UCMJ Article 123: Offenses Concerning Government Computers
On this page
Article 123 of the Uniform Code of Military Justice is one of the newer punitive articles, and its current subject matter surprises people who remember the old code. Until the Military Justice Act of 2016 took effect on January 1, 2019, Article 123 was the forgery article. That offense did not disappear; it was renumbered to Article 105 (10 U.S.C. 905). The number 123 was then reassigned to a brand-new offense aimed at computer intrusion. The current Article 123, codified at 10 U.S.C. 923, criminalizes accessing a government computer without authorization and the related misuse or damage that can follow. Anyone reading older case law or pre-2019 reference material should treat any reference to “Article 123 forgery” as describing the prior code, not current law.
The article gives military prosecutors a dedicated charging tool for computer crime. Before its enactment, computer misconduct was often charged under the general article (Article 134) by assimilating the federal Computer Fraud and Abuse Act, 18 U.S.C. 1030. That route was awkward, particularly for conduct overseas, where the reach of federal criminal jurisdiction could be uncertain. Article 123 closes that gap because it applies to every person subject to the UCMJ wherever they are stationed.
The three offenses inside Article 123
The statute is not a single prohibition. It defines three distinct offenses, each addressing a different kind of harm.
The first and most serious offense applies when a service member knowingly accesses a government computer for an unauthorized purpose, by doing so obtains classified information, and then transmits or communicates that information to a person not entitled to receive it. This variant targets the full chain of an insider leak: improper access, acquisition of national-security material, and onward disclosure.
The second offense applies when a person intentionally accesses a government computer for an unauthorized purpose and thereby obtains classified or other protected information. Here the misconduct is the wrongful acquisition itself. No further transmission is required.
The third offense applies when a person knowingly causes the transmission of a program, information, code, or command and, as a result, intentionally causes damage without authorization to a government computer. This variant reaches sabotage of systems and data rather than the theft of information, and it mirrors the damage provisions of the federal computer-fraud statute.
The structure lets the government charge conduct in proportion to its actual effect, separating the leak of classified material, the mere acquisition of protected data, and the disruption or destruction of a system.
What the government must prove
The elements track the statutory language. For the most serious variant, the prosecution must establish that the accused knowingly accessed a government computer with an unauthorized purpose, that the access produced classified information, that the accused had reason to believe the information could be used to the injury of the United States or to the advantage of a foreign nation, and that the accused intentionally communicated or transmitted it to someone not entitled to receive it.
Two terms carry most of the weight. “Knowingly” means the accused was aware of accessing the computer; an unwitting or accidental connection does not satisfy it. “Unauthorized purpose” is the contested concept in almost every case. It covers both the outsider who has no right to be in the system at all and, more commonly, the insider who holds valid credentials but uses them for an end outside the scope of assigned duties. A service member with a legitimate network account who pulls personnel records unrelated to any duty is using authorized access for an unauthorized purpose. This parallels the “exceeds authorized access” theory under 18 U.S.C. 1030, and civilian case law interpreting that phrase is persuasive but not binding on military courts.
Where classified information is in play, its classification level and national-security relevance must be proven, though the sensitive details are typically handled through the classified-information procedures of Military Rule of Evidence 505 rather than disclosed openly in the courtroom.
What counts as a government computer
The statute defines a government computer as one owned or operated by or on behalf of the United States Government, and it borrows the definitions of “computer” and “damage” directly from 18 U.S.C. 1030. The definition is functional, not geographic. A government-issued laptop a service member uses at home remains a government computer. Military networks such as SIPRNet, NIPRNet, and JWICS qualify, as do government-issued mobile devices, government cloud services, and systems in government facilities operated by contractors on the government’s behalf. Shared-use machines in libraries or morale facilities qualify if the government owns or operates them.
The harder questions arise at the edges. A purely personal device connected to a government network can raise a genuine dispute about whether the prohibited conduct lies in the character of the device or in the unauthorized access to the network reached from it. As military computing moves toward cloud platforms and commercially hosted services, the boundary of “operated on behalf of” the government becomes a live issue that courts work out case by case.
Maximum punishment
Article 123 does not set its own penalty; like most punitive articles, it provides that an offender “shall be punished as a court-martial may direct,” and the maximums are fixed by the President in the Manual for Courts-Martial. The penalties escalate with the harm.
For the most serious variant, unauthorized access that yields classified information later transmitted to an unauthorized recipient, the maximum punishment is a dishonorable discharge, total forfeiture of all pay and allowances, reduction to E-1, and confinement for ten years. Causing damage to a government computer also carries a maximum of ten years’ confinement with comparable discharge and forfeitures. Unauthorized access that obtains classified or other protected information, without onward transmission, carries a maximum of five years’ confinement with comparable consequences. Because the 2024 Manual restructured sentencing through offense categories and parameters for offenses committed on or after December 27, 2023, the precise confinement range available in a given case should be confirmed against the current Manual for Courts-Martial.
Defenses
The most frequently litigated defense attacks the “unauthorized purpose” element. Service members, especially those in technical roles, often have wide-ranging legitimate access, and the line between permissible use and unauthorized purpose is rarely crisp. Acceptable-use policies that members sign define the boundaries, but a court must decide whether a particular access was for an unauthorized purpose as a matter of law, not merely whether it violated a policy. A defense may argue that the access fell within the scope of the member’s authorization even if a commander later disagreed with the choice.
Other defenses follow the elements. The accused may contend that the information obtained was neither classified nor otherwise protected, that no damage occurred for the damage variant, or that nothing was transmitted to an unauthorized person for the transmission variant. Because these cases turn on digital evidence, a defense often challenges the forensic proof itself, including the chain of custody for forensic images and whether the logs reliably tie a specific person to a specific access event.
How these cases are investigated and charged
Article 123 cases are built on digital forensics. Military cyber investigators and the Defense Cyber Crime Center reconstruct conduct from network authentication logs, system audit trails, email routing records, and endpoint analysis of the accused’s workstation, which can reveal file access patterns, removable-media connections, and evidence of data exfiltration. This evidence is voluminous and technical, and it ordinarily requires expert testimony to be intelligible to a court-martial panel.
Article 123 frequently overlaps with other offenses. When a service member accesses a government computer to obtain classified information and delivers it to a foreign government or its agent, the conduct may also support an espionage charge under Article 103a (10 U.S.C. 903a, the current espionage article after the 2019 renumbering). The distinction is the recipient and the intent: espionage focuses on delivery to a foreign power, while Article 123’s transmission variant reaches disclosure to any unauthorized person. Where the recipient is a journalist, a publication platform, or a private contact rather than a foreign agent, Article 123 may be the more fitting charge. Prosecutors often plead both when the evidence supports it, leaving the trier of fact to sort out the appropriate level of culpability.
Sources
- 10 U.S.C. 923 (Article 123, Offenses concerning Government computers), via the Legal Information Institute: https://www.law.cornell.edu/uscode/text/10/923
- 18 U.S.C. 1030 (Computer Fraud and Abuse Act, source of the “computer,” “damage,” and access definitions incorporated by Article 123), via the Legal Information Institute: https://www.law.cornell.edu/uscode/text/18/1030
- Manual for Courts-Martial, United States (2024 edition), Part IV, Punitive Articles, Article 123 (elements and tiered maximum punishments), published by the Joint Service Committee on Military Justice: https://jsc.defense.gov/Military-Law/Current-Publications-and-Updates/
This article is for general informational purposes only and is not legal advice. It describes military law and procedure of public record, does not address any individual case, and does not create an attorney-client relationship.