Within Motive and Law
When Does Curiosity Become a Computer Crime?
A hacker's curiosity may explain the motive, but liability turns on deliberate access that the person knew was not authorised.
On this page
- What the law means by unauthorised access
- Why motive and legal intent are different
- How deliberate exploration can satisfy the offence
Page outline Jump by section
Introduction
Curiosity can explain why someone accessed a computer system, but under UK law it rarely determines whether a criminal offence has been committed. In the context of curiosity-driven hacking, including cases such as Gary McKinnon’s claimed search for evidence of UFOs and advanced technology, the key legal question is usually much narrower: did the person deliberately obtain access to computer material while knowing they were not authorised to do so? The answer focuses on permission rather than purpose. A person motivated by fascination, conspiracy theories or a desire to investigate can still satisfy the legal elements of unauthorised access if they intentionally cross a known access boundary.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
Understanding this distinction helps explain why courts separate a defendant’s motive from the legal mechanism of the offence. Curiosity may influence public opinion or, in some cases, sentencing, but it does not normally convert unauthorised exploration into lawful investigation.
What the Law Means by Unauthorised Access
The foundation of UK computer hacking law is section 1 of the Computer Misuse Act 1990. The offence is committed when a person intentionally causes a computer to perform a function in order to obtain access to programs or data, knowing that the access is unauthorised. The prosecution does not have to prove financial gain, espionage, sabotage or any wider criminal objective.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
This produces an important legal consequence: the offence is complete because of the deliberate breach of permission, not because of what the person hoped to discover afterwards.
Several practical points follow from the legislation:
- Permission must come from someone entitled to grant it.
- The defendant must know, or realise, that the intended access is outside that permission.
- The intended target need not be a particular file or document. Someone who enters a protected system “to see what is there” can still satisfy the statutory intent requirement.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
The Crown Prosecution Service notes that section 1 was deliberately drafted broadly enough to cover hackers who enter systems without any precise idea of what information they expect to find. Curiosity therefore does not prevent the necessary intent from existing.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
Why Motive and Legal Intent Are Different
One of the most common misunderstandings is to confuse motive with intent.
A motive answers the question:
- Why did the person want access?
Examples include:
- searching for evidence of UFOs;
- testing a personal theory;
- intellectual curiosity;
- political activism;
- financial gain.
Legal intent answers a different question:
- Did the person deliberately try to obtain access they knew they were not allowed to obtain?
The law treats these as separate issues. A defendant who honestly believed they were exposing hidden truths may still intentionally access a protected computer without permission. Conversely, someone acting for profit but never obtaining or attempting unauthorised access would not commit the section 1 offence simply because of their motive.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
This distinction explains why defendants sometimes acknowledge entering systems while continuing to argue that their reasons were honourable. Their explanation may be relevant to sentencing or public debate, but it does not normally alter whether the statutory elements of unauthorised access have been proved.
How Deliberate Exploration Can Satisfy the Offence
Curiosity-driven hacking often develops through a series of conscious decisions rather than a single dramatic act.
A typical progression might involve:
- Discovering a vulnerable system.
- Choosing to exploit the weakness.
- Entering protected areas without permission.
- Continuing to browse directories, files or network resources.
- Repeating the process across additional computers.
The legal significance lies less in the person’s emotional motivation than in the repeated choice to continue accessing systems after recognising that permission is absent.
The CPS guidance also emphasises that the offence requires knowledge that the access is unauthorised rather than mere carelessness or accident. An accidental connection, a mistyped address or exposure to publicly accessible information is different from intentionally bypassing authentication or continuing to explore after recognising that the system is restricted.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
The Importance of Knowing the Limits of Permission
Unauthorised access is not confined to outsiders breaking into networks. The Computer Misuse Act can also apply where someone exceeds the authority they already possess.
For example, an employee may legitimately access some databases but deliberately retrieve information from systems they know fall outside their authorised role. The House of Lords confirmed that the offence can apply where an individual intentionally accesses data they know they are not entitled to see, even if they have valid credentials for other parts of the organisation. Whether permission existed depends on the actual limits placed on that person’s authority.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
This illustrates that authorisation is not an all-or-nothing concept. Having some access rights does not automatically authorise every form of exploration.
Gary McKinnon as an Illustration of the Principle
Gary McKinnon’s case is frequently discussed because his stated objective differed from conventional cybercrime. He maintained that he was searching United States government computers for evidence relating to UFOs, advanced propulsion technology and alleged official secrecy rather than attempting financial fraud.
From the perspective of UK computer misuse law, however, the central mechanism remains straightforward. If a person knowingly accesses protected systems without permission, the offence concerns the lack of authorisation rather than the unusual nature of the search. His asserted curiosity helps explain the alleged motive but does not itself create legal authority to enter military or government networks.
For this reason, McKinnon’s case is often cited when explaining that sincere belief, unconventional research interests or perceived public benefit do not automatically negate liability for deliberate unauthorised access.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
Where Curiosity Ends and Criminal Liability Begins
The practical dividing line is usually permission rather than personal motivation.
Curiosity remains lawful when someone:
- examines information intentionally made public;
- conducts authorised security testing;
- works within the scope of explicit permission; or
- responsibly reports vulnerabilities discovered without deliberately exploiting them.
The legal risk increases when someone knowingly moves beyond those boundaries by bypassing authentication, using credentials without authority, exploring protected systems or continuing to access data after recognising that permission is absent.
In that sense, curiosity becomes unauthorised computer access not because curiosity itself is unlawful, but because it motivates deliberate conduct that crosses a recognised legal boundary. Under the Computer Misuse Act, the decisive question is not why the individual wanted to look, but whether they knowingly chose to enter a computer system they were not authorised to access.[Crown Prosecution Service]cps.gov.ukCrown Prosecution Service Computer Misuse Act | The Crown Prosecution ServiceCrown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023…
Amazon book picks
Further Reading
Books and field guides related to When Does Curiosity Become a Computer Crime?. Use these as the next step if you want deeper reading beyond the article.
The Hacker and the State
Rating: 5.0/5 from 18 Google Books ratings
“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...
Computer Crimes and Digital Investigations
A comprehensive and detailed legal analysis of the criminal conduct, investigation, and prosecution of cybercrime, the second edition of...
Cybercrime and the Law: Challenges, Issues, and Outcomes
The first full-scale overview of cybercrime, law, and policy
The Hacker and the State: Cyber Attacks and the New Normal of...
Rating: 5.0/5 from 18 Google Books ratings
“A must-read...It reveals important truths.” —Vint Cerf, Internet pioneer “One of the finest books on information security published so f...
eBay marketplace picks
Marketplace Samples
Live-tested eBay searches with available results related to this page.
Selected fromcomputer security sign oneBay.co.uk.
Endnotes
1.
Source: cps.gov.uk
Title: Crown Prosecution Service Computer Misuse Act | The Crown Prosecution Service
Link:https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act
Source snippet
Crown Prosecution ServiceComputer Misuse Act | The Crown Prosecution ServiceAugust 3, 2023...
Published: August 3, 2023
2.
Source: cps.gov.uk
Title: Crown Prosecution Service Cybercrime
Link:https://www.cps.gov.uk/prosecution-guidance/cybercrime-prosecution-guidance
Source snippet
Cybercrime - prosecution guidance | The Crown Prosecution ServiceMay 1, 2018 — CYBERCRIME - PROSECUTION GUIDANCE 01 May 2018 Updated: 26...
Published: May 1, 2018
3.
Source: health-ni.gov.uk
Title: computer misuse act 1990
Link:https://www.health-ni.gov.uk/articles/computer-misuse-act-1990
Source snippet
The Computer Misuse Act 1990 | Department of HealthAugust 28, 2015 — THE COMPUTER MISUSE ACT 1990 Topics: * Good management, good records...
Published: August 28, 2015
4.
Source: cps.gov.uk
Link:https://www.cps.gov.uk/prosecution-guidance/prosecution-guidance-search?subject_area=2344
Source snippet
Prosecution guidance search | The Crown Prosecution ServicePROSECUTION GUIDANCE SEARCH DISPLAYING 1 - 4 OF 4 RESULTS FOR SUBJECT AREA "CO...
5.
Source: legislation.uk
Title: computer misuse act 1990
Link:https://legislation.uk/computer-misuse-act-1990
6.
Source: nationalcrimeagency.gov.uk
Title: Cyber Choices Ransomeware
Link:https://www.nationalcrimeagency.gov.uk/cyber-choices-ransomware
7.
Source: southeastcyber.police.uk
Title: computer misuse act
Link:https://southeastcyber.police.uk/computer-misuse-act/
8.
Source: youtube.com
Title: Gary Mc Kinnon wins extradition battle
Link:https://www.youtube.com/watch?v=y4lecD44F5E
Source snippet
Computer Misuse Act...
9.
Source: youtube.com
Title: Computer Misuse Act
Link:https://www.youtube.com/watch?v=ws4CrncWEwE
Source snippet
UK Hacker extradition to US blocked...
Additional References
10.
Source: legalclarity.org
Title: computer misuse act 1990 offences penalties and defences
Link:https://legalclarity.org/computer-misuse-act-1990-offences-penalties-and-defences/
Source snippet
Computer Misuse Act 1990: Offences, Penalties and Defences - LegalClarityMay 13, 2026 — COMPUTER MISUSE ACT 1990: OFFENCES, PENALTIES AND...
Published: May 13, 2026
11.
Source: commonslibrary.parliament.uk
Title: cdp 2022 0082
Link:https://commonslibrary.parliament.uk/research-briefings/cdp-2022-0082/
Source snippet
Hall debate on the Computer Misuse Act 1990 - House of Commons LibraryApril 17, 2022 — WESTMINSTER HALL DEBATE ON THE COMPUTER MISUSE ACT...
Published: April 17, 2022
12.
Source: youtube.com
Title: UK Hacker extradition to US blocked
Link:https://www.youtube.com/watch?v=Y5jtyps4oaY
Source snippet
Gary McKinnon will not face prosecution in the UK...
13.
Source: youtube.com
Title: Hacking for UFOs and fighting for his life: Who is Gary Mc Kinnon?
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ
Source snippet
Gary McKinnon wins extradition battle...
14.
Source: youtube.com
Title: Gary Mc Kinnon will not face prosecution in the UK
Link:https://www.youtube.com/watch?v=viLcoe_xPMU
Source snippet
Hacking for UFOs: Who is Gary McKinnon?...
15.
Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3825/stages/19280/amendments/10016915
16.
Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3938/stages/20237/amendments/10027752
17.
Source: bills.parliament.uk
Link:https://bills.parliament.uk/bills/3938/stages/20237/amendments/10027754



