The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, is primarily a federal criminal anti-hacking law, but it also lets private victims sue. Under § 1030(g), anyone who suffers damage or loss because of a CFAA violation may bring a civil action for compensatory damages and injunctive or other equitable relief, as long as the conduct meets one of the statute’s harm thresholds. For most businesses, that means a loss of at least $5,000 in a one-year period. The suit must be filed within two years of the act or of discovering the damage.
Since the Supreme Court’s decision in Van Buren v. United States, 593 U.S. 374 (2021), the CFAA is a tool for unauthorized access to computers or restricted areas of them. It is not a remedy for every misuse of data by someone who was allowed to see it.
Who Can Bring a Civil CFAA Claim
Section 1030(g) creates a private right of action for “any person who suffers damage or loss by reason of a violation” of the statute. A civil claim may be brought only if the conduct involves one of the factors in § 1030(c)(4)(A)(i)(I) through (V):
- A loss to one or more persons during any one-year period aggregating at least $5,000 in value
- The modification or impairment, or potential modification or impairment, of the medical examination, diagnosis, treatment, or care of one or more individuals
- Physical injury to any person
- A threat to public health or safety
- Damage affecting a computer used by or for a U.S. government entity in furtherance of the administration of justice, national defense, or national security
Three additional rules in § 1030(g) shape every case. Damages for a violation involving only the $5,000 loss factor are limited to economic damages. The action must be brought within two years of the act complained of or the date the damage was discovered. And no claim may be brought for the negligent design or manufacture of computer hardware, software, or firmware.
What Conduct Violates the CFAA
Civil plaintiffs most often rely on a few of the statute’s prohibitions, each of which involves a “protected computer.” Under § 1030(e)(2)(B), that includes any computer used in or affecting interstate or foreign commerce or communication, which in practice covers virtually any internet-connected device. The key prohibitions include:
- Obtaining information (§ 1030(a)(2)(C)): intentionally accessing a computer without authorization, or exceeding authorized access, and thereby obtaining information from a protected computer
- Computer fraud (§ 1030(a)(4)): knowingly and with intent to defraud accessing a protected computer without authorization, or exceeding authorized access, and thereby furthering the fraud and obtaining anything of value
- Transmitting harmful code (§ 1030(a)(5)(A)): knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer
- Damaging access (§ 1030(a)(5)(B)–(C)): intentionally accessing a protected computer without authorization and, as a result, recklessly causing damage, or causing damage and loss
“Without Authorization” and “Exceeds Authorized Access” After Van Buren
For years, federal courts split over whether an employee who could log in to a system, but used information for an improper purpose, “exceeded authorized access.” Some courts said yes. That made the CFAA a common add-on claim against departing employees.
The Supreme Court resolved the split in Van Buren. The CFAA defines “exceeds authorized access” in § 1030(e)(6) as accessing a computer with authorization and using that access to obtain or alter information the person “is not entitled so to obtain or alter.” The Court read that language as a “gates-up-or-down inquiry.” A person either can or cannot access a computer system, and either can or cannot access particular areas within it, such as certain files, folders, or databases. Someone who is entitled to access information does not violate the CFAA by using it for a forbidden purpose. The Court expressly left open whether the relevant limits must be technological (“code-based”) or can also come from contracts or policies.
How Courts Have Applied Van Buren
- Employee policy violations. In NRA Group, LLC v. Durenleau, No. 24-1123 (3d Cir. Aug. 26, 2025), employees with legitimate system access created and emailed a spreadsheet of passwords in violation of company computer-use policies. The Third Circuit held that, absent evidence of code-based hacking, the CFAA does not support claims based on current employees’ breaches of workplace computer-use policies. It pointed employers to contract, tort, and other state-law remedies instead.
- Scraping public websites. After the Supreme Court sent hiQ Labs, Inc. v. LinkedIn Corp. back for reconsideration in light of Van Buren, the Ninth Circuit again affirmed a preliminary injunction in hiQ’s favor in 2022 (31 F.4th 1180). It concluded that scraping publicly available profile data was unlikely to be access “without authorization.” Later that year, however, the district court ruled that hiQ had breached LinkedIn’s User Agreement, and the parties settled. The takeaway is that contract claims may succeed where CFAA claims struggle. If your content is being harvested, see our article on what to do when a competitor is scraping your website.
Claims remain strongest where the defendant had no authorization at all, such as an outside hacker, someone using stolen credentials, or a former employee who logs in after access has been revoked. They are also strong where the defendant got past a technical barrier to reach an area of a system that was closed to them.
Proving Damage and Loss
The $5,000 threshold is often the most contested element in civil CFAA litigation, so the definitions matter:
- “Damage” (§ 1030(e)(8)) means any impairment to the integrity or availability of data, a program, a system, or information.
- “Loss” (§ 1030(e)(11)) means any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring data, programs, systems, or information to their prior condition, plus any revenue lost, costs incurred, or other consequential damages incurred because of an interruption of service.
In Van Buren, the Supreme Court observed that these definitions focus on technological harms, such as the corruption of files, of the type unauthorized users cause to computer systems and data. Claims built mainly on the competitive value of the information taken, rather than the cost of investigating and remediating the intrusion, therefore face a harder road. On the other hand, the Eleventh Circuit held in Brown Jordan International, Inc. v. Carmicle, 846 F.3d 1167 (11th Cir. 2017), that reasonable costs of investigating a violation, including consultant fees, can qualify as loss even without an interruption of service. Businesses should carefully track forensic, investigative, and remediation expenses from the start.
Remedies and Deadlines
A successful civil plaintiff may recover compensatory damages (limited to economic damages when the claim rests only on the $5,000 loss factor) and injunctive or other equitable relief. Injunctions can require a defendant to stop accessing systems and return or destroy data. The two-year limitations period runs from the act complained of or the discovery of the damage, so delay can forfeit the claim entirely.
Pairing a CFAA Claim With Trade Secret and State-Law Claims
Because the CFAA now reaches a narrower range of conduct, it is usually one claim among several. When confidential business information is taken, the federal Defend Trade Secrets Act (DTSA), 18 U.S.C. § 1836, is often the more important claim:
- The owner of a misappropriated trade secret related to a product or service used in interstate or foreign commerce may sue under § 1836(b)(1).
- In extraordinary circumstances, a court may order ex parte seizure of property to prevent the propagation or dissemination of the trade secret.
- Courts may award exemplary damages of up to twice actual damages, plus attorney fees, for willful and malicious misappropriation.
- The DTSA limitations period is three years from when the misappropriation was discovered or reasonably should have been discovered.
Not every piece of sensitive data is a trade secret, however. In Durenleau, the Third Circuit also held that the passwords at issue, which protected proprietary business information, were not themselves trade secrets. Understanding the legal definition of a trade secret is essential before filing. Other common companion claims include breach of confidentiality or computer-use agreements, breach of fiduciary duty, and state trade secret claims such as those under Michigan’s Uniform Trade Secrets Act, MCL 445.1901 et seq.
What to Do If Someone Accessed Your Systems Without Permission
- Preserve evidence. Secure access logs, audit trails, devices, and email before they are overwritten.
- Cut off access. Revoke credentials, change passwords, and document when and how access was terminated.
- Investigate and track costs. Engage forensic professionals and keep detailed records of response and remediation expenses, which may establish the $5,000 loss.
- Review your agreements. Employment, confidentiality, and website terms may support claims the CFAA does not.
- Assess notification duties. If personal information was exposed, state breach-notification laws may impose deadlines. Our data breach attorneys can help you evaluate those obligations.
- Act within the deadlines. Keep the CFAA’s two-year and the DTSA’s three-year limitations periods in mind.
Choosing the Right Claims
The CFAA remains a valuable remedy against hackers, credential thieves, and others who break into systems they have no right to enter. After Van Buren, however, businesses dealing with insider misuse of data usually need a broader strategy that combines trade secret, contract, and state-law claims.
If your business’s computer systems or confidential information have been compromised, the trade secret and internet law attorneys at Revision Legal can help you identify the strongest claims, preserve the evidence you need, and move quickly to stop further harm. Contact us through the form on this page or call (855) 473-8474.