Definition

A technology offense involving unauthorized access, interference, deception, or unlawful interception using electronic systems. It is defined by authorization status, protected system or data, and the required intent or harm elements where applicable. It does not include authorized access or communications conduct that satisfies applicable consent requirements. It safeguards system and data integrity and commonly supports restitution and forfeiture remedies. The concept is generally stable, though coverage expands as technical methods evolve over time.

Principle

Principle
The offense is organized around (1) lack of permission or exceeding granted permissions, (2) access to a protected computer or system, and (3) a culpable mental state regarding unauthorized use or harmful purpose; liability may attach even if no further damage occurs once unauthorized access is established.

Demonstration

Demonstration
An individual exploits a vulnerability to log into a company's internal server without credentials and downloads customer records; that person is prosecuted for unauthorized computer access and for any subsequent data theft or misuse.

Misapplication

Misapplication
Criminalizing routine use of a shared workstation where access limitations are unclear, or treating mere violation of a website's terms of service as unauthorized computer access absent statutory elements; prosecuting benign research or mistake where authorization was reasonably implied.

Consequence

Consequence
Conviction can carry criminal penalties, forfeiture of equipment, civil liability for data breaches, injunctive relief, and reputational harm; unauthorized access also facilitates identity theft, financial loss, and undermines system integrity and privacy.

Reversal

Reversal
Access conducted with express consent, under a valid contract, or as an authorized security test (with permission) negates unauthorized access; prompt disclosure and cooperation with system owners can mitigate consequences and may avoid prosecution when law permits.

Boundary

Boundary
Covers access to restricted systems or exceeding access rights and excludes viewing publicly available information, mere use of openly accessible webpages, and some contractual or civil breaches (like ToS violations) that do not meet statutory unauthorized access elements.

Semantic Tension

Semantic Tension
Tension exists between unauthorized access and misuse by authorized insiders: unauthorized access focuses on entry without permission, while insider misuse may involve authorized access used for unlawful ends; other tensions involve benign security research versus malicious hacking.

Synthesis

Synthesis
Unauthorized computer access is the knowing entry into or use of protected computing resources without permission or beyond granted privileges, coupled with an unlawful or harmful intent; the concept separates unauthorised entry from lawful or consented security activity and aims to protect data confidentiality, integrity, and system availability.