Computer Fraud and Abuse Act: Penalties and Case Analysis
This paper examines the Computer Fraud and Abuse Act (CFAA) of 1986, the first major federal legislation criminalizing unauthorized access to computer systems. The paper outlines the act's original scope — covering federal agency computers, financial institution systems, and those involved in interstate commerce — and details the penalties and fines established for various offenses. It further discusses the act's broad societal impact, including its use by private corporations to protect trade secrets. Finally, the paper analyzes the landmark United States v. Morris (1991) case to evaluate the act's effectiveness and identifies a key legislative gap: the absence of an explicit intent-to-damage requirement.
- Introduction to the Computer Fraud and Abuse Act: Origins and scope of the 1986 CFAA
- Penalties and Fines Under the CFAA: Specific sentences and fines for CFAA offenses
- Impact of the Legislation: Societal and corporate use of the CFAA
- United States v. Morris: A Case Study: Facts of the 1991 internet worm case
- The Appeal and Court Ruling: Appeals court upholds Morris conviction
- Legislative Implications and Proposed Amendments: Proposed fix to the intent-to-damage gap
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- Grounds abstract legal concepts in a concrete judicial case, showing how statutory language plays out in real prosecutions.
- Moves logically from legislative background to penalties to societal impact and then to case analysis, creating a coherent argument arc.
- Identifies a specific legislative gap — the lack of an explicit intent-to-damage element — and proposes a targeted amendment, demonstrating critical engagement with the law.
Key academic technique demonstrated
The paper demonstrates statutory interpretation through case analysis. By tracing how the court in United States v. Morris applied the CFAA's language, the author shows how the wording of a statute determines its practical reach — and uses that analysis to argue for a specific amendment. This technique is central to legal writing at the undergraduate level.
Structure breakdown
The paper opens with a brief legislative history of the CFAA, then catalogs its penalty structure. A section on societal impact broadens the scope beyond government use. The core analytical section walks through the Morris case — facts, conviction, appeal, and ruling — before concluding with a critique of the intent element and a concrete reform proposal. Six sections total, each building on the previous one.
Introduction to the Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA) was enacted into law in 1986 to address the hacking of computer systems operated by the American government and certain financial institutions. Through its enactment, the legislation made it a federal offense to access a protected computer without authorization, or to an extent beyond what is authorized. Since it was passed into law, the act has been amended several times in attempts to expand its scope and penalties. In addition, the act has grown into an important piece of legislation, used widely not only by the government to prosecute hackers but also by private corporations to help protect their trade secrets and other proprietary information.
Penalties and Fines Under the CFAA
The Computer Fraud and Abuse Act is considered one of the most essential computer-crime laws because it was the first significant federal legislation to offer protection against computer-based offenses. The main aim of the act was to provide legal protection for computers and computer systems in three major categories: computers and computer systems under the direct control of federal agencies, those that are part of a financial institution, and those involved in foreign or interstate commerce (Easttom & Taylor, 2011, p. 72).
In order to achieve its objectives, the act establishes specific penalties and fines for offenders. These include a minimum of 10 years and a maximum of 20 years imprisonment for offenders who obtain national security information, a maximum 10-year sentence for criminals trespassing in a government computer, and a maximum 10-year sentence for intentional access and damage. Additional penalties include a maximum 10-year sentence for trafficking in passwords, a 20-year sentence for intentional access and reckless damage, and a maximum 10-year sentence for extortion involving threats to damage a computer. Furthermore, offenders found in violation of the act's provisions are subject to fines of up to $250,000 per incident.
Impact of the Legislation
As noted above, the act is regarded as one of the most significant laws in its field because it was the first federal law addressing the hacking of computers and computer systems. This law has had a tremendous impact on American society and the global environment, as it is used by the U.S. government and private corporations alike to prosecute hackers and safeguard proprietary information such as trade secrets. While the legislation was initially intended as a national security tool to help prevent hacking, it has been widely adopted across American society as businesses invoked the act to protect significant proprietary information.
In practice, businesses have cited the law primarily to sue former and current employees suspected of stealing information for competitive or other purposes. Therefore, the major impact of the Computer Fraud and Abuse Act of 1986 is that it has helped safeguard important information and enabled both government and private entities to prosecute hackers effectively. More information on the act's evolving application is available through Cornell Law School's Legal Information Institute.
References
Easttom, C. & Taylor, D.J. (2011). Computer Crime, Investigation, and the Law. Boston, MA: Cengage Learning.
"United States v. Morris — Bloomberg Law." (n.d.). Case Briefs. Retrieved December 3, 2012, from http://www.casebriefs.com/blog/law/criminal-law/criminal-law-keyed-to-dressler/mens-rea/united-states-v-morris/
"United States v. Morris." (n.d.). Law School — Mike Shecket. Retrieved December 3, 2012, from http://lawschool.mikeshecket.com/criminallaw/unitedstatesvmorris.html
"What is the Computer Fraud and Abuse Act?" (n.d.). Search Compliance. Retrieved December 3, 2012, from http://searchcompliance.techtarget.com/guides/FAQ-How-has-the-Computer-Fraud-and-Abuse-Act-of-1986-evolved
Create your account
Always verify citation format against your institution’s current style guide requirements.