Cybercrime Law in the United States

The United States prosecutes computer crime primarily under federal statutes, backed by a patchwork of state laws covering data breaches and privacy.

Key federal laws

  • Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030 — the main anti-hacking statute, enacted in 1984 and amended repeatedly since (most recently in 2020). It criminalises obtaining national-defence or restricted data without authorization (§ 1030(a)(1)), obtaining financial, government or protected-computer information (§ 1030(a)(2)), unauthorized access to non-public government computers (§ 1030(a)(3)), access-based fraud (§ 1030(a)(4)), damaging a protected computer (§ 1030(a)(5)), trafficking in passwords (§ 1030(a)(6)) and computer-related extortion (§ 1030(a)(7)).
    • In Van Buren v. United States, 593 U.S. 374 (decided 3 June 2021) the Supreme Court narrowed “exceeds authorized access”: it reaches someone who obtains information from areas of a computer that are off-limits to them, not someone who is entitled to the information but uses it for an improper purpose. Older summaries of the CFAA that treat a terms-of-service or workplace-policy breach as a federal crime are no longer reliable.
  • Electronic Communications Privacy Act (ECPA) (1986) — comprising the Wiretap Act, 18 U.S.C. ch. 119 (§§ 2510–2523, interception of wire, oral and electronic communications), and the Stored Communications Act, 18 U.S.C. ch. 121 (§§ 2701–2713, access to and disclosure of stored communications and records). Chapter 121 now also contains § 2713, added by the CLOUD Act in 2018, on data held abroad.
  • Identity Theft and Assumption Deterrence Act of 1998 (Pub. L. 105-318, 30 October 1998) — made identity theft a federal crime by amending 18 U.S.C. § 1028. Aggravated identity theft is separately punished under 18 U.S.C. § 1028A.
  • CAN-SPAM Act (2003), codified at 15 U.S.C. ch. 103 (§§ 7701–7713) — rules for commercial email, enforced principally by the FTC.

The United States is a party to the Budapest Convention on Cybercrime (ETS 185), which it ratified on 29 September 2006 and which entered into force for it on 1 January 2007.

State law

Every US state has a data-breach notification law, and the details — trigger, deadline, regulator notice — differ meaningfully from state to state. California’s CCPA, as amended by the CPRA (Cal. Civ. Code §§ 1798.100 et seq.) is the most prominent state privacy regime; many other states have since enacted their own consumer privacy acts. States also have their own computer-crime statutes, which are often broader than the CFAA.

Enforcement

The Department of Justice prosecutes federal cases, with investigations led by the FBI and the US Secret Service; CISA leads federal civilian cyber defence; and the FTC handles consumer-protection and privacy matters. State attorneys general enforce state breach-notification and privacy laws, and the California Privacy Protection Agency enforces the CCPA/CPRA alongside the state Attorney General.


Plain-language overview, not legal advice. Statutes and case law change — read the current United States Code text linked above and consult a qualified attorney for any specific situation.

Sources verified 26 August 2026 against govinfo.gov (US Government Publishing Office), supremecourt.gov, the California Legislative Information site and the Council of Europe Treaty Office. The CFAA credit line and the Van Buren decision date were read from the official texts.