Beyond Swartz and weev: the full pattern of CFAA prosecutions against researchers, white-hats, and vulnerability discoverers.
Contents 44 sections

The Thesis in One Sentence

The United States government, aided by corporate legal departments, has spent four decades prosecuting the people who actually find security vulnerabilities — while paying billions annually to compliance consultancies that produce PDF reports nobody reads.


1. The Law Itself: A Brief Anatomy of the CFAA

The Computer Fraud and Abuse Act (18 U.S.C. § 1030) was enacted in 1986 as an amendment to the first federal computer fraud law from 1984. It was written in an era when “computer” meant a mainframe in a government facility, and “unauthorized access” meant physically breaking into a room.

The statute criminalises:

  • Accessing a computer “without authorization” or “exceeding authorized access”
  • Obtaining information from protected computers
  • Trafficking in passwords
  • Causing damage to protected computers
  • Extortion involving computers

The critical problem: the CFAA never defines “without authorization.” This omission has been the weapon of choice for federal prosecutors and corporate legal departments for nearly 40 years.

Maximum penalties for first-time offenders range from 1 to 10 years depending on the offence category. But the real power is in charge stacking — prosecutors can layer multiple CFAA counts for what is effectively a single act, turning misdemeanours into decades of potential prison time.

Sources:


2. The Famous Three (Brief, Because You Know Them)

Aaron Swartz (2011)

Downloaded ~4.8 million academic articles from JSTOR via the MIT network. Federally indicted on 13 counts of wire fraud and CFAA violations. Faced up to 35 years in prison and $1 million in fines. Prosecutors rejected his plea deal counter-offer. Swartz took his own life on 11 January 2013 at age 26.

JSTOR itself declined to pursue charges. MIT stayed silent. The federal government prosecuted anyway.

Sources:

Andrew “weev” Auernheimer (2012)

Discovered an AT&T vulnerability that exposed iPad owners’ email addresses on a public-facing URL. Notified AT&T, which did nothing. Disclosed to Gawker. Convicted, sentenced to 41 months in federal prison plus $73,000 in restitution. The government attempted to bootstrap a state computer crime charge to elevate the federal CFAA misdemeanour to a felony — a charge-stacking trick the defence called a Double Jeopardy violation since all 50 states have similar statutes, meaning essentially all federal CFAA misdemeanours could be inflated to felonies. Conviction overturned on appeal (venue, not merit) in 2014.

AT&T was never charged for exposing customer data.

Sources:

Marcus Hutchins (2017)

The researcher who stopped WannaCry was arrested at DEF CON and charged under the CFAA for malware he allegedly wrote as a teenager years earlier. Pleaded guilty to two counts in 2019. Sentenced to time served with one year of supervised release. The message to every security researcher was clear: even if you save the internet, they can still come for you.


3. The Ones You Haven’t Heard Of

Robert Morris Jr. (1988) — The First Prosecution

The very first CFAA prosecution was not of a criminal but of a Cornell graduate student. Robert Morris, son of an NSA computer scientist, released the “Morris Worm” as part of his PhD research exploring internet security. The worm was not designed to cause damage but a coding error caused it to replicate uncontrollably, affecting roughly 6,000 of the internet’s then 60,000 connected machines. Convicted of a felony in 1990. Sentenced to three years’ probation, 400 hours of community service, and a $10,050 fine. The CFAA’s baptism: prosecuting a curious graduate student.

Sources:

Bret McDanel (2001) — Imprisoned for Warning Users

McDanel worked at Tornado Development, an email service provider. He discovered that the system stored user login credentials in plaintext as part of the URL — meaning every website a user visited after leaving Tornado could capture their credentials in server logs. He reported it to Tornado. Six months later, the flaw was still unpatched. McDanel emailed Tornado’s users from “Secret Squirrel” to warn them. Tornado reported him to the FBI.

Convicted after a bench trial. Sentenced to 16 months in federal prison. For telling users their passwords were being broadcast in plaintext.

The federal government later admitted the prosecution was an error and voluntarily moved to vacate the conviction. But McDanel had already served his time.

Sources:

Justin Shafer (2016) — Raided for Finding an Open FTP Server

Shafer, a Texas dental software technician and security researcher, discovered that Eaglesoft practice management software (by Patterson Dental) had an anonymous FTP server exposing the protected health records of approximately 22,000 patients. Anyone could access it. No password required. He reported it to Patterson Dental.

Patterson claimed Shafer had “exceeded authorized access” and the FBI raided his home with at least a dozen armed agents. Shafer then blogged about the raids. For blogging about the FBI raiding him, he was charged with cyberstalking an FBI agent and spent eight months in jail awaiting trial. The government eventually dropped five felony charges, and Shafer pleaded guilty to a single misdemeanour.

The anonymous FTP server remained Patterson’s problem. Patterson was not prosecuted for the HIPAA violations.

Sources:

Randal Schwartz (1995) — Password Cracking as a Consultant

Schwartz, author of the O’Reilly Learning Perl book, had worked as a systems administrator contractor at Intel (1988-1993). After leaving, he ran a password cracking tool against Intel’s systems to demonstrate that security had deteriorated since his departure. Convicted of three felony counts under Oregon’s computer crime statute (the state equivalent of CFAA). Sentenced to five years’ probation, 480 hours of community service, 90 days in jail, and ordered to pay Intel $68,000 plus $170,000 in legal defence costs.

The conviction was finally expunged in 2007 — twelve years later.

Sources:

Matthew Keys (2016) — Two Years for a 40-Minute Defacement

Keys, a journalist formerly employed at a Tribune Company television station, shared CMS login credentials in an Anonymous chatroom. An unknown person used them to deface a single Los Angeles Times article for approximately 40 minutes. Keys was convicted on three CFAA counts carrying a maximum of 25 years. Sentenced to two years in federal prison. The “loss” to Tribune was estimated at $249,000 — for a 40-minute headline change that an editor reversed.

Sources:

Coalfire Penetration Testers (2019) — Arrested for Doing Their Job

Gary DeMercurio and Justin Wynn, penetration testers at Coalfire Labs, were contracted by the Iowa Court Information System to conduct physical security tests on courthouses — including impersonating employees, tailgating, and entering restricted areas. During a test at the Dallas County Courthouse, they triggered an alarm. The local sheriff arrived, saw their authorisation contract, and arrested them anyway. Charged with felony third-degree burglary and possessing burglary tools. Held on $100,000 bail. Spent nearly 24 hours in jail.

Charges were eventually downgraded to misdemeanour trespass, then dropped in January 2020. Dallas County later paid a $600,000 settlement for the wrongful arrest.

The sheriff had not been informed of the engagement. The state that hired them prosecuted them.

Sources:


4. Corporate Weaponisation: CFAA as a Silencing Tool

The CFAA’s civil action provision (§ 1030(g)) allows private companies to sue researchers directly. This is where the real volume lives. Criminal prosecutions make headlines; cease-and-desist letters arrive quietly and are designed to.

Cisco vs. Michael Lynn (2005) — “Ciscogate”

Security researcher Michael Lynn, working at ISS (Internet Security Systems), reverse-engineered Cisco IOS and discovered a critical vulnerability in the operating system that runs most of the internet’s core routers. He was scheduled to present his findings at Black Hat 2005 in Las Vegas. Cisco and ISS obtained a federal temporary restraining order. Conference organisers were ordered to rip Lynn’s pages from the printed proceedings. Lynn presented anyway — after quitting his job on stage.

Settlement terms required Lynn to hand over all his research data for forensic analysis, then destroy it. He was permanently prohibited from discussing the vulnerability.

The message: find a bug in the internet’s backbone and we will erase you.

Sources:

Oracle’s CSO Rant (2015)

Oracle Chief Security Officer Mary Ann Davidson published a blog post titled “No, You Really Can’t” — telling customers and security consultants to stop reverse-engineering Oracle products to find vulnerabilities, threatening to enforce licence agreement provisions against anyone who did. She accused researchers of wasting Oracle’s time with false positives and breaking Oracle’s terms of service.

Oracle pulled the post within hours and issued a statement that it did not reflect company policy. But the damage was done: it revealed exactly how a major enterprise vendor views independent security research — as a nuisance to be litigated away.

Sources:

Voatz vs. MIT Researchers (2020)

MIT graduate students Michael Specter and James Koppel conducted a security analysis of Voatz, a mobile voting app used in the 2018 West Virginia midterm elections. They found critical vulnerabilities including opportunities to alter, stop, or expose how users voted. Voatz accused the researchers of “bad faith,” reported a University of Michigan student studying election security to the FBI, and then filed an amicus brief with the Supreme Court arguing that the CFAA should criminalise any security research conducted without explicit vendor permission.

HackerOne cut ties with Voatz over its hostility toward researchers. A coalition of security firms, researchers, and organisations signed a letter opposing Voatz’s position.

A voting app vendor tried to use the nation’s highest court to make it illegal to check whether elections are secure.

Sources:

Missouri Governor vs. a Journalist (2021)

St. Louis Post-Dispatch reporter Josh Renaud discovered that the Missouri Department of Elementary and Secondary Education website was embedding teachers’ Social Security numbers in the HTML source code of public web pages. He found this by pressing F12 — the browser’s built-in “View Source” function. The Post-Dispatch responsibly notified the state, delayed publication to allow the flaw to be patched, and then reported on it.

Missouri Governor Mike Parson held a press conference accusing Renaud of “hacking” and vowing criminal prosecution, claiming the state would seek charges against Renaud and “all those who aided” him. The investigation produced a 158-page file that found zero evidence of hacking. The Cole County prosecutor declined to press charges.

The Governor never retracted his accusations. He spent more effort attacking the reporter than fixing the system that exposed 100,000+ teachers’ Social Security numbers.

Sources:

The Broader Pattern

The disclose.io project maintains a public repository of legal threats against good-faith security researchers — a running catalogue of disclosure gone wrong. Cases include threats from Boeing, CyberLock (invoking the DMCA), and dozens of smaller companies. The repository is a continuation of attrition.org’s earlier documentation work.

Facebook and LinkedIn have both used cease-and-desist letters citing the CFAA against researchers and journalists whose access they wanted to curtail.

Sources:


5. The Prosecutorial Logic: How “Unauthorized Access” Becomes Whatever They Need It to Be

The CFAA’s core weapon is ambiguity. “Without authorization” and “exceeds authorized access” are nowhere defined in the statute. This gives prosecutors — and corporate lawyers filing civil suits — essentially unlimited discretion.

The Government’s Preferred Reading (Pre-2021)

For decades, DOJ’s position was maximally broad: if you accessed a computer in a way the owner didn’t like, that was “unauthorized.” Violating a website’s Terms of Service? Unauthorized. Using a work computer for personal email? Unauthorized. Accessing data that was technically public but that the vendor wished you hadn’t found? Unauthorized.

As Orin Kerr — former federal prosecutor and one of the most cited CFAA scholars — has argued, under the government’s interpretation, prosecutors could put “any Internet user they want” in jail.

The Lori Drew Problem (2009)

Lori Drew created a fake MySpace account to cyberbully 13-year-old Megan Meier, who died by suicide. Prosecutors charged Drew under the CFAA, arguing that creating a fake profile violated MySpace’s Terms of Service and therefore constituted “unauthorized access.” The jury convicted on misdemeanour counts. The judge overturned the conviction, ruling that the government’s theory would render the CFAA “unconstitutionally vague” — because it would criminalise every Terms of Service violation on the internet.

The prosecution was legally absurd but emotionally irresistible, which is exactly the combination the CFAA invites.

Sources:

Van Buren v. United States (2021) — The Supreme Court Finally Weighs In

Nathan Van Buren, a Georgia police officer, used his legitimate access to a law enforcement database to look up a licence plate in exchange for money. The government charged him under the CFAA’s “exceeds authorized access” provision.

In a 6-3 decision, the Supreme Court adopted a “gates-up-or-down” approach: either you are entitled to access the information, or you are not. Merely accessing data for an improper purpose does not “exceed authorized access” if you were technically permitted to view it. The Court explicitly rejected the government’s broad interpretation.

This was a significant narrowing — but it left enormous grey areas for security researchers, whose work by definition involves accessing systems they don’t own without explicit permission.

Sources:

The 2022 DOJ Policy Revision

In May 2022, the DOJ announced it would no longer charge “good-faith security research” under the CFAA. Deputy AG Lisa Monaco claimed “the department has never been interested in prosecuting good-faith computer security research as a crime.”

The definition of “good faith” is the catch: research must be “solely” for testing, investigation, or correction of a security flaw, “designed to avoid any harm,” and information must be “used primarily to promote the security or safety” of the affected systems. Research with “ulterior” or “mixed motives” remains fair game.

Critical limitations:

  1. This is a prosecutorial policy, not a law. Any future administration can reverse it with a memo.
  2. It only covers federal criminal prosecution. It does nothing about civil CFAA lawsuits by companies, which constitute the vast majority of legal threats against researchers.
  3. It does not bind state prosecutors.
  4. The “solely” and “good faith” qualifiers give enormous discretion to the same prosecutors the policy is supposed to restrain.
  5. It explicitly states that receiving a cease-and-desist letter can convert previously permissible access into a CFAA violation.

Sources:


6. The Numbers: What We Know (and What We Don’t)

Hard statistics on CFAA prosecutions are scarce by design. The DOJ does not publish CFAA-specific breakdowns. What we have:

What Exists

  • The Federal Justice Statistics Program (Bureau of Justice Statistics) tracks federal criminal case workloads, including convictions and sentencing, but does not separate CFAA cases as a distinct category.
  • The U.S. Sentencing Commission publishes sentencing data by guideline category but the computer fraud guidelines encompass more than just CFAA.
  • The NACDL maintains the most comprehensive public case database of notable CFAA prosecutions.

The Chilling Effect Data

The Center for Democracy and Technology surveyed security researchers and found over half reported forgoing some research or avoiding research altogether because of potential CFAA liability. A 2018 CDT report interviewing 20 academic and independent researchers found that over half cited the CFAA as a major risk factor in their work.

The majority of concerns stemmed from uncertainty around the undefined term “access” — meaning researchers cannot reliably predict whether their work is legal before they do it.

Cease-and-desist letters citing the CFAA “have become an all-too-common tool for intimidation.” The exact number is unknowable — that’s the point of a chilling effect.

Sources:

Sentencing Patterns from Known Cases

CaseChargeOutcomeSentence
Robert Morris (1988)Felony CFAAConvicted3 yrs probation, 400 hrs community service, $10,050 fine
Randal Schwartz (1995)3 felony counts (state)Convicted (expunged 2007)5 yrs probation, 480 hrs community service, 90 days jail, $238,000 costs
Bret McDanel (2001)CFAA violationConvicted, later vacated16 months prison
Aaron Swartz (2011)13 counts wire fraud + CFAADied before trialFaced up to 35 years
Andrew Auernheimer (2012)CFAA + NJ state bootstrapConvicted, reversed on appeal41 months prison + $73,000 restitution
Matthew Keys (2015)3 CFAA countsConvicted2 years prison
Justin Shafer (2016)CFAA + cyberstalkingPled to 1 misdemeanour8 months jail (pretrial)
Marcus Hutchins (2017)CFAA (malware-related)Pled guilty 2 countsTime served + 1 yr supervised release
Coalfire testers (2019)Felony burglaryCharges dropped$600,000 settlement to defendants

7. International Comparison: Everyone Has the Same Problem, Some Handle It Worse

United Kingdom — Computer Misuse Act 1990

The UK’s Computer Misuse Act (CMA) is arguably worse than the CFAA. The US at least has a more developed vulnerability research ecosystem — companies like Shodan and Censys are headquartered in the US precisely because the methods they use would be illegal under the CMA.

The CMA criminalises “unauthorized access to computer material” with the same definitional vacuum as the CFAA. But it lacks the CFAA’s civil cause of action — meaning the UK problem is purely criminal. The CMA has no explicit carve-out for security research.

The CyberUp Campaign has been pushing for CMA reform for years, producing detailed evidence for Parliament documenting how the law chills legitimate security research. In 2025, the UK government pledged to rewrite the CMA, introducing long-overdue statutory protections for cyber security professionals and threat researchers.

Sources:

Netherlands — The Model That Works

The Netherlands has the most mature responsible disclosure framework in Europe. The Dutch government explicitly states that if researchers comply with disclosure conditions, “the government will not attach any legal consequences to your notification.” The Public Prosecution Office has a standing policy not to prosecute ethical hackers who follow the framework.

Sources:

Belgium — Safe Harbour (2023)

Belgium became the first European country to adopt a comprehensive, nationwide safe harbour for ethical hackers, effective 15 February 2023. The Centre for Cyber Security Belgium (CCB) framework protects anyone who reports security vulnerabilities in Belgian systems from prosecution, provided they meet strict conditions. According to the CCB’s legal officer, Belgium’s framework is the most comprehensive in Europe; France and Slovakia fall short of “full legal protection,” and Lithuania’s is limited to critical infrastructure.

Sources:

European Union — NIS2 Directive (2022)

The NIS2 Directive (EU 2022/2555) includes provisions for coordinated vulnerability disclosure and “encourages” member states to adopt guidelines on non-prosecution of security researchers. Note the word: “encourages.” Not “requires.” Member states “should aim to address the challenges faced by vulnerability researchers, including their potential exposure to criminal liability, in accordance with national law.”

A 2025 paper in the Oxford Journal of Cybersecurity called for defining “good-faith security research” as a legally recognised safe harbour in EU law, arguing that the current patchwork approach creates legal uncertainty that “may hinder or even prevent the reporting of vulnerabilities.”

Sources:

Germany — They’ll Fine You for Finding Their Bugs

In 2021, a German IT consultant known as Hendrik H. discovered that Modern Solution GmbH’s e-commerce software stored database passwords in plaintext, exposing nearly 700,000 customer records. He reported it to the company. Modern Solution reported him to the police. A Jülich District Court initially sided with the consultant, then reversed itself on appeal. In January 2024, Hendrik H. was fined EUR 3,000 for discovering that a company was storing passwords in plaintext. He filed a constitutional complaint; the Cologne Higher Regional Court confirmed the judgment.

Sources:

Australia — No Safe Harbour

Australia’s Cybercrime Act 2001 and the Criminal Code Act 1995 criminalise unauthorised access and modification of data. There is no explicit exemption for security research. IT security professionals “need to be aware of the abovementioned provisions so as not to get caught by a technical breach” — because the mere possession of security tools can trigger the statute.

Australia has no formal coordinated vulnerability disclosure framework with legal protection.

Sources:


8. Reform Efforts: A Catalogue of Failed Attempts

Aaron’s Law (2013, 2015)

Introduced by Reps. Zoe Lofgren and Jim Sensenbrenner, with Senators Ron Wyden and Rand Paul, Aaron’s Law proposed:

  1. Terms of Service are not crimes. Access “without authorization” would require circumventing a technological or physical barrier (passwords, encryption, locked doors) — not violating a website’s TOS.
  2. Anti-charge-stacking. Prosecutors could not inflate sentences by layering multiple CFAA counts for the same underlying act.
  3. Privacy protections. Masking your identity (IP address, MAC address, real name) would not itself constitute unauthorized access.

Both versions died in committee. Congress has never passed CFAA reform legislation.

Sources:

EFF’s Ongoing Campaign

The Electronic Frontier Foundation has been the most persistent advocate for CFAA reform, maintaining a dedicated campaign page and intervening in major CFAA cases including Swartz, Auernheimer, Keys, Drew, and Van Buren. Their position: the CFAA needs both legislative reform and judicial narrowing, because prosecutorial policies can be revoked at any time.

Sources:

The Rapid7 Proposal (2021)

Rapid7 published a detailed proposed statutory amendment to the CFAA that would create explicit protection for security researchers. The proposal would add a new subsection establishing that good-faith security research does not constitute a violation, provided the researcher acts to promote safety and does not cause harm.

Sources:

Harvard Cyberlaw Clinic — “Coming In From the Cold”

The Harvard Cyberlaw Clinic published a comprehensive proposal for a “safe harbour” from both the CFAA and the DMCA for security researchers, arguing that the two statutes create interlocking chilling effects. Without reform to both, researchers face legal risk from multiple directions simultaneously.

Sources:

Academic Scholarship

Key legal scholars:

  • Orin Kerr (UC Berkeley): Former federal prosecutor, filed the pro bono brief in Auernheimer’s appeal, argued for the narrow “code-based” interpretation that the Supreme Court adopted in Van Buren. Has been pushing for narrower CFAA readings for over 20 years.
  • Tim Wu (Columbia): Called the CFAA “the worst law in technology.”
  • Mitchell Hamline School of Law published “Patching the CFAA so Researchers No Longer Pay” — a law review article documenting how the Van Buren decision, while helpful, left the majority of security research in legal limbo because most independent research involves accessing systems “without authorization” rather than “exceeding” it.

Sources:


9. The Compliance Industrial Complex: Who Actually Gets Paid

While the federal government prosecutes people who find real vulnerabilities, the cybersecurity industry has built a $272 billion global market (2025, projected to reach $663 billion by 2033) overwhelmingly oriented around compliance paperwork rather than actual security testing.

Key statistics:

  • 71% of enterprise organisations spend over $100,000 per year on compliance audits alone
  • 69% of organisations say regulatory compliance — not actual security improvement — is their primary security spending driver
  • 70% of service providers must comply with six or more distinct frameworks
  • McKinsey estimates the total addressable cybersecurity market at $1.5 to $2 trillion annually

The business model is clear: companies pay consultancies to produce reports certifying compliance with NIST, ISO 27001, SOC 2, PCI-DSS, HIPAA, and dozens of other frameworks. These reports are largely self-assessments or controlled-scope audits. They test whether your documentation says the right things, not whether your systems can withstand an actual attack.

Meanwhile, the people who actually test systems — by accessing them and finding out what breaks — operate under perpetual legal jeopardy.

Sources:


10. The Pattern, Made Explicit

Every case in this document follows the same arc:

  1. A researcher finds a real vulnerability through actual testing
  2. The vendor/owner/government agency is embarrassed
  3. Instead of fixing the vulnerability, they attack the researcher
  4. The CFAA (or international equivalent) provides the legal weapon
  5. The researcher is prosecuted, threatened, raided, fined, or silenced
  6. The underlying vulnerability may or may not get fixed
  7. Nobody prosecutes the vendor for the insecure system

Meanwhile:

  • Compliance consultancies collect their fees regardless of whether the organisation is actually secure
  • Vendors ship the same vulnerable software with updated compliance certifications
  • The researchers who could find the next vulnerability decide it’s not worth the legal risk
  • Over half of security researchers have abandoned research because of CFAA liability

The CFAA doesn’t protect computer security. It protects the feelings of people who ship insecure systems. And the compliance industry exists to provide cover documentation for the institutions that refuse to let anyone test whether those systems actually work.


Source URLs

For ongoing tracking: