RulesofCivilProcedure.com Civil Procedure · Every State

18 U.S.C. § 1030(g)

Computer Fraud and Abuse Act: the civil claim, and what Van Buren took away

A claim in United States district courts · Last verified August 26, 2026

The Computer Fraud and Abuse Act is a criminal statute with a civil action bolted on, and for three decades employers used it as a general-purpose weapon against departing employees: you took the client list, you violated the computer-use policy, therefore you committed a federal computer crime.

That theory is dead. In 2021 the Supreme Court held that using access you legitimately have, for a purpose your employer disallows, is not a violation.

What survives is narrower and more sensible: liability for getting into places you were never entitled to enter.

What the claim is

Someone accessed a computer without authorisation, or exceeded the access they had, and it cost you at least $5,000.

The recurring cases: a departing employee downloading files from systems they had no rights to; an outside intruder; a competitor scraping data; and disputes over what an employee was permitted to access on the way out the door.

Where the right comes from

Express, and short:

Any person who suffers damage or loss by reason of a violation of this section may maintain a civil action against the violator to obtain compensatory damages and injunctive relief or other equitable relief.

The civil action rides on the criminal prohibitions, so a plaintiff must establish conduct the criminal statute reaches.

What a plaintiff has to prove — and what Van Buren foreclosed

Access without authorization or exceeding authorized access to a protected computer, causing damage or loss within a qualifying statutory category.

In Van Buren v. United States (2021) the Court adopted a "gates-up-or-down" reading. A person "exceeds authorized access" only by obtaining information located in areas of the computer — files, folders, databases — that are off-limits to them.

What that foreclosed: the improper-purpose theory. Accessing data you are entitled to access, for a reason your employer or a website's terms disallow, is not a CFAA violation. A police officer who ran a licence-plate search he was authorised to run, for a bribe, did not violate the statute.

What survives: liability for entering areas you were never entitled to enter, and the "without authorization" prong against true outsiders and intruders.

What remains open: Van Buren did not decide whether authorisation can be limited by contract or terms of service, or only by technological barriers. That question — the heart of the data-scraping litigation — is unresolved and actively contested.

How long you have to file

Two years from the date of the act complained of, or from the date of discovery of the damage.

The alternative discovery trigger matters, because intrusions are often found long after they happen.

What has to happen before you file

Nothing. No exhaustion, no notice, no agency.

Who can be sued — and who cannot

"The violator" — individuals and entities alike. Departing employees are the most common defendants, followed by competitors and unidentified intruders.

Unlike the employment statutes, there is no entity-only rule here. Individual liability is the norm.

Common defenses

The access was authorised — and this is now a strong defence for insiders after Van Buren. An employee who had credentials for the system they used has a real argument regardless of what they did with what they found.

No qualifying $5,000 loss.

Two-year bar.

Note what the statute does not have: a broad good-faith safe harbour for private actors, of the kind the Stored Communications Act provides. The closest thing is the authorisation analysis itself.

What the claim pays — and the $5,000 question

Compensatory damages and injunctive or equitable relief. No punitive damages.

The $5,000 threshold is the gate. For the most common civil predicate, the plaintiff must show loss aggregating at least $5,000 in value during any one-year period.

Character: it is both a substantive threshold for bringing the civil action and, in effect, a damages floor for that predicate. Failure of proof on it is fatal — not a reduction in recovery, but the end of the claim.

Two paths to the threshold, because the statute defines two different things:

  • "Loss" — the cost of responding to the offence, conducting a damage assessment, restoring data, and revenue lost from any interruption of service. Forensic investigation costs count, which is how most plaintiffs clear the bar.
  • "Damage" — impairment to the integrity or availability of data.

For the loss-based predicate, recovery is limited to economic damages.

What people get wrong

"Violating the computer-use policy is a CFAA violation." Not since Van Buren, for the exceeds-access prong.

"Breaching a website's terms of service is federal computer fraud." The same answer, and the scraping question is unresolved even for the without-authorization prong.

"Any hacking supports a civil suit." Only with $5,000 in qualifying loss over a one-year period.

"The $5,000 is just a damages minimum." It is closer to an element — failing to prove it ends the case.

"My investigation costs don't count." They generally do. Response and forensic costs are the usual route to the threshold.

"The clock runs from the intrusion." It runs from the act or from discovery of the damage.

Where it came from

The statute passed in 1984, aimed at a problem that barely existed yet — unauthorised access to government and financial computers. The civil action was added in 1994, and the definition of "loss" was broadened in 2001.

For most of that history the statute was read expansively. Circuits divided sharply: some held that violating an employer's use policy or a site's terms made access unauthorised; others required an actual access barrier. The broad reading meant, as the Van Buren Court noted, that a great deal of ordinary computer use could be federal crime.

Van Buren resolved that split narrowly in 2021 and left the harder question — whether contractual limits can define authorisation for an outsider — for another day. That is where the litigation now sits.

Common questions

Is violating my employer's computer policy a CFAA violation?

Not since Van Buren v. United States. Using access you legitimately have, for a disallowed purpose, does not exceed authorized access. Entering systems you were never entitled to enter still does.

How much loss do I need to sue?

At least $5,000 aggregated over any one-year period, for the usual civil predicate. That includes the cost of investigating and responding to the intrusion, not just direct damage.

How long do I have to file?

Two years from the act complained of, or from the date you discovered the damage — whichever gives you the later date.

Can I sue someone for scraping my website?

Possibly, but it is unsettled. Van Buren did not decide whether terms of service can define authorisation for an outsider, and that question is actively litigated.

Can I get punitive damages?

No. The civil action provides compensatory damages and injunctive or equitable relief only.

Where these rules live

How this page is sourced. The statutory language quoted here is reproduced from the official text at 18 U.S.C. § 1030(g). Court decisions are named for what they hold, not quoted from any commentary. The procedural rules referred to are reproduced verbatim on their own pages on this site. Everything else is original writing. Last verified August 26, 2026.
This page explains what the law says. It is legal information, not legal advice, and it cannot tell you whether you have a claim. Filing deadlines are short, several of the prerequisites below cannot be cured once missed, and the law in your circuit may differ — if the outcome matters, talk to a lawyer.