Unauthorised Access
Definition
The act of accessing a computer, network, or data store without permission from the owner or without lawful authority. The core element of most hacking offences; damage or theft are not required elements of the basic offence in most jurisdictions.
- Core element
- Access without permission or lawful authority
- Damage required
- Not required for the basic offence in most jurisdictions
- Example statute
- Computer Misuse Act 1990 (UK), Computer Fraud and Abuse Act (US)
- Aggravating factor
- Intent to commit a further offence increases severity
Common questions
Does exceeding authorised access count the same as no access at all?+
Many statutes treat them differently. Accessing a system with no permission at all is usually the base offence, while a user who has some access but exceeds its scope, such as an employee viewing records outside their role, may fall under a separate or aggravated provision depending on the jurisdiction.
What evidence typically proves unauthorised access in court?+
Login and authentication logs, IP and device attribution, timestamps correlated with account activity, and any bypass of access controls such as password guessing or exploiting a vulnerability are the usual technical proof.
Related terms
- Anti-Forensic Technique
- Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use...
- Credential Stuffing
- An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Living-Off-the-Land (LotL)
- An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
- Privilege Escalation
- A post-access technique in which an attacker who has gained low-level access to a system exploits a vulnerability or misconfiguration to obtain...