Don’t do SECURITY. Do business SECURELY.

US Supreme Court narrows the Computer Fraud and Abuse Act in Van Buren

The US Supreme Court has narrowed the CFAA’s “exceeds authorized access” limb, limiting criminal liability for misusing legitimately accessible data.

The US Supreme Court has today handed down its judgment in Van Buren v. United States, significantly narrowing the scope of the Computer Fraud and Abuse Act (CFAA), the principal US computer crime law.

Key points

  • By a 6–3 majority, the Court held that a person “exceeds authorized access” only by entering parts of a system, such as files, folders or databases, that are off-limits to them.
  • Misusing information from areas a person is entitled to access, for an improper purpose, is no longer a CFAA offence on that basis alone.
  • The ruling reduces the risk that breaches of terms of service or workplace policies are treated as federal crimes.
  • Organisations will need to rely more on technical access controls, contracts and employment law to address insider misuse.

UK organisations with US systems, staff or users should make sure access rights are clearly defined and enforced technically, rather than relying on policy alone.

Source: Van Buren v. United States opinion (US Supreme Court)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights