The Computer Misuse Act 1990 is an Act of the
Parliament of the United Kingdom
The Parliament of the United Kingdom is the Parliamentary sovereignty in the United Kingdom, supreme Legislature, legislative body of the United Kingdom, the Crown Dependencies and the British Overseas Territories. It meets at the Palace of We ...
, introduced partly in response to the decision in ''R v Gold & Schifreen'' (1988) 1 AC 1063 (see below). Critics of the bill complained that it was introduced hastily and was poorly thought out.
Intention
Intentions are mental states in which the agent commits themselves to a course of action. Having the plan to visit the zoo tomorrow is an example of an intention. The action plan is the ''content'' of the intention while the commitment is the '' ...
, they said, was often difficult to prove, and that the bill inadequately differentiated "joyriding"
hackers like
Gold
Gold is a chemical element with the symbol Au (from la, aurum) and atomic number 79. This makes it one of the higher atomic number elements that occur naturally. It is a bright, slightly orange-yellow, dense, soft, malleable, and ductile ...
and
Schifreen from serious computer criminals. The Act has nonetheless become a model from which several other countries, including
Canada
Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tota ...
and the
Republic of Ireland
Ireland ( ga, Éire ), also known as the Republic of Ireland (), is a country in north-western Europe consisting of 26 of the 32 Counties of Ireland, counties of the island of Ireland. The capital and largest city is Dublin, on the eastern ...
, have drawn inspiration when subsequently drafting their own information security laws, as it is seen "as a robust and flexible piece of legislation in terms of dealing with cybercrime”. Several amendments have been passed to keep the Act up to date.
''R v Gold & Schifreen''
Robert Schifreen
Robert Jonathan Schifreen (born October 1963) is a former UK-based computer hacker and magazine editor, and the founder of IT security awareness training programme SecuritySmart.co.uk. He was the first person charged with illegally accessing a comp ...
and
Stephen Gold
Stephen Gold (15 January 1956 – 12 January 2015) was a skilled hacker and journalist who in the mid-1980s was charged with, convicted and later acquitted of, 'uttering a forgery' in what became known to the popular press of the time as "The Great ...
, using conventional
home computers and
modem
A modulator-demodulator or modem is a computer hardware device that converts data from a digital format into a format suitable for an analog transmission medium such as telephone or radio. A modem transmits data by modulating one or more c ...
s in late 1984 and early 1985, gained unauthorised access to
British Telecom
BT Group plc (trade name, trading as BT and formerly British Telecom) is a British Multinational corporation, multinational telecommunications holding company headquartered in London, England. It has operations in around 180 countries and is th ...
's
Prestel interactive
viewdata service. While at a trade show, Schifreen, by doing what latterly became known as
shoulder surfing, had observed the password of a Prestel engineer. The engineer's username was 22222222 and the password used was 1234.
This later gave rise to accusations that British Telecom (BT) had not taken security seriously. Armed with this information, the pair explored the system, even gaining access to the personal message box of
Prince Philip
Prince Philip, Duke of Edinburgh (born Prince Philip of Greece and Denmark, later Philip Mountbatten; 10 June 1921 – 9 April 2021) was the husband of Queen Elizabeth II. As such, he served as the consort of the British monarch from El ...
.
Prestel installed monitors on the suspect accounts and passed information thus obtained to the police. The pair were charged under section 1 of the
Forgery and Counterfeiting Act 1981
The Forgery and Counterfeiting Act 1981 (c 45) is an Act of the Parliament of the United Kingdom which makes it illegal to make fake versions of many things, including legal documents, contracts, audio and visual recordings, and money of the Uni ...
with defrauding BT by manufacturing a "false instrument", namely the internal condition of BT's equipment after it had processed Gold's eavesdropped password. Tried at
Southwark Crown Court, they were convicted on
specimen charges (five against Schifreen, four against Gold) and fined, respectively, £750 and £600.
Although the fines imposed were modest, they elected to appeal to the Criminal Division of the
Court of Appeal. Their counsel cited the lack of evidence showing the two had attempted to obtain material gain from their exploits, and claimed that the Forgery and Counterfeiting Act had been misapplied to their conduct. They were acquitted by the Lord Justice Lane, but the prosecution appealed to the
House of Lords
The House of Lords, also known as the House of Peers, is the upper house of the Parliament of the United Kingdom. Membership is by appointment, heredity or official function. Like the House of Commons, it meets in the Palace of Westminster ...
. In 1988, the Lords upheld the acquittal.
Lord Justice Brandon said:
The Law Lords' ruling led many legal scholars to believe that hacking was not unlawful as the law then stood. The English
Law Commission
A law commission, law reform commission, or law revision commission is an independent body set up by a government to conduct law reform; that is, to consider the state of laws in a jurisdiction and make recommendations or proposals for legal chan ...
and its counterpart in Scotland both considered the matter. The
Scottish Law Commission concluded that intrusion was adequately covered in Scotland under the
common law
In law, common law (also known as judicial precedent, judge-made law, or case law) is the body of law created by judges and similar quasi-judicial tribunals by virtue of being stated in written opinions."The common law is not a brooding omniprese ...
related to deception, but the English Law Commission believed a new law was necessary.
Since the case, both defendants have written extensively about IT matters. Gold, who detailed the entire case at some length in ''
The Hacker's Handbook'', has presented at conferences alongside the arresting officers in the case.
The Computer Misuse Act
Based on the ELC's recommendations, a
private member's bill
A private member's bill is a bill (proposed law) introduced into a legislature by a legislator who is not acting on behalf of the executive branch. The designation "private member's bill" is used in most Westminster system jurisdictions, in wh ...
was introduced by
Conservative
Conservatism is a cultural, social, and political philosophy that seeks to promote and to preserve traditional institutions, practices, and values. The central tenets of conservatism may vary in relation to the culture and civilization in ...
MP
Michael Colvin. The bill, supported by the government, came into effect in 1990. Sections 1-3 of the Act introduced three criminal offences:
# unauthorised access to computer material, punishable by twelve months' imprisonment (or six months in Scotland) and/or a fine "not exceeding level 5 on the
standard scale" (since 2015, unlimited);
# unauthorised access with intent to commit or facilitate commission of further offences, punishable by twelve months/maximum fine (or six months in Scotland) on
summary conviction and/or five years/fine on
indictment
An indictment ( ) is a formal accusation that a person has committed a crime. In jurisdictions that use the concept of felonies, the most serious criminal offence is a felony; jurisdictions that do not use the felonies concept often use that of an ...
;
# unauthorised modification of computer material, punishable by twelve months/maximum fine (or six months in Scotland) on summary conviction and/or ten years/fine on indictment;
(For other offences see ''
§ The amendments'' below)
The sections 2 and 3 offences are intended to deter the more serious criminals from using a computer to assist in the commission of a criminal offence or from impairing or hindering access to data stored in a computer. The basic section 1 offence is to attempt or achieve access to a computer or the data it stores, by inducing a computer to perform any function with intent to secure access.
Hackers who program their computers to search through password permutations are therefore liable, even if their attempts to log on are rejected by the target computer. The only precondition to liability is that the hacker should be aware that the access attempted is unauthorised. Thus, using another person's
username
A user is a person who utilizes a computer or network service.
A user often has a user account and is identified to the system by a username (or user name). Other terms for username include login name, screenname (or screen name), account ...
or
identifier
An identifier is a name that identifies (that is, labels the identity of) either a unique object or a unique ''class'' of objects, where the "object" or class may be an idea, physical countable object (or class thereof), or physical noncountable ...
(ID) and
password
A password, sometimes called a passcode (for example in Apple devices), is secret data, typically a string of characters, usually used to confirm a user's identity. Traditionally, passwords were expected to be memorized, but the large number of ...
without proper authority to access data or a program, or to alter, delete, copy or move a program or data, or simply to output a program or data to a screen or printer, or to impersonate that other person using
e-mail
Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus conceived as the electronic ( digital) version of, or counterpart to, mail, at a time when "mail" mean ...
,
online chat
Online chat may refer to any kind of communication over the Internet that offers a real-time transmission of text messages from sender to receiver. Chat messages are generally short in order to enable other participants to respond quickly. Th ...
, web or other services, constitute the offence. Even if the initial access is authorised, subsequent exploration, if there is a hierarchy of privileges in the system, may lead to entry to parts of the system for which the requisite privileges are lacking and the offence will be committed. Looking over a user's shoulder or using sophisticated electronic equipment to monitor the
electromagnetic radiation
In physics, electromagnetic radiation (EMR) consists of waves of the electromagnetic (EM) field, which propagate through space and carry momentum and electromagnetic radiant energy. It includes radio waves, microwaves, infrared, (visible ...
emitted by
VDUs ("electronic eavesdropping") is outside the scope of this offence.
The §§2–3 offences are aggravated offences, requiring a specific intent to commit another offence (for these purposes, the other offences are to be
arrestable, and so include all the major
common law
In law, common law (also known as judicial precedent, judge-made law, or case law) is the body of law created by judges and similar quasi-judicial tribunals by virtue of being stated in written opinions."The common law is not a brooding omniprese ...
and
statutory
A statute is a formal written enactment of a legislative authority that governs the legal entities of a city, state, or country by way of consent. Typically, statutes command or prohibit something, or declare policy. Statutes are rules made by ...
offences of
fraud
In law, fraud is intentional deception to secure unfair or unlawful gain, or to deprive a victim of a legal right. Fraud can violate civil law (e.g., a fraud victim may sue the fraud perpetrator to avoid the fraud or recover monetary compen ...
and
dishonesty
Dishonesty is to act without honesty. It is used to describe a lack of probity, cheating, lying, or deliberately withholding information, or being deliberately deceptive or a lack in integrity, knavishness, perfidiosity, corruption or treachero ...
). So a hacker who obtains access to a system intending to transfer money or shares, intends to commit
theft
Theft is the act of taking another person's property or services without that person's permission or consent with the intent to deprive the rightful owner of it. The word ''theft'' is also used as a synonym or informal shorthand term for so ...
, or to obtain confidential information for
blackmail
Blackmail is an act of coercion using the threat of revealing or publicizing either substantially true or false information about a person or people unless certain demands are met. It is often damaging information, and it may be revealed to f ...
or
extortion
Extortion is the practice of obtaining benefit through coercion. In most jurisdictions it is likely to constitute a criminal offence; the bulk of this article deals with such cases. Robbery is the simplest and most common form of extortion, ...
. Thus, the §1 offence is committed as soon as the unauthorised access is attempted, and the §2 offence overtakes liability as soon as specific access is made for the criminal purpose. The §3 offence is specifically aimed at those who write and circulate a
computer virus
A computer virus is a type of computer program that, when executed, replicates itself by modifying other computer programs and inserting its own code. If this replication succeeds, the affected areas are then said to be "infected" with a compu ...
or
worm
Worms are many different distantly related bilateral animals that typically have a long cylindrical tube-like body, no limbs, and no eyes (though not always).
Worms vary in size from microscopic to over in length for marine polychaete worm ...
, whether on a
LAN
Lan or LAN may also refer to:
Science and technology
* Local asymptotic normality, a fundamental property of regular models in statistics
* Longitude of the ascending node, one of the orbital elements used to specify the orbit of an object in sp ...
or across
networks. Similarly, using
phishing
Phishing is a type of social engineering where an attacker sends a fraudulent (e.g., spoofed, fake, or otherwise deceptive) message designed to trick a person into revealing sensitive information to the attacker or to deploy malicious softwar ...
techniques or a
Trojan horse
The Trojan Horse was a wooden horse said to have been used by the Greeks during the Trojan War to enter the city of Troy and win the war. The Trojan Horse is not mentioned in Homer's ''Iliad'', with the poem ending before the war is concluded, ...
to obtain identity data or to acquire any other data from an unauthorised source, or modifying the operating system files or some aspect of the computer's functions to interfere with its operation or prevent access to any data, including the destruction of files, or deliberately generating code to cause a complete system malfunction, are all criminal "modifications". In 2004, John Thornley pleaded guilty to four offences under §3, having mounted an attack on a rival site, and introduced a Trojan horse to bring it down on several occasions, but it was recognised that the wording of the offence needed to be clarified to confirm that all forms of
denial of service attack are included.
Implications for industry practices
Although the Act ostensibly targets those who wish to gain unauthorised access to computer systems for various purposes, its implications on previously relatively widespread or well-known industry practices such as the "time-locking" of software have been described in various computing industry publications. Time-locking is the practice of disabling functionality or whole programs in order to ensure that software, potentially delivered on condition of further payment, will "expire" and thus no longer function. In one featured case, a "developer of bespoke systems in the Midlands" activated a time lock on a piece of software over a dispute with a client about an unpaid bill. The client reported this to the police who charged the programmer under Section 3 of the Act, with the outcome being a conviction by a magistrates court, with a conditional discharge given by the magistrate meaning that no punishment was applied on condition that the programmer did not re-offend.
Latest situation
Schedule 1 Part II of the
Criminal Justice (Terrorism and Conspiracy) Act 1998 ('Conspiracy') amended Section 8 (relevance of external law), Section 9(2)(b) (British citizenship immaterial: conspiracy) and Section 16 (application to Northern Ireland).
In 2004, the All-Party Internet Group published its review of the law and highlighted areas for development. Their recommendations led to the drafting of the Computer Misuse Act 1990 (Amendment) Bill which sought to amend the CMA to comply with the European Convention on Cyber Crime. Under its terms, the maximum sentence of imprisonment for breaching the Act changed from six months to two years. It also sought to explicitly criminalise
denial-of-service attack
In computing, a denial-of-service attack (DoS attack) is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host conn ...
s and other crimes facilitated by denial-of-service. The Bill did not receive
Royal Assent
Royal assent is the method by which a monarch formally approves an act of the legislature, either directly or through an official acting on the monarch's behalf. In some jurisdictions, royal assent is equivalent to promulgation, while in othe ...
because Parliament was
prorogued
A legislative session is the period of time in which a legislature, in both parliamentary and presidential systems, is convened for purpose of lawmaking, usually being one of two or more smaller divisions of the entire time between two electio ...
.
Sections 35 to 38 of the
Police and Justice Act 2006
The Police and Justice Act 2006 (PJA) is an act of the Parliament of the United Kingdom. It received royal assent on 8 November 2006. The PJA created the National Policing Improvement Agency. It changed how members of police authorities may be ...
contain amendments to the Computer Misuse Act 1990.
Section 37 ("Making, supplying or obtaining articles for use in computer misuse offences") inserts a new section 3A into the 1990 Act and has drawn considerable criticism from IT professionals, as many of their tools can be used by criminals in addition to their legitimate purposes, and thus fall under section 3A.
After the
News International phone hacking scandal in 2011, there were discussions about amending the law to define "smart" phones (i.e. those with Internet browsers and other connectivity features) as computers under the Act. Such an amendment might also introduce a new offence of "making information available with intent", i.e. publicly disclosing a password for someone's phone or computer so that others can access it illegally.
In 2015, the Act was further amended by Part 2 sections 41 to 44 (plus others) of the
Serious Crime Act 2015.
The amendments
The amendments to the Computer Misuse Act 1990 by Part 5 of the Police and Justice Act 2006 are
* Section 35. Unauthorised access to computer material, punishable by up to two years in prison or a fine or both.
* Section 36. Unauthorised acts with intent to impair operation of computer, etc. punishable by up to ten years in prison or a fine or both.
* Section 37. Making, supplying or obtaining articles for use in computer misuse offences, punishable by up to two years in prison or a fine or both.
* Section 38. Transitional and saving provision.
The amendments to the Computer Misuse Act 1990 by Part 2 of the Serious Crime Act 2015.
[ are
* Section 41 (new Section 3ZA of the Computer Misuse Act 1990). Unauthorised acts causing, or creating risk of, serious damage – punishable by up to 14 years in prison or a fine or both, possible life imprisonment where human welfare or national security were endangered.
* Section 42. Obtaining articles for purposes relating to computer misuse – amendments to Section 3A.
* Section 43. Territorial scope of computer misuse - amendments to Sections 4, 5 and 10 making the primary territorial scope the United Kingdom but can be worldwide especially if the perpetrator (or conspirators) is British and broke local law.
* Section 44. Savings – covers seizure and enactment amendments to Sections 10 and 16.
* Section 47. Serious Crime Prevention Orders: meaning of "Serious Offence" - adds Computer Misuse to list of serious crimes in the Serious Crime Act 2007 including being grounds for compulsory winding up of a company.
* Section 86. Transition and savings provisions – requires Sections 42 and 43 to be brought into force before they can be used.
* Schedule 1. Amendments to Serious Crimes Act 2007: Scotland – similar changes to Scottish law.
* Schedule 4. Minor and consequential amendments – changes Computer Misuse Act 1990 and the ]Armed Forces Act 2006
The Armed Forces Act 2006 (c 52) is an Act of the Parliament of the United Kingdom.
It came into force on 31 October 2006. It replaces the three separate Service Discipline Acts (the Army Act 1955, the Air Force Act 1955 and the Naval Discipl ...
.
Application to the NHS
In April 2020, Matt Hancock issued directions giving GCHQ
Government Communications Headquarters, commonly known as GCHQ, is an intelligence and security organisation responsible for providing signals intelligence (SIGINT) and information assurance (IA) to the government and armed forces of the Uni ...
temporary powers over National Health Service
The National Health Service (NHS) is the umbrella term for the publicly funded healthcare systems of the United Kingdom (UK). Since 1948, they have been funded out of general taxation. There are three systems which are referred to using the " ...
information systems until the end of 2020 for the purposes of the Act to support and maintain the security of any network and information system which supports, directly or indirectly, the provision of NHS services or public health services intended to address COVID-19
Coronavirus disease 2019 (COVID-19) is a contagious disease caused by a virus, the severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). The first known case was identified in Wuhan, China, in December 2019. The disease quickl ...
.
Reform
In May 2021, UK Home Secretary Priti Patel announced the formal review of the Computer Misuse Act. She also launched a Call for Information on the Act that seeks views on whether there is activity causing harm in the area covered by the Act that is not adequately covered by the offences, including whether the legislation is fit for use following the technological advances since the CMA was introduced, and any other suggestions on how the legislative response to cyber crime could be strengthened.
The review of the Act follows growing calls, in recent year, for a complete government review of the Computer Misuse Act, in order to bring about new reforms.
In November 2019, Dame Lynne Owens, Director General of the National Crime Agency (NCA), warned that "the Computer Misuse Act went through Parliament at a time when cyber wasn't the tool that it is now is to enable all sorts of crimes like fraud" and talked about plans to introduce reforms to make sure the law was "fit for purpose in the modern age".
In January 2020, the Criminal Law Reform Now Network (CLRNN) published a comprehensive report highlighting the Act's shortcomings and making detailed recommendations for reform.
In the same month, the CyberUp Campaign was established with the intention of lobbying the UK government to "update and upgrade" the Act. The Campaign's launch was covered by ''The Guardian
''The Guardian'' is a British daily newspaper
A newspaper is a periodical publication containing written information about current events and is often typed in black ink with a white or gray background.
Newspapers can cover a wide ...
'' in an article that echoed the call for "urgent reform". The CyberUp Campaign is made up of a wide coalition of supportive bodies from within the cyber security industry, including the large cyber consultancies NCC Group
NCC Group (LSE: NCC) is an information assurance firm headquartered in Manchester, United Kingdom. Its service areas cover software escrow and verification, cyber security consulting and managed services. NCC Group claims over 15,000 clients worldw ...
and F-Secure and the cyber industry trade body techUK The cyber security (or information assurance) community in the United Kingdom is diverse, with many stakeholders groups contributing to support the '' UK Cyber Security Strategy''. The following is a list of some of these stakeholders.
Governme ...
. In November 2020, the campaign gained the backing of the Confederation of British Industry
The Confederation of British Industry (CBI) is a UK business organisation, which in total claims to speak for 190,000 businesses, this is made up of around 1,500 direct members and 188,500 non-members. The non members are represented through the 1 ...
.
The coalition was formed based on the shared view that an update of the UK's cyber crime legislation is necessary to protect national security and to increase economic growth for the UK cyber security industry. The Campaign refers to Section 1 of the Act, "prohibiting unauthorised access to computers", stating that it inadvertently criminalises a large amount of cyber security and threat intelligence research and investigation which is frequently conducted by UK cyber security professionals.
The Campaign has called for two key amendments:
# Amend the law to allow cyber security and threat intelligence researchers acting in the public interest to explain and justify their actions and to allow the detection or prevention of crime.
# Create a set of clear legal definitions to ensure that cyber security and threat intelligence researchers who reasonably believe they have authorisation to act can legitimately do so.
On 29 June 2020, to celebrate the Act's 30th birthday, the CyberUp Campaign wrote an open letter to the prime minister on behalf of a number of cyber security industry figures to highlight the Act's outdatedness in a time of rapid digital advancement. This was published in ''The Daily Telegraph
''The Daily Telegraph'', known online and elsewhere as ''The Telegraph'', is a national British daily broadsheet newspaper published in London by Telegraph Media Group and distributed across the United Kingdom and internationally.
It was f ...
'', with the headline "Cyber security experts say they are being prevented from stopping computer fraud".
In July 2020, the Intelligence and Security Committee of Parliament
The Intelligence and Security Committee of Parliament (ISC) is a statutory joint committee of the Parliament of the United Kingdom, appointed to oversee the work of the UK intelligence community.
The committee was established in 1994 by the ...
, responsible for oversight of the UK intelligence services, published the Intelligence and Security Committee Russia report
"The Russia report" is the report of the British Intelligence and Security Committee of Parliament (ISC) into allegations of Russian interference in British politics, including alleged Russian interference in the 2016 Brexit referendum and the ...
and recommended that "the Computer Misuse Act should be updated to reflect modern use of personal electronic devices". While the government response to the report said that the Act was regularly reviewed to determine the benefits of legislative change, the Shadow Foreign Secretary, Lisa Nandy
Lisa Eva Nandy (born 9 August 1979) is a British politician serving as Shadow Secretary of State for Levelling Up, Housing and Communities since 2021. A member of the Labour Party, she has been Member of Parliament (MP) for Wigan since 2010.
...
, highlighted in January 2021 that no progress had been made towards implementing the recommendation.
In November 2020, the CyberUp Campaign and techUK published a new report on the Computer Misuse Act, which was the first piece of work to quantify and analyse the views of the wider UK security community. The report found that 80 per cent of cyber security professionals have worried about breaking the law when researching vulnerabilities or investigating cyber threat actors. Furthermore, 91 per cent of businesses that responded to the report’s survey suggested they had been put at a competitive disadvantage by the Act, and that reform would allow their organisation to reap significant productivity improvements, growth and resilience benefits. The report recommended that the government consider implementing the two above amendments.
See also
* Computer crime
A cybercrime is a crime that involves a computer or a computer network.Moore, R. (2005) "Cyber crime: Investigating High-Technology Computer Crime," Cleveland, Mississippi: Anderson Publishing. The computer may have been used in committing t ...
* Internet fraud
Internet fraud is a type of cybercrime fraud or deception which makes use of the Internet and could involve hiding of information or providing incorrect information for the purpose of tricking victims out of money, property, and inheritance. Inte ...
* Data Protection Act 1998
The Data Protection Act 1998 (DPA, c. 29) was an Act of Parliament of the United Kingdom designed to protect personal data stored on computers or in an organised paper filing system. It enacted provisions from the European Union (EU) Data Prot ...
References
* Neil MacEwan
"The Computer Misuse Act 1990: lessons from its past and predictions for its future"
(2008), ''Criminal Law Review'' 955.
* Stefan Fafinski, ''Computer Misuse: Response, Regulation and the Law'' (Cullomption, Willan 2009)
* Yaman Akdeniz, ''Section 3 of the Computer Misuse Act 1990: an Antidote for Computer Viruses!'' (1996) 3 Web JCL
including reference to the case of Christopher Pile (aka 'the Black Baron') in November 1995.
* Derek Wyatt
''Computer Misuse Act (amendment) speech''
Notes
External links
The Internet Crime Forum
Amendments to the Computer Misuse Act 1990
covered by the Open Rights Group
A list of Computer Misuse Act cases compiled by Michael J L Turner
{{UKlegislation
United Kingdom Acts of Parliament 1990
Computing legislation
Hacking (computer security)