The material in this article is general legal information for educational use only. It should not be treated as legal, financial, or tax advice, and reading it does not form an attorney-client relationship. Legal rules vary by jurisdiction and change frequently. Questions about a specific matter belong with a qualified professional. The author and publisher disclaim liability for actions taken in reliance on this content.
Key Facts
- Federal level: Federal law uses the Computer Fraud and Abuse Act (18 U.S.C. § 1030) to address intentional unauthorized access to computers and related obtaining of information from protected computers.
- Federal level: The CFAA defines “exceeds authorized access” as using authorized access to obtain or alter information that the accesser is not entitled to obtain or alter.
- National overview: In Van Buren v. United States, the Supreme Court tied “exceeds authorized access” to obtaining information in off-limits areas such as files, folders, or databases rather than a general “improper purpose” framing.
- Federal level: DOJ’s Justice Manual describes how prosecutors look for code-based access boundaries for “exceeds authorized access” cases under 18 U.S.C. § 1030 rather than relying only on contract or terms-of-service limits.
- Federal level: Federal criminal risk can also arise under the Stored Communications Act (18 U.S.C. § 2701) for intentional unauthorized access to stored communications and under the Wiretap Act (18 U.S.C. § 2511) for intentional interception.
- Federal level: The Wiretap Act includes an exception for intercepting or accessing electronic communications that are configured to be readily accessible to the general public.
- State level: California Penal Code § 502 defines “access” broadly and targets knowingly and without permission computer-related tampering such as adding, altering, damaging, deleting, destroying, or disrupting data, software, or programs.
- National overview: State rules can use different definitions and permission concepts, and California Penal Code § 502 illustrates how state computer-crime frameworks may frame “access” and permission separately from federal statutes.
Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.
- The federal starting point in active defense scenarios unauthorized access under the CFAA
- What “exceeds authorized access” means after the Supreme Court’s Van Buren decision
- How DOJ’s Justice Manual frames access boundaries for CFAA cases
- Federal risk beyond computer access stored communications and wire interception
- A state specific example California Penal Code § 502 uses its own access and permission concepts
- Federal and state framing different statutes different labels similar permission pressure
- Where confusion usually shows up in “active cyber defense” debates
- A time sensitive federal point in CFAA civil cases the 2 year limitation period
- Sources
In policy and security discussions, “active cyber defense” often describes countermeasures taken in response to cyber threats, including steps that attempt to disrupt, degrade, or interfere with attackers or malicious infrastructure. The phrase itself does not create a legal exemption from federal or state computer-crime and communications-interception statutes, which focus on the underlying conduct and whether any statutory “authorization” applies; communications-handling and privacy concerns often appear in the same debates as well in technology raises significant privacy concerns.
The federal starting point in active defense scenarios unauthorized access under the CFAA
Federal law’s most common framework for intrusion-like conduct is the Computer Fraud and Abuse Act (CFAA) at 18 U.S.C. § 1030). The statute includes liability where a person intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains information from a protected computer; it also defines “exceeds authorized access” as using authorized access to obtain or alter information that the accesser is not entitled to obtain or alter under the CFAA.
What “exceeds authorized access” means after the Supreme Court’s Van Buren decision
In Van Buren v. United States, the Supreme Court interpreted the CFAA phrase “exceeds authorized access.” The Court explained that a person exceeds authorized access when the person accesses a computer with authorization but then obtains information located in particular areas—such as “files, folders, or databases”—that are off-limits to that person, which steers the analysis toward location-based limits on what information the person may obtain rather than every rule violation becoming a CFAA issue.
How DOJ’s Justice Manual frames access boundaries for CFAA cases
Even when federal statutes supply the elements, DOJ’s prosecutorial guidance helps clarify how the federal government tends to frame “authorized access” versus “exceeds authorized access.” DOJ’s Justice Manual on the CFAA explains that DOJ generally will not bring “exceeding authorized access” theories unless the protected computer is divided into areas (such as files, folders, user accounts, or databases) through computer code or configuration, and DOJ also states it will not bring “exceeds authorized access” cases based only on the theory that authorization was conditioned by a contract, agreement, or policy, subject to a narrow exception described in the manual.
Federal risk beyond computer access stored communications and wire interception
Intrusion-like “active defense” activity can also create exposure under other federal communications statutes depending on the conduct’s relationship to stored communications or interception of communications in transit. The Stored Communications Act (SCA) at 18 U.S.C. § 2701 prohibits intentional unauthorized access (or intentional exceeding of authorization) to a facility that provides an electronic communication service when the access results in obtaining or altering a wire or electronic communication “while it is in electronic storage,” and it includes statutory exceptions, including conduct authorized by the communications service provider and conduct by a user with respect to communications of or intended for that user.
Federal law can also be implicated by the Wiretap Act at 18 U.S.C. § 2511). That statute generally prohibits intentional interception (or endeavoring to intercept) of wire, oral, or electronic communications unless a statutory exception applies. DOJ’s Justice Manual DOJ Justice Manual 1052 summarizes the core elements for 18 U.S.C. § 2511(1)(a) as intentional intercepting (or endeavoring to intercept) of a wire, oral, or electronic communication, and the Wiretap Act includes an exception for intercepting or accessing an electronic communication that is “configured so that such electronic communication is readily accessible to the general public.”
A state specific example California Penal Code § 502 uses its own access and permission concepts
State computer-crime statutes may track some ideas found in federal law, but they still use state-specific definitions and permission concepts. California Penal Code § 502 illustrates one state approach by stating legislative intent to expand protection from “tampering, interference, damage, and unauthorized access” relating to lawfully created computer data and computer systems. It defines “access” to include gaining entry and causing computer processing or communications with specified computer resources, and it includes prohibitions described as knowingly and without permission conduct that can cover actions such as adding, altering, damaging, deleting, destroying, or disrupting data, software, or programs.
Federal and state framing different statutes different labels similar permission pressure
Active cyber defense is often discussed as a single concept, but the legal analysis typically separates into different statutory categories, each with its own meaning of permission, access, and communications handling. The table below compares the federal frameworks above with the California example cited here, focusing on what each authority targets.
| Area of conduct | Federal statute commonly implicated | What the statute focuses on | State example (illustration) |
|---|---|---|---|
| Unauthorized computer access to get protected information | 18 U.S.C. § 1030) | Intentional access without authorization or “exceeds authorized access,” and obtaining specified information | California Penal Code § 502 uses its own “access” definition and permission standard rather than the CFAA’s terms |
| Access to stored electronic communications | 18 U.S.C. § 2701 | Unauthorized (or authorization-exceeding) access to communications “while it is in electronic storage” | California Penal Code § 502 targets unauthorized computer tampering through its state definitions |
| Interception of communications | 18 U.S.C. § 2511) | Intentional interception (or endeavoring to intercept) of wire, oral, or electronic communications, with statutory exceptions | California’s access/permission framing does not replace the federal Wiretap Act’s interception elements and exceptions |
Where confusion usually shows up in “active cyber defense” debates
Common confusion comes from treating “active cyber defense” as a legal status, instead of as a description of conduct. The federal statutes and the Supreme Court’s interpretation in Van Buren show that liability analysis depends on authorization concepts defined in the statutes and, for the CFAA “exceeds authorized access” theory, on which off-limits information areas are accessed. DOJ’s Justice Manual adds prosecutorial framing that treats code-based access boundaries as especially important for “exceeds authorized access” charging, while the SCA and Wiretap Act show that stored-communications access and communications interception map to different federal statutes and different statutory exceptions.
A time sensitive federal point in CFAA civil cases the 2 year limitation period
In addition to criminal exposure, the CFAA includes a civil action mechanism. The statute provides that a covered civil action for “damage or loss” may be maintained, but it also imposes a limitation: “No action may be brought” under the specified civil action subsection unless the action is begun within “2 years of the date of the act complained of or the date of the discovery of the damage.”