
The internet has transformed the way people live, work, communicate, study, shop, and manage money. In the United States, millions of people depend on computers, smartphones, cloud services, online banking, social media, and digital platforms every day. Businesses use technology to store customer information, process payments, manage employees, and operate their entire organizations. Government agencies also depend on computer networks for essential public services and sensitive information. This enormous dependence on technology has created tremendous opportunities, but it has also created opportunities for criminals like cybercrime.
Cybercrime is a growing concern because criminals can attack people and organizations without being physically present. A hacker in one country can potentially target a business in another country. A scammer can communicate with thousands of victims through automated messages. A criminal group can steal information from an organization and demand money without ever entering the victim's building.
The U.S. Cybersecurity and Infrastructure Security Agency describes cybercrime as crime committed electronically and identifies activities such as identity theft, financial theft, malware, and malicious social engineering among its examples.
Cybercrime is therefore much broader than simply "hacking." It includes a wide range of illegal activities involving computers, networks, digital information, electronic communications, and online services.
The United States addresses cybercrime through a combination of federal and state laws, law-enforcement agencies, cybersecurity programs, and international cooperation. One of the most important federal laws is the Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030. The U.S. Department of Justice describes the CFAA as an important law for prosecuting cyber-based crimes.
Understanding cybercrime is important for everyone who uses the internet. Knowing how cybercriminals operate, what types of crimes they commit, how U.S. law addresses these activities, and how individuals can protect themselves can make the digital world safer.
Cybercrime refers to criminal activity involving computers, networks, electronic devices, digital systems, or online platforms.
There are several ways a computer can be involved in a crime.
A computer may be the target of an attack. For example, a criminal could break into a company's server and steal confidential files.
A computer may also be the tool used to commit a crime. Someone could use a laptop to conduct financial fraud, create fake websites, or distribute malicious software.
In other situations, digital technology may simply provide the environment in which a crime occurs. Social-media platforms, messaging applications, email systems, and online marketplaces can all be misused by criminals.
Common forms of cybercrime include:
The Department of Justice identifies computer intrusions, data breaches, computer damage, ransomware, digital extortion, botnets, denial-of-service attacks, and malware-related activity as examples of cybercrime requiring specialized attention.
Because these crimes can take many forms, the United States does not rely on one law to address every cybercrime. Different federal statutes may apply depending on the conduct involved.
The Computer Fraud and Abuse Act is one of the central federal laws addressing computer-related crime in the United States.
The law is found in 18 U.S.C. § 1030 and addresses several types of unauthorized access and computer-related misconduct. The Department of Justice describes it as an important tool for prosecutors dealing with cyber-based crimes.
The CFAA was originally enacted in 1986. At that time, computers were far less connected than they are today. Smartphones, cloud computing, social-media networks, and modern online services did not exist in their current forms.
Technology has changed dramatically since then.
The law has consequently been amended over time, while courts and prosecutors have also developed interpretations concerning how it applies to modern technology.
The CFAA focuses heavily on unauthorized access to protected computers and certain forms of damage and fraud.
This makes it particularly important in cases involving hacking and computer intrusions.
Unauthorized access is one of the most important concepts in cybercrime law.
Consider a simple example. Someone obtains another person's password and uses it to enter their email account without permission. The attacker has accessed a computer system or account without authorization.
A similar situation can occur when a criminal breaks into a company's network, database, server, or cloud environment.
Unauthorized access can expose highly sensitive information, including financial records, customer information, passwords, confidential business documents, and private communications.
The Department of Justice's CFAA policy states that prosecutors should focus on circumstances where a person knowingly accessed a computer without authorization and understood the facts that made the access unauthorized.
This requirement is important because criminal law generally distinguishes between accidental behavior and deliberate misconduct.
Someone who accidentally opens the wrong webpage is obviously in a different situation from someone who deliberately steals a password and uses it to enter a restricted system.
Another important concept is accessing information beyond what a person is authorized to access.
Modern computer systems frequently divide information into different areas. An employee might be allowed to access customer records but not payroll information. A contractor might have access to one server but not another. An administrator may have broader privileges than an ordinary employee.
The legal question can become complicated when someone has legitimate access to part of a system but deliberately enters an area they are not permitted to access.
The Department of Justice's current CFAA charging policy says that, for certain offenses involving "exceeds authorized access," prosecutors should focus on situations where a computer is divided into areas such as files, folders, user accounts, or databases through computer code or configuration, and the defendant accesses an area outside the scope of their authorization.
This distinction matters because not every violation of an organization's internal policy automatically becomes a federal hacking offense.
In 2022, the Department of Justice clarified its CFAA charging policy to avoid treating certain ordinary terms-of-service violations as federal criminal cases.
Computers can be used to commit fraud in numerous ways.
A criminal may obtain unauthorized access to a system and use that access to obtain money, information, or something else of value.
Online fraud can involve fake websites, stolen credentials, fraudulent transactions, compromised accounts, or manipulated digital systems.
For example, an attacker could compromise a business account and redirect payments to a fraudulent bank account. Another criminal might use stolen credentials to access an online financial service.
Computer fraud can cause substantial losses because digital transactions can occur rapidly and across geographical boundaries.
Cybercrime investigations involving fraud may involve multiple federal laws. The CFAA can be relevant to unauthorized computer access, while other federal statutes may address the financial or identity-related aspects of the same scheme.
This combination of laws allows prosecutors to address different parts of a complicated cybercrime.
Not every cyberattack requires advanced programming skills.
One of the most successful methods used by criminals is social engineering, which involves manipulating people into revealing information or performing an action.
Phishing is a common example.
A victim might receive an email that appears to come from a bank, employer, delivery company, government agency, or another trusted organization. The message may ask the victim to click a link, provide a password, confirm financial information, or make a payment.
The attacker relies on deception rather than technical exploitation.
Social engineering can be extremely effective because humans are often easier to manipulate than computer systems.
Criminals may create a sense of urgency by claiming that an account will be closed or a payment will fail unless the victim acts immediately.
They may also impersonate someone the victim knows.
As artificial intelligence becomes more capable, criminals can potentially create more convincing messages, fake voices, and personalized scams, making awareness increasingly important.
Malware is malicious software designed to perform unauthorized or harmful actions.
Different forms of malware include viruses, worms, trojans, spyware, and ransomware.
Depending on its design, malware may steal information, monitor activity, damage files, establish unauthorized access, or allow criminals to control infected devices.
Malware can enter a system through malicious downloads, infected files, compromised websites, deceptive emails, or other methods.
Once installed, it may operate silently for an extended period.
Some attackers use malware to establish a foothold inside an organization before moving to other systems. Others use it immediately to damage files or steal information.
The Department of Justice specifically includes the use and dissemination of malware among cybercrime matters handled through specialized federal cybercrime efforts.
Ransomware has become one of the most damaging forms of cybercrime.
In a ransomware attack, criminals typically use malicious software to make computer systems or files inaccessible. They then demand payment from the victim.
Modern attacks can involve an additional threat: data theft.
An attacker may steal confidential information before encrypting a company's systems. The criminals can then threaten to publish the stolen information unless the organization pays.
This creates a difficult situation for victims.
They may simultaneously face operational disruption, financial losses, privacy concerns, reputational damage, and legal obligations concerning affected information.
The Department of Justice identifies ransomware and digital extortion among cybercrime matters requiring enhanced coordination.
Ransomware demonstrates why cybersecurity is not simply an IT issue. A major attack can affect a company's finances, employees, customers, reputation, and ability to operate.
Data has enormous value in the modern economy.
Businesses collect customer names, addresses, payment information, account credentials, purchasing histories, business records, and other information.
Criminals may attempt to steal this information and sell it, use it for fraud, or exploit it in other criminal activities.
A data breach occurs when sensitive information is accessed, exposed, or stolen without authorization.
The consequences can extend far beyond the original organization.
For customers, a stolen password may lead to account takeovers. Exposed financial information can facilitate fraud. Personal information can potentially be combined with information from other sources to create convincing identity-theft schemes.
For businesses, a major breach can result in financial losses, lawsuits, regulatory problems, reputational damage, and expensive recovery efforts.
This makes data protection an important part of cybersecurity.
Identity theft occurs when criminals use another person's identifying information for unlawful purposes.
Stolen information may include names, account credentials, government identification information, financial details, or other personal data.
Cybercriminals may obtain such information through phishing, malware, data breaches, social engineering, or unauthorized access to online accounts.
Once criminals obtain enough information, they may attempt to open accounts, make purchases, obtain financial services, or impersonate the victim.
Identity theft is not necessarily limited to computer-specific laws. Federal prosecutors can use separate statutes dealing with identity theft and related conduct depending on the circumstances.
This illustrates a key point about U.S. cybercrime law: cybercrime often overlaps with traditional crimes.
Technology may provide the method, but the underlying conduct can involve fraud, theft, extortion, or identity-related offenses.
Cybercrime is not limited to attacks against computers.
Digital platforms can also be used to harass, threaten, stalk, or intimidate individuals.
Cyberstalking can involve repeated unwanted communications, threats, monitoring, or other forms of online conduct directed at a victim.
Social media can make harassment especially difficult because harmful communications can reach victims wherever they have internet access.
Federal law contains provisions addressing certain forms of cyberstalking and online harassment, while state laws can also apply depending on the conduct and location.
Victims should preserve evidence such as messages, screenshots, account names, dates, and links.
Deleting evidence can make it more difficult for investigators to establish what happened.
A denial-of-service attack attempts to make a computer system, website, or online service unavailable to legitimate users.
A distributed denial-of-service attack, commonly called a DDoS attack, uses multiple systems to generate large volumes of traffic or requests toward a target.
The objective can be to overwhelm the target's resources.
For businesses that depend on online services, downtime can cause significant financial losses.
Online stores may be unable to process orders. Gaming platforms may become unavailable. Financial services can be disrupted. Public-facing websites can become inaccessible.
The Department of Justice identifies denial-of-service attacks among cybercrime matters that require enhanced coordination.
These attacks demonstrate that cybercrime can affect the availability of information, not merely its confidentiality.
Cyber threats do not always come from strangers outside an organization.
An insider threat can involve a current or former employee, contractor, or business partner who has legitimate access to a company's systems but deliberately misuses that access.
CISA notes that insider threats can involve people with authorized access who intentionally misuse that access to commit cybercrime.
An insider might steal confidential files, misuse customer information, delete important records, or provide access to an outside criminal.
Insider threats are particularly difficult because the individual may already possess legitimate credentials.
Organizations can reduce these risks through access controls, monitoring, employee training, strong account-management practices, and limiting access to information based on job responsibilities.
Some cyberattacks have consequences far beyond individual computers.
The United States depends on digital systems to operate energy networks, telecommunications, transportation, financial services, healthcare systems, government services, and other critical infrastructure.
An attack against such systems could disrupt essential services.
For this reason, federal cybercrime investigations may receive enhanced attention when they involve critical infrastructure, national security, public health, or significant economic interests.
The Department of Justice's CFAA guidance specifically identifies national security, critical infrastructure, public health and safety, market integrity, international relations, and national or economic interests as factors that prosecutors may consider when evaluating CFAA cases.
Protecting critical infrastructure therefore requires cooperation between government agencies, private companies, cybersecurity specialists, and law enforcement.
Cybercrime investigations depend heavily on digital evidence.
Unlike a traditional crime scene, a cybercrime scene may exist across computers, smartphones, servers, cloud platforms, network equipment, and online accounts.
Investigators may examine:
Digital evidence can help establish what happened and potentially identify the people responsible.
However, electronic evidence must be collected and analyzed carefully.
Investigators need to consider authenticity, preservation, relevance, and legal authority.
The Department of Justice's Computer Crime and Intellectual Property Section, known as CCIPS, works to guide investigators and prosecutors on the proper collection of electronic evidence and provides technical and legal assistance concerning computer crime.
This specialized expertise is necessary because digital investigations can involve enormous quantities of complex information.
The U.S. Department of Justice plays a major role in federal cybercrime enforcement.
Within the Department of Justice, the Computer Crime and Intellectual Property Section focuses on computer crime and intellectual-property offenses.
Its responsibilities include supporting investigations and prosecutions, guiding the collection of electronic evidence, and providing technical and legal assistance to law-enforcement officials.
The DOJ also maintains specialized guidance for prosecutors dealing with cyber and cyber-enabled crimes.
These resources help prosecutors determine which cases require enhanced coordination and which federal laws may apply.
Cybercrime investigations can involve many agencies and organizations, so coordination is essential.
The internet has no simple national boundary.
A victim may be in the United States, the criminal may be overseas, and the relevant servers may be located in several other countries.
This creates major challenges for investigators.
Authorities may need assistance from foreign governments or technology companies to obtain evidence.
International cooperation can be particularly important in cases involving organized cybercrime groups.
The Department of Justice maintains international cybercrime programs designed to help foreign law-enforcement and judicial partners combat transnational cybercrime and improve the collection and use of electronic evidence.
International cooperation is therefore an essential component of modern cybercrime enforcement.
Cybersecurity researchers regularly test systems for vulnerabilities.
Their work can help organizations discover security weaknesses before criminals exploit them.
However, unauthorized computer access can raise legal questions.
In 2022, the Department of Justice announced a revised CFAA charging policy stating that good-faith security research should not be charged under the CFAA when the research is conducted solely to test, investigate, or correct security vulnerabilities and is performed in a manner designed to avoid harm.
The policy does not mean that someone can claim to be a researcher after carrying out malicious activity.
For example, using a discovered vulnerability to extort a company would not become legitimate simply because the attacker describes the activity as research.
The distinction between responsible research and malicious exploitation is extremely important to the cybersecurity industry.
Technology changes faster than many traditional legal systems.
When the CFAA was introduced in 1986, modern cloud computing, smartphones, social media, artificial intelligence, cryptocurrency, and billions of internet-connected devices did not exist.
Today, criminals can exploit technologies that lawmakers could not have anticipated decades ago.
Artificial intelligence may be used to automate scams and create convincing impersonations.
Cloud services create complex environments in which information may be distributed across multiple locations.
Cryptocurrency can create challenges for investigators tracking financial transactions.
Connected devices can provide attackers with new entry points.
These developments demonstrate why cybercrime law cannot remain completely static.
At the same time, legislation must be written carefully.
Laws should be strong enough to address serious criminal behavior while remaining clear enough for legitimate users, businesses, researchers, and technology professionals to understand their responsibilities.
Criminals can adopt new technologies quickly. Law enforcement and lawmakers must constantly adapt.
Attackers may hide their identity through fake accounts, compromised devices, or complex infrastructure.
Investigators may need cooperation from multiple countries to identify suspects and obtain evidence.
Modern investigations can involve huge amounts of electronic information, making analysis difficult.
Cybercrime groups can operate like businesses, with different members specializing in malware, stolen credentials, financial transfers, or infrastructure.
Even sophisticated security systems can be undermined by a single employee clicking a malicious link or revealing a password.
These challenges mean that combating cybercrime requires much more than simply passing laws.
Businesses are major targets because they often possess valuable information and financial resources.
A cybersecurity strategy should begin with understanding what information and systems are most important.
Organizations should use strong authentication, restrict access to sensitive systems, keep software updated, maintain reliable backups, monitor networks, train employees, and prepare incident-response procedures.
Access should also be based on necessity.
Employees generally do not need unlimited access to every database in an organization.
Limiting privileges can reduce the damage caused by compromised accounts or insider threats.
CISA's guidance on insider threats similarly emphasizes practices such as strict account management, limiting sensitive information to people who require it, monitoring activity, and providing security training.
Cybersecurity should therefore be integrated into everyday business operations rather than treated as an emergency-only responsibility.
Individuals can take several simple steps to reduce their risk.
Avoid using the same password for multiple important accounts.
If one password is stolen, attackers may attempt to use it elsewhere.
Multi-factor authentication adds another security layer beyond a password.
Do not automatically trust emails, texts, or social-media messages simply because they appear professional.
Always confirm payment requests, especially when they involve urgency or unusual instructions.
Security updates can fix vulnerabilities that criminals may otherwise exploit.
Avoid sharing passwords, financial information, identification details, and other sensitive data unnecessarily.
Backups can be extremely valuable after ransomware, hardware failures, or other incidents.
A person who believes they have experienced cybercrime should avoid taking revenge or attempting to hack the attacker.
Instead, they should preserve evidence and report the incident through appropriate channels.
Evidence may include:
CISA advises victims to report different types of cybercrime to appropriate agencies and identifies the FBI's Internet Crime Complaint Center, or IC3, among the reporting options.
The Department of Justice also provides information directing people to resources for reporting computer hacking, fraud, identity theft, and other internet-related crimes.
Fast reporting can be important, particularly when financial transactions or compromised accounts are involved.
Cybersecurity and privacy are closely connected.
Law enforcement needs effective tools to investigate serious cybercrime, but investigations can involve extremely sensitive personal information.
Computers and smartphones may contain photographs, private messages, financial information, location data, documents, and other personal material.
This means cybercrime investigations must balance security with legal protections.
The Department of Justice's Cybersecurity Unit states that its mission includes helping law enforcement address cyber threats while protecting the privacy of ordinary Americans.
This balance is essential.
A strong cybercrime system should protect people from criminals without treating ordinary digital activity as suspicious simply because it occurs online.
Cybercrime can create substantial economic costs.
A successful attack can cause direct financial losses through stolen money or fraudulent transactions.
There can also be indirect costs.
A business may need to stop operations, investigate an incident, restore systems, notify customers, replace compromised equipment, hire specialists, and deal with legal or regulatory consequences.
Customers can also suffer financial and personal harm.
For small businesses, a major cyberattack can be especially damaging because they may have fewer resources available for recovery.
Cybersecurity investment should therefore be viewed as risk management rather than simply an IT expense.
Cybercrime will continue to evolve as technology develops.
Artificial intelligence may make some attacks faster and more convincing.
Deepfake technology could make impersonation scams more difficult to recognize.
Cloud services will continue to change how organizations store and process information.
Cryptocurrency and other digital assets may create new opportunities for criminals while also providing investigators with new sources of financial evidence.
The Internet of Things will connect increasing numbers of devices to networks, potentially expanding the number of systems that attackers can target.
At the same time, defensive technology will improve.
Artificial intelligence can assist security teams in detecting unusual activity. Automated monitoring can identify suspicious behavior more quickly. Better authentication systems can make stolen passwords less useful.
The future will therefore involve an ongoing competition between attackers and defenders.
Cybersecurity is often treated as a technical subject, but ordinary people play an important role in preventing cybercrime.
A person who recognizes a phishing message can prevent an account compromise.
An employee who reports suspicious activity can help an organization stop an attack before it spreads.
A business owner who maintains reliable backups may be able to recover from ransomware.
A student who learns not to share passwords can protect their accounts for years.
Small decisions can therefore have significant consequences.
Cybersecurity awareness does not require everyone to become a computer expert.
It requires people to understand basic risks and develop safe habits.
Cybercrime is one of the most significant challenges created by the modern digital world.
The United States has developed a broad legal and institutional framework for responding to these threats. The Computer Fraud and Abuse Act is an important federal law addressing unauthorized computer access, computer-related fraud, and certain forms of damage to protected computers.
However, cybercrime is much broader than hacking.
Phishing, ransomware, identity theft, malware, cyberstalking, online fraud, denial-of-service attacks, insider threats, and data theft can all cause serious harm. Different federal and state laws may apply depending on the circumstances.
The fight against cybercrime also requires specialized expertise. The Department of Justice's Computer Crime and Intellectual Property Section supports investigations and prosecutions, provides guidance concerning electronic evidence, and offers technical and legal assistance to law-enforcement officials.
International cooperation is equally important because cybercriminals can operate across borders. Investigations may require collaboration between governments, technology companies, cybersecurity specialists, and law-enforcement agencies in different countries.
Businesses and individuals also have an important role.
Organizations should protect their systems through strong authentication, access controls, employee training, monitoring, backups, and incident-response planning. Individuals should use strong and unique passwords, enable multi-factor authentication, be cautious with suspicious messages, protect sensitive information, and keep their devices updated.
Most importantly, people should understand that cybercrime is not simply a problem for large technology companies or government agencies. Anyone who uses a connected device can become a target.
The digital world will continue to change. Artificial intelligence, cloud computing, connected devices, digital payments, and other technologies will create new opportunities while also creating new security challenges.
The law will need to evolve alongside those technologies.
Effective cybercrime prevention will ultimately depend on a combination of clear laws, skilled investigators, responsible technology companies, strong cybersecurity practices, international cooperation, and informed users.
Technology has made society more connected than ever before. Protecting that connected world is therefore not only a technical responsibility but also a legal, economic, and social one.
A safer internet begins with understanding the risks—and taking those risks seriously.