USA Federal Laws for cyber crime of HACKING

Definition of Hacking

Hacking is broadly defined as the act of breaking into a computer system. Hacking isn't always a crime as "ethical hacking" occurs when a hacker is legally permitted to exploit security networks. In other words, it's when a hacker has the appropriate consent or authorization. However, hacking crosses the criminal line when a hacker accesses someone's computer system without such consent or authority.

For instance, if an individual act without consent or any lawful authorization (i.e. from law enforcement agency and/or court order) and penetrates a business' firewall to access private servers and cloud storage systems or uses phishing to install malware to desktop and laptop computers with the intent to monitor communications and activities, they can be charged with a crime.

Federal Hacking Laws

There are several federal laws that address hacking, including:

  • The Computer Fraud and Abuse Act (CFAA);
  • The Stored Communications Act (SCA);
  • The Electronic Communications Privacy Act (ECPA); and
  • The Defend Trade Secrets Act (DTSA).

Computer Fraud and Abuse Act

The Computer Fraud and Abuse Act (CFAA) is the leading federal anti-hacking legislation that prohibits unauthorized access to another's computer system. Although the law was originally meant to protect the computer systems of U.S. government entities and financial institutions, the scope of the Act expanded with amendments to include practically any computer in the country (including devices such as servers, desktops, laptops, cellphones, and tablets).

Criminal Penalties Under the CFAA

The chart below provides select examples of violations of the CFAA and the penalties.

Offense

Penalties (Prison Sentence)

Obtaining National Security Information

10 years; 20 years maximum for a second conviction.

Accessing a Computer to Defraud and Obtain Value

5 years; 10 years maximum for a second conviction.

Accessing a Computer and Obtaining Information

1-5 years; 10 years maximum for a second conviction.1-10 years; 20 years maximum for a second conviction.

Intentionally Damaging by Knowing Transmission

1-10 years; 20 years maximum for a second conviction.

Extortion Involving Computers

5 years; 10 years maximum for a second conviction.

Trafficking in Passwords

1 year; 10 years maximum for a second conviction.

Civil Violations Under the CFAA

Although the CFAA's penalties are mostly for criminal violations, the 1994 amendment expanded the Act to include causes of action for civil suits, in addition to criminal prosecution.

Civil violations include the following:

  • Obtaining information from a computer through unauthorized access;
  • Trafficking in a computer password that can be used to access a computer;
  • Transmitting spam; and
  • Damaging computer data.

Federal anti-hacking legislation provides civil remedies for hacking victims, including the following:

  • Injunctive relief;
  • Seizure of property; and
  • Impounding of the stolen information and the electronic devices used to carry out the invasion.

Other Federal Hacking Laws

The Stored Communications Act mirrors the prohibitions of the CFAA and protects stored electronic communications and data or data at rest (including email, texts, instant messages, social media accounts, cloud computing and storage, and blogs/microblogs). There is a lot of overlap with the CFAA and often hackers will be in violation of both statutes.

The EPCA, a counterpart law to the SCA forbids intentional interception of electronic communications in transit or "data in motion," rather than "data at rest."

Comments

Post a Comment

Popular posts from this blog

Consumer Dispute resolution under the Telecom Act 2023

Types of Cyber Attacks

What to do when police does not take your FIR?