Within Motive and Law

When Does Curiosity Become a Computer Crime?

A hacker's curiosity may explain the motive, but liability turns on deliberate access that the person knew was not authorised.

17 sources 3 graphics
Preview for When Does Curiosity Become a Computer Crime?

On this page

  • What the law means by unauthorised access
  • Why motive and legal intent are different
  • How deliberate exploration can satisfy the offence

Introduction

Curiosity can explain why someone accessed a computer system, but under UK law it rarely determines whether a criminal offence has been committed. In the context of curiosity-driven hacking, including cases such as Gary McKinnon’s claimed search for evidence of UFOs and advanced technology, the key legal question is usually much narrower: did the person deliberately obtain access to computer material while knowing they were not authorised to do so? The answer focuses on permission rather than purpose. A person motivated by fascination, conspiracy theories or a desire to investigate can still satisfy the legal elements of unauthorised access if they intentionally cross a known access boundary.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

Unauthorised Access illustration 1

Understanding this distinction helps explain why courts separate a defendant’s motive from the legal mechanism of the offence. Curiosity may influence public opinion or, in some cases, sentencing, but it does not normally convert unauthorised exploration into lawful investigation.

What the Law Means by Unauthorised Access

The foundation of UK computer hacking law is section 1 of the Computer Misuse Act 1990. The offence is committed when a person intentionally causes a computer to perform a function in order to obtain access to programs or data, knowing that the access is unauthorised. The prosecution does not have to prove financial gain, espionage, sabotage or any wider criminal objective.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

This produces an important legal consequence: the offence is complete because of the deliberate breach of permission, not because of what the person hoped to discover afterwards.

Several practical points follow from the legislation:

  • Permission must come from someone entitled to grant it.
  • The defendant must know, or realise, that the intended access is outside that permission.
  • The intended target need not be a particular file or document. Someone who enters a protected system “to see what is there” can still satisfy the statutory intent requirement.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

The Crown Prosecution Service notes that section 1 was deliberately drafted broadly enough to cover hackers who enter systems without any precise idea of what information they expect to find. Curiosity therefore does not prevent the necessary intent from existing.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

One of the most common misunderstandings is to confuse motive with intent.

A motive answers the question:

  • Why did the person want access?

Examples include:

  • searching for evidence of UFOs;
  • testing a personal theory;
  • intellectual curiosity;
  • political activism;
  • financial gain.

Legal intent answers a different question:

  • Did the person deliberately try to obtain access they knew they were not allowed to obtain?

The law treats these as separate issues. A defendant who honestly believed they were exposing hidden truths may still intentionally access a protected computer without permission. Conversely, someone acting for profit but never obtaining or attempting unauthorised access would not commit the section 1 offence simply because of their motive.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

This distinction explains why defendants sometimes acknowledge entering systems while continuing to argue that their reasons were honourable. Their explanation may be relevant to sentencing or public debate, but it does not normally alter whether the statutory elements of unauthorised access have been proved.

Unauthorised Access illustration 2

How Deliberate Exploration Can Satisfy the Offence

Curiosity-driven hacking often develops through a series of conscious decisions rather than a single dramatic act.

A typical progression might involve:

  1. Discovering a vulnerable system.
  2. Choosing to exploit the weakness.
  3. Entering protected areas without permission.
  4. Continuing to browse directories, files or network resources.
  5. Repeating the process across additional computers.

The legal significance lies less in the person’s emotional motivation than in the repeated choice to continue accessing systems after recognising that permission is absent.

The CPS guidance also emphasises that the offence requires knowledge that the access is unauthorised rather than mere carelessness or accident. An accidental connection, a mistyped address or exposure to publicly accessible information is different from intentionally bypassing authentication or continuing to explore after recognising that the system is restricted.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

The Importance of Knowing the Limits of Permission

Unauthorised access is not confined to outsiders breaking into networks. The Computer Misuse Act can also apply where someone exceeds the authority they already possess.

For example, an employee may legitimately access some databases but deliberately retrieve information from systems they know fall outside their authorised role. The House of Lords confirmed that the offence can apply where an individual intentionally accesses data they know they are not entitled to see, even if they have valid credentials for other parts of the organisation. Whether permission existed depends on the actual limits placed on that person’s authority.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

This illustrates that authorisation is not an all-or-nothing concept. Having some access rights does not automatically authorise every form of exploration.

Gary McKinnon as an Illustration of the Principle

Gary McKinnon’s case is frequently discussed because his stated objective differed from conventional cybercrime. He maintained that he was searching United States government computers for evidence relating to UFOs, advanced propulsion technology and alleged official secrecy rather than attempting financial fraud.

From the perspective of UK computer misuse law, however, the central mechanism remains straightforward. If a person knowingly accesses protected systems without permission, the offence concerns the lack of authorisation rather than the unusual nature of the search. His asserted curiosity helps explain the alleged motive but does not itself create legal authority to enter military or government networks.

For this reason, McKinnon’s case is often cited when explaining that sincere belief, unconventional research interests or perceived public benefit do not automatically negate liability for deliberate unauthorised access.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

Unauthorised Access illustration 3

Where Curiosity Ends and Criminal Liability Begins

The practical dividing line is usually permission rather than personal motivation.

Curiosity remains lawful when someone:

  • examines information intentionally made public;
  • conducts authorised security testing;
  • works within the scope of explicit permission; or
  • responsibly reports vulnerabilities discovered without deliberately exploiting them.

The legal risk increases when someone knowingly moves beyond those boundaries by bypassing authentication, using credentials without authority, exploring protected systems or continuing to access data after recognising that permission is absent.

In that sense, curiosity becomes unauthorised computer access not because curiosity itself is unlawful, but because it motivates deliberate conduct that crosses a recognised legal boundary. Under the Computer Misuse Act, the decisive question is not why the individual wanted to look, but whether they knowingly chose to enter a computer system they were not authorised to access.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…Published: August 3, 2023

Amazon book picks

Further Reading

Books and field guides related to When Does Curiosity Become a Computer Crime?. Use these as the next step if you want deeper reading beyond the article.

BookCover for The Hacker and the State

The Hacker and the State

By Ben Buchanan

Rating: 5.0/5 from 18 Google Books ratings

“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromcomputer security sign oneBay.co.uk.

Endnotes

1. Source: cps.gov.uk
Title: Crown Prosecution Service Computer Misuse Act | The Crown Prosecution Service
Link:https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act

Source snippet

Crown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023...

Published: August 3, 2023

2. Source: cps.gov.uk
Title: Crown Prosecution Service Cybercrime
Link:https://www.cps.gov.uk/prosecution-guidance/cybercrime-prosecution-guidance

Source snippet

Cybercrime - prosecution guidance | The Crown Prosecution ServiceMay 1, 2018 — CYBERCRIME - PROSECUTION GUIDANCE 01 May 2018 Updated: 26...

Published: May 1, 2018

3. Source: health-ni.gov.uk
Title: computer misuse act 1990
Link:https://www.health-ni.gov.uk/articles/computer-misuse-act-1990

Source snippet

The Computer Misuse Act 1990 | Department of HealthAugust 28, 2015 — THE COMPUTER MISUSE ACT 1990 Topics: * Good management, good records...

Published: August 28, 2015

4. Source: cps.gov.uk
Link:https://www.cps.gov.uk/prosecution-guidance/prosecution-guidance-search?subject_area=2344

Source snippet

Prosecution guidance search | The Crown Prosecution ServicePROSECUTION GUIDANCE SEARCH DISPLAYING 1 - 4 OF 4 RESULTS FOR SUBJECT AREA "CO...

5. Source: legislation.uk
Title: computer misuse act 1990
Link:https://legislation.uk/computer-misuse-act-1990

6. Source: nationalcrimeagency.gov.uk
Title: Cyber Choices Ransomeware
Link:https://www.nationalcrimeagency.gov.uk/cyber-choices-ransomware

7. Source: southeastcyber.police.uk
Title: computer misuse act
Link:https://southeastcyber.police.uk/computer-misuse-act/

8. Source: youtube.com
Title: Gary Mc Kinnon wins extradition battle
Link:https://www.youtube.com/watch?v=y4lecD44F5E

Source snippet

Computer Misuse Act...

9. Source: youtube.com
Title: Computer Misuse Act
Link:https://www.youtube.com/watch?v=ws4CrncWEwE

Source snippet

UK Hacker extradition to US blocked...

Additional References

10. Source: legalclarity.org
Title: computer misuse act 1990 offences penalties and defences
Link:https://legalclarity.org/computer-misuse-act-1990-offences-penalties-and-defences/

Source snippet

Computer Misuse Act 1990: Offences, Penalties and Defences - LegalClarityMay 13, 2026 — COMPUTER MISUSE ACT 1990: OFFENCES, PENALTIES AND...

Published: May 13, 2026

11. Source: commonslibrary.parliament.uk
Title: cdp 2022 0082
Link:https://commonslibrary.parliament.uk/research-briefings/cdp-2022-0082/

Source snippet

Hall debate on the Computer Misuse Act 1990 - House of Commons LibraryApril 17, 2022 — WESTMINSTER HALL DEBATE ON THE COMPUTER MISUSE ACT...

Published: April 17, 2022

12. Source: youtube.com
Title: UK Hacker extradition to US blocked
Link:https://www.youtube.com/watch?v=Y5jtyps4oaY

Source snippet

Gary McKinnon will not face prosecution in the UK...

13. Source: youtube.com
Title: Hacking for UFOs and fighting for his life: Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

Gary McKinnon wins extradition battle...

14. Source: youtube.com
Title: Gary Mc Kinnon will not face prosecution in the UK
Link:https://www.youtube.com/watch?v=viLcoe_xPMU

Source snippet

Hacking for UFOs: Who is Gary McKinnon?...

15. Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3825/stages/19280/amendments/10016915

16. Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3938/stages/20237/amendments/10027752

17. Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3938/stages/20237/amendments/10027754