# Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute and Related Federal Criminal Laws

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/crs%3A97-1025

## Record

- **Collection:** Congressional research report
- **Document type:** CRS Report
- **Published:** October 15, 2014
- **Citation:** 97-1025

## Text

Cybercrime: An Overview of the
Federal Computer Fraud and Abuse Statute
and Related Federal Criminal Laws
(name redacted)
Senior Specialist in American Public Law
October 15, 2014

Congressional Research Service
7-....
www.crs.gov
97-1025

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Summary
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030, outlaws conduct that victimizes
computer systems. It is a cyber security law. It protects federal computers, bank computers, and
computers connected to the Internet. It shields them from trespassing, threats, damage, espionage,
and from being corruptly used as instruments of fraud. It is not a comprehensive provision, but
instead it fills cracks and gaps in the protection afforded by other federal criminal laws. This is a
brief sketch of CFAA and some of its federal statutory companions, including the amendments
found in the Identity Theft Enforcement and Restitution Act, P.L. 110-326, 122 Stat. 3560 (2008).
In their present form, the seven paragraphs of subsection 1030(a) outlaw
•

computer trespassing (e.g., hacking) in a government computer, 18 U.S.C.
1030(a)(3);

•

computer trespassing (e.g., hacking) resulting in exposure to certain
governmental, credit, financial, or computer-housed information, 18 U.S.C.
1030(a)(2);

•

damaging a government computer, a bank computer, or a computer used in, or
affecting, interstate or foreign commerce (e.g., a worm, computer virus, Trojan
horse, time bomb, a denial of service attack, and other forms of cyber attack,
cyber crime, or cyber terrorism), 18 U.S.C. 1030(a)(5);

•

committing fraud an integral part of which involves unauthorized access to a
government computer, a bank computer, or a computer used in, or affecting,
interstate or foreign commerce, 18 U.S.C. 1030(a)(4);

•

threatening to damage a government computer, a bank computer, or a computer
used in, or affecting, interstate or foreign commerce, 18 U.S.C. 1030(a)(7);

•

trafficking in passwords for a government computer, or when the trafficking
affects interstate or foreign commerce, 18 U.S.C. 1030(a)(6); and

•

accessing a computer to commit espionage, 18 U.S.C. 1030(a)(1).

Subsection 1030(b) makes it a crime to attempt or conspire to commit any of these offenses.
Subsection 1030(c) catalogs the penalties for committing them, penalties that range from
imprisonment for not more than a year for simple cyberspace trespassing to a maximum of life
imprisonment when death results from intentional computer damage. Subsection 1030(d)
preserves the investigative authority of the Secret Service. Subsection 1030(e) supplies common
definitions. Subsection 1030(f) disclaims any application to otherwise permissible law
enforcement activities. Subsection 1030(g) creates a civil cause of action for victims of these
crimes. Subsections 1030(i) and (j) authorize forfeiture of tainted property.
This report is available in abbreviated form—without the footnotes, citations, quotations, or
appendixes found in this report—under the title CRS Report RS20830, Cybercrime: A Sketch of
18 U.S.C. 1030 and Related Federal Criminal Laws, by (name redacted).

Congressional Research Service

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Contents
Introduction...................................................................................................................................... 1
Trespassing in Government Cyberspace (18 U.S.C. 1030(a)(3)) .................................................... 2
Intent .......................................................................................................................................... 3
Unauthorized Access ................................................................................................................. 4
Affects the Use .......................................................................................................................... 5
Jurisdiction ................................................................................................................................ 5
Extraterritorial Jurisdiction ................................................................................................. 6
Penalties..................................................................................................................................... 7
Juveniles .............................................................................................................................. 8
Overview ............................................................................................................................. 8
Other Crimes ............................................................................................................................. 9
Attempt ................................................................................................................................ 9
Conspiracy......................................................................................................................... 10
Accomplices as Principals ................................................................................................. 11
Limited Application and State law .................................................................................... 12
Obtaining Information by Unauthorized Computer Access (18 U.S.C. 1030(a)(2)) ..................... 14
Intent ........................................................................................................................................ 15
Unauthorized Access ............................................................................................................... 15
Obtaining Information and Jurisdiction................................................................................... 17
Consequences .......................................................................................................................... 19
Penalties ............................................................................................................................ 19
Sentencing Guidelines ....................................................................................................... 20
Forfeiture ........................................................................................................................... 21
Restitution ......................................................................................................................... 22
Civil Cause of Action ........................................................................................................ 22
Attempt, Conspiracy, and Complicity ............................................................................... 24
Other Crimes ........................................................................................................................... 25
Interstate or Foreign Transportation of Stolen Property .................................................... 26
Theft of Federal Government Information ........................................................................ 27
Economic Espionage ......................................................................................................... 28
Copyright infringement ..................................................................................................... 29
Money Laundering ............................................................................................................ 30
Causing Computer Damage (18 U.S.C. 1030(a)(5))...................................................................... 30
Intent ........................................................................................................................................ 31
Damage .................................................................................................................................... 32
Without Authorization ............................................................................................................. 33
Jurisdiction .............................................................................................................................. 33
Consequences .......................................................................................................................... 35
Penalties ............................................................................................................................ 35
Juveniles ............................................................................................................................ 39
Sentencing Guidelines ....................................................................................................... 39
Forfeiture and Restitution.................................................................................................. 40
Cause of Action ................................................................................................................. 40
Crimes of Terrorism .......................................................................................................... 41
Attempt, Conspiracy, and Complicity ............................................................................... 42
Other Crimes ........................................................................................................................... 43

Congressional Research Service

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Damage or Destruction of Federal Property...................................................................... 43
Damage or Destruction of Financial Institution Property ................................................. 45
Damage or Destruction to Property in Interstate Commerce ............................................ 45
RICO ................................................................................................................................. 48
Money Laundering ............................................................................................................ 49
Computer Fraud (18 U.S.C. 1030(a)(4))........................................................................................ 50
Jurisdiction .............................................................................................................................. 50
Unauthorized or Excessive Access .......................................................................................... 51
Fraud and Intent....................................................................................................................... 52
Consequences .......................................................................................................................... 53
Other Crimes ........................................................................................................................... 53
Interstate and Foreign Commerce ..................................................................................... 53
Defrauding the Federal Government ................................................................................. 58
Bank Fraud ........................................................................................................................ 60
General Crimes.................................................................................................................. 61
Extortionate Threats (18 U.S.C. 1030(a)(7)) ................................................................................. 64
Jurisdiction .............................................................................................................................. 65
Threat of “Damage” ................................................................................................................ 65
Intent ........................................................................................................................................ 67
Consequences .......................................................................................................................... 67
Penalties and Civil Liability .............................................................................................. 67
Other Consequences .......................................................................................................... 68
Attempt, Conspiracy, and Complicity ............................................................................... 68
Other Crimes ........................................................................................................................... 68
Hobbs Act .......................................................................................................................... 68
Threat Statutes ................................................................................................................... 69
RICO, Money Laundering, and the Travel Act ................................................................. 70
Trafficking in Computer Access (18 U.S.C. 1030(a)(6)) ............................................................... 70
Jurisdiction .............................................................................................................................. 71
Intent ........................................................................................................................................ 72
Consequences .......................................................................................................................... 72
Penalties ............................................................................................................................ 72
Other Consequences .......................................................................................................... 72
Other Crimes ........................................................................................................................... 72
Computer Espionage (18 U.S.C. 1030(a)(1)) ................................................................................ 73
Jurisdiction .............................................................................................................................. 74
Intent ........................................................................................................................................ 75
Consequences .......................................................................................................................... 75
Penalties and Sentencing Guidelines................................................................................. 75
Federal Crime of Terrorism ............................................................................................... 75
Other Consequences .......................................................................................................... 76
Attempt, Conspiracy, and Complicity ............................................................................... 76
Other Crimes ........................................................................................................................... 77
Espionage Offenses ........................................................................................................... 77
Economic Espionage ......................................................................................................... 80
18 U.S.C. 1030. Computer Fraud and Abuse (text) ....................................................................... 81
18 U.S.C. 1956. Money Laundering (text) .................................................................................... 85
18 U.S.C. 1961(1). RICO Predicate Offenses (text) ...................................................................... 90

Congressional Research Service

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

18 U.S.C. 2332b(g)(5)(B). Federal Crimes of Terrorism (text) ..................................................... 91

Contacts
Author Contact Information........................................................................................................... 91

Congressional Research Service

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Introduction
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. 1030,1 protects computers in which there
is a federal interest—federal computers, bank computers, and computers used in or affecting
interstate and foreign commerce. It shields them from trespassing, threats, damage, espionage,
and from being corruptly used as instruments of fraud. It is not a comprehensive provision;
instead it fills cracks and gaps in the protection afforded by other state and federal criminal laws.
It is a work that over the last three decades, Congress has kneaded, reworked, recast, amended,
and supplemented to bolster the uncertain coverage of the more general federal trespassing,
threat, malicious mischief, fraud, and espionage statutes.2 This is a brief description of §1030 and
its federal statutory companions. There are other laws that address the subject of crime and
computers. CFAA deals with computers as victims; other laws deal with computers as arenas for
crime or as repositories of the evidence of crime or from some other perspective. These other
laws—laws relating to identity theft, obscenity, pornography, gambling, among others—are
beyond the scope of this report.3
In their present form, the seven paragraphs of subsection 1030(a) outlaw
•

computer trespassing in a government computer, 18 U.S.C. 1030(a)(3);

1

The full text of 18 U.S.C. 1030 can be found at the end of this report. Earlier versions of this report appeared under
the title, Computer Fraud and Abuse: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws.
2
Congressional inquiry began no later than 1976, S. Comm. on Government Operations, Problems Associated with
Computer Technology in Federal Programs and Private Industry—Computer Abuses, 94th Cong., 2d Sess. (1976)
(Comm.Print). Hearings were held in successive Congresses thereafter until passage of the original version of §1030 as
part of the Comprehensive Crime Control Act of 1984, P.L. 98-473, 98 Stat. 2190; e.g., Federal Computer Systems
Protection Act: Hearings Before the Subcomm. on Criminal Laws and Procedures of the Senate Comm. on the
Judiciary, 95th Cong., 2d Sess.(1978); S. 240, the Computer Systems Protection Act of 1979: Hearings Before the
Subcomm. on Criminal Justice of the Senate Comm. on the Judiciary, 96th Cong., 2d Sess.(1980); Federal Computer
System Protection Act, H.R. 3970: Hearings Before the House Comm. on the Judiciary, 97th Cong., 2d Sess.(1982);
Computer Crime: Hearings Before the House Comm. on the Judiciary, 98th Cong., 1st Sess. (1983).
Refurbishing of the original 1984 legislation occurred in 1986, 1988, 1989, 1990, 1994, and 1996: P.L. 99-474, 100
Stat. 1213; P.L. 100-690, 102 Stat. 4404; P.L. 101-73, 103 Stat. 502; P.L. 101-647, 104 Stat. 4831; P.L. 103-322, 108
Stat. 2097; P.L. 104-294, 110 Stat. 3491. Most recently, both the USA PATRIOT Act, P.L. 107-56, 115 Stat. 272
(2001), the Department of Homeland Security Act, P.L. 107-296, 116 Stat. 2135 (2002), and the Identity Theft
Enforcement and Restitution Act of 2008, Title II of P.L. 110-326, 122 Stat. 3560 (2008) amended provisions of the
section.
For a chronological history of the statute up to but not including the 1996 amendments, see Adams, Controlling
Cyberspace: Applying the Computer Fraud and Abuse Act to the Internet, 12 SANTA CLARA COMPUTER & HIGH
TECHNOLOGY LAW JOURNAL 403 (1996). For a general description of the validity and application of this act, see
Buchman, Validity, Construction, and Application of Computer Fraud and Abuse Act, 174 ALR Fed. 101; Prosecuting
Intellectual Property Crimes, COMPUTER CRIME AND INTELLECTUAL PROPERTY SECTION, CRIMINAL DIVISION, UNITED
STATES DEPARTMENT OF JUSTICE (4th ed.)[(2013)](DoJ Computer Crime), available at
http://www.justice.gov/criminal/cybercrime/docs/prosecuting_ip_crimes_manual_2013_pdf and Prosecuting Computer
Crimes, COMPUTER CRIME AND INTELLECTUAL PROPERTY SECTION, CRIMINAL DIVISION, UNITED STATES DEPARTMENT
OF JUSTICE [(2010)](DoJ Cyber Crime), available at http://www.justice.gov/criminal/cybercrime/docs/ccmanual.pdf.
3
For a discussion of these and similar matters see, Twenty-Eighth Survey of White Collar Crime: Computer Crimes, 50
AMERICAN CRIMINAL LAW REVIEW 681 (2013); DoJ Cyber Crime; CRS Report R40599, Identity Theft: Trends and
Issues, by (name redacted); CRS Report 98-670,Obscenity, Child Pornography, and Indecency: Brief Background and
Recent Developments, by (name redacted); CRS Report 97-619,
Internet Gambling: An Overview of Federal
Criminal Law, by (name redacted); Kerr,Applying The Fourth Amendment to the Internet: A General Approach, 62
STANFORD LAW REVIEW 1005 (2010); Mehra, Law and Cybercrime in the United States Today, 58 AMERICAN JOURNAL
OF COMPARATIVE LAW 659 (2010).

Congressional Research Service

1

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

•

computer trespassing resulting in exposure to certain governmental, credit,
financial, or computer-housed information, 18 U.S.C. 1030(a)(2);

•

damaging a government computer, a bank computer, or a computer used in, or
affecting, interstate or foreign commerce, 18 U.S.C. 1030(a)(5);

•

committing fraud an integral part of which involves unauthorized access to a
government computer, a bank computer, or a computer used in, or affecting,
interstate or foreign commerce, 18 U.S.C. 1030(a)(4);

•

threatening to damage a government computer, a bank computer, or a computer
used in, or affecting, interstate or foreign commerce, 18 U.S.C. 1030(a)(7);

•

trafficking in passwords for a government computer, or when the trafficking
affects interstate or foreign commerce, 18 U.S.C. 1030(a)(6); and

•

accessing a computer to commit espionage, 18 U.S.C. 1030(a)(1).

Subsection 1030(b) makes it a crime to attempt or conspire to commit any of these offenses.
Subsection 1030(c) catalogs the penalties for committing them, penalties that range from
imprisonment for not more than a year for simple cyberspace trespassing to imprisonment for not
more than 20 years for a second espionage-related conviction and to life imprisonment for deathresult offenses. Subsection 1030(d) preserves the investigative authority of the Secret Service.
Subsection 1030(e) supplies common definitions. Subsection 1030(f) disclaims any application to
otherwise permissible law enforcement activities. Subsection 1030(g) creates a civil cause of
action for victims of these crimes. Subsection 1030(h), which has since expired, called for annual
reports through 1999 from the Attorney General and Secretary of the Treasury on investigations
under the damage paragraph (18 U.S.C. 1030(a)(5)). And subsections 1030(i) and (j) authorize
the confiscation of property generated by, or used to facilitate the commission of, one of the
offenses under subsection 1030(a) or (b).

Trespassing in Government Cyberspace
(18 U.S.C. 1030(a)(3))
(a) Whoever ... (3) intentionally, without authorization to access any nonpublic computer4 of
a department or agency of the United States,5 accesses such a computer of that department
or agency that is exclusively for the use of the Government of the United States or, in the
case of a computer not exclusively for such use, is used by or for the Government of the
United States and such conduct affects that use by or for the Government of the United States
... shall be punished as provided in subsection (c) of this section.
(b) Whoever attempts to commit an offense under subsection (a) of this section shall be
punished as provided in subsection (c) of this section.

4
“(e) As used in this section ... (1) the term ‘computer’ means an electronic, magnetic, optical, electrochemical, or
other high speed data processing device performing logical, arithmetic, or storage functions, and includes any data
storage facility or communications facility directly related to or operating in conjunction with such device, but such
term does not include an automated typewriter or typesetter, a portable hand held calculator, or other similar device,”
18 U.S.C. 1030(e)(1).
5
“(e) As used in this section ... (7) the term ‘department of the United States’ means the legislative or judicial branch of
the Government or one of the executive departments enumerated in [s]ection 101 of title 5,” 18 U.S.C. 1030(e)(7).

Congressional Research Service

2

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Paragraph 1030(a)(3) condemns unauthorized intrusion (“hacking”) into federal government
computers whether they are used exclusively by the government or the government shares access
with others. With the help of subsection 1030(b) it also outlaws attempted intrusions and
conspiracies to intrude. In the case of shared computers, a crime only occurs if the unauthorized
access “affects ... use by or for” the government or would affect such use if an attempted effort
had succeeded.6
Broken down into its elements, paragraph (a)(3) makes it unlawful for anyone to
•

without authorization

•
•

intentionally
either
- access a government computer maintained exclusively for the use of the federal
government,
- access a government computer used, at least in part, by or for the federal government
and the access affects use by or for the federal government,
- attempts to do so (18 U.S.C. 1030(b)) or
- conspires to do so (18 U.S.C. 1030(c)).

This pure trespassing proscription dates from 1986 and its legislative history leaves little doubt
that nothing more than unauthorized entry is required:
“[S]ection 2(b) will clarify the present 18 U.S.C. 1030(a)(3), making clear that it applies to
acts of simple trespass against computers belonging to, or being used by or for, the Federal
Government. The Department of Justice and others have expressed concerns about whether
the present subsection covers acts of mere trespass, i.e., unauthorized access, or whether it
requires a further showing that the information perused was ‘used, modified, destroyed, or
disclosed.’ To alleviate those concerns, the Committee wants to make clear that the new
subsection will be a simple trespass offense, applicable to persons without authorized access
to Federal computers.”7

Intent
The paragraph only bans “intentional” trespassing. The reports are instructive here, for they make
it apparent that the element cannot be satisfied by a mere inadvertent trespass and nothing more.
It is intended, however, to cover anyone who purposefully accomplishes the proscribed
unauthorized entry into a government computer, and, at least in the view of the House report,
anyone “whose initial access was inadvertent but who then deliberatively maintains access after a
non-intentional initial contact.”8

6

18 U.S.C. 1030(a)(3).
S.Rept. 99-432 at 7 (1986); see also, H.Rept. 99-612 at 11 (1986).
8
H.Rept. 99-612 at 9-10 (1986); see also, S.Rept. 99-432 at 5-6 (1986).
7

Congressional Research Service

3

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Unauthorized Access
While the question of what constitutes “access without authorization” might seem fairly
straightforward, Congress was willing to accept a certain degree of trespassing by government
employees in order to protect whistleblowers:
The Committee wishes to be very precise about who may be prosecuted under the new
subsection (a)(3). The Committee was concerned that a Federal computer crime statute not
be so broad as to create a risk that government employees and others who are authorized to
use a Federal Government computer would not face prosecution for acts of computer access
and use that, while technically wrong, should not rise to the level of criminal conduct. At the
same time, the Committee was required to balance its concern for Federal employees and
other authorized users against the legitimate need to protect Government computers against
abuse by “outsiders.” The Committee struck that balance in the following manner.
In the first place, the Committee has declined to criminalize acts in which the offending
employee merely ‘exceeds authorized access’ to computers in his own department
(“department”‘ is defined in [s]ection 2(g) of S. 2281 [now 18 U.S.C. 1030(e)(7)]). It is not
difficult to envision an employee or other individual who, while authorized to use a
particular computer in one department, briefly exceeds his authorized access and peruses
data belonging to the department that he is not supposed to look at. This is especially true
where the department in question lacks a clear method of delineating which individuals are
authorized to access certain of its data. The Committee believes that administrative sanctions
are more appropriate than criminal punishment in such a case. The Committee wishes to
avoid the danger that every time an employee exceeds his authorized access to his
department’s computers—no matter how slightly—he could be prosecuted under this
subsection. That danger will be prevented by not including “exceeds authorized access” as
part of this subsection’s offense.
In the second place, the Committee has distinguished between acts of unauthorized access
that occur within a department and those that involve trespasses into computers belonging to
another department. The former are not covered by subsection (a)(3); the latter are. Again, it
is not difficult to envision an individual who, while authorized to use certain computers in
one department, is not authorized to use them all. The danger existed that S. 2281, as
originally introduced, might cover every employee who happens to sit down, within his
department, at a computer terminal which he is not officially authorized to use. These acts
can also be best handled by administrative sanctions, rather than by criminal punishment. To
that end, the Committee has constructed its amended version of (a)(3) to prevent prosecution
of those who, while authorized to use some computers in their department, use others for
which they lack the proper authorization. By precluding liability in purely ‘insider’ cases
such as these, the Committee also seeks to alleviate concerns by Senators Mathias and Leahy
that the existing statute cases a wide net over “whistleblowers”....
The Committee has thus limited 18 U.S.C. 1030(a)(3) to cases where the offender is
completely outside the Government, and has no authority to access a computer of any agency
or department of the United States, or where the offender’s act of trespass is
interdepartmental in nature. The Committee does not intend to preclude prosecution under
this subsection if, for example, a Labor Department employee authorized to use Labor’s
computers accesses without authorization an FBI computer. An employee who uses his
department’s computer and, without authorization, forages into data belonging to another
department is engaged in conduct directly analogous to an ‘outsider’ tampering with
Government computers....

Congressional Research Service

4

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

The Committee acknowledges that in rare circumstances this may leave serious cases of
intradepartmental trespass free from criminal prosecution under (a)(3). However, the
Committee notes that such serious acts may be subject to other criminal penalties if, for
example, they violate trade secrets laws or 18 U.S.C. 1030(a)(1), (a)(4), (a)(5), or (a)(6), as
proposed in this legislation.9

Affects the Use
Trespassing upon governmental computer space on computers that are not exclusively for
governmental use is prohibited only when it affects use by the government or use for
governmental purposes. The committee reports provide a useful explanation of the distinctive,
“affects-the-use” element of the trespassing ban:
[T]respassing in a computer used only part-time by the Federal Government need not be
shown to have affected the operation of the government as a whole. The Department of
Justice has expressed concerns that the present subsection’s language could be construed to
require a showing that the offender’s conduct would be an exceedingly difficult task for
Federal prosecutors. Accordingly, [s]ection 2(b) will make clear that the offender’s conduct
need only affect the use of the Government’s operation of the computer in question [or the
operation of the computer in question on behalf of the Government]. S.Rept. 99-432 at 6-7
(1986); see also, H.Rept. 99-612 at 11 (1986); S.Rept. 104-357 at 9 (1996).

Jurisdiction
The reports offer little insight into the meaning of the third element—what computers are
protected from trespassing. There may be two reasons. Paragraph 1030(a)(3) protects only
government computers and therefore explanations of the sweep of its coverage in the area of
interstate commerce or of financial institutions are unnecessary. Besides, at least for purposes of
these trespassing offenses of paragraph 1030(a)(3), the statute itself addresses several of the
potentially more nettlesome questions.
First, the construction of the statute itself strongly suggests that it reaches only computers owned
or leased by the federal government: “whoever ... without authorization to access any nonpublic
computer of a department or agency of the United States, accesses such a computer of that
department or agency....”
Second, the language of the statute indicates that “nonpublic” computers may nevertheless
include government computers that the government allows to be used by nongovernmental
purposes: “in the case of a [government] computer not exclusively for the use of the Government
of the United States....”
Third, the statute covers government computers that are available to nongovernment users:
“accesses such a computer ... that ... in the case of a [government] computer not exclusively for
the use of the Government of the United States, is used by or for the Government of the United
States....” The use of the term “nonpublic,” however, makes it clear that this shared access may
not be so broad as to include the general public.

9

S.Rept. 99-432 at 7-8 (1986); see also, H.Rept. 99-612 at 11 (1986).

Congressional Research Service

5

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Finally, the section supplies a definition of “department of the United States”: “[a]s used in this
section ... the term ‘department of the United States’ means the legislative or judicial branch of
the Government or one of the executive departments enumerated in [s]ection 101 of title 5”;10 and
the title supplies a definition of “agency of the United States”: “[a]s used in this title ... [t]he term
‘agency’ includes any department, independent establishment, commission, administration,
authority, board or bureau of the United States or any corporation in which the United States has a
proprietary interest, unless the context shows that such term was intended to be used in a more
limited sense.”11

Extraterritorial Jurisdiction
There is one jurisdictional aspect of paragraph 1030(a)(3) that is unclear. Under what
circumstances, if any, does the paragraph reach hacking initiated or occurring overseas? As a
general rule, federal laws are presumed to apply within the United States and not overseas.12 In
some instances, Congress explicitly negates the presumption. The treason statute, for example,
outlaws the offense whether committed “within the United States or elsewhere.”13
In other instances, when the criminal statute is silent, the courts will conclude that Congress must
have intended the statute to apply to overseas misconduct because of the nature of the offense and
the circumstances under which it was committed. For example, the Supreme Court concluded that
Congress must have intended the federal statute that prohibited fraud against the federal
government to apply to fraud against the United States committed abroad, particularly when
the offenders were Americans.14 The Court later decided that a federal statute that outlawed
conspiracy to violate federal law applied to an overseas conspiracy to smuggle liquor into this
country.15

10

18 U.S.C. 1030(e)(7). “The Executive departments are: The Department of State. The Department of the Treasury.
The Department of Defense. The Department of Justice. The Department of the Interior. The Department of
Agriculture. The Department of Commerce. The Department of Labor. The Department of Health and Human Services.
The Department of Housing and Urban Development. The Department of Transportation. The Department of Energy.
The Department of Education. The Department of Veterans Affairs. The Department of Homeland Security.” 5 U.S.C.
101.
11
18 U.S.C. 6.
12
Morrison v. National Australia Bank, Ltd., 561 U.S. 247, 255 (2010)(“It is a longstanding principle of American law
that legislation of Congress, unless a contrary intent appears, is meant to apply only within the territorial jurisdiction of
the United States”). See CRS Report 94-166, Extraterritorial Application of American Criminal Law, by (name re
dacted).
13
18 U.S.C. 2381.
14
United States v. Bowman, 260 U.S. 94, 98 (1922)(“But the same rule of [territorial] interpretation should not be
applied to criminal statutes which ... are enacted because of the right of the Government to defend itself against
obstruction, or fraud wherever perpetrated, especially if committed by its own citizens, officers or agents. Some such
offenses ... are such that to limit their locus to the strictly territorial jurisdiction would be greatly to curtail the scope
and usefulness of the statute and leave open a large immunity for frauds as easily committed by citizens on the high
seas and in foreign countries as at home. In such cases, Congress has not thought it necessary to make specific
provision in the law that the locus shall include the high seas and foreign countries, but allows it to be inferred from the
nature of the offense”).
15
Ford v. United States, 273 U.S. 589, 623 (1927)(“The principle that a man who outside a country willfully puts in
motion a force to take effect in it is answerable at the place where the evil is done, is recognized in the criminal
jurisprudence of all countries”).

Congressional Research Service

6

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

In the cybercrime context, at least one court determined that paragraph 1030(a)(4), which
prohibits unauthorized computer access to defraud, applied to a hacker in Russia who gained
unauthorized access to “protected computers” in this country.16 The court’s conclusion was
influenced by an amendment in which Congress had added computers used in “foreign commerce
or communications” to the definition of “protected computers” and by the legislative history of
why it did so.17 While the case was pending, Congress further amended the definition of
“protected computer” to include “a computer located outside the United States that is used in a
manner that affects interstate or foreign commerce or communication of the United States.”18
Paragraph 1030(a)(3) does not cover “protected computers”; it covers nonpublic, federal
government computers. Congress explicitly provided extraterritorial jurisdiction over the
computer-related information acquisition, fraud, damage, and extortion offenses by amending the
definition of protected computer. It provided no such explicit provision for simple trafficking
offense under paragraph 1030(a)(3).
A court might conclude that Congress meant both to grant extraterritorial application in
computer-related information acquisition, fraud, damage, and extortion cases under paragraphs
1030(a)(2), (4), (5), and (7) and to foreclose extraterritorial application in simple trespassing
cases under paragraph 1030(a)(3)—even under circumstances when the courts would have
otherwise found it appropriate in a simple trespassing case.

Penalties
The penalties for conspiracy to violate, or for violations or attempted violations of, paragraph
1030(a)(3) are imprisonment for not more than one year and/or a fine of not more than $100,000
($200,000 for organizations) for the first offense and imprisonment for not more than 10 years
and/or a fine of not more than $250,000 ($500,000 for organizations) for all subsequent
convictions.19

16

United States v. Ivanov, 175 F.Supp.2d 367, 374-75 (D. Conn. 2001).
Id. at 374 (“The Committee specifically noted its concern that the statute as it existed prior to the 1996 amendments
did not cover ‘computers used in foreign communications or commerce, despite the fact hackers are often foreignbased.’ The Committee cited two specific cases in which foreign-based hackers had infiltrated computer systems in the
United States, as examples of the kind of situation the amendments were intended to address.... Congress has the power
to apply its statutes extraterritorially, and in the case of 18 U.S.C. 1030, it has clearly manifested its intention to do
so”), quoting and citing, S.Rept. 104-357, at 4-5 (1996).
18
18 U.S.C. 1030(e)(2)(B). Paragraph 814(d)(1) of the USA PATRIOT Act, P.L. 107-56, 115 Stat. 384 (2001), made
the change.
19
18 U.S.C. 1030(c), 3571. By virtue of 18 U.S.C. 3571, all felonies are subject to fines of not more than the greater of
$250,000 or twice the amount of the pecuniary gain or loss associated with the offense, unless provisions applicable to
a specific crime either call for a higher maximum fine or were enacted subsequent to 1984 when the general provisions
of §3571 became effective.
Most federal criminal statutes give the impression that offenders may be sentenced to imprisonment, to a fine or to both
imprisonment and a fine. This may be something of an illusion in most serious federal cases. Federal sentencing is
influenced by sentencing guidelines that calibrate sentencing levels beneath the maximum terms established in the
statute for a particular offense, according to the circumstances of the crime and the offender, see CRS Report R41696,
How the Federal Sentencing Guidelines Work: An Overview, by (name redacted). While a sentence in compliance with
the Guidelines is no longer mandatory, United States v. Booker, 543 U.S. 220, 226-27 (2005), federal courts must begin
the sentencing process by calculating the applicable sentencing range under the Guidelines and justify any departure
from that range, Gall v. United States, 552 U.S. 38, 49 (2007).
17

Congressional Research Service

7

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Offenses under other paragraphs may trigger forfeiture, restitution, racketeering, money
laundering, sentencing guidelines, and civil liability provisions elsewhere in the law. For reasons
that will become apparent when they are discussed later in this report, those provisions have little,
if any, relevance in case of simple trespassing offenses under paragraph 1030(a)(3). The forfeiture
provisions of subsections 1030(i) and (j), however, do authorize the confiscation of a cyber
trespasser’s computer and any other property that facilitated the offense.20

Juveniles
Historically, federal authorities did not prosecute juvenile offenders. Most federal crimes,
including computer hacking, are crimes under the laws of most states. When a juvenile violates a
federal law, he must be turned over to state juvenile authorities unless the state is unwilling or
unable to proceed against him, or unless the state has inadequate facilities for his treatment, or
unless the crime is a violent federal felony or a federal drug or firearms offense.21

Overview
Paragraph 1030(a)(3) has remained essentially unchanged since 1986,22 and there appear to have
been relatively few prosecutions under its provisions.23 The explanation may be that paragraph
20
18 U.S.C. 1030(i), (j)(“(i)(1) The court, in imposing sentence on any person convicted of a violation of this section,
or convicted of conspiracy to violate this section, shall order, in addition to any other sentence imposed and irrespective
of any provision of State law, that such person forfeit to the United States—(A) such person's interest in any personal
property that was used or intended to be used to commit or to facilitate the commission of such violation; and (B) any
property, real or personal, constituting or derived from, any proceeds that such person obtained, directly or indirectly,
as a result of such violation. (2) The criminal forfeiture of property under this subsection, any seizure and disposition
thereof, and any judicial proceeding in relation thereto, shall be governed by the provisions of §413 of the
Comprehensive Drug Abuse Prevention and Control Act of 1970 (21 U.S.C. 853), except subsection (d) of that section.
“(j) For purposes of subsection (i), the following shall be subject to forfeiture to the United States and no property right
shall exist in them: (1) Any personal property used or intended to be used to commit or to facilitate the commission of
any violation of this section, or a conspiracy to violate this section. (2) Any property, real or personal, which constitutes
or is derived from proceeds traceable to any violation of this section, or a conspiracy to violate this section”).
21
18 U.S.C. 5032. See generally, DoJ Cyber Crime, ch.4.D.; CRS Report RL30822, Juvenile Delinquents and Federal
Criminal Law: The Federal Juvenile Delinquency Act and Related Matters, by (name redacted).
22
In 1994, Congress amended the paragraph to emphasize that trespassing upon computers used part-time for the
government required a showing that government use was “adversely” affected rather than merely affected, P.L. 103322, 108 Stat. 2099. Concerned that it might suggest that trespassing could be beneficial, Congress repealed the 1994
amendment in 1996 when it also made changes to make it clear that a person “permitted to access publicly available
Government computers ... may still be convicted under (a)(3) for accessing without authority any nonpublic Federal
Government computer” and that a person may be convicted under paragraph (a)(3) for access that affects the use of a
computer employed on behalf of the government regardless of whether the computer is actually operated by the
government or is merely operated for the government, P.L. 104-294, 110 Stat. 3491; S.Rept. 104-357 at 9 (1996).
23
Olivenbaum, : Rethinking Federal Computer Crime Legislation, 27 SETON HALL LAW
REVIEW 574, 600-1 (1997); United States v. Rice, aff’g w/o published op., 961 F.2d 211 (4th Cir. 1992), subsequent
motion for correction of sentence, 815 F.Supp. 158 (W.D.N.C. 1993).
Rice is a curious case. The unpublished opinion indicates that Rice, a longtime Internal Revenue Service (IRS) agent,
hacked into the IRS computers at the behest of a drug dealer and disclosed to the dealer the status of an IRS
investigation of the dealer; the agent also advised the dealer on means of evading forfeiture of his house. For this he
was convicted of conspiracy to launder his friend’s drug profits (18 U.S.C. 1956(a)(1)(b)(i)), conspiracy to defraud the
United States of forfeitable property (26 U.S.C. 7214), computer fraud, i.e., accessing the computer system of a
government agency without authority (18 U.S.C. 1030(a)(3)), and unauthorized disclosure of confidential information
(18 U.S.C. 1905)(sometimes known as the Trade Secrets Act). The court did not address the apparent conflict between
the conviction and the legislative history of paragraph 1030(a)(3) indicating that the paragraph does not govern cases of
(continued...)

Congressional Research Service

8

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

1030(a)(3) tracks paragraph 1030(a)(2) so closely that the prosecution is ordinarily reserved for
the more serious cases which warrant the more serious felony sanctions available under the
information acquisition offense of paragraph 1030(a)(2), but not the simple trespassing offense of
paragraph 1030(a)(3).24

Other Crimes25
Attempt
An attempt to hack into a federal computer in violation of paragraph 1030(a)(3) is also punishable
as a federal crime, 18 U.S.C. 1030(b). In fact, subsection 1030(b) punishes as a federal crime any
attempt to violate any of the paragraphs of subsection 1030(a).26 The subsection dates from the
original enactment and evokes no comment in the legislative history other than the notation of its
existence.27
This is not particularly unusual. There is no general federal attempt statute,28 but Congress has
elected to penalize attempts to commit many individual federal crimes.29 A body of case law has
grown up around them that provides a common understanding of their general dimensions.30
Thus, as a general rule, in order to convict a defendant of attempt, the government must prove
beyond a reasonable doubt that, acting with the intent required to commit the underlying
offense,31 the defendant took some substantial step towards the commission of the underlying
(...continued)
an employee hacking into the computer systems of his own agency. See also, Brownlee v. Dyncorp, 349 F.3d 1343,
1346 (Fed Cir. 2003) (noting that the guilty plea to charges under §1030(a)(3) of the employee of a government
contractor resulting from the employee’s entering false data regarding hours worked into the government computer
system).
24
DoJ Computer Crime, at 25 (“Prosecutors rarely charge section 1030(a)(3) and few cases interpret it, probably
because section 1030(a)(2) applies in many of the same cases in which section 1030(a)(3) could be charged. In such
cases, section 1030(a)(2) may be the preferred charge because statutory sentencing enhancements sometimes allow
section 1030(a)(2) to be charged as a felony on the first offense. A violation of section 1030(a)(3), on the other hand, is
only a misdemeanor for a first offense”).
25
Throughout this report, “other crimes” refers to closely related crimes. In any given case, a defendant charged under
one of the paragraphs of 1030(a) may also be charged under one or more of these other federal companion statutes. As
long as there is at least one element required for conviction of one but not the other, a defendant guilty of violating one
or more of the various paragraphs of §1030 may also be held liable for one or more related offenses, e.g. United States
v. Czubinski, 106 F.3d 1069 (1st Cir. 1997) (convictions under 18 U.S.C. 1343 (wire fraud) and 18 U.S.C. 1030(a)(4)
(computer fraud) overturned for other reasons); United States v. Petersen, 98 F.3d 502 (9th Cir. 1996) (upholding a
sentence imposed for convictions under 18 U.S.C. 371 (conspiracy), 18 U.S.C. 1343 (wire fraud), and 18 U.S.C.
1030(a)(4) (computer fraud)).
26
Subsection 1030(b) states in its entirety, “Whoever conspires to commit or attempts to commit an offense under
subsection (a) of this section shall be punished as provided in subsection (c) of this section.” §207 of the Identity Theft
Enforcement and Restitution Act added the phrase in italics to the subsection 1030(b), P.L. 110-326, 122 Stat. 3563
(2008).
27
H.Rept. 98-894 at 22 (1984).
28
United States v. Neal, 78 F.3d 901, 906 (4th Cir. 1996); United States v. Adams, 305 F. 3d 30, 34 (1st Cir. 2002).
29
E.g., 18 U.S.C. 1951 (attempt to obstruct interstate commerce by extortion or robbery); 18 U.S.C. 794 (attempt to
communicate national defense information to a foreign government). There are separate attempt offenses in over 130
sections of title 18 alone: e.g., 18 U.S.C. 32, 33, 37, 112, 115, 152.
30
See CRS Report R42001, Attempt: An Overview of Federal Criminal Law, by (name redacted).
31
United States v. Resendiz-Ponce, 549 U.S. 102, 106-107 (2007); United States v. Anderson, 747 F.3d 51, 73 (2d Cir.
(continued...)

Congressional Research Service

9

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

offense32 that strongly corroborates his criminal intent.33 Mere preparation does not constitute a
substantial step.34 The line between preparation and a substantial step towards final commission
depends largely upon the facts of a particular case,35 and the courts have offered varying
descriptions of its location.36

Conspiracy
Conspiracy to violate any federal law is a separate federal crime.37 Thus, if two or more
individuals agree to intentionally access a government computer without authorization and one of
them takes some affirmative action to effectuate their plan, each of the individuals is guilty of
conspiracy under this general conspiracy statute, regardless of whether the scheme is ultimately
successful.38 If one of the conspirators manages to “hack” into a government computer, he and his
coconspirators may all be prosecuted for violating paragraph 1030(a)(3).39
The general conspiracy statute notwithstanding, subsection 1030(b) declares that conspiracy to
commit any of the subsection 1030(a) offenses shall be punished as provided in subsection (c),
which delineates the punishment for each of the subsection 1030(a) offenses. The principles that
(...continued)
2014); United States v. Goodwin, 719 F.3d 857, 860 (8th Cir. 2013); United States v. Pavulak, 700 F.3d 651, 669 (3d
Cir. 2012).
32
United States v. Gonzalez, 745 F.3d 1237, 1243 (9th Cir. 2014); United States v. Mehanna, 735 F.3d 32, 53 (1st Cir.
2013); United States v. Brown, 702 F.3d 1060, 1064 (8th Cir. 2013).
33
United States v. Aldawsari, 740 F.3d 1015, 1020 (5th Cir. 2014); United States v. Gordon, 710 F.3d 1124, 1150-151
(10th Cir. 2013); United States v. Desposito, 704 F.3d 221, 231 (2d Cir. 2013).
34
United States v. Anderson, 747 F.3d 51, 74 (2d Cir. 2014); United States v. Gonzalez-Monterroso, 745 F.3d 1237,
1243 (9th Cir. 2014); United States v. Goodwin, 719 F.3d 857, 860 (8th Cir. 2013); United States v. Kindle, 698 F.3d
401, 407 (7th Cir. 2013).
35
United States v. Muratovic, 719 F.3d 809, 815 (7th Cir. 2013); United States v. Villarreal, 707 F.3d 942, 960 (8th Cir.
2013); United States v. Desposito, 704 F.3d 221, 231 (2d Cir. 2013); United States v. Irving, 665 F.3d 1184, 1195 (10th
Cir. 2011).
36
United States v. Muratovic, 719 F.3d at 815 (here and elsewhere internal quotation marks and citations have
generally been omitted)(“A substantial step is some overt act adapted to, approximating, and which in the ordinary and
likely course of things will result in, the commission of the particular crime. It requires something more than mere
preparation, but less than the last act necessary before actual commission of the substantive crime. This line between
mere preparation and a substantial step is inherently fact specific; conduct that would appear to be mere preparation in
one case might qualify as a substantial step in another. Generally a defendant takes a substantial step when his actions
make it reasonably clear that had the defendant not been interrupted or made a mistake . . . he would have completed
the crime”); United States v. Turner, 501 F.3d 59, 68 (1st Cir. 2007)(“While ‘mere preparation’ does not constitute a
substantial step, a defendant does not have to get very far along the line toward ultimate commission of the object
crime in order to commit the attempt offense”); United States v. Goetzke, 494 F.3d 1231, 1237 (9th Cir. 2007)(“To
constitute a substantial step, a defendant’s actions must cross the line between preparation and attempt by
unequivocally demonstrating that the crime will take place unless interrupted by independent circumstances”).
37
18 U.S.C. 371; see generally, CRS Report R41223, Federal Conspiracy Law: A Brief Overview; Twenty-Eighth
Survey of White Collar Crime: Federal Criminal Conspiracy, 50 AMERICAN CRIMINAL LAW REVIEW 663 (2013);
Developments in the Law—Criminal Conspiracy, 72 HARVARD LAW REVIEW 920 (1959).
38
United States v. Chhun, 744 F.3d 1110, 1117 (9th Cir. 2014); United States v. Njoku, 737 F.3d 55, 63-4 (5th Cir.
2013); United States v. Appolon, 715 F.3d 362, 370 (1st Cir. 2013).
39
Pinkerton v. United States, 328 U.S. 640, 645-48 (1946); United States v. Newman, 755 F.3d 545, 546 (7th Cir.
2014); United States v. Blachman, 746 F.3d 137, 141 (4th Cir. 2014); United States v. Ali, 718 F.3d 929, 941 (D.C. Cir.
2013)(Under the doctrine of Pinkerton v. United States, “as long as a substantive offense was done in furtherance of the
conspiracy, and was reasonably foreseeable as a necessary or natural consequence of the unlawful agreement, then a
conspirator will be held vicariously liable for the offense committed by his or her co-conspirators”).

Congressional Research Service

10

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

apply to prosecution under the general conspiracy statute apply with equal force to prosecution
under subsection 1030(b), with two exceptions. Section 371 general conspiracy prosecutions
require proof of an overt act in furtherance of the scheme, subsection 1030(b) conspiracy
prosecutions do not.40
There is a second difference. Section 371 punishes conspiracy to commit any federal felony with
imprisonment for not more than 5 years, regardless of the maximum term of imprisonment that
attends the underlying substantive offense. The section declares that the punishment for
conspiracy to commit any federal misdemeanor may not exceed the maximum penalty for the
underlying misdemeanor. Subsection 1030(b), on other hand, seems to contemplate punishing
alike conspiracy and underlying violation of subsection 1030(a): “Whoever conspires to commit
or attempts to commit an offense under subsection (a) of this section shall be punished a provided
in subsection (c) of this section [which establishes the punishment for violating the various
paragraphs of subsection 1030(a)].”41

Accomplices as Principals
Anyone who counsels, commands, aids or abets, or otherwise acts as an accessory before the fact
with respect to any federal crime is liable as a principal for the underlying substantive offense to
the same extent as the individual who actually commits the offense.42 More than mere inadvertent
assistance is required; but an accomplice who embraces the criminal objectives of another and
acts to bring about their accomplishment is criminally liable as a principal for the completed
offense.43

40
Whitfield v. United States, 543 U.S. 209, 214 (2005)(when in a conspiracy provision, Congress “omits any express
overt-act requirement, it dispenses with such a requirement”), quoting, United States v. Shabani, 513 U.S. 10, 14
(1994).
41
18 U.S.C. 1030(b). This is not as indisputable as it might be, however, since Congress mentioned attempt in
subsection 1030(c), but failed to mention conspiracy, perhaps inadvertently: 18 U.S.C. 1030(b), (c)(emphasis added)
(“(b) Whoever conspires to commit or attempts to commit an offense under subsection (a) of this section shall be
punished as provided in subsection (c) of this section. (c) The punishment for an offense under subsection (a) or (b) of
this section is . . . (2)(A) . . . a fine under this title or imprisonment for not more than one year, or both, in the case of an
offense under subsection . . . (a)(3) . . . of this section which does not occur after a conviction for another offense under
this section, or an attempt to commit an offense punishable under this subparagraph; . . . and (C) a fine under this title
or imprisonment for not more than ten years, or both, in the case of an offense under subsection . . . (a)(3) . . . of this
section which occurs after a conviction for another offense under this section, or an attempt to commit an offense
punishable under this subparagraph”).
42
“(a) Whoever commits an offense against the United States or aids, abets, counsels, commands, induces or procures
its commission, is punishable as a principal.
“(b) Whoever willfully causes an act to be done which if directly performed by him or another would be an offense
against the United States, is punishable as a principal,” 18 U.S.C. 2; see generally, Blakey & Roddy, Reflections on
Reves v. Ernst & Young: Meaning and Impact on Substantive, Accessory, Aiding Abetting and Conspiracy Liability
Under RICO, 33 AMERICAN CRIMINAL LAW REVIEW 1345, 1385-418 (1996); see also, United States v. Yakou, 393 F.3d
231, 242 (D.C. Cir. 2005)(“The statute typically applies to any criminal statute unless Congress specifically carves out
an exception that precludes aiding and abetting liability, and it long has been established that a person can be convicted
of aiding and abetting another person’s violation of a statute even if it would be impossible to convict the aider and
abettor as a principal”)(citations omitted).
43
United States v. Rosemond, 134 S.Ct. 1240, 1245 (2014)(“[T]hose who provide knowing aid to persons committing
federal crimes, with the intent to facilitate the crime, are themselves committing a crime”); United States v. Garcia, 752
F.3d 382, 389 n.6 (4th Cir. 2014); United States v. Thum, 749 F.3d 1143, 1148-149 (9th Cir. 2014); United States v.
Lyons, 740 F.3d 702, 715 (1st Cir. 2014).

Congressional Research Service

11

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

The fact that subsection 1030(b) outlaws attempts to violate any of the prohibitions of subsection
1030(a) raises an interesting question concerning accessories. As a general rule, an accomplice
may only be liable as a principal or accessory before the fact, for a completed crime; the aid must
be given before the crime is committed, but liability as a principal will not attach until after the
crime has been committed.44 This does not bar conviction of one who aids or abets the
commission of a crime that never succeeds beyond the attempt phase, if, as in the case of
paragraph 1030(a)(3), attempt to commit the offense has been made a separate crime.45

Limited Application and State law
Beyond these auxiliary offenses and bases for criminal liability, the simple trespassing crime
created in paragraph 1030(a)(3) is the least likely of the seven crimes established in subsection
1030(a) to share coverage with other laws outside the section. Simply hacking into government
computers—without damage to the system, injury to the government, or gain by the hacker—
implicates only a few other laws. Computer trespassing in one form or another is an element of
most of the offenses proscribed in 18 U.S.C. 1030. Moreover, hacking into someone else’s e-mail
stored in a government computer system is likely to offend the federal statute that protects e-mail
and stored telephone company records, 18 U.S.C. 2701.46 Hackers who misidentify themselves in
order to gain access to a federal computer may be guilty of violating 18 U.S.C. 100147 and 18
44

United States v. Thum, 749 F.3d at 1148-149; United States v. Lyons, 740 F.3d at 715; United States v. Rufai, 732
F.3d 1175, 1190 (10th Cir. 2013); United States v. Capers, 708 F.3d 1286, 1306 (11th Cir. 2013).
45
United States v. Washington, 106 F.3d 983, 1004-5 (D.C.Cir. 1997)(“If the principal had actually attempted to
commit a crime but had failed, the aider and abettor would be charged with the same offense as the principal (attempt
to commit the crime)”); see also, United States v. Villanueva, 408 F.3d 193, 202 (5th Cir. 2005) (finding defendant
guilty of aiding and abetting an attempted crime); United States v. Gardner, 488 F.3d 700, 711 (6th Cir. 2007)(aiding
and abetting attempted possession of cocaine).
46
“(a) Offense.B Except as provided in subsection (c) of this section whoever—(1) intentionally accesses without
authorization a facility through which an electronic communication service is provided; or (2) intentionally exceeds an
authorization to access that facility; and thereby obtains, alters, or prevents authorized access to a wire or electronic
communication while it is in electronic storage in such system shall be punished as provided in subsection (b) of this
section.
“(b) Punishment.B The punishment for an offense under subsection (a) of this section isB (1) if the offense is
committed for purposes of commercial advantage, malicious destruction or damage, or private commercial gain or in
furtherance of any criminal or tortious act in violation of the Constitution or laws of the United States or any StateB (A)
a fine under this title or imprisonment for not more than 5 years, or both, in the case of a first offense under this
subparagraph; and (B) a fine under this title or imprisonment for not more than 10 years, or both, for any subsequent
offense under this subparagraph; and (2) in any other caseB (A) a fine under this title or imprisonment for not more than
1 year or both, in the case of a first offense under this paragraph; and (B) a fine under this title or imprisonment for not
more than 5 years, or both, in the case of an offense under this subparagraph that occurs after a conviction of another
offense under this section.
“(c) Exceptions.B Subsection (a) of this section does not apply with respect to conduct authorized B (1) by the person
or entity providing a wire or electronic communications service; (2) by a user of that service with respect to a
communication of or intended for that user; or (3) in section 2703, 2704 or 2518 of this title,” 18 U.S.C. 2701.
The provisions of 18 U.S.C. 2511 (wiretapping) may apply to the unlawful interception of e-mail transmissions while
in transit and 18 U.S.C. 2701 may apply to the unlawful seizure of stored e-mail. Offenses under §2511 are punishable
by imprisonment for not more than 5 years as well, 18 U.S.C. 2511(4).
47
“(a) Except as otherwise provided in this section, whoever, in any matter within the jurisdiction of the executive,
legislative, or judicial branch of the Government of the United States, knowingly and willfully—(1) falsifies, conceals,
or covers up by any trick, scheme, or device a material fact; (2) makes any materially false, fictitious, or fraudulent
statement or representation; or (3) makes or uses any false writing or document knowing the same to contain any
materially false, fictitious, or fraudulent statement or entry; shall be fined under this title or imprisoned not more than 5
years or, if the offense involves international or domestic terrorism (as defined in section 2331), imprisoned not more
(continued...)

Congressional Research Service

12

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

U.S.C. 912,48 in the view of at least one commentator.49 The case law may make the claim
difficult to defend. The Supreme Court has suggested that §1001 should be constructed
narrowly,50 and the courts have consistently held that the false statement must somehow tend to
adversely impact the functioning of a governmental agency or department to trigger coverage
under §1001.51 Cases in other contexts demonstrate the difficulty of convincing the courts that
simple trespassing in government cyberspace has an adverse impact upon the government.52
The difficulty with using the impersonation statute, 18 U.S.C. 912, is that it requires a showing of
an official act or of a fraud, something that need not be proven for conviction under paragraph
1030(a)(3).53 Like 18 U.S.C. 1001, §912 may be more appropriately employed in cases falling
under the ambit of paragraph 1030(a)(4) (unauthorized access of a government computer, bank
computer, or computer in interstate or foreign commerce as integral part of a scheme to fraud).

(...continued)
than 8 years, or both.
“(b) Subsection (a) does not apply to a party to a judicial proceeding, or that party’s counsel, for statements,
representations, writings or documents submitted by such party or counsel to a judge or magistrate in that proceeding.
“(c) With respect to any matter within the jurisdiction of the legislative branch, subsection (a) shall apply only to—(1)
administrative matters, including a claim for payment, a matter related to the procurement of property or services,
personnel or employment practices, or support services, or a document required by law, rule, or regulation to be
submitted to the Congress or any office or officer within the legislative branch; or (2) any investigation or review,
conducted pursuant to the authority of any committee, subcommittee, commission or office of the Congress, consistent
with applicable rules of the House or Senate,” 18 U.S.C. 1001; see generally, Twenty-Eighth Survey of White Collar
Crime: False Statements and False Claims, 50 AMERICAN CRIMINAL LAW REVIEW 953 (2013).
48
“Whoever falsely assumes or pretends to be an officer or employee acting under the authority of the United States or
any department, agency or officer thereof, and acts as such, or in such pretended character demands or obtains any
money, paper, document, or thing of value, shall be fined under this title or imprisoned not more than three years, or
both,” 18 U.S.C. 912.
49
Olivenbaum, : Rethinking Federal Computer Legislation, 27 SETON HALL LAW REVIEW
574, 600 (1997)(citing an instance from the infancy of §1030 where a hacker was indicted under the false statement, 18
U.S.C. 1001, and wire fraud, 18 U.S.C. 1343, statute. The case ended when the defendant pled to a misdemeanor fraud
charge). No comparable prosecutions followed and so the author’s thesis remains unproven.
50
Hubbard v. United States, 514 U.S. 695 (1995)(overturning an earlier holding that §1001 applied to false statements
made to federal courts and to Congress as well as those made to the executive branch)(superseded by statute, P.L. 104292, 110 Stat. 3459 (1996)(the modification preserved the exception that it did not apply “to a party to a judicial
proceeding, or that party’s counsel, for statements, representations, writings or documents submitted by such party or
counsel to a judge or magistrate in that proceeding.”)(§1001(b)); United States v. Gaudin, 515 U.S. 509 (1995)(holding
that materiality of the false statement, as an element of §1001, is a question for the jury to decide).
51
United States v. Gaudin, 515 U.S. 506, 509 (1995)(“[T]he statement must have a natural tendency to influence, or be
capable of influencing the decision of the decision-making body to which it was addressed”); United States v. Baker,
200 F.3d 558, 561 (8th Cir. 2000) (“The materiality inquiry focuses on whether the false statement had a natural
tendency to influence or was capable of influencing the government agency or official”). United States v. Mitchell, 388
F.3d 1139, 1143 (8th Cir. 2004) (noting that a false statement must have “a natural tendency to influence or is capable
of influencing the government agency or official” and that “[m]ateriality does not require proof that the government
actually relied on the statement”); but see, United States v. Safavian, 649 F.3d 688, 691 (D.C. Cir. 2011)(“[A]
statement need not actually influence an agency in order to be material; it need only have a natural tendency to
influence or be capable of influencing an agency function or decision”).
52
United States v. Collins, 56 F.3d 1416 (D.C.Cir. 1995) and United States v. Czubinski, 106 F.3d 1069 (1st Cir. 1997),
overturned convictions under 18 U.S.C. 641 (theft of government property), and 18 U.S.C. 1343 (wire fraud) and
1030(a)(4)(computer fraud) respectively, on the ground that the prosecution had failed to show any adverse impact
upon the government caused by the defendant’s unauthorized access of government computer files.
53
“Whoever ... pretends to be an officer ... acting under the authority of the United States ... and acts as such, or in
such pretended character demands or obtains any ... thing of value,” 18 U.S.C. 912 (emphasis added).

Congressional Research Service

13

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Simple computer trespassing is also a crime under the anti-hacking laws of most of the states.54

Obtaining Information by Unauthorized Computer
Access (18 U.S.C. 1030(a)(2))
(a) Whoever ... (2) intentionally accesses a computer without authorization or exceeds
authorized access, and thereby obtains B
(A) information contained in a financial record of a financial institution, or of a card
issuer as defined in [s]ection 1602(n) of title 15,55 or contained in a file of a consumer
reporting agency on a consumer, as such terms are defined in the Fair Credit Reporting
Act (15 U.S.C. 1681 et seq.);56
(B) information from any department or agency of the United States; or
(C) information from any protected computer ...
shall be punished as provided in subsection (c) of this section.
(b) Whoever attempts to commit an offense under subsection (a) of this section shall be
punished as provided in subsection (c) of this section.

One step beyond simple hacking is the prohibition against acquiring certain protected information
by intentional unauthorized computer access.57 As a practical matter, in any instance involving a
54
E.g., ALA. CODE §13A-8-102; ALASKA STAT. §11.46.484; ARIZ. REV. STAT. ANN. §13-2316; ARK. CODE ANN. §5-41104; CAL. PENAL CODE §502; COLO. REV. STAT. ANN. §18-5.5-102; CONN. GEN. STAT. ANN. §53a-251; DEL. CODE
ANN. tit.11 §932; FLA. STAT. ANN. §815.06; HAWAII REV. STAT. §708-895.7; IDAHO CODE §18-2202; 720 ILL. COMP.
STAT. ANN. §5/17-51; IND. CODE ANN. §35-43-2-3; IOWA CODE ANN. §716.6B; KAN. STAT. ANN. §21-5839; KY. REV.
STAT. ANN. §434.853; LA. REV. STAT. ANN. §14:73.7; ME. REV. STAT. ANN. tit.17-A §432; MD. CODE ANN. CRIM. LAW
§7-302; MASS. GEN. LAWS ANN. ch.266 §120F; MICH. COMP. LAWS §752.795; MINN. STAT. ANN. §609.891; MISS.
CODE ANN. §97-45-5; MO. ANN. STAT. §569.099; MONT. CODE ANN. §45-6-311; NEB. REV. STAT. §28-1347; NEV. REV.
STAT. §205.4765; N.H. REV. STAT. ANN. §638:17; N.M. STAT. ANN. §30-45-5; N.Y. PENAL LAW §156.05; OHIO REV.
CODE ANN. §2913.04; OKLA. STAT. ANN. tit.21 §1953; S.D. COD. LAWS §43-43B-1; TENN. CODE ANN. §39-14-602;
TEX. PENAL CODE ANN. §33.02; UTAH CODE ANN. §76-6-703; VT. STAT. ANN. tit.13 §4102; WASH. REV. CODE ANN.
§9A.52.120; W.VA. CODE ANN. §61-3C-5; WIS. STAT. ANN. §943.70; WYO. STAT. §6-3-504.
55
“The term ‘card issuer’ means any person who issues a credit card, or the agent of such person with respect to such
card,” 15 U.S.C. 1602(n).
“The term ‘person’ means a natural person or an organization. The term ‘organization’ means a corporation,
government or governmental subdivision or agency, trust, estate, partnership, cooperative, or association. The term
‘credit card’ means any card, plate, coupon book or other credit device existing for the purpose of obtaining money,
property, labor, or services on credit. The term ‘credit’ means the right granted by a creditor to a debtor to defer
payment of debt or to incur debt and defer its payment.
“The term ‘creditor’ refers only to a person who both (1) regularly extends, whether in connection with loans, sales of
property or services, or otherwise, consumer credit which is payable by agreement in more than four installments or for
which the payment of a finance charge is or may be required, and (2) is the person to whom the debt arising from the
consumer credit transaction is initially payable on the face of the evidence of indebtedness or, if there is no such
evidence of indebtedness, by agreement. Notwithstanding the preceding sentence, in the case of an open-end credit plan
involving a credit card, the card issuer and any person who honors the credit card and offers a discount which is a
finance charge are creditors ...” 15 U.S.C. 1602(d), (c),(k), (e), and (f), respectively.
56
“The term ‘file’, when used in connection with information on any consumer, means all of the information on that
consumer recorded and retained by a consumer reporting agency regardless of how the information is stored.
“The term ‘consumer reporting agency’ means any person which, for monetary fees, dues, or on a cooperative
nonprofit basis, regularly engages in whole or in part in the practice of assembling or evaluating consumer credit
information or other information on consumers for the purpose of furnishing consumer reports to third parties, and
which uses any means or facility of interstate commerce for the purpose of preparing or furnishing consumer reports.
“The term ‘consumer’ means an individual,” 15 U.S.C. 1681a(g), (f) and (c), respectively.
57
“To prove a violation of [subparagraph 1030](a)(2)(C), the Government must show that the defendant (1)
(continued...)

Congressional Research Service

14

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

government computer it may be very difficult to distinguish between cases evidencing a violation
of the simple trespass proscriptions of paragraph 1030(a)(3) and the trespassing-withinformation-acquisition prohibitions of paragraph 1030(a)(2). The history of the trespass
provisions speaks clearly of an intent to place beyond their reach whistleblowers and other federal
employees for simple trespassing with respect to computers within their own agency. This
explains the absence of an “exceeds-authorized-access” provision in the trespassing provisions of
paragraph 1030(a)(3). But the trespass-and-be-exposed-to-information provisions of paragraph
1030(a)(2) do feature a “exceeds-authorized-access” clause and seem facially applicable to
whistleblowers. It remains to be seen whether the courts will read paragraph 1030(a)(2) as
effectively amending the simple trespassing provisions of paragraph 1030(a)(3) or will attempt to
reconcile the two.
In any event, to sustain a conviction under paragraph 1030(a)(2), “the Government must prove
that the defendant (1) intentionally (2) accessed without authorization (or exceeded authorized
access to) a (3) protected computer and (4) thereby obtained information.”58

Intent
The intent requirement is the same as that required in the case of simple trespassing. The offender
must have “intentionally” gained access. The paragraph only bans “intentional” trespassing. As in
the case of simple trespassing the intent element can be satisfied by anyone who purposefully
gains access to a computer covered by the paragraph or by anyone “whose initial access was
inadvertent but who then deliberatively maintains access after a non-intentional initial contact.”59
Moreover, the government need not show that the trespass was committed to defraud or for any
other purpose for that matter.60

Unauthorized Access
Thus far, the courts have experienced some difficulty applying the terms “without authorization”
and “exceeds authorized access” as used in paragraph 1030(a)(2) and the other paragraphs of 18
U.S.C. 1030, even though the statute supplies a specific definition of the term “exceeds
(...continued)
intentionally accessed a computer, (2) without authorization (or exceeding authorized access), (3) and thereby obtained
information from any protected computer if the conduct involved interstate or foreign communication,” United States v.
Willis, 476 F.3d 1121, 1125 (10th Cir. 2007); Ticketmaster L.L.C. v. RMG Technologies, Inc., 507 F.Supp.2d. 1096,
1113 (C.D. Cal. 2007). The third element of the offense becomes—“thereby obtained information from a financial
institution” or “thereby obtained information from a federal agency”—when the violation involves subparagraphs
1030(a)(2)(A)(relating to obtaining financial institution information) or 1030(a)(2)(B)(relating to obtaining federal
agency information).
58
United States v. Auernheimer, 748 F.3d 525, 533 (3d Cir. 2014); see also, United States v. Teague, 646 F.3d 1119,
1122 (8th Cir. 2011); United States v. Willis, 476 F.3d 1121, 1125 (10th Cir. 2007).
59
H.Rept. 99-612 at 9-10 (1986); see also, S.Rept. 99-432 at 5-6 (1986)(“[S]uch conduct ... must have been the
person’s conscious objective”); Butera & Andrews v. IBM, Inc., 456 F.Supp.2d 104, 110 (D.D.C. 2006); United States
v. Drew, 259 F.R.D. 449, 459 (C.D.Cal. 2009), quoting, United States v. Willis, 476 F.3d at 1125 (“Under
§1030(a)(2)(C), the ‘requisite intent’ is ‘to obtain unauthorized access of a protected computer’”).
60
United States v. Rodriguez, 628 F.3d 1258, 1264 (11th Cir. 2010); United States v. Willis, 476 F.3d at 1125; see also,
United States v. Nosal, 676 F.3d 854, 859 (9th Cir. 2012)(emphasis of the court)(“In the case of the CFAA, the broadest
provision is subsection 1030(a)(2)(C), which makes it a crime to exceed authorized access of a computer connected to
the Internet without any culpable intent”).

Congressional Research Service

15

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

authorized access.”61 Some have applied the terms to access by authorized employees who use
their access in any unauthorized manner or for unauthorized purposes and to access by outsiders
who have been granted access subject to explicit reservations.62 Others have concluded that “a
person who ‘intentionally accesses a computer without authorization’ §§1030(a)(2) and (4),
accesses a computer without any permission at all, while a person who ‘exceeds authorized
access,’ id., has permission to access the computer, but accesses information on the computer that
the person is not entitled to access.”63 One court concluded that the conscious breach of
MySpace’s terms of service could “potentially constitute accessing the MySpace computer/server
without authorization and/or in excess of authorization.”64 The court, however, went on to find the
section unconstitutionally vague under such a construction, “if any conscious breach of a
website’s terms of service is held to be sufficient by itself to constitute intentionally accessing a
computer without authorization or in excess of authorization, the result will be that section
1030(a)(2)(C) becomes a law ‘that affords too much discretion to the police and too little notice
to citizens who wish to use the [Internet].’”65

61

18 U.S.C. 1030(e)(6)(“[T]he term ‘exceeds authorized access’ means to access a computer with authorization and to
use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter”).
62
United States v. Rodriguez, 628 F.3d 1258, 1263 (11th Cir. 2010); United States v. John, 597 F.3d 263, 270-73 (5th
Cir. 2010); Shurgard Storage Centers v. Safeguard Self Storage, 119 F. Supp. 2d 1121, 1124-125 (W.D. Wash. 2000)
(unauthorized access found when employees used their access to benefit a competitor); YourNetDating v. Mitchell, 88
F. Supp. 2d 870, 872 (N.D. Ill. 2000) (former employee found to be exceeding authorized access because he used his
access codes to divert users from his ex-employer’s website); Southwest Airlines Co. v. Farecase, Inc., 318 F.Supp.2d
435, 439-40 (N.D. Tex. 2004) (use of software to gather fare information from airline’s website in spite of “no
scraping” warnings constitutes a violation of paragraph 1030(a)(2)).
63
LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1133 (9th Cir. 2009); see also, WEC Carolona Energy Solutions LLC
v. Miller, 687 F.3d 199, 203 (4th Cir. 2012)(“CFAA fails to provide a remedy for misappropriation of trade secrets or
violation of a use policy where authorization has not been rescinded”); Lewis-Burke Assoc. LLC v. Widder, 725
F.Supp.2d 187, 192-93 (D.D.C. 2010); US Bioservices Corp. v. Lugo, 595 F.Supp.2d 1189, 1192 (D.Kan. 2009)(citing
cases on either side of the divide); Bell Aerospace Services, Inc. v. U.S. Aero Services, Inc., 690 F.Supp.2d 1267, 1272
(M.D.Ala. 2010)(“‘Exceeds authorized access’ should not confused with exceeds authorized use”).
64
United States v. Drew, 259 F.R.D. 449, 461 (C.D.Cal. 2009).
65
Id. at 467, quoting Chicago v. Morales, 527 U.S. 41, 64 (1999). The Ninth Circuit in Nosal agreed, United States v.
Nosal, 676 F.3d 854, 860-63 (9th Cir. 2011)(internal citations omitted)(“Minds have wandered since the beginning of
time and the computer gives employees new ways to procrastinate, by g-chatting with friends, playing games, shopping
or watching sports highlights. Such activities are routinely prohibited by many computer-use policies, although
employees are seldom disciplined for occasional use of work computers for personal purposes. Nevertheless, under the
broad interpretation of the CFAA, such minor dalliances would become federal crimes. . . . Employers wanting to rid
themselves of troublesome employees without following proper procedures could threaten to report them to the FBI
unless they quit. Ubiquitous, seldom prosecuted crimes invite arbitrary and discriminatory enforcement. . . . The effect
this broad construction of the CFAA has on workplace conduct pales by comparison with its effect on everyone else
who uses a computer. . . . [U]p until very recently, Google forbade minors from using its services. Adopting the
government’s interpretation would turn vast numbers of teens and pre-teens into juvenile delinquents—and their
parents and teachers into delinquency contributors. . . . Or consider the numerous dating websites whose terms of use
prohibit inaccurate or misleading information. Or eBay and Craigslist, where it’s a violation of the terms of use to post
items in an inappropriate category. Under the government’s proposed interpretation of the CFAA, posting for sale an
item prohibited by Craigslist’s policy, or describing yourself as ‘tall, dark and handsome,’ when you’re actually short
and homely, will earn you a handsome orange jumpsuit. . . . The government assures us that, whatever the scope of the
CFAA, it won’t prosecute minor violations. But we shouldn’t have to live at the mercy of our local prosecutor. And it’s
not clear we can trust the government when a tempting target comes along. Take the case of the mom who posed as a
17-year-old boy and cyber –bullied her daughter’s classmate. The Justice Department prosecuted her under 18 U.S.C.
§1030(a)(2)(C) for violating MySpace’s terms of service, which prohibited lying about identifying information,
including age. . . . [W]e continue to follow in the path blazed by Brekka, and the growing number of courts that have
reached the same conclusion . . . the plain language of the CFAA targets the unauthorized procurement or alternation of
information, not its misuse or misappropriation”).

Congressional Research Service

16

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Obtaining Information and Jurisdiction
Paragraph 1030(a)(2) is at once more and less restricted than the simple trespassing proscription
of paragraph 1030(a)(3). On one hand, its prosecution requires more than a simple trespass.66 On
the other hand, it covers a wider range of computers. Paragraph 1030(a)(2), unlike 1030(a)(3),
covers more than government computers. It covers computers from which three types of
information may be obtained—information of the federal government, consumer credit or other
kinds of financial information, and information acquired from a protected computer.
The protection for financial information has its origins in the initial legislation and was among the
first adjusted. Comments from the Senate report accompanying the 1986 amendments illustrate
the intended scope of the protection for financial information:
“The premise of 18 U.S.C. 1030(a)(2) will remain the protection, for privacy reasons, of
computerized credit records and computerized information relating to customers’
relationships with financial institutions. This protection is imperative in light of the sensitive
and personal financial information contained in such computer files. However, by referring
to the Right to Financial Privacy Act, the current statute limits its coverage to financial
institution customers who are individuals, or are partnerships with five or fewer partners.
The Committee intends ... to extend the same privacy protections to the financial records of
all customers—individual, partnership, or corporate—of financial institutions.
“The Department of Justice has expressed concerns that the term ‘obtains information’ in 18
U.S.C. 1030(a)(2) makes that subsection more than an unauthorized access offense, i.e., that
it might require the prosecution to prove asportation of the data in question. Because the
premise of this subsection is privacy protection, the Committee wishes to make clear that
‘obtaining information’ in this context includes mere observation of the data. Actual
asportation, in the sense of physically removing the data from its original location or
transcribing the data, need not be proved in order to establish a violation of this subsection,”
S.Rept. 99-432 at 6-7 (1986).

The committee explanation of the language amending paragraph 1030(a)(2), ultimately enacted as
part of the Economic Espionage Act of 1996, endorsed this reading and extended it to cover
information obtained from federal computers and information secured by interstate or overseas
cyberspace trespassing:
“‘Information’ as used in this subsection [1030(a)(2)] includes information stored in
intangible form. Moreover, the term ‘obtaining information’ includes merely reading it.
There is no requirement that the information be copied or transported. This is critically
important because, in an electronic environment, information can be ‘stolen’ without
asportation, and the original usually remains intact. This interpretation of ‘obtaining
information’ is consistent with congressional intent expressed ... in connection with 1986
amendments to the Computer Fraud and Abuse statute....
“The proposed subsection 1030(a)(2)(C) is intended to protect against the interstate or
foreign theft of information by computer. This information, stored electronically, is
intangible, and it has been held that the theft of such information cannot be charged under
66

Yet it may not require a great deal more than a paragraph 1030(a)(3) prosecution, since merely viewing material on a
computer screen has been found to constitute obtaining information for purposes of paragraph 1030(a)(2), Healthcare
Advocates, Inc. v. Harding, Early, Follmer & Frailey, 497 F.Supp.2d 627, 648 (E.D. Pa. 2007), citing S.Rept. 99-432
at 6-7 (1986).

Congressional Research Service

17

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

more traditional criminal statutes such as Interstate Transportation of Stolen Property Act, 18
U.S.C. 2314. See United States v. Brown, 925 F.2d 1301, 1308 (10th Cir. 1991). This
subsection would ensure that the theft of intangible information by the unauthorized use of a
computer is prohibited in the same way theft of physical items are protected. In instances
where the information stolen is also copyrighted, the theft may implicate certain rights under
the copyright laws. The crux of the offense under subsection 1030(a)(2)(C), however, is the
abuse of a computer to obtain the information,” S.Rept. 104-357 at 6-7 (1996).

The Identity Theft Enforcement and Restitution Act of 2008 expanded the reach of paragraph
1030(a)(2) when it eliminated the requirement that the forbidden access “involve[] an interstate or
foreign communication”67 and then redefined “protected computer” to include computers
“affecting” interstate or foreign commerce. The elimination permits authorities to “address the
increasing number of computer hacking crimes that involve computers located within the same
state.”68 The expansion from computers used in interstate or foreign commerce to computers used
in or affecting such commerce extends coverage beyond computers with an interstate Internet
connection and appears to encompass any freestanding or other computer that has at least a de
minimis impact on commerce.69 A computer that accesses the Internet is a computer used in
interstate or foreign commerce.70
The earlier USA PATRIOT Act amendment of the definition of “protected computer” confirmed
Congress’s intent to proscribe unauthorized access and information acquisition from abroad with
respect to protected computers.71 A closer question may be whether in doing so it forecloses
extraterritorial application of paragraph 1030(a)(2) in other situations, for example, unauthorized
access to federal computer or computer networks located overseas.

67

The deleted phrase required “that the conduct of unlawfully accessing a computer, and not the obtained information
... involve an interstate or foreign communication,” Patrick Patterson Custom Homes v. Bach, 586 F.Supp.2d 1026,
1033 (N.D.Ill. 2008).
68
153 Cong. Rec. S14570 (daily ed. November 15, 2007)(remarks of Sen. Leahy).
69
The courts have generally held that only a slight impact on commerce is necessary to satisfy an offense’s “affect on
interstate or foreign commerce” element, United States v. Davis, 750 F.3d 1186, 1193 n.7 (10th Cir. 2014); United
States v. Kivanc, 714 F.3d 782, 796 (4th Cir. 2013); United States v. Gelin, 712 F.3d 612, 620-12 (1st Cir. 2013); United
States v. Mann,701 F.3d 274, 295 (8th Cir. 2012); United States v. Kincaid-Chauncey, 556 F.3d 923, 936 (9th Cir.
2009); United States v. Mejia, 545 F.3d 179, 203 (2d Cir. 2008); United States v. DeCologero, 53 F.3d 36, 37-8 (1st Cir.
2008); cf., Gonzales v. Raich, 545 U.S. 1, 17 (2005)(internal quotation marks omitted)(“[W]hen a general regulatory
statute bears a substantial relation to commerce, the de minimis character of individual instances arising under that
statute is of no consequences”). Section 207 of the Identity Theft Enforcement and Restitution Act added “or affecting”
to the definition of “protected computer,” P.L. 110-326, 122 Stat. 3563 (2008). Before the amendment, when the
definition was confined to computers “used in interstate or foreign commerce or communication,” the courts had
concluded that “a computer that provides access to worldwide communications through applications accessible through
the internet qualifies as a protected computer,” Patrick Patterson Custom Homes, Inc. v. Bach, 586 F.Supp.2d 1026,
1032 (N.D. Ill. 2008).
70
United States v. Drew, 259 F.R.D. 449, 457-58 (C.D.Cal. 2009), quoting, United States v. Sutcliffe, 505 F.3d 944,
952 (9th Cir. 2007)(“We are therefore in agreement with the Eighth Circuit’s conclusion that as both the means to
engage in commerce and the method by which transactions occur, the Internet is an instrumentality and channel of
interstate commerce. United States v. Trotter, 478 F.3d 918, 921 (8th Cir. 2007)(per curiam)(quoting United States v.
MacEwan, 445 F.3d 237, 245 (3d Cir. 2006))”).
71
“As used in this section ... (2) the term ‘protected computer’ means a computer ... (B) which is used in or affecting
interstate or foreign commerce or communication, including a computer located outside the United States that is
used in a manner that affects interstate or foreign commerce or communication of the United States,” 18
U.S.C. 1030(e)(2)(B)(language of the USA PATRIOT Act amendment in enlarged italics; 2008 amendment in regular
italics).

Congressional Research Service

18

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Consequences
The simple trespass offenses condemned in paragraph 1030(a)(3) are unlikely to significantly
implicate the Sentencing Guidelines, restitution, forfeiture, or civil liability provisions elsewhere
in the law. Not so paragraph 1030(a)(2) offenses. Criminal penalties attend it, but so do other
consequences.

Penalties
Paragraph 1030(a)(2) has a three tier sentencing structure. Simple violations are punished as
misdemeanors, imprisonment for not more than one year and/or a fine of not more than $100,000
($200,000 for organizations).72
The second tier carries penalties of imprisonment for not more than five years and/or a fine of not
more $250,000 ($500,000 for organizations) and is reserved for cases in which “(i) the offense
was committed for purposes of commercial advantage or private financial gain; (ii) the offense
was committed in furtherance of any criminal or tortious act in violation of the Constitution or
laws of the United States or of any State; or (iii) the value of the information obtained exceeds
$5,000.”73
This second level was added in 1996. With respect to the alternative thresholds, (i) and (ii), “[t]he
terms ‘for purposes of commercial advantage or private financial gain’ and ‘for the purpose of
committing any criminal or tortious act’ are taken from the copyright statute (17 U.S.C. 506(a))
and the wiretap statute (18 U.S.C. 2511[(2)] (d)), respectively, and are intended to have the same
meaning as in those statutes.”74 The references to copyright and wiretap law may be less
instructive than Congress anticipated for the phrases in question are of uncertain meaning in their
original settings.75 Nevertheless, the phrases seems to contemplate some criminal, tortious, or
financially advantageous purpose beyond the computer-trespassing-and-obtaining-information
misconduct outlawed in the paragraph generally. Otherwise nothing would be left to be punished
as a misdemeanor and the $5,000 distinction of exception (iii) would be swallowed up as well.76
As for exception (iii), the value of information acquired by a hacker may not always be easily
ascertained. In the absence of evidence of fair market value, one appellate court approved the
district court’s use of the cost of production to assess the value of information acquired in
72

18 U.S.C. 1030(c)(2)(A), 3571.
18 U.S.C. 1030(c)(2)(B), 3571.
74
S.Rept. 104-357 at 8 (1996).
75
4 NIMMER & NIMMER, NIMMER ON COPYRIGHT §15.01 n.1.2 (1997) (emphasis added)(“Apparently, the phrase
‘commercial advantage or private financial gain’ is intended as the equivalent of ‘for profit’”); 1 FISHMAN &
MCKENNA, WIRETAPPING AND EAVESDROPPING, THIRD EDITION §3:38 (2010) comparing, Stockler v. Garratt, 893 F.2d
856 (6th Cir. 1990), with, By-Product Corp. v. Armen-Berry Co., 668 F.2d 956 (7th Cir. 1982)(in disagreement over
whether an offender must act upon his or her criminal or tortious purpose after recording a conversation to which they
are a party or where one party to the conversation has consented to the recording).
76
However, the presence of a mirror-image state computer crime statute may be enough to justify enhancement, i.e.,—
no more than hacking in violation of a state hacking law, United States v. Auernheimer, 748 F.3d 525, 533 (3d Cir.
2014)(reversing for want of proper venue)(“Count one charged Auernheimer with conspiracy to violate CFAA
§1030(a)(2)(C) and (c)(2)(B)(ii). In the indictment and at trial, the Government identified the nature of the conduct
constituting the offense as the agreement to commit a violation of CFAA in furtherance of a violation of New Jersey’s
computer crime statute”).
73

Congressional Research Service

19

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

violation of subsection 1030(a)(2).77 It suggested, however, any calculation reasonable under the
circumstances might be acceptable.78
The third tier is for repeat offenders whose punishment is increased to imprisonment of not more
than 10 years and/or a fine of not more than $250,000 ($500,000 for organizations) for a second
or subsequent conviction.79
Federal law is no more hospitable to the prosecution of juveniles for the intrusion plus
information acquisition offenses under paragraph 1030(a)(2) than it is for the simple trespass
offenses under paragraph 1030(a)(3). Essentially, federal proceedings are only possible if the state
in which the offense occurs is unwilling or unable to proceed.80

Sentencing Guidelines
The Sentencing Guidelines color the procedure under which the penalties for serious federal
crimes are imposed.81 They were established to eliminate sentencing disparity among cases
involving the same offense and to ensure that the sentences imposed reflect the relative
seriousness of the circumstances under which the offense was committed in a given case.82 As a
general rule, the Guidelines assign each federal crime to a particular guideline.83 The individual
guideline in turn assigns a beginning number (base offense level) and then adds and subtracts
from that number based on the presence of designated aggravating or mitigating circumstances.84
The final total translates to an authorized sentencing range in months of imprisonment and dollars
of fines.85
77

United States v. Batti, 631 F.3d 371, 378 (6th Cir. 2011).
Id. (“With this approach in mind, we believe that, where information obtained by a violation of §1030(c)(2)(B)(iii)
does not have a readily ascertainable market value, it is reasonable to use the cost of production as a means to
determine the value of the information obtained. . . . §1030(a)(2)(C) protects, broadly, ‘information [obtained] from any
protected computer,’ and it is often the case, as it was here, that this information is intangible and lacks any easily
ascertainable market value. In such circumstances, we approve of the use of ‘any reasonable method’ to determine the
value of information obtained by a breach . . . . We recognize, however, that, given the broad nature of the statute,
violations of §1030(a)(2)(C) may arise in many different contexts. We therefore express no opinion regarding either the
propriety of other methods by which to calculate the value of information obtained under 18 U.S.C. §1030(a)(2)(C) and
(c)(2)(B)(iii) or the applicability of the method we approve today to dissimilar factual circumstances”).
79
18 U.S.C. 1030(c), 3571.
80
18 U.S.C. 5032.
81
At one time, federal sentencing courts were essentially bound by the Guidelines, 18 U.S.C. 3553(b)(1). Booker
changed that, see United States v. Booker, 543 U.S. 220, 245 (2005)(“We answer the question of remedy by finding the
provision of the federal sentencing statute that makes the Guidelines mandatory, 18 U.S.C.A. 3553(b)(1)(Supp. 2004),
incompatible with today’s constitutional holding. We conclude that this provision must be severed and excised....”).
Now, federal sentencing courts must begin by identifying the appropriate sentencing range under the Guidelines, but
enjoy discretion to make justifiable reasonable departures, Gall v. United States, 552 U.S. 38, 49-53 (2007). The
Identity Theft Enforcement and Restitution Act directed the United States Sentencing Commission to re-examine, for
consistency with the tenor of the act, the sentencing guidelines and policy statements applicable to those convicted of
violations of §1030 as well as those convicted of violating 18 U.S.C. 1028 (identity fraud), 1028A (aggravated identity
theft), 2511 (wiretapping), and 2701 (stored electronic communications and communications records), §209, P.L. 110326, 122 Stat. 3564 (2008).
82
S.Rept. 98-225, at 50-2 (1983).
83
U.S.S.G. §§1B1.1, 8A1.2.
84
Id.
85
U.S.S.G. ch.5, pt.A, §5E1.2, ch.8 pt.C.
78

Congressional Research Service

20

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Violations of paragraph 1030(a)(2) are governed by U.S.S.G. §2B1.1 which sets the base offense
level at 6. The Tenth Circuit’s opinion in Willis provides an example of the process from that
point:
The District Court agreed with the Government and found Ms. Fischer’s conduct [which
resulted in losses of more than $10,000] foreseeable to [her accomplice] Mr. Willis. It
therefore imposed a 4-level enhancement on Mr. Willis’s base offense level.86
It also applied the §2B1.1(b)(10)(C)(i) enhancement because the offense involved using a
means of identification to produce another means of identification,87as well as the §3B1.3
enhancement because Mr. Willis abused a position of trust.88 This produced an adjusted
offense level of 14, which when coupled with his criminal history category of V, resulted in
an advisory Guideline range of 33 to 41 months. The District Court sentenced Mr. Willis to
41 months’ imprisonment.89

Although not mentioned in Willis, the Guidelines now add 2-6 offense levels if the offense
involves a critical infrastructure computer90 and 2 levels if the information acquired is personal
information.91

Forfeiture
Under the general forfeiture provisions, “[a]ny property, real or personal, which constitutes or is
derived from proceeds traceable, to a violation of section ... 1030” is subject to confiscation by
the United States under either the general civil or criminal forfeiture provisions.92 The Identity
86

United States v. Willis, 476 F.3d 1121, 1127-128 (10th Cir. 2007), citing U.S.S.G. §2B1.1(b)(1)(C). Paragraph
2B1.1(b)(1) instructs a sentencing court to increase to an offender’s offense level under §2B1.1 according to the
amount of the loss associated with the offense. In Mr. Willis’s case, the loss was more than $10,000 but less than
$30,000. Had it been more than $30,000 but less than $70,000 an increase of 6 would have been appropriate. The
enhancements are calibrated to account for losses from $5,000 (add 2) to more than $4 million (add 30).
87
Id. at 1128. U.S.S.G. §2B1.1(b)(10)(C)(i) states, “If the offense involved ...(C)(i) the unauthorized transfer or use of
any means of identification unlawfully to produce or obtain any other means of identification ... increase by 2 levels.”
Mr. Willis had given Ms. Fischer a username and password that gave her unauthorized access to a financial information
database, which she used in an identity theft scheme.
88
Id. U.S.S.G. §3b1.3 states, “If the defendant abused a position of public or private trust, or used a special skill, in a
manner that significantly facilitated the commission or concealment of the offense, increase by 2 levels.” Mr. Willis
acquired in his position as supervisor in a debt collection agency the username and password which he had then passed
on to his accomplice. Although not implicated here, the special skill enhancement is often implicated in the offenses
outlawed in the various paragraphs of 18 U.S.C. 1030.
89
Id. Mr. Willis had a fairly extensive record of previous convictions. Had he been a first time offender, his criminal
history category would have been I and his sentencing range at an offense level of 14 would have been 15 to 21
months, U.S.S.G. Ch.5, Pt. A (Sentencing Table).
90
U.S.S.G. §2B1.1(b)(17)(“(A)(Apply the greatest) If the defendant was convicted of an offense under: (i) 18 U.S.C.
§1030, and the offense involved a computer system used to maintain or operate a critical infrastructure, or used by or
for a government entity in furtherance of the administration of justice, national defense, or national security, increase
by 2 levels. (ii) 18 U.S.C. §1030(a)(5)(A), increase by 4 levels. (iii) 18 U.S.C. §1030, and the offense caused a
substantial disruption of a critical infrastructure, increase by 6 levels. (B) If subdivision (A)(iii) applies, and the offense
level is less than level 24, increase to level 24”).
91
U.S.S.G. §2B1.1(b)(16)(“If (A) the defendant was convicted of an offense under 18 U.S.C. §1030, and the offense
involved an intent to obtain personal information . . . increase by 2 levels”).
92
18 U.S.C. 981(a)(1)(C)(civil forfeiture); see also, 18 U.S.C 982(a)(2)(B)(criminal forfeiture)(“[A]ny property
constituting, or derived from proceeds the person obtained directly or indirectly, as the result of such violations”).
Criminal forfeiture is accomplished following the criminal prosecution of the property owner, 18 U.S.C. 982. Civil
(continued...)

Congressional Research Service

21

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Theft Enforcement and Restitution Act of 2008 inserted separate criminal and civil forfeiture
subsections within §1030.93 Section 1030 now authorizes confiscation pursuant to criminal
procedure both real and personal property derived from a violation of §1030,94 as well as any
personal property used or intended to be used to facilitate such a violation.95

Restitution
Restitution is victim compensation for loss or damage associated with the offense.96 Federal
courts must order a convicted defendant to pay restitution in the case of (i) a federal crime of
violence, or (ii) federal crime involving fraud or property damage, or (iii) a crime in which the
victim suffers physical injury or pecuniary loss.97 It is within the discretion of the court to order
restitution in the case of all other federal crimes proscribed in Title 18 of the United States
Code.98
Paragraph 1030(a)(2) acquisition offenses are not crimes of violence and restitution is therefore
not mandatory on those grounds. There, they come within the discretionary restitution provisions,
but those provisions have a limitation on the type of losses for which restitution may be ordered.99
The limitation, however, does not apply in the case of a plea bargain100 or when restitution is
ordered as a condition of probation or supervised release.101 On the other hand, the court may be
required to order restitution when the victim of the defendant’s computer security breach suffers a
pecuniary loss associated with its investigation of the breach.102

Civil Cause of Action
Subsection 1030(g) creates a cause of action for compensatory damages and injunctive relief for
the benefit of victims of any §1030 violation, but only if violation results in the kind of loss or
damage described in clauses 1030(c)(4)(A)(i)(I) through (V),103 that is:
(...continued)
forfeiture is accomplished through an in rem proceeding directed against the property itself, 18 U.S.C. 983. See
generally, CRS Report 97-139, Crime and Forfeiture.
93
18 U.S.C. 1030(i), (j).
94
18 U.S.C. 1030(i)(1)(B), 1030(j)(2).
95
18 U.S.C. 1030(i)(1)(A), 1030(j)(1).
96
See generally, CRS Report RL34138, Restitution in Federal Criminal Cases.
97
18 U.S.C. 3663A; e.g., United States v. Phillips, 477 F.3d 215, 224-25 (5th Cir. 2007)(restitution ordered for
violations of paragraph 1030(a)(5)(damage of a protected computer)).
98
18 U.S.C. 3663
99
“(b) The [restitution] order may require that such defendant—(1) in the case of an offense resulting in damage to or
loss or destruction of property of a victim of the offense—(A) return the property to the owner of the property or
someone designated by the owner; or (B) if return of the property under subparagraph (A) is impossible, impractical, or
inadequate, pay an amount equal to the greater of—(i) the value of the property on the date of the damage, loss, or
destruction, or (ii) the value of the property on the date of sentencing, less the value (as of the date the property is
returned) of any part of the property that is returned,” 18 U.S.C. 3663(b)(1).
100
18 U.S.C. 3663(a)(3).
101
18 U.S.C. 3563(b)(2), 3583(d)(3). Supervised release is a period of supervision to be served after an individual is
released from prison, 18 U.S.C. 3583(a).
102
E.g., United States v. Batti, 631 F.3d 371, 378 (8th Cir. 2011).
103
“Any person who suffers damage or loss by reason of a violation of this section may maintain a civil action against
(continued...)

Congressional Research Service

22

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

(I) loss to 1 or more persons during any 1-year period (and, for purposes of an investigation,
prosecution, or other proceeding brought by the United States only, loss resulting from a
related course of conduct affecting 1 or more other protected computers) aggregating at least
$5,000 in value;
(II) the modification or impairment, or potential modification or impairment, of the medical
examination, diagnosis, treatment, or care of 1 or more individuals;
(III) physical injury to any person;
(IV) a threat to public health or safety;
(V) damage affecting a computer system used by or for a government entity in furtherance of
the administration of justice, national defense, or national security;
(VI) damage affecting 10 or more protected computers during any 1-year period.104
There is no need to prove that a violation of paragraph 1030(a)(5) has occurred. As long as this
type of loss or damage has been suffered, a violation of any of the paragraphs will suffice,
including a violation of paragraph 1030(a)(2).105 Moreover, some courts have held that victims
may join their losses together to reach the $5,000 threshold of subclause 1030(c)(4)(A)(i)(I), at
least as long as the same defendant caused the same damage in the same manner to each.106
At one time there may have been some uncertainty over the range of victims and losses
envisioned in subsection 1030(g). Victims entitled to relief are described as “any person who
suffers loss or damage by reason of a violation of this section,” but until recently there was no
specific definition of the term “person” in either any of the subsections of 1030 or in the generally
applicable definitions of Title 18.107 The legislative history offered no further edification and the
courts had not addressed the issue. “Person” can mean individuals, or individuals and other legal
entities including governmental entities, or individuals and other legal entities but not including
governmental entities.108 Credible arguments might have been made for each of the possible
(...continued)
the violator to obtain compensatory damages and injunctive relief or other equitable relief. A civil action for a violation
of this section may be brought only if the conduct involves 1 of the factors set forth in subclauses (I), (II), (III), (IV), or
(V) of subsection (c)(4)(A)(i)....” 18 U.S.C. 1030(g).
104
18 U.S.C. 1030(c)(4)(A)(i). §204 of the Identity Theft Enforcement and Restitution Act of 2008 moved these
examples of serious damage to the sentencing provisions of clause 1030(c)(4)(A)(i) and added a damage-affecting-10or-more example, P.L. 110-326, 122 Stat. 3561-562 (2008). While harm to more than 10 computers triggers a more
severe criminal penalty, it alone does not provide the basis for a cause of action.
105
Theofel v. Farey-Jones, 359 F.3d 1066, 1078 n.5 (9th Cir. 2004)(“Defendants argue that subsection (a)(5)(A)
prescribes the act’s only civil offenses. But subsection (g) applies to any violation of ‘this section’ and, while the
offenses must involve one of the five factors in (a)(5)(B), it need not be one of three offenses in (a)(5)(A)”); see also,
WEC Carolina Energy Solutions LLC v. Miller, 687 F.3d 199, 201 (4th Cir. 2012); Czech v. Wall Street on Demand,
Inc., 674 F.Supp.2d 1102, 1108-109 (D. Minn. 2009); Bansal v. Russ, 513 F.Supp.2d 264, 278 n. 11 (E.D. Pa. 2007);
America Online, Inc. v. National Health Care Discount, Inc., 174 F.Supp.2d 890, 899 (N.D. Iowa 2001); cf., P.C.
Yonkers, Inc. v. Celebrations, the Party, and Seasonal Superstore, LLC, 428 F.3d 504, 512 (3d Cir. 2005)(reaching the
same conclusion in the context of a suit under paragraph (a)(4)); Nexans Wires S.A. v. Sark-USA, Inc., 319 F.Supp.2d
468, 472 (S.D.N.Y. 2004)(holding that plaintiffs must satisfy the 1030(a)(5)(B) threshold for each of several claims
under 1030(a)(2), (a)(4), and (a)(5)).
106
In re Apple & AT & TM Antitrust Litigation, 596 F.Supp.2d 1288, 1308 (N.D. Cal. 2008)(citing an earlier,
unreported district court opinion as persuasive).
107
The courts have concluded that the civil remedies under the statute are available to third parties. The court in
Theofel v. Farey-Jones, 359 F.3d 1066, 1078 (9th Cir. 2004), emphasized that the statute extends a civil remedy to any
individual who suffers loss or damage, thus “[i]ndividuals other than the computer’s owner may be proximately harmed
by unauthorized access, particularly if they have rights to data stored on it.”
108
The Dictionary Act, for example, defines the term to include “corporations, associations, firms, partnerships,
societies, and joint stock companies, as well as individuals,” unless the context suggests otherwise, 1 U.S.C. 1.

Congressional Research Service

23

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

definitions, but the fact that Congress elected to use the term “person” to mean only individuals in
paragraph 1030(a)(7)(extortionate threats)109 might seem to favor those who call for a similar
interpretation of subsection 1030(g). The USA PATRIOT Act resolved the issue by supplying a
definition: “the term ‘person’ means any individual, firm, corporation, educational institution,
governmental entity, or legal or other entity.”110
It also added a generous definition of the kinds of losses that might give rise to civil liability—
“the term ‘loss’ means any reasonable cost to any victim, including the cost of responding to an
offense, conducting a damage assessment, and restoring the data, program, system, or information
to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential
damages incurred because of interruption of service.”111 The amendment has obvious benefits for
the victims of a paragraph (a)(2) intrusion and information acquisition offense with post-intrusion
investigation and system evaluation costs.
Subsection 1030(g) suits must be brought within two years of the offense.112 Compensatory
damages are limited to economic damages, a limitation that does not negate the reach of the broad
definition of the term “loss” quoted above.113

Attempt, Conspiracy, and Complicity
The same general observations concerning attempt, conspiracy, and aiding and abetting noted for
the simple trespass offense apply here. It is a separate crime to attempt or conspire to violate
paragraph 1030(a)(2) under 18 U.S.C. 1030(b). Those who conspire or attempt to violate its
provisions or aid and abet the violation of another are subject to the same penalties as those who
commit the substantive offense.114 Conspirators to violate paragraph 1030(a)(2) are also subject to
the same penalties for a completed underlying offense, and to liability for any foreseeable crime
committed in furtherance of the scheme.115

109
“Whoever ... (7) with intent to extort from any person, firm, association, educational institution, financial
institution, government entity, or other legal entity, any money or other thing of value ...” 18 U.S.C. 1030(a)(7)
(emphasis added)(the 2002 amendments struck out “firm, association, educational institution, financial institution,
government entity, or other legal entity”).
110
18 U.S.C. 1030(e)(12); Paradigm Alliance, Inc. v. Celeritas Technologies, LLC, 659 F.Supp.2d 1167, 1192 n.80 (D.
Kan. 2009).
111
18 U.S.C. 1030(e)(11); Paradigm Alliance, Inc. v. Celeritas Technologies, LLC, 659 F.Supp.2d 1167, 1190 n.74 (D.
Kan. 2009).
112
18 U.S.C. 1030(g). The statute of limitations dates from when the victim knew or should have known of the wrong,
Higgins v. NMI Enterprises, Inc., 969 F.Supp.2d 628, 640-42 (E.D.La. 2013).
113
Id.; A.V. ex rel. Vanderhyde v. iParadigms, 562 F.3d 630, 646 (4th Cir. 2009)(“iParadigms counters that ‘economic
damages’ ought be accorded its ordinary meaning, which would include consequential damages but exclude recovery
for pain and suffering or emotional distress... [The definition of ‘loss’] plainly contemplates consequential damages of
the type sought by iParadigms-cost incurred as part of the response to a CFAA violation, including investigation of an
offense”).
114
18 U.S.C. 2, 1030(b), 1030(c)(2).
115
Pinkerton v. United States, 328 U.S. 640, 645-48 (1946); United States v. Newman, 755 F.3d 545, 546 (7th Cir.
2014); United States v. Blachman, 746 F.3d 137, 141 (4th Cir. 2014); United States v. Ali, 718 F.3d 929, 941 (D.C. Cir.
2013).

Congressional Research Service

24

Cybercrime: An Overview of 18 U.S.C. 1030 and Related Federal Criminal Laws

Other Crimes
Paragraph 1030(a)(2) is somewhat unique. There are a host of other federal conversion statutes,
but all of the others appear to require that the offender either commit embezzlement by failing to
comply with some fiduciary obligation or commit larceny by intending to acquire the property or
to deprive another of it. Paragraph 1030(a)(2) in contrast to the conversion statutes and to the
computer fraud provisions of paragraph 1030(a)(4) requires no larcenous intent.116 As a practical
matter, it essentially gives prosecutors a more serious charge against hackers, who do more than
simply breach the outskirts

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/crs%3A97-1025. Public record. Not legal advice.
