Within UFO Hackers

Does Curiosity Make Illegal Hacking Less Serious?

A claimed search for public-interest information does not erase unauthorised access, but it can affect how motives and punishment are debated.

125 sources 3 graphics
Preview for Does Curiosity Make Illegal Hacking Less Serious?

On this page

  • Intent versus unlawful conduct
  • Public interest arguments
  • Where ethical hacking differs

Introduction

Curiosity does not normally cancel criminal responsibility for hacking. In cases such as Gary McKinnon’s, a claimed search for UFO evidence or suppressed technology may distinguish the intruder from a thief, extortionist or foreign agent, but the central legal question remains whether access was knowingly obtained without permission. Motive matters more when prosecutors assess the public interest, when courts judge culpability and punishment, and when the public debates proportionality. It is not usually a licence to enter another organisation’s systems.

Overview image for Motive and Law

That distinction is important because “I was investigating” can describe very different conduct. One person may cautiously test a flaw, avoid private data and report it to the owner; another may explore military networks for months, copy material or interfere with machines while pursuing a personally compelling theory. Both may claim curiosity or public benefit, but law and ethical practice place greater weight on authorisation, necessity, restraint, disclosure and harm than on the label the intruder gives the activity.[parliament.uk]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…

Intent Versus Unlawful Conduct

Under the UK Computer Misuse Act 1990, the basic offence centres on unauthorised access. Section 1 applies where a person causes a computer to perform a function intending to secure access to data or programs, knows that the access is unauthorised, and nevertheless proceeds. The offence does not require proof that the person sought money, intended espionage or planned to damage the computer. A search motivated by UFO curiosity can therefore satisfy the core offence just as readily as a search motivated by commercial advantage.[Legislation.gov.uk]legislation.gov.ukComputer Misuse Act 1990An Act to make provision for securing computer material against unauthorised access or modification; and for conn…

This separates intention in the legal sense from motive in the everyday sense. The relevant intention may be simply to enter a protected system or retrieve information without permission. The motive explains why the person wanted access: curiosity, ideology, profit, revenge, prestige or a claimed public service. A benign-sounding motive may alter the moral picture, but it does not change whether the access was deliberate and known to be unauthorised.

McKinnon’s case illustrates the point. The United States alleged that he accessed 97 government computers between February 2001 and March 2002, including machines associated with defence and national security. He said he was searching for evidence of UFO secrecy, antigravity technology and suppressed energy systems. The House of Lords treated the case as one involving admitted unauthorised access while recording disputed allegations about damage and disruption. His asserted purpose explained the intrusion, but it did not transform it into authorised investigation.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…

The seriousness of curiosity-driven hacking therefore depends on more than the absence of greed. Several features can increase culpability or harm:

  • Duration and repetition: a brief accidental discovery differs from sustained access across numerous machines.
  • Sensitivity of the target: military, health, infrastructure and government systems create risks beyond the value of any particular file.
  • Depth of intrusion: viewing an exposed page is not equivalent to obtaining credentials, escalating privileges or moving through internal networks.
  • Treatment of data: copying, retaining or publishing information can affect privacy, security and later exploitation.
  • Operational effects: deletion, service interruption or alteration is more serious than access that leaves systems untouched.
  • Conduct after discovery: prompt confidential reporting supports a research explanation; concealment or continued exploration weakens it.

Crown Prosecution Service guidance similarly identifies the scale of damage, victim vulnerability, sophistication, concealment and financial motivation as relevant considerations in Computer Misuse Act cases. The absence of financial gain can remove one aggravating feature, but it does not neutralise the others.[Crown Prosecution Service]cps.gov.ukcomputer misuse actCrown Prosecution ServiceComputer Misuse Act5 Feb 2020 — This guidance sets out how to consider prosecuting cases under the Computer Misu…

Motive and Law illustration 1

Can a Public-Interest Claim Justify the Intrusion?

A public-interest argument is strongest when the conduct is directed at exposing a concrete danger or wrongdoing and is carefully limited to what is necessary. It becomes weaker when the person is pursuing an unverified theory, searching broadly in the hope that evidence might exist, or entering systems whose occupants have no meaningful opportunity to consent.

UFO-related hacking presents a particular difficulty. The hacker may sincerely believe that officials are concealing information of enormous public importance. Sincerity, however, does not establish that the belief is well founded or that indiscriminate access is proportionate. Without such limits, almost any intruder could claim that a suspected conspiracy, unsafe practice or institutional secret justified entering systems first and looking for proof afterwards.

A workable public-interest test would therefore have to examine conduct rather than accepting motive at face value. Relevant questions include:

  1. Was there a credible basis for suspecting serious wrongdoing or danger?
  2. Were lawful routes, such as freedom-of-information requests, journalism, regulatory complaints or protected disclosures, unavailable or genuinely ineffective?
  3. Was the intrusion narrowly confined to material necessary to test the concern?
  4. Were unrelated personal or operational data avoided?
  5. Were reasonable steps taken to prevent harm?
  6. Was the information reported responsibly to someone able to verify or remedy the issue?
  7. Did the person stop once the relevant evidence had been obtained?

McKinnon’s stated search does not fit comfortably into this model. His objective was exploratory: to locate evidence that he believed might be hidden somewhere within NASA or military networks. The alleged access extended across many machines rather than a single, identified repository connected to a demonstrable defect or specific act of misconduct. Even accepting his account of a non-commercial purpose, the breadth and sensitivity of the targets gave the authorities reasons to regard the conduct as serious.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…

This does not mean motive is legally irrelevant. UK prosecutors apply both an evidential test and a public-interest test. They consider matters including seriousness, culpability, harm, the suspect’s circumstances and whether prosecution is proportionate. A person’s purpose, restraint, health and level of responsibility can therefore influence whether a case is charged even where the underlying access appears unlawful.[Crown Prosecution Service]cps.gov.ukcode crown prosecutorsCrown Prosecution ServiceThe Code for Crown Prosecutors26 Oct 2018 — CPS guidance contains further evidential and public interest factors…

McKinnon’s eventual outcome also shows why a decision not to prosecute should not be mistaken for legal approval of the hacking. In October 2012, the Home Secretary blocked his extradition because medical evidence indicated that extradition would create an exceptionally high risk of suicide and would be incompatible with his human rights. The decision was expressly framed around health and extradition, not a finding that UFO curiosity had justified the intrusions.[GOV.UK]GOV.UKgary mckinnon extradition case home secretarys statementGary McKinnon extradition case: Home Secretary's statement16 Oct 2012 — I have concluded that Mr McKinnon's extradition would give rise t…

British authorities subsequently declined to prosecute him in the UK. Contemporary reporting said the police and Crown Prosecution Service considered that evidential and jurisdictional difficulties created a poor prospect of conviction. That outcome reflected the practical viability of a prosecution after a long, cross-border case; it did not establish a general “curiosity defence” to unauthorised access.[The Guardian]theguardian.comgary mckinnon no uk chargesgary mckinnon no uk charges

Why Motive Still Matters to Punishment

Although motive may not erase liability, it can significantly affect how blame and proportionality are assessed. Criminal justice ordinarily distinguishes between an offender seeking personal profit, an offender intending political or military harm, and an offender pursuing information without a plan to exploit it. Those differences can influence prosecutorial discretion, charging choices, mitigation and sentence.

For curiosity-driven hacking, the most persuasive mitigating features would be a lack of financial benefit, limited access, cooperation with investigators, genuine remorse, no dissemination of sensitive information and little or no actual harm. Conversely, repeated intrusion after warnings, efforts to conceal identity, disruption of services, extraction of credentials or disregard for obvious security risks can outweigh the claimed motive.

The McKinnon debate became unusually intense because the potential consequences appeared to many observers to be out of proportion to his self-described role as an obsessive amateur investigator. His lawyers challenged the pressure created by the American plea-bargaining and extradition process, while supporters contrasted his claimed purpose with espionage or terrorism. The House of Lords nevertheless rejected his legal challenge to extradition in 2008, emphasising that differences between British and American criminal procedure did not themselves make the process abusive.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…

The later human-rights decision addressed a different question: whether extradition was permissible given the medical evidence. Separating these issues is essential. A person may have committed a serious offence yet still have a valid argument that a particular trial location, custodial risk or punishment would be unjust or disproportionate. Mercy, mitigation and procedural fairness do not require the law to pretend that the original access was authorised.

The case therefore supports two propositions at once. Governments have a legitimate interest in protecting sensitive networks even from non-commercial intruders. At the same time, punishment should take account of actual harm, mental health, personal culpability and the difference between investigation, vandalism, theft and hostile intelligence activity.

Motive and Law illustration 2

Where Ethical Hacking Differs

Ethical hacking is not defined merely by good intentions. Its defining feature is a controlled relationship between the researcher and the system owner, usually established through prior permission, a published vulnerability-disclosure policy or a bug-bounty programme. The permission sets boundaries: which systems may be tested, which methods are prohibited, how much data may be accessed and how findings must be reported.

The UK National Cyber Security Centre describes penetration testing as a commissioned security activity and operates the CHECK scheme for authorised testing of public-sector and critical systems. Its vulnerability-disclosure guidance encourages organisations to create clear channels through which researchers can report weaknesses. These structures convert useful curiosity into governed investigation rather than leaving researchers to decide unilaterally that a desired outcome justifies intrusion.[National Cyber Security Centre]ncsc.gov.ukvulnerability disclosure toolkitvulnerability disclosure toolkit

A responsible researcher will normally:

  • remain within the published scope;
  • use the least intrusive method capable of confirming the flaw;
  • avoid accessing real user data unless essential;
  • stop when testing could disrupt a service;
  • preserve confidentiality;
  • report the finding promptly; and
  • allow reasonable time for remediation before any public disclosure.

Coordinated vulnerability disclosure matters because even well-intentioned testing can expose private information, damage systems or reveal an exploitable weakness to others. European Union cybersecurity guidance has consequently treated clear reporting processes and legal protection for good-faith researchers as important parts of vulnerability governance.[ENISA]enisa.europa.euENISACoordinated Vulnerability Disclosure policies in the EUENISACoordinated Vulnerability Disclosure policies in the EU

The United States Department of Justice’s Computer Fraud and Abuse Act charging policy provides a useful contrast with open-ended curiosity. It says that good-faith security research should not be charged where access is undertaken solely to test, investigate or correct a security flaw, is designed to avoid harm, and is used primarily to improve the security or safety of the affected class of systems or users. The policy does not protect every person who describes an intrusion as research; it links protection to purpose, safety and responsible use of the results.[Department of Justice]justice.govOpen source on justice.gov.

UFO hunting inside government networks differs at the most basic level. Its purpose is not to identify and help correct a technical vulnerability, even though the hacker may exploit one to gain entry. The vulnerability is a means of reaching secret information, not the subject of the investigation. Nor does the intruder ordinarily have a defined testing scope or a duty to minimise contact with unrelated material. Calling such activity “research” therefore confuses research about a system’s security with unauthorised investigation conducted through that system.

The Governance Lesson

The hardest cases are not those involving obvious theft or sabotage, but those in which genuine curiosity coexists with deliberate trespass. Treating every curious intruder as equivalent to a profit-seeking criminal can obscure meaningful differences in culpability. Treating professed public interest as a complete answer, however, would allow individuals to appoint themselves investigator, judge and authorising authority.

A sound approach keeps three decisions separate. First, liability asks whether the access was knowingly unauthorised and whether any further offences, damage or data misuse occurred. Secondly, prosecutorial and sentencing decisions assess motive, actual harm, personal circumstances and proportionality. Thirdly, policy determines whether researchers need clearer safe harbours for carefully bounded security work.

The continuing UK debate over Computer Misuse Act reform reflects concern that legitimate cybersecurity researchers may face uncertainty when testing and reporting weaknesses. The government’s review recorded calls for greater legal clarity and protection for responsible research, while also recognising the need to avoid creating cover for harmful intrusions. That debate concerns defined security activity, not a general entitlement to search other people’s systems whenever the searcher believes the subject is important.[GOV.UK]GOV.UKanalysis of responses accessibleanalysis of responses accessible

For UFO hackers such as Gary McKinnon, curiosity is therefore relevant but not exculpatory. It can explain why the intrusion occurred, distinguish the case from conventional cybercrime and support arguments for restrained punishment. It cannot by itself supply permission, prove public benefit or remove the risks imposed on the owners and users of the systems. The dividing line between investigator and offender is drawn less by what the hacker hoped to find than by who authorised the search, how narrowly it was conducted, what harm it created and what the hacker did with the access.

Motive and Law illustration 3

Amazon book picks

Further Reading

Books and field guides related to Does Curiosity Make Illegal Hacking Less Serious?. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromcybersecurity t shirt oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: mckinn 1
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentMckinnon V Government of The United States of America...30 Jul 2008 — The appellant is a 42 year old British citizen, an un...

2. Source: cps.gov.uk
Title: computer misuse act
Link:https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act

Source snippet

Crown Prosecution ServiceComputer Misuse Act5 Feb 2020 — This guidance sets out how to consider prosecuting cases under the Computer Misu...

3. Source: justice.gov
Title: Department of Justice9-48.000
Link:https://www.justice.gov/jm/jm-9-48000-computer-fraud

Source snippet

Computer Fraud and Abuse Act“good faith security research” means accessing a computer solely for purposes of good-faith testing, investig...

4. Source: legislation.gov.uk
Link:https://www.legislation.gov.uk/ukpga/1990/18/contents

Source snippet

Computer Misuse Act 1990An Act to make provision for securing computer material against unauthorised access or modification; and for conn...

5. Source: GOV.UK
Title: latest on [gary mckinnon case]({{ ‘mc-kinnon-case/’ | relative_url }})
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case

Source snippet

4 Nov 2010 — Mr McKinnon is accused by US authorities of the unauthorised access of 97 government computers concerned with national defen...

6. Source: GOV.UK
Title: gary mckinnon extradition case home secretarys statement
Link:https://www.gov.uk/government/speeches/gary-mckinnon-extradition-case-home-secretarys-statement

Source snippet

Gary McKinnon extradition case: Home Secretary's statement16 Oct 2012 — I have concluded that Mr McKinnon's extradition would give rise t...

7. Source: cps.gov.uk
Title: code crown prosecutors
Link:https://www.cps.gov.uk/publication/code-crown-prosecutors

Source snippet

Crown Prosecution ServiceThe Code for Crown Prosecutors26 Oct 2018 — CPS guidance contains further evidential and public interest factors...

8. Source: cps.gov.uk
Link:https://www.cps.gov.uk/principles-we-follow

9. Source: hansard.parliament.uk
Title: Hansard Extradition
Link:https://hansard.parliament.uk/commons/2012-10-16/debates/12101642000005/Extradition

10. Source: publications.parliament.uk
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-2.htm

11. Source: ncsc.gov.uk
Title: vulnerability disclosure toolkit
Link:https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit

12. Source: ncsc.gov.uk
Title: penetration testing
Link:https://www.ncsc.gov.uk/guidance/penetration-testing

13. Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/schemes/check/introduction

14. Source: enisa.europa.eu
Title: ENISACoordinated Vulnerability Disclosure policies in the EU
Link:https://www.enisa.europa.eu/sites/default/files/publications/Coordinated%20Vulnerability%20Disclosure%20policies%20in%20the%20EU.pdf

15. Source: enisa.europa.eu
Title: ENISAVulnerability Disclosure
Link:https://www.enisa.europa.eu/topics/vulnerability-disclosure

16. Source: justice.gov
Link:https://www.justice.gov/archives/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act

17. Source: GOV.UK
Title: analysis of responses accessible
Link:https://www.gov.uk/government/consultations/review-of-the-computer-misuse-act-1990/outcome/analysis-of-responses-accessible

18. Source: GOV.UK
Link:https://www.gov.uk/government/consultations/review-of-the-computer-misuse-act-1990/review-of-the-computer-misuse-act-1990-consultation-and-response-to-call-for-information-accessible

19. Source: hansard.parliament.uk
Title: uk Gary Mc Kinnon (Extradition)
Link:https://hansard.parliament.uk/commons/2009-12-01/debates/09120144000002/GaryMckinnon%28Extradition%29

20. Source: hansard.parliament.uk
Link:https://hansard.parliament.uk/commons/2022-04-19/debates/AE9413F3-D4F2-44EC-890E-75B0250328C4/ComputerMisuseAct1990

21. Source: committees.parliament.uk
Link:https://committees.parliament.uk/writtenevidence/53322/html/

22. Source: bills.parliament.uk
Link:https://bills.parliament.uk/publications/60406/documents/6385

23. Source: data.parliament.uk
Title: uk The Code
Link:https://data.parliament.uk/DepositedPapers/Files/DEP2013-0157/Code2013FINAL_WEB.pdf

24. Source: www2.richmond.gov.uk
Title: sd 011 statement of consultation local plan january 2024
Link:https://www2.richmond.gov.uk/docs/localplan/sd_011_statement_of_consultation_local_plan_january_2024.pdf
Published: january 2024

25. Source: richmond.gov.uk
Title: local plan statement of consultation
Link:https://www.richmond.gov.uk/media/large/local_plan_statement_of_consultation.pdf

26. Source: justice.gov
Link:https://www.justice.gov/

27. Source: ncsc.gov.uk
Title: secure deployment maintenance
Link:https://www.ncsc.gov.uk/collection/software-security-code-of-practice-implementation-guidance/secure-deployment-maintenance

28. Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/files/NCSC-Vulnerability-disclosure-Toolkit-v2.pdf

29. Source: ncsc.gov.uk
Title: reporting disclosure
Link:https://www.ncsc.gov.uk/collection/vulnerability-management/reporting-disclosure

30. Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/

31. Source: ncsc.gov.uk
Title: from bugs to bypasses adapting vulnerability disclosure for ai safeguards
Link:https://www.ncsc.gov.uk/blog-post/from-bugs-to-bypasses-adapting-vulnerability-disclosure-for-ai-safeguards

32. Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/collection/vulnerability-management/guidance

33. Source: GOV.UK
Link:https://www.gov.uk/government/organisations/ministry-of-justice

34. Source: justice-ni.gov.uk
Link:https://www.justice-ni.gov.uk/

35. Source: lawcom.gov.uk
Link:https://lawcom.gov.uk/project/protection-of-official-data/

36. Source: college.police.uk
Link:https://www.college.police.uk/print/pdf/node/2596

37. Source: sentencing.uk
Title: fraud failing to disclose
Link:https://sentencing.uk/offences/fraud-failing-to-disclose

38. Source: assets.publishing.service.gov.uk
Title: public views 4
Link:https://assets.publishing.service.gov.uk/media/5a7aaeb5e5274a34770e661b/public-views-4.pdf

39. Source: time.com
Title: hack attack 2
Link:https://time.com/archive/6943962/hack-attack-2/

40. Source: southeastcyber.police.uk
Title: computer misuse act
Link:https://southeastcyber.police.uk/computer-misuse-act/

41. Source: nationalcrimeagency.gov.uk
Link:https://www.nationalcrimeagency.gov.uk/news/one-in-five-children-found-to-engage-in-illegal-activity-online?highlight=WyJuYXRpb24iLCJuYXRpb25hbCIsIm5hdGlvbmFsbHkiLCJuYXRpb25zJyIsIm5hdGlvbmFsaXR5IiwibmF0aW9uYWxzIiwibmF0aW9ucyIsIm5hdGlvbmFsbHknIiwibmF0aW9uYWxpdGllcyIsIm5hdGlvbidzIl0%3D

42. Source: gov.scot
Link:https://www.gov.scot/publications/scottish-cyber-coordination-centre-vulnerability-coordination-policy-procedure/pages/3/

43. Source: mojdigital.blog.gov.uk
Title: blog.gov.uk Vulnerability disclosure policy
Link:https://mojdigital.blog.gov.uk/vulnerability-disclosure-policy/

44. Source: open.edu
Link:https://www.open.edu/openlearn/ocw/mod/oucontent/view.php?id=80038&section=_unit8.3.3

45. Source: theguardian.com
Title: gary mckinnon no uk charges
Link:https://www.theguardian.com/world/2012/dec/14/gary-mckinnon-no-uk-charges

46. Source: ncsc.nl
Link:https://www.ncsc.nl/en/services/report-a-vulnerability

47. Source: enisa.europa.eu
Title: eu Good Practice Guide on Vulnerability Disclosure
Link:https://www.enisa.europa.eu/publications/vulnerability-disclosure

48. Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon

49. Source: Wikipedia
Title: United States Department of Justice
Link:https://en.wikipedia.org/wiki/United_States_Department_of_Justice

50. Source: craevidence.com
Title: coordinated vulnerability disclosure
Link:https://craevidence.com/cra-compliance/coordinated-vulnerability-disclosure

51. Source: theguardian.com
Link:https://www.theguardian.com/technology/2008/aug/28/hacking.security

52. Source: sites.google.com
Title: computer misuse act
Link:https://sites.google.com/rgc.aberdeen.sch.uk/rgc-highercomputing/computer-systems/security-risks-and-precautions/computer-misuse-act

53. Source: nesc.co.uk
Title: Vulnerability Disclosure
Link:https://www.nesc.co.uk/vulnerability-disclosure/

Additional References

54. Source: stuartmillersolicitors.co.uk
Link:https://www.stuartmillersolicitors.co.uk/computer-misuse-act-offences/

55. Source: webmasterworld.com
Link:https://www.webmasterworld.com/foo/3963063-2-30.htm

56. Source: ucb.ac.uk
Link:https://www.ucb.ac.uk/university/higher-education-student-handbook/computer-misuse-policy/

57. Source: jonesday.com
Link:https://www.jonesday.com/en/insights/2022/06/department-of-justice-significantly-revises-policy-on-charging-cfaa-violations

58. Source: nebrcentre.co.uk
Link:https://www.nebrcentre.co.uk/defenses-for-ethical-hacking-proposed-under-uk-computer-misuse-act/

59. Source: sentencingacademy.org.uk
Link:https://www.sentencingacademy.org.uk/wp-content/uploads/2025/08/ExplainerFines.pdf

60. Source: sentencingcouncil.org.uk
Link:https://sentencingcouncil.org.uk/guidelines/fraud/

61. Source: sentencingcouncil.org.uk
Link:https://sentencingcouncil.org.uk/guidelines/general-guideline-overarching-principles/

62. Source: hackcur.io
Link:https://hackcur.io/raising-the-bar-how-the-uk-extradition-laws-were-put-to-the-test/

63. Source: hackerone.com
Link:https://hackerone.com/ncsc_uk