Consultation on Unauthorised Access to Online Accounts

The Government has published a call for information in order to explore how better to respond to the unauthorised access to online accounts and personal data.

The Computer Misuse Act 1990 makes it an offense to maliciously access or misuse a computer. It therefore is the main piece of legislation that covers the use of computers to hack into another person’s online accounts.

The nature and number of cybercrimes has increased significantly since 1990, when internet rollout was negligible and there were no social media, online banking or smartphones. It may be that part of the challenge to tackling unauthorised account access, which the Government estimates has increase by 158% since 2020, is outdated legislation.

While the GDPR and other legislation underpin effective information governance by setting out a framework for lawful use – including appropriate security of information – there are few specific penalties for malicious behaviour.

The Government is asking people to tell it about their experience, both as individuals and as businesses. The aim is to understand both the scope of unauthorised access to online accounts through the misuse of computers, and to think about what more can be done to tackle it.

You can take part of the consultation here.