaus

D_Best_2025

D Magazine

MTLFeaturedInGold

acs-chal-e1541617212660

AAFS-Logo-54a9dcbcv1_site_icon

2018-11-07-e1541617171504

avvo1

28000080_cl_badge-300×276

28000080_pi_badge-300×276

Deandra Grant - Best Lawyers 2026

DUIDLA-BadAss-Award

bestd-e1542223498668

dg-aal

deandra_justia-removebg-preview-300×236

deandrabadge-removebg-preview.002-300×295

dui-defense-e1541617116937

Expertise-DUI-2022_copia-300×240

Round_Rock-300×240

tx_allen_dui-attorney_2020_copia-300×240

asdef

Deandra_Grant-removebg-preview-300×78

NORML.svg_-e1541616977296

top-fort-300×106

AAEAAQAAAAAAAAdSAAAAJGQwNDc1NmY2LTQxYTItNGFkNS1hMGUxLWRmNGRlYWRkMjI0Yg-300×93

SuperLawyers_gold