Photo by Zulfugar Karimov on Unsplash
The Common Belief
$5,000. That is the entire hinge on which a federal computer-crime case can swing — and as of August 10, 2026, American courts still cannot agree on how to count to it.
The common belief among IT leaders is that if an insider walks out with your customer database, the Computer Fraud and Abuse Act is a straightforward hammer: prove the theft, prove the harm, collect. According to Google News coverage of the issue via Security Boulevard, the reality is considerably messier. The statute's damages threshold — the number that determines whether you can sue at all — depends on a definition of "loss" that federal circuits have read in materially different ways for years.
The practical consequence, and the thesis of this post: your legal position under the CFAA is decided less by what the threat actor did than by what your incident response team wrote down in the first 72 hours.
The Evidence: What the Statute Actually Says
The CFAA, 18 U.S.C. § 1030, was enacted in 1986 as the primary U.S. anti-hacking law. Buried in its definitions section, at § 1030(e)(11), is the operative language. Per the Cornell Legal Information Institute's publication of the statutory text, "loss" means "any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service."
Read it slowly and you find five distinct categories of harm: response costs, damage assessment costs, restoration costs, lost revenue, and consequential damages from interruption of service. Under § 1030(c)(4)(A)(i)(I) — and for many civil actions brought under § 1030(g) — those categories must aggregate to at least $5,000 within a one-year period.
Here is where the courts diverge. One reading, the narrow or data-focused one, treats the first three categories as the real content of "loss" and treats the last two as available only when there was an actual interruption of service. Under that view, an employee who quietly copies a file and emails it to a competitor has caused zero qualifying loss, because nothing was impaired, nothing went down, and nothing needed restoring. The broader reading permits business harm — lost revenue, the value of misappropriated data — to count toward the threshold. Same facts. Opposite outcome. The determining variable is the courthouse.
Where the Math Breaks Down for a Mid-Size Company
Run the arithmetic that the surface reporting skips.
Suppose a departing sales engineer exfiltrates a pricing database. Under the narrow reading, your recoverable loss is limited to what it cost to respond and assess: forensic imaging of the endpoint, a review of access logs, an outside consultant's damage assessment. At a typical blended rate for incident response work, clearing $5,000 requires roughly 20 to 30 billable hours of investigation — which a competent internal team might complete in two days, at an internal labor cost that a defense attorney will argue was going to be paid anyway. That is the trap. A fast, efficient, well-run response can leave you below the statutory floor, while a sloppy one clears it easily.
Now flip to the broad reading. The same incident, with the misappropriated data's commercial value in play, blows past $5,000 before the forensic examiner opens a case file.
So the effective "cost of a breach" under the CFAA is not one number — it is a range whose width is set entirely by the circuit. Below is the shape of that divergence for a single hypothetical insider-copy incident with no service interruption.
Chart: The § 1030(e)(11) definition lists five categories of harm. Narrow-reading courts effectively make only the three impairment-linked categories (response, assessment, restoration) available absent an interruption of service; broader-reading courts allow all five. Same incident, different denominator.
A careful skeptic will push back here, and the pushback is fair: doesn't the Supreme Court's 2021 ruling settle this? It does not. Van Buren v. United States was decided 6–3 on June 3, 2021, and it narrowed what "exceeds authorized access" means — curbing prosecutions built on mere policy violations. It reframed the authorization question. It did not touch the loss element. Lower courts have been left to keep interpreting § 1030(e)(11) on their own, which is precisely why the split persists five years on. The related hiQ Labs v. LinkedIn litigation raised the same family of questions around scraping publicly available data, again on the authorization axis rather than the damages axis.
The Defense Stack: Three Layers, and the Legal One Comes Last
The instinct is to treat this as a lawyer's problem. Our read is the opposite: the CFAA loss question is a documentation problem that lands squarely on the security team, and the legal layer only works if the first two layers did their job.
Layer one — technical control: log the access, not just the login. The narrow reading rewards organizations that can prove impairment or reconstruct exactly what was touched. That means file-level and database-level access logging with sufficient retention, not just authentication events. If your telemetry can only tell a court that someone logged in, you have handed the defense the argument that no measurable harm occurred. Data protection here is evidentiary as much as preventive.
Layer two — process: cost-code your incident response. This is the control most teams skip, and it is the one that decides cases. Every hour of forensic work, every consultant invoice, every damage assessment should be tracked against a named incident number from the moment the case opens. Not reconstructed six months later from memory when counsel asks. Contemporaneous cost records are what convert a response into a documented, defensible "reasonable cost to a victim" under the statute. A well-run incident response program that also happens to keep a clean ledger clears the $5,000 threshold with evidence rather than estimation.
Layer three — people: security awareness aimed at offboarding. The CFAA is invoked in civil disputes over employee data theft and trade-secret misappropriation far more often than in dramatic criminal hacking cases. The blast radius of an insider-access dispute is usually contained to one departing employee, one dataset, and one competitor — but the legal exposure runs in both directions. Reform advocates have long argued that the vague damages threshold lets the statute reach ordinary contractual and employment disputes, which means your own organization can end up on the receiving end of a stretched CFAA claim. Offboarding training and clear acceptable-use documentation cut both ways.
The AI Angle: Automated Access Makes the Ambiguity Expensive
As AI systems increasingly scrape data and automate access to computer systems at machine speed, disputes over unauthorized access and quantifiable loss are positioned to multiply — and the loss definition is what determines whether any of them are actionable. An agent that pulls 40,000 records over a weekend causes no interruption of service and impairs nothing; under a narrow reading, the victim may have no qualifying loss at all despite an obvious commercial harm. This is the same governance gap that AI Agents Weekly examined in Rubrik's agent-identity approach — if you cannot attribute a tool call to an identity, you cannot document what it accessed, and you cannot price the harm. Threat intelligence platforms and UEBA tooling (user and entity behavior analytics — software that flags abnormal access patterns rather than known-bad signatures) are increasingly the only source of the granular access record a loss calculation requires.
Harden This Today
Ship one control: add an incident cost field to your IR ticket template.
Not a policy rewrite, not a 30-item checklist. A single required field in whatever system tracks your incidents — hours spent, hourly rate, vendor invoices, assessment costs — populated as the response happens. It takes an afternoon to configure. It is the difference between telling a court "we spent about a week on this" and handing it a contemporaneous ledger that satisfies three of the five statutory loss categories on its own.
On balance, our analysis is that the split will not resolve soon. Van Buren showed the Court is willing to narrow the CFAA when the question is squarely presented, but the loss element has not reached it, and Congress has shown no appetite for amending a 40-year-old statute. The more likely outcome is continued forum-shopping and unpredictable results — which makes organizational documentation, not case law, the variable you can actually control. Cybersecurity best practices and legal preparedness converged on this point some time ago; most teams just haven't noticed.
Frequently Asked Questions
Does my company need $5,000 in losses to sue under the Computer Fraud and Abuse Act?
For many civil claims brought under 18 U.S.C. § 1030(g), and for certain felony charges under § 1030(a)(5), yes — the statute requires aggregate loss of at least $5,000 in a one-year period, per § 1030(c)(4)(A)(i)(I). Whether your specific costs count toward that total depends on which of the five § 1030(e)(11) categories your jurisdiction recognizes absent a service interruption. Consult counsel in your circuit.
What incident response costs count as CFAA loss?
The statute names response costs, damage assessment costs, restoration costs, lost revenue, and consequential damages from interruption of service. Courts consistently accept the first three when tied to investigating or repairing the incident. The last two are contested where no service interruption occurred — that is the heart of the current split.
Did Van Buren v. United States change how courts calculate CFAA loss?
No. The 6–3 decision issued June 3, 2021 addressed the "exceeds authorized access" clause, limiting prosecutions premised on violating an employer's usage policy. It reframed the authorization analysis but did not resolve the definition of loss, so lower courts continue to interpret § 1030(e)(11) independently.
How should we document a suspected insider data theft to preserve a CFAA claim?
Open a numbered incident record immediately, preserve endpoint and access logs before any reimaging, and track every hour and invoice against that record from day one. Contemporaneous cost documentation is far more persuasive than a reconstructed estimate, and it is the single most controllable factor in whether you clear the threshold.
Disclaimer: This article is editorial commentary for informational purposes only and does not constitute legal advice or professional security consulting advice. It reflects analysis of publicly reported facts and primary statutory sources, not independent legal or product testing. Always consult a qualified attorney and cybersecurity professional for your specific situation. Research based on publicly available sources current as of August 10, 2026.