What is breach of computer security under Texas law?
Breach of computer security is Texas’s general computer-intrusion crime. Under § 33.02(a), a person commits the offense by knowingly accessing a computer, computer network, or computer system without the effective consent of the owner. "Access" under § 33.01(1) is broad — no malware or password-cracking is required.
What surprises most clients is how little it takes to satisfy "access." The definition in § 33.01(1) reaches approaching, instructing, communicating with, storing data in, retrieving or intercepting data from, altering software in, or otherwise making use of any computer resource. Opening a folder, reading an email, running a database query, or logging into a cloud account all count. No malware, no password-cracking, no "hacking" in the Hollywood sense is required.
Because the conduct line is so low, the cases that get charged almost never look like cyberattacks. They look like a fired employee who downloaded a file over the weekend, a spouse who read text messages during a divorce, a business partner who pulled records off a shared server after a falling-out, or an IT contractor who went one step past the scope of work. In each of those, the access plainly happened. The defense is rarely "I didn’t touch it" — it is "I had permission" or "I didn’t know I didn’t." That is why the consent element, not the access element, is where these cases are decided.
- Knowing access — § 33.02(a)
- The accused must knowingly access a computer resource as § 33.01(1) defines it. An automated sync, a background app, or an accidental click is not knowing access. The "knowing" mental state is the starting point, and under Muhammed v. State it extends past the act to the absence of consent.
- A computer, network, or system — § 33.01
- The thing accessed must meet the § 33.01 definitions, which cover servers, laptops, phones, email and cloud accounts, point-of-sale terminals, and connected devices. The breadth of the definition means almost any digital device or account falls within the statute.
- Without the owner’s effective consent — § 33.01(12)
- No authorized person gave valid permission, or the permission failed one of the five § 33.01(12) tests. Consent is the heart of the offense and the most heavily contested element. Possessing valid credentials is not the same as having effective consent for the use actually made of them.
- Knowledge that consent was absent
- This is the element that wins cases. Texas courts have held the "knowing" mental state attaches to the consent, not just the act. In Muhammed v. State, 331 S.W.3d 187, 192 (Tex. App.—Houston [14th Dist.] 2011, pet. ref’d), the court held the State must prove the defendant knowingly accessed a computer knowing that the access was without the effective consent of the owner. A genuine, even mistaken, belief that access was allowed defeats the charge.
A § 33.02 case is rarely about whether a keystroke occurred — it is about authorization and the defendant’s state of mind. The State frequently overcharges by treating a departing employee’s file export, or a family member’s use of a shared password, as a felony intrusion when the consent picture is far murkier than the charging instrument suggests. Each of those is a fact-bound question, and each gives the defense room to argue for acquittal, charge reduction, declination, or a civil-side resolution.
The grade is not a footnote. The same conduct can be a fine-only Class C misdemeanor or a first-degree felony depending entirely on the number the State attaches to it and on whether identity information or a government system is involved. That is why the consent fight and the loss-amount audit run in parallel from the moment of retention.
The real fight: what does "effective consent" mean?
Consent is the heart of a § 33.02 case, and it is more technical than it sounds. Under § 33.01(12), "effective consent" means consent by the owner or by a person legally authorized to act for the owner — but that consent is stripped away in five specific situations.
Consent is the heart of a § 33.02 case, and it is more technical than it sounds. Under § 33.01(12), "effective consent" means consent by the owner or by a person legally authorized to act for the owner — but that consent is stripped away in five situations:
- consent induced by deception or coercion;
- consent given by a person the actor knows is not legally authorized to act for the owner;
- consent given by someone who, because of youth, mental disease or defect, or intoxication, cannot make a reasonable decision;
- consent given solely to detect the commission of an offense; or
- consent used for a purpose other than that for which the consent was given.
That last clause — § 33.01(12)(E) — is the one prosecutors lean on hardest, and the one we most often have to dismantle. It means a person can start with real permission and lose it by stepping outside the original purpose. A spouse who was given a password to pay household bills, and who then logs in to copy messages for a custody fight, may be accused of using consent for a different purpose. An employee allowed into a CRM to service customers, who exports the whole client list on the way out the door, faces the same theory. The defense response is to nail down precisely what the owner authorized, when, and for what — usually from emails, onboarding documents, text messages, and company policy — because a vague or generous original grant of access defeats the State’s "different purpose" argument.
Scope is therefore proven on documents, not memory. Where the owner’s grant of access was broad or never clearly limited, the State’s § 33.01(12)(E) theory collapses — there is no second purpose to point to. The earliest defense work is the collection and preservation of every record that shows what permission existed: onboarding paperwork, IT provisioning logs, acceptable-use policies, prior practice, and the messages exchanged at the time access was granted.
What must the State prove?
For the base offense under § 33.02(a), the State must prove knowing access, a computer or network or system, the absence of the owner’s effective consent, and — critically — that the defendant knew consent was absent when the access happened.
For the base offense under § 33.02(a), the State must prove each element beyond a reasonable doubt:
- 1. Knowing access
- The accused knowingly accessed a computer resource as § 33.01(1) defines it. An automated sync, a background app, or an accidental click is not knowing access.
- 2. A computer, network, or system
- The thing accessed must meet the § 33.01 definitions, which cover servers, laptops, phones, email and cloud accounts, point-of-sale terminals, and connected devices.
- 3. Without the owner’s effective consent
- No authorized person gave valid permission, or the permission failed one of the five § 33.01(12) tests above.
- 4. Knowledge that consent was absent
- This is the element that wins cases. In Muhammed v. State, 331 S.W.3d 187, 192 (Tex. App.—Houston [14th Dist.] 2011, pet. ref’d), the court held the State must prove the defendant "knowingly accessed a computer… knowing that this act was without the effective consent of the owner." A genuine, even mistaken, belief that access was allowed defeats the charge.
The Tenth Court of Appeals reaffirmed and applied that rule in Farris v. State, No. 10-21-00204-CR (Tex. App.—Waco Feb. 15, 2023, no pet.) (mem. op.). Quoting the controlling line of authority, the court explained that "what makes accessing a computer unlawful under section 33.02(a) is that when the access occurs, the circumstances exist that the actor knows it is without the owner’s consent." On the facts, a person who accessed an SD card he found under his own desk — to figure out whose it was, believing it might be his — had not violated § 33.02, because there was no evidence he knew he lacked the owner’s consent. Farris is a clean illustration of the mistaken-authority defense: when the accused had a reasonable basis to think the access was permitted, the knowledge element fails.
A felony case under § 33.02(b-1) layers more on top: the specific intent to defraud or harm another, or to alter, damage, or delete property — and, on the policy-violation branch of § 33.02(b-1)(2), proof of a clear and conspicuous prohibition or an express contractual agreement plus intent to obtain or use data to carry out the fraud or harm. Every added element is one more thing the State can fail to prove.
What are the penalties under § 33.02?
Section 33.02 runs on two grading tracks. Simple access under subsection (a) starts as a Class B misdemeanor with two felony bumps. Fraud-or-harm cases under subsection (b-1) are graded by "aggregate amount" — the total dollar value — on the same value bands Texas uses for theft, up to a first-degree felony.
Section 33.02 runs on two grading tracks. Simple access under subsection (a) starts as a Class B misdemeanor with two built-in felony bumps. Fraud-or-harm cases under subsection (b-1) are graded by "aggregate amount" — the total dollar value involved — on the same value bands Texas uses for theft. The table below maps the full ladder; the takeaway for anyone facing a charge is that the same keystrokes can be a fine-only offense or a first-degree felony depending entirely on the number the State attaches to them.
| Conduct | Classification | Confinement | Max fine |
|---|---|---|---|
| Knowing access without effective consent — § 33.02(a) | Class B misdemeanor | Up to 180 days, county jail | $2,000 |
| Subsection (a) access against a government/critical-infrastructure computer, or with two or more prior Chapter 33 convictions — § 33.02(b) | State jail felony | 180 days–2 years, state jail | $10,000 |
| Fraud/harm intent, aggregate amount under $100 — § 33.02(b-2)(1) | Class C misdemeanor | None (fine only) | $500 |
| $100 to under $750 — § 33.02(b-2)(2) | Class B misdemeanor | Up to 180 days, county jail | $2,000 |
| $750 to under $2,500 — § 33.02(b-2)(3) | Class A misdemeanor | Up to 1 year, county jail | $4,000 |
| $2,500 to under $30,000 — § 33.02(b-2)(4) | State jail felony | 180 days–2 years, state jail | $10,000 |
| $30,000 to under $150,000 — § 33.02(b-2)(5) | Third-degree felony | 2–10 years, TDCJ | $10,000 |
| $150,000 to under $300,000; any amount against a government/critical-infrastructure system; or identifying information from one computer — § 33.02(b-2)(6) | Second-degree felony | 2–20 years, TDCJ | $10,000 |
| $300,000 or more; or identifying information from more than one computer — § 33.02(b-2)(7) | First-degree felony | 5–99 years or life, TDCJ | $10,000 |
Two grading traps drive most of the felony exposure we see. The identity-information bumps in § 33.02(b-2)(6)(C) and (7)(B) make the offense a second-degree felony when identifying information is obtained from one computer and a first-degree felony when it comes from more than one — regardless of dollar amount. A zero-dollar intrusion that touches personal data on two systems can be indicted at the same grade as a $300,000 fraud. The ownership bumps push any fraud-or-harm offense against a government or critical-infrastructure computer to at least a second-degree felony under (b-2)(6)(B), and even simple no-fraud access to those systems is a state jail felony under (b)(2). On the other side of the ledger, state-jail cases carry one practical relief valve: under Penal Code § 12.44(a), a judge can punish a state jail felony as a Class A misdemeanor in appropriate cases, which is often the negotiated landing spot for a first-time client in the $2,500–$30,000 band.
Employees who exceed their access
The most common § 33.02 fact pattern in a corporate corridor like North Texas is the departing employee who copies a customer list, pricing model, source code, or deal pipeline. The defense lives in the gap between "had login rights" and "had effective consent."
The single most common § 33.02 fact pattern in a corporate corridor like North Texas is the departing employee. Someone resigns or is terminated, and on the way out copies a customer list, a pricing model, source code, or a deal pipeline they built or worked on. The employer’s IT team documents the export, an incident-response vendor quantifies it, and the file arrives at the district attorney’s office already packaged as a felony. These are the cases where the gap between "had login rights" and "had effective consent" matters most.
The defense lives in the details of authorization. Was access ever actually revoked, or did the company simply forget to deprovision the account? Did any written policy clearly prohibit the specific conduct, or is the State stretching a generic acceptable-use clause? Did the employee believe the materials were partly their own work product? Most importantly, can the State prove the employee knew the access was unauthorized at the moment it happened — the Muhammed and Farris requirement? When credentials stayed live and the policies were vague, that knowledge proof is thin. And when the dispute is really about who owns the data, that is a civil fight between a former employer and a former employee, not a crime — a framing that supports declination, charge reduction, or a restitution-driven resolution. Where the copied material is a protected trade secret rather than money or identity data, the State may add a count of theft of trade secrets under § 31.05, which carries its own elements and its own defenses.
A hypothetical captures the pattern. Suppose a sales manager is let go on a Friday, but the company never disables her single sign-on. Over the weekend she logs in from home and downloads the commission spreadsheet she maintained for three years. Access happened and data left the building — but the termination letter said nothing about system access, the account still worked, and she viewed the spreadsheet as her own work. Those facts aim squarely at the knowledge element the State must prove under Muhammed, and at the consent-scope question the company’s own deprovisioning failure created. This is a hypothetical, not a result, and every case turns on its specific facts — but it shows why the defense starts with consent and knowledge, not with the keystrokes.
How § 33.02 compares to the federal CFAA
The federal Computer Fraud and Abuse Act, 18 U.S.C. § 1030, overlaps with § 33.02 but splits on one decisive point: after Van Buren, misusing access you are allowed to have is not a federal crime — yet it can still be charged under Texas law.
The federal Computer Fraud and Abuse Act, 18 U.S.C. § 1030, covers overlapping conduct but splits from Texas law on one decisive point: misuse of access you are allowed to have. In Van Buren v. United States, 593 U.S. 374 (2021), the Supreme Court adopted a "gates-up-or-down" reading of the CFAA — a person "exceeds authorized access" only by entering areas of a computer that are off-limits to him, not by accessing information he is entitled to reach for an improper reason. Under that reading, misusing authorized access is not a federal CFAA crime.
Texas law is built the other way. Section 33.01(12)(E) strips consent that is "used for a purpose other than that for which the consent was given," and § 33.02(b-1)(2) expressly reaches access in violation of a written prohibition or contract when paired with fraud-or-harm intent. The result: conduct that no longer supports a CFAA charge after Van Buren can still be charged under § 33.02 in a Texas courthouse. Forum also changes the stakes. Intrusions touching interstate systems, financial institutions, or federal agencies can draw a federal indictment in the Northern or Eastern District of Texas, where loss under the federal sentencing guidelines — not the § 33.02(b-2) bands — drives exposure. The same conduct can be prosecuted in both systems, and § 33.02(d) separately lets Texas prosecutors charge § 33.02 alongside any other Penal Code section the same conduct violates.
Where these cases are heard in DFW
L and L Law Group defends § 33.02 cases across the four core DFW counties from our Frisco office. Where a case is heard — Collin, Dallas, Denton, or Tarrant — shapes how it moves and where the highest-leverage window falls.
L and L Law Group defends § 33.02 cases across the four core DFW counties from our Frisco office. Where a case is heard shapes how it moves.
Collin County. Misdemeanor § 33.02(a) cases are filed in the county courts at law and felonies in the district courts, all sitting at the Collin County Courthouse at 2100 Bloomdale Road in McKinney. The Frisco–Plano–Allen corporate corridor makes employer-referral cases common here: a company’s IT department documents the intrusion, an incident-response firm quantifies it, and the file lands pre-packaged.
Dallas County. Felony computer-crime cases are heard in the district courts at the Frank Crowley Courts Building and typically move alongside the white-collar docket; misdemeanors run through the county criminal courts. Cases referred by banks, hospital systems, and universities tend to arrive with extensive civil-side forensic work already done.
Denton County. Cases are heard at the Denton County Courts Building in Denton, where family-dispute and small-business fact patterns recur, and outcomes often track how cleanly the consent story can be told on paper.
Tarrant County. Filings run through the Tim Curry Criminal Justice Center in Fort Worth — misdemeanors in the county criminal courts, felonies in the district courts. As elsewhere, early defense contact with the assigned prosecutor, before grand-jury presentment on felony tracks, is frequently the highest-leverage window.
Most § 33.02 cases are investigation-first. By the time an arrest happens, a detective has often had the forensic report, the IT affidavit, and a search-warrant return for weeks. Some clients first learn of the case when officers arrive with a device warrant; others get a phone call inviting them "to give their side." Decline that interview until counsel is present — statements about passwords, permissions, and purposes are exactly what the knowledge element gets built from. After arrest and magistration under CCP art. 15.17, expect bond conditions that can include no-contact orders covering a former employer and sometimes computer- or internet-use restrictions — conditions that can be negotiated and modified, which is critical for clients who work in IT or security. Under the Michael Morton Act, CCP art. 39.14, the defense obtains the State’s file — including forensic images and examiner notes — which an independent expert should re-examine rather than accept.
Enhancements and collateral consequences
Beyond the grading bumps, two prior Chapter 33 convictions make even simple access a state jail felony, and § 33.02(d) lets the State stack charges. For a charge that often starts as workplace friction, the collateral fallout — firearm rights, professional licensing, immigration — is heavy.
Beyond the grading bumps in the table, two prior Chapter 33 convictions make even simple access a state jail felony, and § 33.02(d) lets the State prosecute the same conduct under § 33.02 and any other applicable section — theft, fraudulent use of identifying information under § 32.51, or tampering with a governmental record among them. Victims also hold a parallel civil claim: Civil Practice and Remedies Code Chapter 143 authorizes a damages suit for harmful access by computer, so a criminal file is frequently shadowed by a civil one.
For a charge that often starts as workplace friction, the collateral fallout is heavy. A felony conviction forfeits firearm rights under Penal Code § 46.04 and 18 U.S.C. § 922(g). Any conviction carrying fraud-type intent invites professional-license scrutiny and is poison for careers in IT, security, finance, and healthcare — the very fields where background checks flag computer-misuse offenses. Security clearances, employment in regulated industries, and immigration status (fraud-intent offenses raise moral-turpitude questions that need case-specific analysis) can all be affected. Those consequences, more than the jail range, usually drive defense strategy in a first-offense case — which is why charge posture early matters. A dismissal or acquittal generally supports expunction under CCP Chapter 55A, and completed deferred adjudication usually supports an order of nondisclosure, while a final conviction generally stays on the record for good.
