Definition

A technology offense involving unauthorized access, interference, deception, or unlawful interception using electronic systems. It is defined by authorization status, protected system or data, and the required intent or harm elements where applicable. It does not include authorized access or communications conduct that satisfies applicable consent requirements. It safeguards system and data integrity and commonly supports restitution and forfeiture remedies. The concept is generally stable, though coverage expands as technical methods evolve over time.

Principle

Principle
Protection of informational integrity and privacy: the offense focuses on consent and authorization boundaries rather than only on the outcome of the access, recognizing unauthorized intrusion as harmful in itself.

Demonstration

Demonstration
An individual obtains valid credentials for a workplace system, uses them after access has been revoked to view personnel files, or exploits an unpatched service to establish an interactive session on a server without any account.

Misapplication

Misapplication
Conflating legitimate automated indexing of publicly available webpages by search engines with unauthorized access to a protected internal system; or criminalizing innocuous use of public terminals without evidence of restricted-area intrusion.

Consequence

Consequence
Applied correctly, unauthorized access provisions permit law enforcement and organizations to deter, investigate, and sanction intrusions, require remediation of vulnerabilities, and protect systems and user data even when no theft occurs.

Reversal

Reversal
Reversing the concept would allow entry and use of systems without consent so long as no harm manifests; this inversion would privilege access over consent and undermine privacy and security norms.

Boundary

Boundary
Covers access lacking consent or exceeding granted privileges to a computer system; excludes interaction with wholly public information, authorized third-party use under explicit consent, and activities permitted by law (e.g., court-ordered access), subject to statutory definitions of systems and authorization.

Semantic Tension

Semantic Tension
Tension exists between this offense and related doctrines like unauthorized access to networks, trespass to chattels, or misuse of credentials; courts debate whether exceeding authorized access requires technical bypass or simply violating use policies.

Synthesis

Synthesis
Unauthorized access to a computer system is any entry or use of computing resources beyond lawful permission, judged by authorization status and intent, and actionable even absent data manipulation or theft.