Computer Fraud and Abuse Act

Computer Fraud and Abuse Act

The Computer Fraud and Abuse Act is a US federal law from 1986 that criminalizes unauthorized access to computer systems. It is considered the most important criminal statute in the United States in the area of cybercrime, but has been controversially debated for years because of its vague wording.

The Computer Fraud and Abuse Act, or CFAA for short, is a United States federal law dating from 1986. It makes it a crime to access someone else’s computer without being authorized to do so. What exactly “unauthorized access” means was deliberately left broadly defined by lawmakers at the time — and this remains the source of nearly all debates about the law to this day. It originally arose in response to growing concerns about hackers and espionage targeting government computers. Since then it has been expanded several times, but its basic principle has never been fundamentally changed.

Scope and explosive potential of the law

The CFAA is so significant because it can be applied very broadly. It does not only cover classic hacking, meaning breaking into someone else’s systems. Prosecutors have also used it against people who simply violated a website’s terms of service — for example by using a pseudonym or by automatically retrieving data without the operators having expressly permitted it.

The case of activist Aaron Swartz became particularly well known. In 2011 he had downloaded scientific articles from a database on a large scale. Although he had caused no commercial damage, he faced up to 35 years in prison under the CFAA. Swartz died in 2013 before the case went to trial. The case triggered a debate about the proportionality of the law that continues to this day.

What the law specifically prohibits

The CFAA lists several prohibited acts. The core provision prohibits accessing a “protected computer” without authorization or in excess of authorized access. In practice, a “protected computer” is considered to be nearly any computer connected to the internet — which effectively means all modern devices.

This includes, among other things: stealing passwords, altering or deleting data, disabling systems through overload, and distributing malware. Penalties range from fines to several years in prison, depending on the severity of the damage and whether the offender has prior convictions. For especially serious cases — such as attacks on critical infrastructure like power grids or hospitals — the law provides for maximum sentences of up to 20 years.

An important point: the CFAA is a federal law, not a state law. This means it applies equally across all 50 US states and is enforced by federal agencies such as the FBI. Many states additionally have their own cybercrime laws, which can apply in parallel.

CFAA in the tech debate: scraping, AI, and reform efforts

The CFAA regularly comes up in the tech and AI context. Companies that automatically extract data from publicly accessible websites — a process called web scraping — operate in a legal gray area. Several courts have ruled that scraping public data does not violate the CFAA because no access barrier is being circumvented. Other rulings have left the question open. It has still not been definitively resolved to this day.

This is relevant for AI companies because much of their training data comes from the web. If a company scrapes data despite an explicit prohibition in the robots.txt file or the terms of service, this could be deemed a violation of the CFAA. Corresponding lawsuits are currently ongoing in the United States.

Reform efforts have existed for years. Critics demand that the vague wording be clarified so that ordinary users and security researchers do not unintentionally become criminally liable. Security researchers who uncover vulnerabilities in systems in order to report them have long run the risk of being prosecuted themselves — even when they had no malicious intent. It was not until 2022 that the US Department of Justice clarified its guidelines, stating that it generally does not intend to prosecute good-faith security research. A legislative reform, however, is still pending.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.