• Skip to main content
  • Skip to primary sidebar

Criminal Justice

iResearchNet




Criminal Justice > Criminology > Cyber Criminology > Hacking and Unauthorized Access

Hacking and Unauthorized Access




Hacking and Unauthorized AccessHacking and unauthorized access constitute the paradigmatic offenses of cybercrime, encompassing the intentional intrusion into computer systems, networks, and digital accounts without the permission of the system owner or in excess of authorized privileges. As foundational concerns within Cyber Criminology, these offenses have shaped the legal, investigative, and policy architecture of cybercrime response in the United States more than any other category of digital criminal conduct. The Computer Fraud and Abuse Act (CFAA), enacted in 1986 and amended repeatedly since, was crafted primarily to address unauthorized computer access, and its interpretive evolution reflects the broader challenges of applying legal categories developed for an era of mainframe computing to a world of cloud services, mobile applications, and the Internet of Things. This article examines the technical methods, legal frameworks, offender profiles, organizational impacts, and enforcement challenges associated with hacking and unauthorized access, situating these offenses within broader theoretical perspectives in Criminology.

Introduction

The terms “hacking” and “unauthorized access” encompass a broad spectrum of conduct, from the exploration of system vulnerabilities by curious amateurs through to the systematic penetration of government and corporate networks by organized criminal groups and nation-state actors. This spectrum has complicated efforts to define, measure, and respond to hacking as a criminal phenomenon. The original hacker subculture of the 1960s and 1970s — associated with MIT’s Tech Model Railroad Club and the early computing communities of Stanford and Berkeley — valued intellectual curiosity, technical mastery, and the free exchange of information, producing an ethic of “hacking” that was exploratory rather than destructive. The criminalization of computer access beginning in the 1980s, accelerated by high-profile cases such as the prosecution of Kevin Mitnick and the emergence of malicious hacking groups, transformed public understanding of hacking from a subcultural practice into a criminal threat.

Contemporary hacking encompasses activities that range from benign to catastrophic in their consequences. Security researchers conduct authorized penetration testing to identify and remediate vulnerabilities. Bug bounty participants probe corporate systems under terms of service that authorize limited testing. At the other extreme, advanced persistent threat (APT) groups conduct multi-year intrusion campaigns against critical infrastructure, defense contractors, and financial institutions, extracting data and establishing persistent access that can be activated for espionage or sabotage. Between these poles lies a vast middle ground of unauthorized access incidents — credential theft, brute-force account compromise, exploitation of unpatched vulnerabilities, SQL injection attacks against web applications — that constitutes the bulk of hacking activity by volume. This article surveys the landscape of hacking and unauthorized access with attention to the technical, legal, and criminological dimensions of these offenses.




Technical Methods and Attack Vectors

Exploitation of Software Vulnerabilities

The exploitation of vulnerabilities in software — coding errors, design flaws, and configuration weaknesses that permit unintended access or control — represents the most technically sophisticated category of hacking methodology. Vulnerability exploitation follows a lifecycle that begins with discovery (identifying a flaw in a system’s code or configuration), proceeds through development (creating a working exploit that leverages the flaw to achieve unauthorized access or control), and culminates in deployment (using the exploit against one or more target systems). The Common Vulnerabilities and Exposures (CVE) system maintained by MITRE documented over 29,000 new vulnerabilities in 2023, a record that reflects both the expanding volume of software in use and the increasing rigor of vulnerability discovery programs.

Zero-day vulnerabilities — flaws that are unknown to the software vendor and for which no patch exists — represent the most valuable and dangerous category of exploitable weaknesses. Zero-day exploits command premium prices on both legitimate (government procurement) and illegitimate (underground market) channels, with prices for high-impact zero-days in widely deployed software reportedly reaching $1 million or more. The Zerodium exploit acquisition platform has publicly listed bounties of up to $2.5 million for zero-day exploits targeting iOS and Android mobile operating systems, providing a benchmark for the market value of these capabilities. Nation-state actors, particularly those attributed to Russia, China, North Korea, and Iran, are the most prolific users of zero-day exploits, employing them in targeted espionage and sabotage campaigns against government, defense, and critical infrastructure targets.

The majority of successful hacking incidents, however, exploit known vulnerabilities for which patches are available but have not been applied. The Verizon DBIR has consistently found that the exploitation of known, patchable vulnerabilities accounts for a substantially larger share of breaches than zero-day exploitation. The gap between vulnerability disclosure and patch application — often measured in weeks to months for many organizations — creates an exposure window during which widely published exploit code can be used by attackers of varying sophistication levels. Automated scanning tools enable even low-skill attackers to identify and exploit unpatched systems at scale, democratizing access to vulnerability exploitation in ways that compress the traditional skill hierarchy of hacking.

Credential-Based Attacks

Credential-based attacks — methods that obtain or exploit valid usernames and passwords to gain access to systems — represent the most common entry vector for unauthorized access. The Verizon DBIR’s 2024 analysis identified stolen credentials as a factor in approximately 50 percent of confirmed data breaches, exceeding vulnerability exploitation, phishing, and all other initial access methods. Credential compromise occurs through multiple pathways: data breaches that expose password databases, phishing campaigns that harvest login information, keylogger malware that captures credentials during entry, brute-force attacks that systematically test password combinations, and credential stuffing attacks that exploit password reuse by testing credentials stolen from one service against login portals of other services.

The scale of credential compromise in circulation is staggering. Security researchers have documented compilations of billions of username-password pairs aggregated from historical data breaches and available for purchase on underground forums or accessible through free leak repositories. The “Collection #1” compilation identified in 2019 contained over 773 million unique email addresses paired with passwords, and subsequent compilations have been substantially larger. This reservoir of compromised credentials fuels automated credential stuffing operations that can test millions of login combinations per hour against targeted services, generating unauthorized access wherever password reuse or weak credentials permit entry.

Password-based authentication remains the dominant access control mechanism for most digital services despite its well-documented weaknesses. The National Institute of Standards and Technology (NIST) revised its Digital Identity Guidelines (SP 800-63B) in 2017 to discourage many traditional password policies — mandatory periodic changes, complexity requirements — that research had shown to be counterproductive, instead emphasizing password length, breach-checked password screening, and multi-factor authentication. The adoption of passkeys and other passwordless authentication standards, promoted by the FIDO Alliance and supported by major technology platforms, represents a potential long-term shift away from the credential-based access model that underlies most unauthorized access incidents.

Network and Infrastructure Attacks

Network-level attacks target the infrastructure through which computer systems communicate rather than the systems themselves. Distributed denial-of-service (DDoS) attacks overwhelm target systems with traffic volume that exceeds their processing capacity, rendering services unavailable to legitimate users. While DDoS does not typically involve data theft or system compromise, it constitutes unauthorized interference with computer systems and is prosecuted under the CFAA. DDoS attack volume has escalated dramatically, with Cloudflare documenting attacks exceeding 5 terabits per second in 2024 — traffic volumes that can overwhelm even well-provisioned infrastructure without specialized mitigation services.

Man-in-the-middle attacks intercept communications between two parties, enabling the attacker to eavesdrop on or alter transmitted data. These attacks exploit weaknesses in network protocols, certificate validation, and wireless network security to position the attacker between the victim and their intended communication partner. While encryption has substantially reduced the effectiveness of man-in-the-middle attacks for web traffic — the widespread adoption of HTTPS means that most web communications are encrypted in transit — the technique remains viable against unencrypted services, poorly configured systems, and situations in which the attacker can compromise certificate authorities or exploit protocol downgrade vulnerabilities.

Supply chain attacks compromise the software or hardware that organizations trust by inserting malicious code into legitimate products during development, distribution, or update processes. The SolarWinds attack discovered in December 2020 exemplified this method: attackers inserted a backdoor into updates for SolarWinds’ Orion network management software, which was then distributed through the company’s legitimate update mechanism to approximately 18,000 customers, including multiple U.S. federal agencies and major corporations. Supply chain attacks are particularly dangerous because they exploit the trust that organizations necessarily place in their technology providers, bypassing perimeter defenses that are designed to block external threats rather than compromised internal tools.

Legal Framework

The Computer Fraud and Abuse Act

The CFAA provides the primary federal statutory framework for the prosecution of hacking and unauthorized access in the United States. Originally enacted in 1984 as the Counterfeit Access Device and Computer Fraud and Abuse Act and substantially amended in 1986, 1994, 1996, 2001, and 2008, the CFAA criminalizes a range of conduct involving unauthorized access to “protected computers” — a category that, through progressive statutory expansion, now encompasses virtually any computer connected to the internet. The Act’s core prohibitions target accessing a computer without authorization or exceeding authorized access to obtain information, commit fraud, cause damage, or traffic in passwords.

The meaning of “exceeds authorized access” has generated the CFAA’s most significant interpretive controversy. Federal circuits split over whether the provision applied only to individuals who violated technical access restrictions on computer systems or also encompassed individuals who had legitimate access but used it for unauthorized purposes — an employee who accessed a database for personal rather than work-related reasons, for example. The Supreme Court resolved this circuit split in Van Buren v. United States (2021), holding that “exceeds authorized access” applies only to those who access areas of a computer system to which their authorization does not extend, not to those who misuse access they otherwise legitimately possess. The Van Buren decision narrowed the CFAA’s scope and addressed concerns that the broader interpretation criminalized commonplace conduct such as checking personal email on a work computer or violating a website’s terms of service.

Sentencing under the CFAA varies by the specific provision violated and the presence of aggravating factors. Basic unauthorized access to obtain information carries a maximum sentence of one year for first offenses and ten years for subsequent offenses. Access committed in furtherance of fraud carries up to five years, while access causing damage to protected computers carries up to ten years (twenty for subsequent offenses or offenses involving critical infrastructure). The identity theft sentencing enhancements established by the ITPEA add mandatory consecutive terms when unauthorized access involves stolen identity documents. In practice, federal sentences for hacking convictions have ranged from probation for minor intrusions to decades of imprisonment for offenders convicted of large-scale data breaches, ransomware operations, or espionage-related intrusions.

State Laws and Regulatory Frameworks

All fifty states maintain computer crime statutes that supplement federal law, with significant variation in definitions, scope, and penalties. Some states define unauthorized access narrowly to encompass only access to systems from which the individual was explicitly excluded, while others adopt broader definitions that encompass access for unauthorized purposes. State laws are particularly important for cases involving individual victims, small-scale intrusions, and incidents that lack the interstate commerce nexus required for federal CFAA jurisdiction, though the interconnected nature of computer networks means that most hacking incidents satisfy federal jurisdictional requirements.

Regulatory frameworks add additional legal dimensions to unauthorized access. The Health Insurance Portability and Accountability Act (HIPAA) imposes criminal penalties for unauthorized access to protected health information. The Gramm-Leach-Bliley Act establishes requirements for the protection of financial data. Sector-specific regulations including those administered by the Federal Energy Regulatory Commission (FERC) for energy infrastructure and the Nuclear Regulatory Commission (NRC) for nuclear facilities establish cybersecurity requirements whose violation may carry both civil and criminal penalties. The overlapping jurisdictions of criminal statutes and regulatory frameworks create a legal landscape in which a single hacking incident may simultaneously violate federal criminal law, state criminal law, and multiple regulatory requirements.

Offender Profiles and Subcultures

The Hacking Community Spectrum

Hacker communities encompass a spectrum of actors whose motivations, methods, and ethical frameworks vary widely. The traditional color-coded taxonomy — white hat (authorized security testing), black hat (criminal hacking), and gray hat (unauthorized but non-malicious hacking) — provides a useful shorthand but oversimplifies a more nuanced landscape. Within the security research community, participants in bug bounty programs, penetration testers employed by cybersecurity firms, and independent security researchers operate within legal frameworks that authorize their testing activities, though the boundaries between authorized research and unauthorized access are not always clear and have generated legal disputes even when the researcher’s intent was benign.

Criminal hacking communities range from loosely affiliated online groups to sophisticated organized operations. Holt (2007) documented the subcultural dynamics of online hacking communities, finding that participants were stratified by technical skill, with high-skill members commanding respect and influence while low-skill members — disparagingly termed “script kiddies” — occupied subordinate positions. The community functioned as both a learning environment, where newcomers acquired skills through observation and mentorship, and a social system with its own norms, status hierarchies, and enforcement mechanisms. Participation in hacking communities served expressive functions — providing identity, social belonging, and status — alongside instrumental functions such as skill development and access to tools and targets.

The professionalization of hacking has produced a significant population of offenders who approach unauthorized access as economic activity rather than subcultural practice. Ransomware affiliates, initial access brokers, and operators of automated exploitation frameworks treat hacking as a business, applying investment calculations to their operations and seeking to maximize return on effort. This professional population overlaps only partially with the traditional hacker subculture, and many professional cybercriminals have no particular attachment to hacker ideology or identity. The economic actor model better describes their behavior than subcultural theories, with implications for deterrence and prevention strategies that should address the rational incentive structures driving professionalized hacking.

Nation-State and APT Actors

Nation-state cyber actors represent the most capable and persistent category of unauthorized access threat. The Mandiant threat intelligence firm tracks dozens of APT groups attributed to China, Russia, Iran, North Korea, and other nations, each with distinctive targeting patterns, technical capabilities, and operational signatures. Chinese APT groups have focused extensively on intellectual property theft and espionage targeting defense, technology, and pharmaceutical sectors. Russian groups have conducted operations ranging from election interference and critical infrastructure reconnaissance to financially motivated ransomware campaigns. North Korean groups have pursued both espionage and financial theft, with the Lazarus Group responsible for major cryptocurrency heists and the Bangladesh Bank attack that attempted to steal $1 billion.

The attribution of nation-state cyber operations relies on a combination of technical indicators (malware signatures, infrastructure reuse, operational timing) and intelligence assessments that integrate technical evidence with geopolitical context. Attribution remains contested and imperfect — sophisticated actors employ false flags and operational security measures designed to frustrate attribution — but the consensus of the U.S. intelligence community and major cybersecurity firms supports the attribution of significant unauthorized access campaigns to specific nation-state sponsors. The Department of Justice has pursued indictments against identified members of nation-state hacking groups, including members of China’s PLA Unit 61398, Russia’s GRU, and North Korea’s Lazarus Group, though the practical impact of these indictments on individuals beyond U.S. jurisdiction is primarily symbolic and diplomatic rather than punitive.

Enforcement and Prevention

Investigative Approaches

The investigation of hacking and unauthorized access cases requires specialized capabilities that differ substantially from those employed in traditional criminal investigation. Digital forensics — the preservation, extraction, and analysis of evidence from computer systems, networks, and storage media — provides the evidentiary foundation for hacking prosecutions. The FBI’s Regional Computer Forensics Laboratories (RCFLs), the Secret Service’s Electronic Crimes Task Forces, and state-level digital forensics units conduct the technical analysis necessary to reconstruct intrusion timelines, identify attack methods, and attribute unauthorized access to specific individuals or groups.

Network forensics extends the investigative focus from individual systems to the communication patterns that reveal how attacks progressed through an organization’s infrastructure. Log analysis, packet capture review, and intrusion detection system alerts provide data that investigators use to trace the attacker’s path from initial access through lateral movement, privilege escalation, and data exfiltration. The evidentiary challenges are significant: sophisticated attackers routinely delete logs, employ encryption, use anonymization services, and route traffic through compromised systems in multiple jurisdictions to complicate attribution and evidence collection.

International cooperation is essential for investigating hacking cases that cross borders, which the majority of significant cases do. Mutual legal assistance treaties provide the formal mechanism for requesting evidence from foreign jurisdictions, but MLAT processes are slow — often requiring months — relative to the evidentiary timelines of digital investigations. The Budapest Convention on Cybercrime, to which the United States is a party, establishes standards for the criminalization of unauthorized access and provides frameworks for expedited cooperation, but its effectiveness is limited by the non-participation of major cybercrime source countries including Russia and China. The FBI’s legal attaché network and informal law enforcement cooperation channels supplement formal MLAT processes but cannot fully compensate for the jurisdictional gaps that international cybercriminals exploit.

Defensive Technologies and Organizational Measures

Organizational defense against unauthorized access operates across multiple layers that collectively reduce the probability of successful intrusion and limit the impact when intrusions occur. Perimeter defenses — firewalls, intrusion detection and prevention systems, web application firewalls — filter incoming traffic and block known attack patterns. Endpoint protection platforms detect and remediate malware on individual devices. Network segmentation limits the lateral movement that attackers can achieve after initial compromise. Data encryption protects information at rest and in transit, reducing the value of exfiltrated data even when access controls are bypassed.

The zero-trust security model, articulated by Forrester Research and subsequently endorsed by NIST and CISA as a recommended architectural approach for federal agencies, represents a fundamental shift in how organizations approach access control. Traditional security models assumed that users and devices inside the organizational network perimeter were trustworthy, creating a “hard shell, soft center” vulnerability profile in which an attacker who breached perimeter defenses gained broad access to internal resources. Zero trust eliminates this implicit trust, requiring continuous verification of every user, device, and network request regardless of location. The Biden administration’s 2022 Executive Order on Improving the Nation’s Cybersecurity mandated the adoption of zero-trust architecture across federal agencies, reflecting the policy consensus that perimeter-based models are inadequate for contemporary threat environments.

Vulnerability management programs — the systematic identification, prioritization, and remediation of known vulnerabilities in organizational systems — address the exploitation of known vulnerabilities that accounts for the majority of successful intrusions. CISA maintains a Known Exploited Vulnerabilities (KEV) catalog that identifies vulnerabilities known to be actively exploited in the wild, and federal agencies are required to remediate KEV-listed vulnerabilities within specified timeframes. Private sector organizations face no comparable mandate, and the speed of vulnerability remediation varies enormously across industries and organization sizes, with smaller organizations typically lagging significantly behind in patch deployment.

Conclusion

Hacking and unauthorized access remain central to the cybercrime landscape, serving both as standalone offenses with direct consequences for victims and as enabling activities that facilitate data breaches, financial fraud, espionage, and ransomware operations. The technical methods through which unauthorized access is achieved have diversified and matured, encompassing vulnerability exploitation, credential-based attacks, and supply chain compromise alongside social engineering techniques that blur the boundary between technical hacking and psychological manipulation. The legal framework, anchored by the CFAA at the federal level and supplemented by state laws and regulatory requirements, has evolved through statutory amendment and judicial interpretation but continues to face challenges in addressing the full scope of unauthorized access conduct in an environment of rapid technological change.

The offender population spans an extraordinary range, from curious teenagers experimenting with readily available tools through professional cybercriminals treating hacking as economic activity to nation-state actors conducting strategic operations with implications for national security. This diversity of offenders resists the application of any single theoretical framework and demands enforcement and prevention strategies that are calibrated to the specific threat actors and methods at issue. The continued development of defensive technologies, legal authorities, investigative capabilities, and international cooperation mechanisms remains essential to managing a threat that is embedded in the fundamental architecture of networked digital systems.

References

  1. Brenner, S. W. (2010). Cybercrime: Criminal threats from cyberspace. Praeger.
  2. Cloudflare. (2024). DDoS threat report for 2024 Q1. https://blog.cloudflare.com/ddos-threat-report-2024-q1/
  3. Computer Fraud and Abuse Act, 18 U.S.C. § 1030.
  4. Holt, T. J. (2007). Subcultural evolution? Examining the influence of on- and off-line experiences on deviant subcultures. Deviant Behavior, 28(2), 171–198. https://doi.org/10.1080/01639620601131065
  5. Holt, T. J., & Bossler, A. M. (2016). Cybercrime in progress: Theory and prevention of technology-enabled offenses. Routledge.
  6. Jordan, T., & Taylor, P. (2004). Hacktivism and cyberwars: Rebels with a cause? Routledge.
  7. Kerr, O. S. (2003). Cybercrime’s scope: Interpreting “access” and “authorization” in computer misuse statutes. New York University Law Review, 78(5), 1596–1668.
  8. Mandiant. (2024). M-Trends 2024 special report. Google Cloud. https://www.mandiant.com/m-trends
  9. MITRE Corporation. (2024). Common Vulnerabilities and Exposures program. https://cve.mitre.org/
  10. National Institute of Standards and Technology. (2017). Digital identity guidelines: Authentication and lifecycle management (SP 800-63B). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-63b
  11. National Institute of Standards and Technology. (2020). Zero trust architecture (SP 800-207). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207
  12. Olson, P. (2012). We are Anonymous: Inside the hacker world of LulzSec, Anonymous, and the global cyber insurgency. Little, Brown and Company.
  13. Rogers, M. K. (2006). A two-dimensional circumplex approach to the development of a hacker taxonomy. Digital Investigation, 3(2), 97–102. https://doi.org/10.1016/j.diin.2006.03.001
  14. Steinmetz, K. F. (2015). Craft(y)ness: An ethnographic study of hacking. British Journal of Criminology, 55(1), 125–145. https://doi.org/10.1093/bjc/azu061
  15. Thomas, K., Li, F., Zand, A., Barrett, J., Ranieri, J., Invernizzi, L., Markov, Y., Comanescu, O., Eranti, V., Moscicki, A., Margolis, D., Paxson, V., & Bursztein, E. (2017). Data breaches, phishing, or malware? Understanding the risks of stolen credentials. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1421–1434). https://doi.org/10.1145/3133956.3134067
  16. Van Buren v. United States, 593 U.S. 374 (2021).
  17. Verizon. (2024). 2024 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
  18. Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
  19. Yar, M., & Steinmetz, K. F. (2019). Cybercrime and society (3rd ed.). SAGE Publications.
  20. Zetter, K. (2014). Countdown to zero day: Stuxnet and the launch of the world’s first digital weapon. Crown.

Related Articles

  • Malware and Ransomware Attacks
  • Cybercrime Typologies
  • Federal Cybercrime Law in America
  • Cybercrime Investigation and Digital Forensics
  • Nation-State Cyberattacks and U.S. Security




Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube
  • Criminology
    • Clinical Criminology
    • Comparative Criminology
    • Crime as a Social Phenomenon
    • Crime in Criminology
    • Criminology and Criminal Justice Careers
    • Criminology and Criminal Justice Degrees
    • Criminology and Criminal Justice Education
    • Criminology and Public Policy
    • Criminology as Social Science
    • Cyber Criminology
      • Algorithmic Bias in Criminal Justice
      • Artificial Intelligence and Crime
      • Big Data and Criminal Justice
      • Body-Worn Cameras and Policing
      • Child Sexual Exploitation Online
      • Corporate Cybercrime and Data Breaches
      • Crime in the Digital Age
      • Cryptocurrency and Crime
      • Cyberbullying in America
      • Cybercrime and Organized Crime
      • Cybercrime and the Dark Web
      • Cybercrime Investigation and Digital Forensics
      • Cybercrime Offenders and Motivations
      • Cybercrime Prevention and Digital Literacy
      • Cybercrime Reporting and Statistics in America
      • Cybercrime Typologies
      • Cybercrime Victimization
      • Cyberstalking and Online Harassment
      • Cyberterrorism and National Security
      • Digital Criminology and Public Policy
      • Digital Divide and Crime
      • Digital Evidence in American Courts
      • Digital Society and Crime
      • Digital Surveillance and Crime Control
      • Digital Vigilantism in America
      • Emerging Cybercrime Threats
      • Facial Recognition and Law Enforcement
      • Federal Cybercrime Law in America
      • Hacking and Unauthorized Access
      • Identity Theft in America
      • International Cybercrime Cooperation
      • Malware and Ransomware Attacks
      • Nation-State Cyberattacks and U.S. Security
      • Online Drug Markets
      • Online Fraud and Financial Cybercrime
      • Online Radicalization and Extremism
      • Phishing and Social Engineering
      • Platform Accountability and Online Harm
      • Privacy, Civil Liberties, and Digital Crime Control
      • Sextortion and Image-Based Abuse
      • Social Media and Criminal Behavior
      • The Dark Web and Digital Crime
    • History of Criminology
    • Psychology and Criminology
    • Sociology and Criminology
    • Urban Criminology