Federal Defense · Cybercrime

Federal Computer Crime & CFAA Defense

Deandra M. Grant
Reviewed by Deandra M. Grant, JD, GC, MS, ACS-CHAL Forensic Lawyer-Scientist
Updated July 29, 2026
Read time 10 min
The Short Answer

The Computer Fraud and Abuse Act criminalises accessing a computer without authorisation or exceeding authorized access. In 2021 the Supreme Court held in Van Buren that "exceeds authorized access" means entering areas of a system you are not entitled to enter — not misusing information you were entitled to obtain. That narrowed the statute dramatically.

For two decades the CFAA was read so broadly that violating a website's terms of service was arguably a federal crime. Employees who took customer lists, researchers who scraped public data, and people who shared passwords all faced exposure.

Van Buren ended the broadest version of that theory, and a great many charging decisions made before 2021 would not be made today.

The structure of the CFAA

18 U.S.C. § 1030 is not one offense but several, and the penalty depends entirely on which subsection is charged:

§ 1030(a)(2) — obtaining information from a protected computer. A misdemeanour on a first offense unless aggravating factors apply, in which case 5 years.
§ 1030(a)(4) — access with intent to defraud, obtaining anything of value. Up to 5 years.
§ 1030(a)(5) — damage: transmitting code causing damage, or accessing and causing damage. Up to 10 years, more with serious harm.
§ 1030(a)(7) — extortion involving threats to damage a computer or release data. Up to 5 years. The ransomware provision.
§ 1030(a)(1) — national security information. Up to 10 years.

"Protected computer" is defined so broadly — any computer used in or affecting interstate commerce — that it covers essentially every internet-connected device.

Van Buren: the decision that changed everything

A police sergeant ran a license plate search on a law enforcement database in exchange for money. He was authorized to use the database — just not for that purpose. The government charged him with exceeding authorized access.

In Van Buren v. United States, 593 U.S. 374 (2021), the Supreme Court reversed. It adopted a gates-up-or-down reading: "exceeds authorized access" covers accessing areas of a computer — files, folders, databases — that are off limits to you. It does not cover obtaining information you were entitled to obtain and then using it for an improper purpose.

The Court was explicit about why. The government's reading would have criminalised a breathtaking amount of ordinary conduct, from using a work computer for personal email to embellishing a dating profile.

The practical consequences are large:

• An employee who downloads customer data they had legitimate access to, then takes it to a competitor, has not violated the CFAA on that basis. That may be trade secret misappropriation, breach of contract, or a state offense — but not exceeding authorized access.
• Violating terms of service is not a CFAA violation.
• Scraping publicly accessible data is generally outside the statute.
• Password sharing, standing alone, is a much weaker theory than it was.

If your case was charged on a purpose-based theory of authorisation, Van Buren is the first thing to raise.

"Without authorisation" still means what it always did

Van Buren narrowed the "exceeds authorized access" prong. It did not touch the "without authorisation" prong.

Genuine intrusion — using stolen credentials, exploiting a vulnerability, bypassing authentication, accessing a system after access was revoked — remains squarely covered. The line is between someone who was let in and misbehaved, and someone who was never let in at all.

The contested middle ground is revoked authorisation: an employee whose credentials were still technically active after termination, or a user who continued accessing a system after a cease-and-desist. Circuit law here is not uniform and the arguments are live.

The statutes charged alongside

Wire fraud — the most common companion, and it requires no computer-specific theory at all
§ 1029 — access device fraud, covering stolen card and credential trafficking
§ 1028A — aggravated identity theft, adding a mandatory consecutive two years
§ 2511 and § 2701 — Wiretap Act and Stored Communications Act
• 18 U.S.C. § 1831 and § 1832 — economic espionage and theft of trade secrets, which frequently replace a post-Van Buren CFAA theory
Money laundering — routine in ransomware cases involving cryptocurrency

Note the pattern: where Van Buren closed the CFAA route, prosecutors have moved to trade secret and wire fraud theories. A defense that only addresses the CFAA count may win it and lose the case.

Ransomware and extortion cases

Ransomware prosecutions combine § 1030(a)(5) damage counts, § 1030(a)(7) extortion counts, wire fraud, and money laundering, and they are investigated through blockchain tracing, infrastructure attribution, and international cooperation.

Attribution is the central defense issue. Linking a person to a wallet, a server, or an online handle involves inferential chains that are often longer and weaker than the indictment suggests — shared infrastructure, VPN and proxy layers, spoofed identifiers, and cluster analysis that is probabilistic rather than definitive. Expert scrutiny of that attribution is essential.

Loss calculation drives the sentence

Sentencing runs through U.S.S.G. § 2B1.1. The CFAA defines "loss" to include the cost of responding to an offense, conducting a damage assessment, and restoring data and systems, plus lost revenue from interruption of service.

That definition invites inflation. Organizations routinely include the cost of security upgrades they needed anyway, internal salary time that would have been paid regardless, and consulting engagements far broader than the incident. Whether claimed costs were genuinely caused by and reasonably necessary to respond to the offense is a factual question worth litigating carefully — it is usually the largest single variable in the sentence.

Wire fraud · Aggravated identity theft · Federal identity theft · Suppression of digital evidence

Key Terms

The words that come up most on this page, in plain English.

Protected computer
Any computer used in or affecting interstate commerce — in practice, nearly every internet-connected device.
Exceeds authorized access
Accessing areas of a system that are off limits, per Van Buren. Not misuse of information one was entitled to obtain.
Gates-up-or-down
The Van Buren framework: liability turns on whether a gate was closed to you, not on your purpose in passing through an open one.
CFAA loss
Response, assessment, and restoration costs plus service-interruption revenue. Frequently overstated.
Deandra M. Grant
Written & Reviewed By

Deandra M. Grant, JD, GC, MS, ACS-CHAL Forensic Lawyer-Scientist

She holds a Master of Science in Pharmaceutical Science and a Graduate Certificate in Forensic Toxicology, both from the University of Florida. She is the author of The Texas DWI Manual and has defended Texas DWI cases since 1994.

Full profile and credentials →

Your Defense Starts Now

Under Federal Investigation or Charged?

In federal cases, the most important decisions often come before an indictment. The sooner you have a defense lawyer, the more can be done. Talk to us today.

No Cost · No Obligation

Request a Free Case Evaluation

Tell us what happened. We'll respond as soon as possible.