5425 Wisconsin Ave Ste 600 · Chevy Chase, MD 20815 (301) 901-3109Request a consultation

Computer Fraud and Cybersecurity Offenses

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, turns on two concepts: accessing a computer without authorization, and exceeding authorized access. That second phrase is why the statute appears so often in departing-employee cases — the employee had credentials, and the question becomes what they were entitled to do with them.

Waxman Litigation acts for companies and their boards. Seth B. Waxman spent 13 years as an Assistant United States Attorney in the District of Columbia, roughly eight of them on fraud and public corruption.

What § 1030 reaches

(a) Whoever— (1) having knowingly accessed a computer without authorization or exceeding authorized access, and by means of such conduct having obtained information that has been determined by the United States Government pursuant to an Executive order or statute to require protection against unauthorized disclosure for reasons of national defense or foreign relations, or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954 , with reason to believe that such information so obtained could be used to the injury of the United States, or to the advantage of any foreign nation willfully communicates, delivers, transmits, or causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it, or willfully retains the same and fails to deliver it to the officer or employee of the United States entitled to receive it; (2) intentionally accesses a computer without authorization or exceeds authorized access , and ther

18 U.S.C. § 1030

Where it meets employment and trade secret disputes

A departing employee who takes files usually raises three separate questions at once: a computer-access question under § 1030, a trade secret question under D.C. Code §§ 36–401 to 36–406, and a contractual question under any confidentiality agreement. They have different elements, different remedies and different limitation periods.

For the company on the receiving end, the civil routes usually matter more than the criminal one — and they move faster.

When there has been an intrusion

Preserve logs and images before remediation overwrites them. That is both an evidential point and a legal one: 18 U.S.C. § 1519 reaches destruction of records in contemplation of a federal matter. An internal investigation run properly from the start keeps both options open.

What are the penalty tiers under the Computer Fraud and Abuse Act?

The CFAA is tiered: the same statute carries anywhere from one year to twenty, depending on which subsection is charged and whether it is a repeat offense. That range is why the charging decision matters more here than in most offenses.

Exposure tier under 18 U.S.C. § 1030Maximum term
Certain first offenses under the lower subsections1 year
Offenses under the subsections carrying the intermediate penalty5 years
Specified offenses, and repeat offenses under the lower tiers10 years
The most serious tiers, including specified repeat offenses20 years
Sources: 18 U.S.C. § 1030, whose penalty subsection sets each tier by reference to the subsection charged, as published by the Cornell Legal Information Institute. Penalty provisions are summarized — read the sections.

Frequently asked questions

Is an employee who copies files committing a federal crime?

§ 1030 concerns access without authorization or exceeding authorized access. Whether particular conduct falls within it is fact-specific and much litigated.

Should we call law enforcement after a breach?

That decision has consequences for control, timing and disclosure. It is worth taking advice before making it.

Do we have civil remedies as well?

Often the stronger route — trade secret and confidentiality claims under D.C. law, with injunctive relief available.

What should we preserve?

Logs, images and access records, before remediation overwrites them.

Who can bring a civil claim after an intrusion?

Any person who suffered damage or loss. 18 U.S.C. § 1030(g) allows them to maintain a civil action against the violator for compensatory damages and injunctive or other equitable relief, provided the conduct involves one of the factors listed in § 1030(c)(4)(A)(i).

Why is the civil deadline the first thing to check?

Because it is unusually short. Under 18 U.S.C. § 1030(g) no civil action may be brought unless begun within 2 years of the act complained of or of the date the damage was discovered — less than the three years D.C. Code § 12–301(8) allows for an action with no period specially prescribed.

How does § 1030 apply to an employee who already had a login?

Through the second limb of the access element. 18 U.S.C. § 1030(a)(2) reaches a person who intentionally accesses a computer “without authorization or exceeds authorized access” and thereby obtains information from a protected computer — so the question is the scope of the permission, not whether credentials existed.

Sources and legal authorities

General information about federal law, not legal advice, and not a prediction of any outcome. Federal criminal exposure turns on facts this page cannot assess. If your company has been contacted by investigators or has received a subpoena, take advice before gathering documents or interviewing staff.

Related: White-Collar Defense · Trade Secret Misappropriation · NDA / Confidentiality Disputes · Internal Investigations. Call (301) 901-3109 or use the contact page.

Attorney Advertising