Within UFO Hackers
Does Curiosity Make Illegal Hacking Less Serious?
A claimed search for public-interest information does not erase unauthorised access, but it can affect how motives and punishment are debated.
On this page
- Intent versus unlawful conduct
- Public interest arguments
- Where ethical hacking differs
Page outline Jump by section
Introduction
Curiosity does not normally cancel criminal responsibility for hacking. In cases such as Gary McKinnon’s, a claimed search for UFO evidence or suppressed technology may distinguish the intruder from a thief, extortionist or foreign agent, but the central legal question remains whether access was knowingly obtained without permission. Motive matters more when prosecutors assess the public interest, when courts judge culpability and punishment, and when the public debates proportionality. It is not usually a licence to enter another organisation’s systems.

That distinction is important because “I was investigating” can describe very different conduct. One person may cautiously test a flaw, avoid private data and report it to the owner; another may explore military networks for months, copy material or interfere with machines while pursuing a personally compelling theory. Both may claim curiosity or public benefit, but law and ethical practice place greater weight on authorisation, necessity, restraint, disclosure and harm than on the label the intruder gives the activity.[parliament.uk]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…
Intent Versus Unlawful Conduct
Under the UK Computer Misuse Act 1990, the basic offence centres on unauthorised access. Section 1 applies where a person causes a computer to perform a function intending to secure access to data or programs, knows that the access is unauthorised, and nevertheless proceeds. The offence does not require proof that the person sought money, intended espionage or planned to damage the computer. A search motivated by UFO curiosity can therefore satisfy the core offence just as readily as a search motivated by commercial advantage.[Legislation.gov.uk]legislation.gov.ukComputer Misuse Act 1990An Act to make provision for securing computer material against unauthorised access or modification; and for conn…
This separates intention in the legal sense from motive in the everyday sense. The relevant intention may be simply to enter a protected system or retrieve information without permission. The motive explains why the person wanted access: curiosity, ideology, profit, revenge, prestige or a claimed public service. A benign-sounding motive may alter the moral picture, but it does not change whether the access was deliberate and known to be unauthorised.
McKinnon’s case illustrates the point. The United States alleged that he accessed 97 government computers between February 2001 and March 2002, including machines associated with defence and national security. He said he was searching for evidence of UFO secrecy, antigravity technology and suppressed energy systems. The House of Lords treated the case as one involving admitted unauthorised access while recording disputed allegations about damage and disruption. His asserted purpose explained the intrusion, but it did not transform it into authorised investigation.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…
The seriousness of curiosity-driven hacking therefore depends on more than the absence of greed. Several features can increase culpability or harm:
- Duration and repetition: a brief accidental discovery differs from sustained access across numerous machines.
- Sensitivity of the target: military, health, infrastructure and government systems create risks beyond the value of any particular file.
- Depth of intrusion: viewing an exposed page is not equivalent to obtaining credentials, escalating privileges or moving through internal networks.
- Treatment of data: copying, retaining or publishing information can affect privacy, security and later exploitation.
- Operational effects: deletion, service interruption or alteration is more serious than access that leaves systems untouched.
- Conduct after discovery: prompt confidential reporting supports a research explanation; concealment or continued exploration weakens it.
Crown Prosecution Service guidance similarly identifies the scale of damage, victim vulnerability, sophistication, concealment and financial motivation as relevant considerations in Computer Misuse Act cases. The absence of financial gain can remove one aggravating feature, but it does not neutralise the others.[Crown Prosecution Service]cps.gov.ukcomputer misuse actCrown Prosecution ServiceComputer Misuse Act5 Feb 2020 — This guidance sets out how to consider prosecuting cases under the Computer Misu…
Can a Public-Interest Claim Justify the Intrusion?
A public-interest argument is strongest when the conduct is directed at exposing a concrete danger or wrongdoing and is carefully limited to what is necessary. It becomes weaker when the person is pursuing an unverified theory, searching broadly in the hope that evidence might exist, or entering systems whose occupants have no meaningful opportunity to consent.
UFO-related hacking presents a particular difficulty. The hacker may sincerely believe that officials are concealing information of enormous public importance. Sincerity, however, does not establish that the belief is well founded or that indiscriminate access is proportionate. Without such limits, almost any intruder could claim that a suspected conspiracy, unsafe practice or institutional secret justified entering systems first and looking for proof afterwards.
A workable public-interest test would therefore have to examine conduct rather than accepting motive at face value. Relevant questions include:
- Was there a credible basis for suspecting serious wrongdoing or danger?
- Were lawful routes, such as freedom-of-information requests, journalism, regulatory complaints or protected disclosures, unavailable or genuinely ineffective?
- Was the intrusion narrowly confined to material necessary to test the concern?
- Were unrelated personal or operational data avoided?
- Were reasonable steps taken to prevent harm?
- Was the information reported responsibly to someone able to verify or remedy the issue?
- Did the person stop once the relevant evidence had been obtained?
McKinnon’s stated search does not fit comfortably into this model. His objective was exploratory: to locate evidence that he believed might be hidden somewhere within NASA or military networks. The alleged access extended across many machines rather than a single, identified repository connected to a demonstrable defect or specific act of misconduct. Even accepting his account of a non-commercial purpose, the breadth and sensitivity of the targets gave the authorities reasons to regard the conduct as serious.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…
This does not mean motive is legally irrelevant. UK prosecutors apply both an evidential test and a public-interest test. They consider matters including seriousness, culpability, harm, the suspect’s circumstances and whether prosecution is proportionate. A person’s purpose, restraint, health and level of responsibility can therefore influence whether a case is charged even where the underlying access appears unlawful.[Crown Prosecution Service]cps.gov.ukcode crown prosecutorsCrown Prosecution ServiceThe Code for Crown Prosecutors26 Oct 2018 — CPS guidance contains further evidential and public interest factors…
McKinnon’s eventual outcome also shows why a decision not to prosecute should not be mistaken for legal approval of the hacking. In October 2012, the Home Secretary blocked his extradition because medical evidence indicated that extradition would create an exceptionally high risk of suicide and would be incompatible with his human rights. The decision was expressly framed around health and extradition, not a finding that UFO curiosity had justified the intrusions.[GOV.UK]GOV.UKgary mckinnon extradition case home secretarys statementGary McKinnon extradition case: Home Secretary's statement16 Oct 2012 — I have concluded that Mr McKinnon's extradition would give rise t…
British authorities subsequently declined to prosecute him in the UK. Contemporary reporting said the police and Crown Prosecution Service considered that evidential and jurisdictional difficulties created a poor prospect of conviction. That outcome reflected the practical viability of a prosecution after a long, cross-border case; it did not establish a general “curiosity defence” to unauthorised access.[The Guardian]theguardian.comgary mckinnon no uk chargesgary mckinnon no uk charges
Why Motive Still Matters to Punishment
Although motive may not erase liability, it can significantly affect how blame and proportionality are assessed. Criminal justice ordinarily distinguishes between an offender seeking personal profit, an offender intending political or military harm, and an offender pursuing information without a plan to exploit it. Those differences can influence prosecutorial discretion, charging choices, mitigation and sentence.
For curiosity-driven hacking, the most persuasive mitigating features would be a lack of financial benefit, limited access, cooperation with investigators, genuine remorse, no dissemination of sensitive information and little or no actual harm. Conversely, repeated intrusion after warnings, efforts to conceal identity, disruption of services, extraction of credentials or disregard for obvious security risks can outweigh the claimed motive.
The McKinnon debate became unusually intense because the potential consequences appeared to many observers to be out of proportion to his self-described role as an obsessive amateur investigator. His lawyers challenged the pressure created by the American plea-bargaining and extradition process, while supporters contrasted his claimed purpose with espionage or terrorism. The House of Lords nevertheless rejected his legal challenge to extradition in 2008, emphasising that differences between British and American criminal procedure did not themselves make the process abusive.[UK Parliament]publications.parliament.ukmckinn 1UK ParliamentMckinnon V Government of The United States of America…30 Jul 2008 — The appellant is a 42 year old British citizen, an un…
The later human-rights decision addressed a different question: whether extradition was permissible given the medical evidence. Separating these issues is essential. A person may have committed a serious offence yet still have a valid argument that a particular trial location, custodial risk or punishment would be unjust or disproportionate. Mercy, mitigation and procedural fairness do not require the law to pretend that the original access was authorised.
The case therefore supports two propositions at once. Governments have a legitimate interest in protecting sensitive networks even from non-commercial intruders. At the same time, punishment should take account of actual harm, mental health, personal culpability and the difference between investigation, vandalism, theft and hostile intelligence activity.
Where Ethical Hacking Differs
Ethical hacking is not defined merely by good intentions. Its defining feature is a controlled relationship between the researcher and the system owner, usually established through prior permission, a published vulnerability-disclosure policy or a bug-bounty programme. The permission sets boundaries: which systems may be tested, which methods are prohibited, how much data may be accessed and how findings must be reported.
The UK National Cyber Security Centre describes penetration testing as a commissioned security activity and operates the CHECK scheme for authorised testing of public-sector and critical systems. Its vulnerability-disclosure guidance encourages organisations to create clear channels through which researchers can report weaknesses. These structures convert useful curiosity into governed investigation rather than leaving researchers to decide unilaterally that a desired outcome justifies intrusion.[National Cyber Security Centre]ncsc.gov.ukvulnerability disclosure toolkitvulnerability disclosure toolkit
A responsible researcher will normally:
- remain within the published scope;
- use the least intrusive method capable of confirming the flaw;
- avoid accessing real user data unless essential;
- stop when testing could disrupt a service;
- preserve confidentiality;
- report the finding promptly; and
- allow reasonable time for remediation before any public disclosure.
Coordinated vulnerability disclosure matters because even well-intentioned testing can expose private information, damage systems or reveal an exploitable weakness to others. European Union cybersecurity guidance has consequently treated clear reporting processes and legal protection for good-faith researchers as important parts of vulnerability governance.[ENISA]enisa.europa.euENISACoordinated Vulnerability Disclosure policies in the EUENISACoordinated Vulnerability Disclosure policies in the EU
The United States Department of Justice’s Computer Fraud and Abuse Act charging policy provides a useful contrast with open-ended curiosity. It says that good-faith security research should not be charged where access is undertaken solely to test, investigate or correct a security flaw, is designed to avoid harm, and is used primarily to improve the security or safety of the affected class of systems or users. The policy does not protect every person who describes an intrusion as research; it links protection to purpose, safety and responsible use of the results.[Department of Justice]justice.govOpen source on justice.gov.
UFO hunting inside government networks differs at the most basic level. Its purpose is not to identify and help correct a technical vulnerability, even though the hacker may exploit one to gain entry. The vulnerability is a means of reaching secret information, not the subject of the investigation. Nor does the intruder ordinarily have a defined testing scope or a duty to minimise contact with unrelated material. Calling such activity “research” therefore confuses research about a system’s security with unauthorised investigation conducted through that system.
The Governance Lesson
The hardest cases are not those involving obvious theft or sabotage, but those in which genuine curiosity coexists with deliberate trespass. Treating every curious intruder as equivalent to a profit-seeking criminal can obscure meaningful differences in culpability. Treating professed public interest as a complete answer, however, would allow individuals to appoint themselves investigator, judge and authorising authority.
A sound approach keeps three decisions separate. First, liability asks whether the access was knowingly unauthorised and whether any further offences, damage or data misuse occurred. Secondly, prosecutorial and sentencing decisions assess motive, actual harm, personal circumstances and proportionality. Thirdly, policy determines whether researchers need clearer safe harbours for carefully bounded security work.
The continuing UK debate over Computer Misuse Act reform reflects concern that legitimate cybersecurity researchers may face uncertainty when testing and reporting weaknesses. The government’s review recorded calls for greater legal clarity and protection for responsible research, while also recognising the need to avoid creating cover for harmful intrusions. That debate concerns defined security activity, not a general entitlement to search other people’s systems whenever the searcher believes the subject is important.[GOV.UK]GOV.UKanalysis of responses accessibleanalysis of responses accessible
For UFO hackers such as Gary McKinnon, curiosity is therefore relevant but not exculpatory. It can explain why the intrusion occurred, distinguish the case from conventional cybercrime and support arguments for restrained punishment. It cannot by itself supply permission, prove public benefit or remove the risks imposed on the owners and users of the systems. The dividing line between investigator and offender is drawn less by what the hacker hoped to find than by who authorised the search, how narrowly it was conducted, what harm it created and what the hacker did with the access.
Amazon book picks
Further Reading
Books and field guides related to Does Curiosity Make Illegal Hacking Less Serious?. Use these as the next step if you want deeper reading beyond the article.
Hackers, Heroes of the Computer Revolution
The origins and history of electronic intruders that includes the first written "code of ethics" of the computer underground.
The Hacker and the State: Cyber Attacks and the New Normal of...
Rating: 5.0/5 from 18 Google Books ratings
“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...
Ghost in the Wires: My Adventures as the World's Most Wanted...
In this "intriguing, insightful and extremely educational" novel, the world's most famous hacker teaches you easy cloaking and counter-me...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromcybersecurity t shirt oneBay.co.uk.
Endnotes
1.
Source: publications.parliament.uk
Title: mckinn 1
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm
Source snippet
UK ParliamentMckinnon V Government of The United States of America...30 Jul 2008 — The appellant is a 42 year old British citizen, an un...
2.
Source: cps.gov.uk
Title: computer misuse act
Link:https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act
Source snippet
Crown Prosecution ServiceComputer Misuse Act5 Feb 2020 — This guidance sets out how to consider prosecuting cases under the Computer Misu...
3.
Source: justice.gov
Title: Department of Justice9-48.000
Link:https://www.justice.gov/jm/jm-9-48000-computer-fraud
Source snippet
Computer Fraud and Abuse Act“good faith security research” means accessing a computer solely for purposes of good-faith testing, investig...
4.
Source: legislation.gov.uk
Link:https://www.legislation.gov.uk/ukpga/1990/18/contents
Source snippet
Computer Misuse Act 1990An Act to make provision for securing computer material against unauthorised access or modification; and for conn...
5.
Source: GOV.UK
Title: latest on [gary mckinnon case]({{ ‘mc-kinnon-case/’ | relative_url }})
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case
Source snippet
4 Nov 2010 — Mr McKinnon is accused by US authorities of the unauthorised access of 97 government computers concerned with national defen...
6.
Source: GOV.UK
Title: gary mckinnon extradition case home secretarys statement
Link:https://www.gov.uk/government/speeches/gary-mckinnon-extradition-case-home-secretarys-statement
Source snippet
Gary McKinnon extradition case: Home Secretary's statement16 Oct 2012 — I have concluded that Mr McKinnon's extradition would give rise t...
7.
Source: cps.gov.uk
Title: code crown prosecutors
Link:https://www.cps.gov.uk/publication/code-crown-prosecutors
Source snippet
Crown Prosecution ServiceThe Code for Crown Prosecutors26 Oct 2018 — CPS guidance contains further evidential and public interest factors...
8.
Source: cps.gov.uk
Link:https://www.cps.gov.uk/principles-we-follow
9.
Source: hansard.parliament.uk
Title: Hansard Extradition
Link:https://hansard.parliament.uk/commons/2012-10-16/debates/12101642000005/Extradition
10.
Source: publications.parliament.uk
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-2.htm
11.
Source: ncsc.gov.uk
Title: vulnerability disclosure toolkit
Link:https://www.ncsc.gov.uk/information/vulnerability-disclosure-toolkit
12.
Source: ncsc.gov.uk
Title: penetration testing
Link:https://www.ncsc.gov.uk/guidance/penetration-testing
13.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/schemes/check/introduction
14.
Source: enisa.europa.eu
Title: ENISACoordinated Vulnerability Disclosure policies in the EU
Link:https://www.enisa.europa.eu/sites/default/files/publications/Coordinated%20Vulnerability%20Disclosure%20policies%20in%20the%20EU.pdf
15.
Source: enisa.europa.eu
Title: ENISAVulnerability Disclosure
Link:https://www.enisa.europa.eu/topics/vulnerability-disclosure
16.
Source: justice.gov
Link:https://www.justice.gov/archives/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act
17.
Source: GOV.UK
Title: analysis of responses accessible
Link:https://www.gov.uk/government/consultations/review-of-the-computer-misuse-act-1990/outcome/analysis-of-responses-accessible
18.
Source: GOV.UK
Link:https://www.gov.uk/government/consultations/review-of-the-computer-misuse-act-1990/review-of-the-computer-misuse-act-1990-consultation-and-response-to-call-for-information-accessible
19.
Source: hansard.parliament.uk
Title: uk Gary Mc Kinnon (Extradition)
Link:https://hansard.parliament.uk/commons/2009-12-01/debates/09120144000002/GaryMckinnon%28Extradition%29
20.
Source: hansard.parliament.uk
Link:https://hansard.parliament.uk/commons/2022-04-19/debates/AE9413F3-D4F2-44EC-890E-75B0250328C4/ComputerMisuseAct1990
21.
Source: committees.parliament.uk
Link:https://committees.parliament.uk/writtenevidence/53322/html/
22.
Source: bills.parliament.uk
Link:https://bills.parliament.uk/publications/60406/documents/6385
23.
Source: data.parliament.uk
Title: uk The Code
Link:https://data.parliament.uk/DepositedPapers/Files/DEP2013-0157/Code2013FINAL_WEB.pdf
24.
Source: www2.richmond.gov.uk
Title: sd 011 statement of consultation local plan january 2024
Link:https://www2.richmond.gov.uk/docs/localplan/sd_011_statement_of_consultation_local_plan_january_2024.pdf
Published: january 2024
25.
Source: richmond.gov.uk
Title: local plan statement of consultation
Link:https://www.richmond.gov.uk/media/large/local_plan_statement_of_consultation.pdf
26.
Source: justice.gov
Link:https://www.justice.gov/
27.
Source: ncsc.gov.uk
Title: secure deployment maintenance
Link:https://www.ncsc.gov.uk/collection/software-security-code-of-practice-implementation-guidance/secure-deployment-maintenance
28.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/files/NCSC-Vulnerability-disclosure-Toolkit-v2.pdf
29.
Source: ncsc.gov.uk
Title: reporting disclosure
Link:https://www.ncsc.gov.uk/collection/vulnerability-management/reporting-disclosure
30.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/
31.
Source: ncsc.gov.uk
Title: from bugs to bypasses adapting vulnerability disclosure for ai safeguards
Link:https://www.ncsc.gov.uk/blog-post/from-bugs-to-bypasses-adapting-vulnerability-disclosure-for-ai-safeguards
32.
Source: ncsc.gov.uk
Link:https://www.ncsc.gov.uk/collection/vulnerability-management/guidance
33.
Source: GOV.UK
Link:https://www.gov.uk/government/organisations/ministry-of-justice
34.
Source: justice-ni.gov.uk
Link:https://www.justice-ni.gov.uk/
35.
Source: lawcom.gov.uk
Link:https://lawcom.gov.uk/project/protection-of-official-data/
36.
Source: college.police.uk
Link:https://www.college.police.uk/print/pdf/node/2596
37.
Source: sentencing.uk
Title: fraud failing to disclose
Link:https://sentencing.uk/offences/fraud-failing-to-disclose
38.
Source: assets.publishing.service.gov.uk
Title: public views 4
Link:https://assets.publishing.service.gov.uk/media/5a7aaeb5e5274a34770e661b/public-views-4.pdf
39.
Source: time.com
Title: hack attack 2
Link:https://time.com/archive/6943962/hack-attack-2/
40.
Source: southeastcyber.police.uk
Title: computer misuse act
Link:https://southeastcyber.police.uk/computer-misuse-act/
41.
Source: nationalcrimeagency.gov.uk
Link:https://www.nationalcrimeagency.gov.uk/news/one-in-five-children-found-to-engage-in-illegal-activity-online?highlight=WyJuYXRpb24iLCJuYXRpb25hbCIsIm5hdGlvbmFsbHkiLCJuYXRpb25zJyIsIm5hdGlvbmFsaXR5IiwibmF0aW9uYWxzIiwibmF0aW9ucyIsIm5hdGlvbmFsbHknIiwibmF0aW9uYWxpdGllcyIsIm5hdGlvbidzIl0%3D
42.
Source: gov.scot
Link:https://www.gov.scot/publications/scottish-cyber-coordination-centre-vulnerability-coordination-policy-procedure/pages/3/
43.
Source: mojdigital.blog.gov.uk
Title: blog.gov.uk Vulnerability disclosure policy
Link:https://mojdigital.blog.gov.uk/vulnerability-disclosure-policy/
44.
Source: open.edu
Link:https://www.open.edu/openlearn/ocw/mod/oucontent/view.php?id=80038§ion=_unit8.3.3
45.
Source: theguardian.com
Title: gary mckinnon no uk charges
Link:https://www.theguardian.com/world/2012/dec/14/gary-mckinnon-no-uk-charges
46.
Source: ncsc.nl
Link:https://www.ncsc.nl/en/services/report-a-vulnerability
47.
Source: enisa.europa.eu
Title: eu Good Practice Guide on Vulnerability Disclosure
Link:https://www.enisa.europa.eu/publications/vulnerability-disclosure
48.
Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon
49.
Source: Wikipedia
Title: United States Department of Justice
Link:https://en.wikipedia.org/wiki/United_States_Department_of_Justice
50.
Source: craevidence.com
Title: coordinated vulnerability disclosure
Link:https://craevidence.com/cra-compliance/coordinated-vulnerability-disclosure
51.
Source: theguardian.com
Link:https://www.theguardian.com/technology/2008/aug/28/hacking.security
52.
Source: sites.google.com
Title: computer misuse act
Link:https://sites.google.com/rgc.aberdeen.sch.uk/rgc-highercomputing/computer-systems/security-risks-and-precautions/computer-misuse-act
53.
Source: nesc.co.uk
Title: Vulnerability Disclosure
Link:https://www.nesc.co.uk/vulnerability-disclosure/
Additional References
54.
Source: stuartmillersolicitors.co.uk
Link:https://www.stuartmillersolicitors.co.uk/computer-misuse-act-offences/
55.
Source: webmasterworld.com
Link:https://www.webmasterworld.com/foo/3963063-2-30.htm
56.
Source: ucb.ac.uk
Link:https://www.ucb.ac.uk/university/higher-education-student-handbook/computer-misuse-policy/
57.
Source: jonesday.com
Link:https://www.jonesday.com/en/insights/2022/06/department-of-justice-significantly-revises-policy-on-charging-cfaa-violations
58.
Source: nebrcentre.co.uk
Link:https://www.nebrcentre.co.uk/defenses-for-ethical-hacking-proposed-under-uk-computer-misuse-act/
59.
Source: sentencingacademy.org.uk
Link:https://www.sentencingacademy.org.uk/wp-content/uploads/2025/08/ExplainerFines.pdf
60.
Source: sentencingcouncil.org.uk
Link:https://sentencingcouncil.org.uk/guidelines/fraud/
61.
Source: sentencingcouncil.org.uk
Link:https://sentencingcouncil.org.uk/guidelines/general-guideline-overarching-principles/
62.
Source: hackcur.io
Link:https://hackcur.io/raising-the-bar-how-the-uk-extradition-laws-were-put-to-the-test/
63.
Source: hackerone.com
Link:https://hackerone.com/ncsc_uk


