Computer Fraud and Abuse Act
CFAA
Data security · Other
The CFAA is an anti-hacking law, included here because section 1030(a)(2) protects the confidentiality of information on computers, including financial records, consumer reports, and information on any protected computer. It is the main federal basis for prosecuting data theft and gives victims of unauthorized access a civil remedy.
- Where
- Federal
- Citation
- 18 U.S.C. 1030
- Status
- In force
- In force since
- 1984-10-12
- Last amended
- 2020-10-20
- Enforced by
- U.S. Department of Justice (criminal); private civil actions by persons suffering damage or loss
- People can sue
- Limited
- Penalties
- Criminal fines and imprisonment scaled by offense; civil actions for compensatory damages and injunctive relief if a statutory harm threshold (e.g., $5,000 in loss) is met.
- Applies to
- Any person who accesses a protected computer without authorization or exceeds authorized access
Practices it requires
- Do not intentionally access a protected computer without authorization, or exceed authorized access, and thereby obtain information.18 U.S.C. 1030(a)(2)(C)
- Do not obtain financial institution records or consumer reporting agency files through unauthorized access.18 U.S.C. 1030(a)(2)(A)
- Do not traffic in passwords or similar access information with intent to defraud.18 U.S.C. 1030(a)(6)
Other duties
- Persons suffering damage or loss may sue within two years if a listed harm factor is met.18 U.S.C. 1030(g)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: 1030(a)(6) wording was not re-read | effective_date is the enactment date of Pub. L. 98-473
Research reference, not legal advice.