Computer misuse (hacking)
Computer misuse, often called hacking, covers accessing a computer, program or data without permission, doing so to commit further crime, and impairing computers through malware or denial-of-service attacks. The main law is the Computer Misuse Act 1990, which also bans making or supplying hacking tools.
Law checked as at 25 September 2026. Legal information only, not legal advice, and not a prediction of any sentence.
At a glance
| Also known as | Hacking, Unauthorised access to computer material, Computer Misuse Act offences, Cybercrime |
|---|---|
| The law | Computer Misuse Act 1990 |
| Where it is tried | sections 1, 2, 3 and 3A are either way and can be tried in the magistrates' court or the Crown Court. Section 3ZA (acts causing or risking serious damage) is indictable only and tried in the Crown Court. |
| Maximum penalty | Section 1 (unauthorised access): 2 years' imprisonment. Section 2 (access with intent to commit further offences): 5 years. Section 3 (impairing a computer or data): 10 years. Section 3ZA (acts causing or risking serious damage to human welfare, the environment, the economy or national security): 14 years, or life where there is serious damage or risk to human life or health, or national security. Section 3A (making, supplying or obtaining hacking tools): 2 years. Each can also attract a fine. |
Maximum penalties are the most a court can impose for the worst cases. Most sentences are far lower, and the actual sentence depends on the facts, any guilty plea and the court's assessment.
What the prosecution must prove
- Section 1: the defendant caused a computer to perform a function intending to secure, or enable, access to a program or data held in a computer.
- The access was unauthorised: they were not entitled to control that kind of access and did not have consent from someone who was (s.17(5)).
- They knew at the time that the access was unauthorised.
- Section 2: in addition, they intended to commit or facilitate a further serious offence, such as fraud.
- Section 3: they did an unauthorised act intending to impair, or reckless as to impairing, the operation of a computer or the reliability of data, for example deploying malware, ransomware or a denial-of-service attack.
Defences and common issues
- Authorisation: you were entitled to the access, or had consent from someone entitled to give it, and stayed within its limits.
- Lack of knowledge: you genuinely did not know the access was unauthorised.
- Jurisdiction: there must be at least one significant link with the UK, such as the defendant or the target computer being here (ss.4-5).
Frequently asked questions
Is it illegal to log into someone else's account?
Yes, if you do it without permission. Accessing someone's email, social media, phone or cloud account without their consent is unauthorised access under section 1 of the Computer Misuse Act 1990, even if you know or guessed their password, and even if they are your partner or family member. The maximum is 2 years' imprisonment. If you do it to commit another offence, such as fraud or stalking, a more serious charge under section 2 may apply.
Is ethical hacking or security research legal?
Only with proper authorisation. The Computer Misuse Act 1990 has no specific defence for security research or good intentions, so testing a system you have no permission to access can be an offence even if you meant to report a flaw. Professional penetration testers work under written agreements setting out what they may access. Prosecutors consider the public interest when deciding whether to charge, but that is a discretion, not a defence.
What is the maximum sentence for hacking?
It depends on the offence. Basic unauthorised access under section 1 of the Computer Misuse Act 1990 carries up to 2 years' imprisonment, and access with intent to commit further offences up to 5 years. Impairing a computer, for example with malware or ransomware, carries up to 10 years. Attacks causing or risking serious damage, such as to critical infrastructure, carry up to 14 years, or life imprisonment where lives or national security are at risk. Making or supplying hacking tools carries up to 2 years.
Is a DDoS attack or using ransomware a crime?
Yes. Deliberately or recklessly impairing the operation of a computer, preventing access to data, or damaging data is an offence under section 3 of the Computer Misuse Act 1990, with a maximum of 10 years' imprisonment. That covers denial-of-service attacks, ransomware, viruses and deleting or encrypting files without permission. Buying or supplying tools such as booter services or malware for those purposes can be a separate offence under section 3A. Related fraud, blackmail or money laundering offences may also be charged.
Can I be prosecuted in England for hacking a computer abroad?
You can if there is a significant link with the UK. Under sections 4 and 5 of the Computer Misuse Act 1990, the courts of England and Wales can deal with an offence where, for example, the person was in the UK at the time, or the computer accessed or affected was in the UK. Some offences can also be prosecuted where a UK national commits them abroad and the act is also illegal in that country. Extradition may be possible in cross-border cases.
Official sources
Primary sources and official guidance on this topic, for anyone who wants to read the underlying rules directly.
Charged or under investigation? Ask LawBot a general question, or find a criminal defence solicitor near you.
Ask LawBot →