> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/law-and-compliance/computer-misuse-act.md).

# Computer Misuse Act

The computer Misuse Act is the main piece of UK legistation that criminalises unauthorised access to computer systems and data, and other acts that can impair, or risk impairing, computer operations. It was enacted in 1990 in response to the R vs Gold and Schifreen case that occurred between 1984-85.

They used weak credentials to access British Telecom's Prestel system and were originally prosecuted under the Forgery and Counterfeiting Act 1981.&#x20;

However, they were acquitted under appeal because "the language of the Act was not intended to apply to the situation". The CMA was therefore introduced to make "computer hacking" a criminal offense under UK Law.

\
When Introduced, the Act had three main sections:

* **Section 1** - makes it an offence to gain unauthorised access to computer material, which means systems or data.
* **Section 2** - makes it an offence to gain unauthorized access with intent to commit or facilitate further offences.
* **Section 3 -** makes it an offence to perform unauthorised act against computer systems, either with intent to impair, or that may cause impairment, even if accidental.

The Act does not discriminate against the 'motive' of those involved. Gaining unauthorized access to computer material, even with good intensions, is still an offence. The Gray Mckinnon case was well publicised in the early 2000's. He was systems administrator who hacked into multiple NASA and United States military systems, looking for evidence of coverups. He faced extradition charges and up to 70 years in jail. His extradtion was eventually blocked by the UK Government and the case slowly lost traction owing to his mental decline.

A lesser-known case was that of Daniel  Cuthbert, who was a penetration tester at ABN Amro. He made a donation to a charity website setup in the wake of the 2004 Boxing Day Tsunami, but became suspicious when the transaction appeared to not complete properly. Fearing it was a phishing site, he performed directory traversal scans against it. However, the site was legitimate and his scans triggered multiple IDS alerts. Cuthbert was prosecuted and found guility under the Computer Misuse Act. Although he wasn't sent to prison, he was fined and lost his job.

### Police And Justice Act

The Police and Justice Act 2006 provided some amendments to the CMA. It updated the Act's wording to put a stronger emphasis on requiring clear proof of intent before somebody could be found to have committed an offence.

It also introduced a new section - **Section 3A.** This section criminalizes the making, supplying, or obtaining of, any "articles" that are used to commit an offence under the Act. An "article" includes any program or data held in electronic form, which could include malware or hacking instructions. It's possible that, had Marcus Hutchins (aka MalwareTech) been prosecuted in the UK, it would have been under this section because he produced the Kronos malware used to commit offences, but did not commit the offences himself.

### Serious Crime Act

\
The Serious Crime Act 2015, also provided amendments to the CMA. It added another new section - **Section 3 ZA**. This enforces much harsher sentences for unauthorised acts that cause, or risk causing, serious damage. This includes illness or death, disruption to food, water, energy, or fuel supplies; or disruption to transportation, communication, health or government networks. Typical offences carry a jail term of up to 14 years but significant risk or damage to human welfare or national security could result in life imprisonment.\
\
The Act also updated the territorial scope of computer misuse offences to include those that are carried out against another country, and offences that are carried out by a UK citizen, but from another country.
