Skip to content

Computer access and insider misuse · U.S. · 2021

Van Buren v. United States

593 U.S. 374 (2021)

The Supreme Court narrowed the Computer Fraud and Abuse Act: a person 'exceeds authorized access' only by reaching files, folders, or databases that are off-limits to them — not by misusing access they legitimately have. Insider data-theft cases now turn on access architecture and other statutes.

An individual 'exceeds authorized access' when he accesses a computer with authorization but then obtains information located in particular areas of the computer—such as files, folders, or databases—that are off limits to him.
Van Buren v. United States, 593 U.S. 374 (2021) read the opinion

Issue

A police sergeant ran a license-plate lookup in a law-enforcement database in exchange for money — a use that plainly violated department policy, through credentials he plainly held. He was convicted under the CFAA's 'exceeds authorized access' clause. The question was whether the statute reaches those who misuse access they have, or only those who obtain information from places their access does not extend.

Rule

The CFAA's 'exceeds authorized access' clause covers obtaining information from areas of a computer — files, folders, databases — that are off-limits to the accesser. The inquiry is a gates-up-or-down one: either you are entitled to access the information or you are not. Purpose-based limits in an employer's policy do not convert authorized access into a federal computer crime, a reading the Court reinforced by noting the alternative would criminalize a breathtaking amount of commonplace computer activity — every policy violation from checking sports scores at work upward.

Application

Van Buren's use was corrupt, and the Court did not suggest otherwise — it held the CFAA was the wrong instrument. Both sides agreed he was entitled to run plate queries in that system; his misconduct was in why he ran one. Because the license-plate records sat in an area his credentials legitimately reached, the gates were up, and obtaining them did not 'exceed authorized access' however improper the purpose. An interpretation that turned on how an employer happened to phrase its policies, the Court added, was too fragile to carry federal criminal liability.

Conclusion

Reversed. After Van Buren, an insider who misuses data they were permitted to reach has not violated the CFAA's exceeds-authorized-access clause — the conduct must be addressed through trade-secret law, contract, fiduciary duty, or state statutes. The decision also raised the stakes of a question it expressly left open: whether the gates are defined only by technical controls or also by contract, an issue that now recurs in scraping and departing-employee litigation.

What this means in practice

Van Buren moved the battleground from the statute to the evidence. A departing-employee case now rests on proving what was taken and where it went — forensic reconstruction of USB activity, cloud sync, and exfiltration timelines feeding a Defend Trade Secrets Act claim — rather than on a CFAA count that policy language can no longer support. It also made access architecture a legal design decision: data that is technically segregated, with permissions that mirror policy, keeps the gates-down argument available when it matters.

Related services: Trade Secret Investigations · Corporate Risk & Internal Assessment · Forensic Investigations

From our work

Need this looked at properly?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.

This summary is provided for general information and is not legal advice. The linked opinion is the authoritative source; citation and quotation verified against the CourtListener record (cluster 4888668).