Computer Fraud and Abuse Act (CFAA)
Definition
18 U.S.C. § 1030, the primary US federal computer crime statute. Criminalises unauthorised access to protected computers, data theft, system damage, and extortion involving computers. Applies to any computer used in interstate or foreign commerce, covering virtually all internet-connected devices.
- Citation
- 18 U.S.C. § 1030
- Jurisdiction
- United States federal law
- Scope
- Any computer used in interstate or foreign commerce
- Covers
- Unauthorised access, data theft, system damage, extortion
Common questions
Why does the CFAA apply to almost any internet-connected device?+
Because it defines a protected computer as one used in or affecting interstate or foreign commerce, and courts have read that broadly enough to cover virtually any device that connects to the internet, since internet traffic routinely crosses state and national lines.
How has the CFAA's scope been narrowed by courts?+
The Supreme Court's Van Buren decision in 2021 held that exceeding authorised access means accessing files or areas a person is not permitted to access at all, not misusing access they are otherwise entitled to, narrowing the statute's reach over policy violations by authorised users.
Does the CFAA create civil liability as well as criminal penalties?+
Yes, it includes a private right of action allowing victims of unauthorised access or damage to sue for compensatory damages and injunctive relief, which is why it appears in civil computer misuse disputes and not only in criminal prosecutions.
Related terms
- Budapest Convention
- The Council of Europe Convention on Cybercrime (2001), the first binding international treaty on cyber offences. Requires signatory states to criminalise illegal...
- Bharatiya Sakshya Adhiniyam 2023 (BSA)
- India's current evidence statute, which replaced the Indian Evidence Act 1872. Section 63 of the BSA governs electronic records and requires a...
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Computer Misuse Act 1990 (CMA)
- The primary UK statute creating offences of unauthorised access to computer material, unauthorised access with intent to commit further offences, and unauthorised...
- Computer Misuse Act (CMA)
- UK statute enacted in 1990 and substantially amended in 2006 and 2015. Creates three base offences (unauthorised access, access with further intent,...
- Connecting Factor
- A jurisdictional link between an offence and a state: the offender's location, the victim's location, where the targeted system operates, or the...
- Hash Value
- A fixed-length digital fingerprint produced by running a file through a cryptographic algorithm such as SHA-256 or MD5. Identical files produce identical...
- Mutual Legal Assistance Treaty (MLAT)
- A bilateral or multilateral treaty under which signatory states agree to assist each other in gathering evidence for criminal investigations. MLATs define...
- Section 65B Certificate (Now BSA 2023 Certificate)
- A statutory certificate required under Indian law to authenticate electronic records tendered in evidence. Under the Bharatiya Sakshya Adhiniyam 2023, the certificate...
Explained in these topics
- Computer Crime Statutes and Global Legal Frameworks
- Electronic Evidence Statutes and Cyber OffencesThe primary US federal statute criminalising unauthorised access to computers and computer fraud. Enacted in 1986, amended multiple times. Applies to any compu...