Skip to main content
Essay Undergraduate 1,065 words

Computer Fraud and Abuse Act: Penalties and Case Analysis

~6 min read 6 sections Law · Federal Laws
Abstract

This paper examines the Computer Fraud and Abuse Act (CFAA) of 1986, the first major federal legislation criminalizing unauthorized access to computer systems. The paper outlines the act's original scope — covering federal agency computers, financial institution systems, and those involved in interstate commerce — and details the penalties and fines established for various offenses. It further discusses the act's broad societal impact, including its use by private corporations to protect trade secrets. Finally, the paper analyzes the landmark United States v. Morris (1991) case to evaluate the act's effectiveness and identifies a key legislative gap: the absence of an explicit intent-to-damage requirement.

Key Takeaways
  • Introduction to the Computer Fraud and Abuse Act: Origins and scope of the 1986 CFAA
  • Penalties and Fines Under the CFAA: Specific sentences and fines for CFAA offenses
  • Impact of the Legislation: Societal and corporate use of the CFAA
  • United States v. Morris: A Case Study: Facts of the 1991 internet worm case
  • The Appeal and Court Ruling: Appeals court upholds Morris conviction
  • Legislative Implications and Proposed Amendments: Proposed fix to the intent-to-damage gap
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • Grounds abstract legal concepts in a concrete judicial case, showing how statutory language plays out in real prosecutions.
  • Moves logically from legislative background to penalties to societal impact and then to case analysis, creating a coherent argument arc.
  • Identifies a specific legislative gap — the lack of an explicit intent-to-damage element — and proposes a targeted amendment, demonstrating critical engagement with the law.

Key academic technique demonstrated

The paper demonstrates statutory interpretation through case analysis. By tracing how the court in United States v. Morris applied the CFAA's language, the author shows how the wording of a statute determines its practical reach — and uses that analysis to argue for a specific amendment. This technique is central to legal writing at the undergraduate level.

Structure breakdown

The paper opens with a brief legislative history of the CFAA, then catalogs its penalty structure. A section on societal impact broadens the scope beyond government use. The core analytical section walks through the Morris case — facts, conviction, appeal, and ruling — before concluding with a critique of the intent element and a concrete reform proposal. Six sections total, each building on the previous one.

Essay 1,065 words

Introduction to the Computer Fraud and Abuse Act

The Computer Fraud and Abuse Act (CFAA) was enacted into law in 1986 to address the hacking of computer systems operated by the American government and certain financial institutions. Through its enactment, the legislation made it a federal offense to access a protected computer without authorization, or to an extent beyond what is authorized. Since it was passed into law, the act has been amended several times in attempts to expand its scope and penalties. In addition, the act has grown into an important piece of legislation, used widely not only by the government to prosecute hackers but also by private corporations to help protect their trade secrets and other proprietary information.

Penalties and Fines Under the CFAA

The Computer Fraud and Abuse Act is considered one of the most essential computer-crime laws because it was the first significant federal legislation to offer protection against computer-based offenses. The main aim of the act was to provide legal protection for computers and computer systems in three major categories: computers and computer systems under the direct control of federal agencies, those that are part of a financial institution, and those involved in foreign or interstate commerce (Easttom & Taylor, 2011, p. 72).

In order to achieve its objectives, the act establishes specific penalties and fines for offenders. These include a minimum of 10 years and a maximum of 20 years imprisonment for offenders who obtain national security information, a maximum 10-year sentence for criminals trespassing in a government computer, and a maximum 10-year sentence for intentional access and damage. Additional penalties include a maximum 10-year sentence for trafficking in passwords, a 20-year sentence for intentional access and reckless damage, and a maximum 10-year sentence for extortion involving threats to damage a computer. Furthermore, offenders found in violation of the act's provisions are subject to fines of up to $250,000 per incident.

Impact of the Legislation

As noted above, the act is regarded as one of the most significant laws in its field because it was the first federal law addressing the hacking of computers and computer systems. This law has had a tremendous impact on American society and the global environment, as it is used by the U.S. government and private corporations alike to prosecute hackers and safeguard proprietary information such as trade secrets. While the legislation was initially intended as a national security tool to help prevent hacking, it has been widely adopted across American society as businesses invoked the act to protect significant proprietary information.

In practice, businesses have cited the law primarily to sue former and current employees suspected of stealing information for competitive or other purposes. Therefore, the major impact of the Computer Fraud and Abuse Act of 1986 is that it has helped safeguard important information and enabled both government and private entities to prosecute hackers effectively. More information on the act's evolving application is available through Cornell Law School's Legal Information Institute.

3 Sections Hidden · 400 words
United States v. Morris: A Case Study130 words
Since its enactment, the Computer Fraud and Abuse Act of 1986 has been used to convict offenders suspected of hacking computers and computer systems for illegal purposes. An important example of the law's application is the United States…
The Appeal and Court Ruling120 words
The defendant appealed to the United States Court of Appeals on the basis that he had not planned to damage the federal computers. Since he was charged under the Computer Fraud and Abuse Act…
Legislative Implications and Proposed Amendments150 words
Based on this case, the application of the Computer Fraud and Abuse Act of 1986 requires critical consideration with regard to its effectiveness in convicting offenders. The defendant challenged the act on the basis that it addresses…

References

Easttom, C. & Taylor, D.J. (2011). Computer Crime, Investigation, and the Law. Boston, MA: Cengage Learning.

"United States v. Morris — Bloomberg Law." (n.d.). Case Briefs. Retrieved December 3, 2012, from http://www.casebriefs.com/blog/law/criminal-law/criminal-law-keyed-to-dressler/mens-rea/united-states-v-morris/

"United States v. Morris." (n.d.). Law School — Mike Shecket. Retrieved December 3, 2012, from http://lawschool.mikeshecket.com/criminallaw/unitedstatesvmorris.html

"What is the Computer Fraud and Abuse Act?" (n.d.). Search Compliance. Retrieved December 3, 2012, from http://searchcompliance.techtarget.com/guides/FAQ-How-has-the-Computer-Fraud-and-Abuse-Act-of-1986-evolved

Key Concepts in This Paper
Computer Fraud and Abuse Act Unauthorized Access Federal Cybercrime Law Intent to Damage United States v. Morris Trade Secret Protection Internet Worm Statutory Interpretation Computer Crime Penalties Legislative Amendment
Cite This Paper
PaperDue. (2026). Computer Fraud and Abuse Act: Penalties and Case Analysis. PaperDue. https://www.paperdue.com/study-guide/computer-fraud-abuse-act-penalties-case-analysis-76809

Always verify citation format against your institution’s current style guide requirements.