Ethical hackers no longer face prosecution in the US

Cyber gavel on a data flow background
(Image credit: Shutterstock)

The US Department of Justice (DoJ) has softened its treatment of ethical hackers.

Hackers carrying out “good faith” security research will no longer be charged under the Computer Fraud and Abuse Act (CFAA).

The department defined “good faith” security research as accessing a computer solely for the purposes of “good-faith testing, investigation, or the correction of a security flaw or vulnerability, where such activity is carried out in a manner designed to avoid any harm to individuals or the public”.

What is now allowed?

However, the DoJ highlights that claiming to be conducting security research is not a “free pass” for those acting in bad faith.

For example, the DoJ clarified that discovering vulnerabilities in devices to extort their owners, even if claimed as “research,” is not in good faith.

The policy advises prosecutors to consult with the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) about specific applications of this factor. 

The DoJ were also able to confirm that certain activities will not be sufficient to warrant federal criminal charges.

These include creating misleading profiles on dating websites; creating fictional accounts on hiring, housing, or rental websites; using a pseudonym on a social networking site that prohibits them; checking sports scores at work; paying bills at work; or violating an access restriction contained in a term of service.

All federal prosecutors who wish to charge cases under the Computer Fraud and Abuse Act are required to follow the new policy, and to consult with CCIPS before bringing any charges.

Prosecutors must inform the Deputy Attorney General (DAG), and in some cases receive approval from the DAG, before charging a CFAA case if CCIPS recommends against it. 

The new policy, which takes effect immediately, replaces an earlier one issued in 2014.

Independent white hat hackers are increasingly playing a role in uncovering cybersecurity vulnerabilities.

A lone wolf researcher going by the name of hyp3rlinx has discovered that some of the most popular ransomware strains, such as Conti, REvil, LockBit, including many others, carry a flaw that makes them vulnerable to DLL hijacking.

Will McCurdy has been writing about technology for over five years. He has a wide range of specialities including cybersecurity, fintech, cryptocurrencies, blockchain, cloud computing, payments, artificial intelligence, retail technology, and venture capital investment. He has previously written for AltFi, FStech, Retail Systems, and National Technology News and is an experienced podcast and webinar host, as well as an avid long-form feature writer.

Read more
An image of network security icons for a network encircling a digital blue earth.
Why effective cybersecurity is a team effort
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Apple users facing new security risks after critical USB component hacked
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras