The digital age has seen an exponential rise in cybercrime, prompting legislative bodies worldwide to enact statutes designed to criminalize unauthorized access and manipulation of computer systems. When considering potential violations, it's crucial to distinguish between the actions of an initial unauthorized intruder and subsequent parties who may interact with compromised data or systems. This essay will explore various statutes that might have been broken by an hypothetical original hacker and by a party named Scott, focusing on common elements found in computer crime legislation, such as unauthorized access, damage, and data theft.
An original hacker, entering a system without permission, most directly confronts statutes concerning unauthorized access. In the United States, the Computer Fraud and Abuse Act (CFAA) serves as a primary federal statute. Section 1030(a)(2) of the CFAA, for instance, criminalizes intentionally accessing a computer without authorization or exceeding authorized access, and thereby obtaining information from any protected computer. A hacker who gains entry into a private company’s network, accessing customer databases or proprietary algorithms, would likely be in violation of this provision. Furthermore, if the hacker’s intent was to cause damage, such as deleting files or disrupting operations, they could face charges under CFAA § 1030(a)(5), which addresses intentionally causing damage to a protected computer. This could involve deploying malware, ransomware, or simply corrupting critical data. Depending on the nature of the information accessed, other statutes, such as the Stored Communications Act or the Electronic Communications Privacy Act, might also apply if the hacker intercepted communications or accessed stored data with intent to defraud.
Now, consider the actions of Scott, who comes into possession of information or access gained by the original hacker. Scott's legal culpability hinges on his knowledge and intent regarding the illicit origin of the data or access. If Scott knowingly receives, possesses, or uses data that was obtained through unauthorized access, he could be implicated under statutes that criminalize aiding or abetting such crimes, or specific statutes addressing the receipt of stolen data. For example, if Scott was aware that the customer list he received from the original hacker was stolen from a company’s network, and he then used this list for his own commercial gain (e.g., marketing his own products), he could be charged with violating the CFAA for aiding and abetting the original hacker's offense, or under state-level laws that criminalize the possession or use of stolen property, even if that property is digital.
The nature of Scott's interaction with the compromised system or data is critical. If Scott, after the original hacker’s breach, then uses the credentials provided or exploits a vulnerability left open by the first intruder to further access the system or exfiltrate additional data, his actions would likely be viewed as a separate or continuing instance of unauthorized access. This would bring him under the purview of statutes similar to those that applied to the original hacker, particularly if he acted intentionally. For example, if Scott, knowing the system was breached, used the original hacker's access to download confidential financial reports for personal profit, he would likely be liable for unauthorized access and potentially for theft of trade secrets under various federal and state laws. The key element for Scott is often his mens rea—his guilty mind. Did he know or should he have known that the information or access he was dealing with was obtained illegally?
The distinction between the original hacker and Scott is one of primary versus secondary involvement, though both can lead to significant legal consequences. The original hacker is the perpetrator of the initial unauthorized intrusion. Scott, on the other hand, might be an accessory, a recipient of illicit gains, or a secondary perpetrator depending on the specifics of his actions and his awareness of the preceding breach. Statutes are drafted to capture a range of malicious digital activities, from the initial breach itself to the subsequent exploitation of that breach. Therefore, both individuals could face charges under laws like the CFAA, the Electronic Communications Privacy Act, or various state-level computer crime statutes, depending on the evidence of their intent, knowledge, and the specific actions they took.