☎ Call Today
Criminal Defense • Frisco, Texas
Serving 9 DFW Counties — Collin • Dallas • Denton • Tarrant • Rockwall • Kaufman • Ellis • Johnson • Hunt — Available 24/7
The L and L Law Group team at our Frisco, Texas office — co-founding partners Reggie London and Njeri London with staff
Our Frisco office●Est. 2011
The L and L Law Group team·Frisco, Texas

Texas electronic data tampering — Penal Code § 33.023

Electronic data tampering under Texas Penal Code § 33.023 makes it a crime to intentionally alter data as it moves between computers, or to plant ransomware, through deception and without a legitimate business purpose. The base offense is a Class C misdemeanor, but once the State proves intent to defraud or harm, the grade climbs a loss-based ladder to a first-degree felony.

Free, Confidential Case Review

Tell us what happened. A defense attorney reviews every submission — usually within an hour, day or night.

24/7 availability — day, night, weekends, holidays. Submitting this form does not create an attorney-client relationship.
Published 2026-07-09 · Reviewed by Reggie London and Njeri London, Co-Founding Partners · Last reviewed: 2026-07-09
Peer Recognition

Martindale-Hubbell® 2026 Honors

Independent peer-review ratings recognizing legal ability and ethical standards.

Martindale-Hubbell Distinguished — Peer Rated for High Professional Achievement 2026 Martindale-Hubbell Client Champion Platinum 2026 Martindale-Hubbell AV Preeminent — Peer Rated for Highest Level of Professional Excellence 2026

Awards reflect peer-reviewed ratings only. Past results do not guarantee future outcomes.

Controlling statute: Tex. Penal Code § 33.023 (Chapter 33 — Computer Crimes)
Classification: Class C misdemeanor base grade; escalates by the aggregate amount involved once the State proves intent to defraud or harm, up to a first-degree felony; a separate, higher track applies where the offense restricts access to privileged or protected information
Punishment range: Fine up to $500 at the base, rising through every misdemeanor and felony class to 5–99 years or life plus a fine up to $10,000 for a first-degree felony (§§ 12.23–12.32)

The controlling statute

Electronic data tampering sits in Chapter 33 of the Texas Penal Code — Computer Crimes — alongside breach of computer security (§ 33.02) and electronic access interference (§ 33.022). The Legislature added § 33.023 in 2017 to reach two kinds of conduct the older statutes did not squarely cover: altering data while it is in motion between machines, and planting ransomware. Two separate offenses are defined:

“A person commits an offense if the person intentionally alters data as it transmits between two computers in a computer network or computer system through deception and without a legitimate business purpose.” — Tex. Penal Code § 33.023(b)
“A person commits an offense if the person intentionally introduces ransomware onto a computer, computer network, or computer system through deception and without a legitimate business purpose.” — Tex. Penal Code § 33.023(c)

Both offenses borrow their vocabulary from § 33.01, the definitions section for the whole chapter. “Data” carries the § 33.01 meaning and expressly includes a computer program. “Ransomware” is defined in § 33.023(a) as a computer contaminant or lock that restricts access to a computer, system, network, or the data on it, under circumstances in which someone demands money, property, or a service to remove the contaminant, restore access, or otherwise undo its effect. Every prosecution therefore turns on three gates the State must clear for each offense: the act was done intentionally, it was done through deception, and it was done without a legitimate business purpose.

What conduct does § 33.023 criminalize?

Section 33.023 targets two distinct scenarios. Subsection (b) is a data-in-transit offense — altering information while it is moving between two machines. Subsection (c) is a ransomware offense — introducing code that locks a system and forces a ransom demand. Neither reaches ordinary, authorized computer use; both require deception and the absence of a legitimate business purpose.

The subsection (b) offense captures classic “man-in-the-middle” conduct: intercepting a transmission between two systems and quietly changing it before it arrives — rewriting the destination account or amount on a wire transfer as it passes between banking systems, editing the contents of a file synchronizing between servers, or swapping a payment address embedded in an invoice email in transit. What the statute punishes is not the interception itself (that is the domain of Chapter 16) but the alteration of the data in motion, accomplished by deception.

The subsection (c) offense is aimed at ransomware. Deploying code that encrypts a hospital’s records or a business’s file server and then demanding cryptocurrency to release it is the paradigm case. Because the definition of ransomware turns on restricting access under a demand for payment, the prosecution must show both the technical lock or contaminant and the extortionate condition attached to it. A researcher who quarantines a suspected malware sample, or an administrator who legitimately restricts access under company policy, is not introducing ransomware “through deception and without a legitimate business purpose.”

Classification & the loss-based punishment ladder

At its floor, electronic data tampering is a Class C misdemeanor — a fine-only offense. It becomes a jailable, and then a felony, offense only when the State proves the accused acted with intent to defraud or harm another and establishes the aggregate amount involved. The higher the proven loss, the higher the grade, exactly as the statute lays out in § 33.023(d-1).

Table 1. Base grade and intent-to-defraud-or-harm ladder — Tex. Penal Code § 33.023(d), (d-1)
Conduct / aggregate amount involvedOffense gradePunishment range
Alter data in transit or introduce ransomware, with no intent to defraud or harm — § 33.023(d)Class C misdemeanorFine up to $500 (§ 12.23)
Intent to defraud or harm; amount less than $100 or cannot be determined — (d-1)(1)Class C misdemeanorFine up to $500 (§ 12.23)
$100 or more but less than $750 — (d-1)(2)Class B misdemeanorUp to 180 days county jail + fine up to $2,000 (§ 12.22)
$750 or more but less than $2,500 — (d-1)(3)Class A misdemeanorUp to 1 year county jail + fine up to $4,000 (§ 12.21)
$2,500 or more but less than $30,000 — (d-1)(4)State jail felony180 days–2 years state jail + fine up to $10,000 (§ 12.35)
$30,000 or more but less than $150,000 — (d-1)(5)Third-degree felony2–10 years TDCJ + fine up to $10,000 (§ 12.34)
$150,000 or more but less than $300,000 — (d-1)(6)Second-degree felony2–20 years TDCJ + fine up to $10,000 (§ 12.33)
$300,000 or more — (d-1)(7)First-degree felony5–99 years or life + fine up to $10,000 (§ 12.32)

A second, higher ladder in § 33.023(d-2) applies where the offense restricts access to privileged or protected information — the situation ransomware most often creates. That track starts at a state jail felony and climbs with both the amount involved and the human harm caused:

Table 2. Restricted-access / privileged-information track — Tex. Penal Code § 33.023(d-2)
Aggregate amount involved or harmOffense gradePunishment range
Less than $2,500State jail felony180 days–2 years state jail + fine up to $10,000 (§ 12.35)
$2,500 or more but less than $30,000, or the conduct causes harm to a client or patientThird-degree felony2–10 years TDCJ + fine up to $10,000 (§ 12.34)
$30,000 or more but less than $150,000, or the conduct causes bodily injurySecond-degree felony2–20 years TDCJ + fine up to $10,000 (§ 12.33)
$150,000 or more, or the conduct causes serious bodily injury or deathFirst-degree felony5–99 years or life + fine up to $10,000 (§ 12.32)
Statute text & ranges last verified2026-07-09, against Tex. Penal Code § 33.023 and Penal Code ch. 12

Because grade — and therefore prison exposure — is driven entirely by two facts (the intent to defraud or harm and the aggregate amount involved), those two facts are where a felony case is usually won or lost. The State must prove the amount beyond a reasonable doubt to reach any felony tier; a shortfall in that proof caps the offense at a misdemeanor.

Elements the State must prove

To convict under § 33.023, the State must prove every element of the charged subsection beyond a reasonable doubt. For the data-alteration offense, those elements break down as follows; the ransomware offense substitutes “introduced ransomware onto a computer, network, or system” for the alteration element.

1. A person — identity and attribution
The State must tie this defendant to the conduct. In computer cases attribution is rarely simple: an IP address identifies a connection, not a person, and shared devices, spoofing, botnets, and compromised accounts all sever the link between a keystroke and a defendant.
2. Intentionally — the culpable mental state
Section 33.023 requires the highest culpable mental state, acting intentionally (§ 6.03(a)) — a conscious objective to alter the data or introduce the ransomware. An accidental change, an automated process, or a good-faith troubleshooting step does not satisfy this element.
3. Alters data as it transmits between two computers (or introduces ransomware)
For subsection (b), the data must be altered while it transmits between two computers in a network or system — data at rest on a single device is a different question. For subsection (c), the act is introducing a qualifying ransomware contaminant or lock. “Data,” “computer,” “computer network,” and “computer system” all carry their § 33.01 definitions.
4. Through deception
The conduct must be accomplished by deception. Chapter 33 does not separately define the word, so jurors give it its ordinary meaning, informed by how the Penal Code uses “deception” elsewhere (for example, in the theft definition at § 31.01(1)). Open, disclosed, or consented-to conduct is not deceptive.
5. Without a legitimate business purpose
This is a distinct element, not an afterthought. Authorized penetration testing under contract, network administration within an employee’s scope, security research, and vendor maintenance all supply a legitimate business purpose the State must negate.
6. For felony grades: intent to defraud or harm + the aggregate amount
To lift the offense off its Class C floor, the State must additionally prove the accused acted with intent to defraud or harm another (§ 33.023(d-1)) and prove the aggregate amount involved that sets the tier. “Harm” and “benefit” carry their § 1.07 meanings.

How § 33.023 differs from § 33.02 and § 33.022

Chapter 33 holds a cluster of computer crimes that are easy to conflate but legally distinct. Charging documents sometimes pile them together, so it matters which statute actually fits the alleged conduct. The three core offenses divide cleanly by what the accused is said to have done.

Breach of Computer Security — § 33.02
Punishes unauthorized access: knowingly accessing a computer, network, or system without the effective consent of the owner. The wrong is getting in without permission — not what happens to the data afterward.
Electronic Access Interference — § 33.022
Punishes denial of access: intentionally interrupting or suspending another’s access to a computer system or network without consent — the denial-of-service lane. The wrong is knocking a legitimate user offline.
Electronic Data Tampering — § 33.023 (this page)
Punishes altering data in transit or planting ransomware, through deception and without a legitimate business purpose. The wrong is corrupting data on the move or locking a system for ransom — not merely getting in (§ 33.02) or shutting others out (§ 33.022).

The practical point for a defense is that the State does not get to treat these as interchangeable. If the evidence shows an unauthorized login but no altered data and no ransomware, § 33.023 does not fit — whatever else might. Keeping § 33.023 in its own lane (data alteration and ransomware) can narrow or defeat a count that was charged by reflex.

How Texas courts have interpreted § 33.023

Section 33.023 is new — enacted in 2017 — and no published Texas opinion has yet construed it directly. But it is not written on a blank slate: it incorporates Chapter 33’s shared definitions in § 33.01 and the Penal Code’s culpable-mental-state framework, both of which the courts have interpreted at length under the sibling statute § 33.02. Those decisions map the ground a § 33.023 case will be fought on.

The mental state reaches the wrongfulness, not just the act. In Muhammed v. State, the Fourteenth Court of Appeals held that under Chapter 33 the State must prove the defendant “knowingly accessed a computer, computer network, or computer system, knowing that this act was without the effective consent of the owner” — the culpable mental state attaches to both the conduct and the element that makes it wrongful.1 Translated to § 33.023, which demands the still-higher “intentionally” plus deception and the absence of a legitimate business purpose, the State cannot convict merely by showing that data changed or that a system locked; it must prove the defendant’s culpable state of mind as to the deception and wrongfulness. The court also confirmed that a culpable mental state “almost invariably depends upon circumstantial evidence” — cutting both ways, and opening the intent element to attack.

“Access” already includes altering data — and “consent” is the battleground. In Thomas v. State, the same court explained that a person “accesses” a computer under § 33.01(1) by, among other things, “altering data or computer software in” it, and reaffirmed that Chapter 33’s mental state applies to both the access and the effective-consent elements.2 The court read “consent” through § 1.07(a)(11) as “assent in fact, whether express or apparent,” and held that no offense occurred because the person who accessed the phone did not know she lacked consent. For a § 33.023 defense, the decision underscores that authorization, apparent consent, and the defendant’s understanding of it are litigable facts, not foregone conclusions.

The device must actually be a statutory “computer.” In Salinas v. State, the Thirteenth Court of Appeals held that a standalone thumb drive is not a “computer” under § 33.01(4) because it does not perform high-speed data processing and was not connected to a qualifying device when it was accessed.3 The holding matters because § 33.023 is built entirely on the § 33.01 definitions of “computer,” “computer network,” and “computer system.” If the hardware or system at issue does not meet those definitions, the statute does not apply — a threshold the defense can force the State to prove.

A value-graded intent element demands real proof, not inference from the bare act. Section 33.023’s felony tiers turn on an “intent to defraud or harm” another and on the aggregate amount involved. On how demanding Texas courts are about that kind of proof, Lee v. State is instructive by analogy. There, reviewing an abuse-of-official-capacity conviction that likewise required an intent to obtain a benefit or to harm, the Eastland Court of Appeals reversed and rendered an acquittal because the State never established a “nexus” between the defendant’s access to confidential information and any economic gain or disadvantage; the “mere act” of accessing private data did not, by itself, prove intent to harm.4 The Penal Code’s definitions of “benefit” (§ 1.07(a)(7)) and “harm” (§ 1.07(a)(25)) that the court applied are the same ones that govern § 33.023’s felony grading — a reminder that the State must connect the conduct to a concrete intended loss or gain, not simply point at a computer.

  1. Muhammed v. State, 331 S.W.3d 187 (Tex. App.—Houston [14th Dist.] 2011, pet. ref’d). ↩
  2. Thomas v. State, No. 14-16-00666-CR (Tex. App.—Houston [14th Dist.] Oct. 3, 2017, no pet.) (mem. op., not designated for publication) (companion case No. 14-16-00665-CR). ↩
  3. Salinas v. State, No. 13-19-00504-CR (Tex. App.—Corpus Christi–Edinburg May 13, 2021, pet. ref’d). ↩
  4. Lee v. State, 676 S.W.3d 912 (Tex. App.—Eastland 2023, no pet.) (construing abuse of official capacity, § 39.02; cited by analogy for the intent-to-harm-or-defraud and value elements). ↩

Defense strategies

Because § 33.023 is stacked with elements the State must independently prove — intentional conduct, deception, the absence of a legitimate business purpose, and, for any felony, an intent to defraud or harm plus a provable loss — a defense usually attacks the weakest link rather than the whole chain. L and L Law Group builds § 33.023 defenses around the statute’s own limits and the Chapter 33 case law above. See our criminal defense strategies hub for the broader toolkit.

Ransomware, privileged data & collateral consequences

Ransomware cases occupy the most dangerous corner of § 33.023. When the code restricts access to privileged or protected information — medical records, client files — the § 33.023(d-2) track applies, and the grade can climb on human harm as well as dollars, reaching a first-degree felony where the conduct causes serious bodily injury or death. Beyond the sentence, the collateral consequences are severe.

After a computer-crime arrest in Collin, Dallas, Denton, or Tarrant County

Electronic-data-tampering investigations are digital-evidence cases from the outset — built on device images, server logs, and network captures. If you are contacted by investigators or arrested in the North Texas counties we serve, what you do in the first days shapes the case. Two steps protect you more than any other.

First, do not consent to a search of your devices or accounts and do not try to explain your way out in an interview — forensic access and any statement you give become the State’s exhibits. Second, preserve everything: authorization emails, contracts, scope documents, and logs that show a legitimate business purpose or the absence of deception are often the heart of the defense. L and L Law Group defends § 33.023 and related Chapter 33 charges in Collin, Dallas, Denton, and Tarrant counties. Call (972) 370-5060 for a free, confidential consultation.

Key legal terms

Ransomware
A computer contaminant or lock that restricts access to a computer, system, network, or its data under circumstances in which a person demands money, property, or a service to remove it or restore access. Tex. Penal Code § 33.023(a).
Computer
An electronic, magnetic, optical, electrochemical, or other high-speed data-processing device that performs logical, arithmetic, or memory functions, including connected input, output, processing, storage, or communication facilities. Tex. Penal Code § 33.01(4).
Aggregate amount involved
The total value the State must prove to set a felony grade under § 33.023(d-1) or (d-2). It is a fact the prosecution must establish beyond a reasonable doubt; failure to prove it caps the offense at a lower grade.
Legitimate business purpose
A statutory element the conduct must lack. Authorized testing, administration, research, and maintenance supply a legitimate business purpose that the State must negate to obtain a conviction.

Electronic Data Tampering FAQ

Is electronic data tampering a felony in Texas?
Not always. Under Penal Code § 33.023 the base offense is a Class C misdemeanor. It becomes a felony only when the State proves the accused acted with intent to defraud or harm another and proves the aggregate amount involved. At $2,500 it is a state jail felony, and it climbs to a first-degree felony at $300,000 or more. A separate, higher track applies when the offense restricts access to privileged data.
How is § 33.023 different from hacking under § 33.02?
Breach of computer security (§ 33.02) punishes unauthorized access — getting into a computer or network without the owner’s effective consent. Electronic data tampering (§ 33.023) punishes what happens to the data: altering it while it moves between machines, or planting ransomware, through deception and without a legitimate business purpose. Access alone, with no altered data and no ransomware, does not fit § 33.023.
Is deploying ransomware charged under this statute?
Yes. Subsection (c) makes it an offense to intentionally introduce ransomware onto a computer, network, or system through deception and without a legitimate business purpose. “Ransomware” is defined as a contaminant or lock that restricts access under a demand for money, property, or a service. The same conduct frequently draws parallel federal charges under the Computer Fraud and Abuse Act.
Can a security researcher or penetration tester be charged?
The statute requires both deception and the absence of a legitimate business purpose. Authorized penetration testing under contract, sanctioned research, and administration within an employee’s scope supply a legitimate business purpose the State must negate. Disputes usually turn on the scope of authorization — which is exactly why written scope documents and authorization emails are critical to preserve.
How does the State decide the felony level?
The grade is loss-driven. Once intent to defraud or harm is shown, § 33.023(d-1) sets the class by the aggregate amount involved — misdemeanors below $2,500, a state jail felony at $2,500, and rising to a first-degree felony at $300,000. Because the amount must be proven beyond a reasonable doubt, contesting valuation and aggregation can lower the grade.
What does “alters data as it transmits between two computers” mean?
Subsection (b) targets changing data while it is in motion between machines — a “man-in-the-middle” alteration, such as rewriting a wire transfer’s amount or destination as it passes between banking systems. It does not reach data sitting at rest on a single device; that scenario, if criminal at all, falls under a different statute. This distinction is often a live defense issue.
Is § 33.023 the same as electronic access interference (§ 33.022)?
No. Electronic access interference (§ 33.022) punishes denying or interrupting someone’s access to a system — the denial-of-service lane. Electronic data tampering (§ 33.023) punishes altering data in transit or introducing ransomware. Both live in Chapter 33 and can be charged together, but they target different wrongs, and evidence supporting one does not automatically support the other.
Can federal charges apply to the same conduct?
Often, yes. Computer intrusions, data alteration, and ransomware frequently cross state lines and implicate the federal Computer Fraud and Abuse Act (18 U.S.C. § 1030) and wire-fraud statutes, which can carry heavier penalties. When both sovereigns are involved, the defense has to be coordinated across the state and federal cases from the start.
What should I do if I am under investigation for a computer crime?
Do not consent to a search of your devices or accounts, and do not give a “quick explanation” to investigators — both become evidence. Preserve authorization emails, contracts, scope documents, and logs that show a legitimate purpose or the absence of deception, and contact a defense lawyer before speaking with anyone. Call L and L Law Group at (972) 370-5060.

References & Authoritative Sources

  1. Tex. Penal Code § 33.023 — Electronic Data Tampering
  2. Tex. Penal Code § 33.01 — Definitions (computer, data, access)
  3. Tex. Penal Code § 33.02 — Breach of Computer Security
  4. Tex. Penal Code § 33.022 — Electronic Access Interference
  5. Tex. Penal Code § 1.07 — Definitions (benefit, harm)
  6. Tex. Penal Code ch. 12 — Punishments
  7. Muhammed v. State, 331 S.W.3d 187 (Tex. App.—Houston [14th Dist.] 2011, pet. ref’d)
  8. Thomas v. State, No. 14-16-00666-CR (Tex. App.—Houston [14th Dist.] Oct. 3, 2017, no pet.) (mem. op.)
  9. Salinas v. State, No. 13-19-00504-CR (Tex. App.—Corpus Christi–Edinburg May 13, 2021, pet. ref’d)
  10. Lee v. State, 676 S.W.3d 912 (Tex. App.—Eastland 2023, no pet.)
  11. Texas Courts · Texas State Law Library

About the Authors

Reggie London

Co-Founding Partner · Texas Bar No. 24043514

Reggie London co-founded L and L Law Group with a focus on federal criminal defense, complex felony defense, and computer-crime matters. Licensed in Texas, admitted to the Northern and Eastern Districts of Texas.

Njeri London

Co-Founding Partner · Texas Bar No. 24043266

Njeri London co-founded L and L Law Group with a focus on felony defense, family violence cases, and juvenile defense. Licensed in Texas, admitted to the Northern and Eastern Districts of Texas.

Charged with electronic data tampering? Talk to L and L Law Group.

Co-founding partners Reggie London and Njeri London ensure attorney-level review at every stage. Free, confidential consultation. Frisco, Texas.

Call (972) 370-5060

Service Areas

L&L Law Group represents clients across North Texas counties for DWI, assault, drug crimes, juvenile defense, outstanding warrants, bond reduction, and expunction matters.

Call Email Map Top
developed by MPR Digital Legal Services