Aaron Swartz was 14 when he co-authored the RSS 1.0 specification. He was 19 when he built the web framework that became Reddit's backend. By the time he was arrested at MIT in 2011 at age 24, he had co-founded Reddit, launched Demand Progress (which helped defeat SOPA), and become one of the most technically capable and politically engaged figures in internet freedom activism. The federal indictment against him alleged he had committed wire fraud, computer fraud, and related offenses by using MIT's network to download academic journal articles. The maximum sentence on all counts was 35 years and $1 million in fines.
His prosecution under the Computer Fraud and Abuse Act became, and remains, the most widely discussed example of what critics call CFAA overreach: the application of a law written to address malicious hacking to conduct that, in any other context, would have been treated as a terms-of-service violation at most. The case raised fundamental questions about the scope of "unauthorized access" under federal computer crime law, the prosecutorial discretion afforded to US Attorneys, and whether the punishment framework built for state-sponsored hackers and financial criminals was appropriate when applied to an activist downloading publicly-funded academic research.
JSTOR, MIT, and the Downloads
JSTOR is a digital library of academic journals, books, and primary sources. It licenses access to universities, which in turn provide access to their students and faculty. MIT had a JSTOR license, and like many large research universities, provided open network access - anyone physically on MIT's campus network could access JSTOR without a separate login, because MIT had negotiated campuswide access based on IP range.
Between September 2010 and January 2011, Swartz used this access to systematically download a large portion of JSTOR's article database. He initially used a laptop connected to MIT's network, then moved to more direct methods: he registered a guest account with MIT, gained access to a network wiring closet in MIT's Building 16 basement, connected a laptop directly to the network switch, hid it under a cardboard box, and used it to run automated download scripts. At peak, the downloads were fast enough that JSTOR temporarily blocked MIT's IP range to reduce server load.
JSTOR detected the unusual download volume and worked with MIT to identify the source. When the laptop was discovered in the network closet in January 2011, MIT notified JSTOR and both organizations notified the Secret Service (which has jurisdiction over federal computer crime). Swartz was identified and arrested on January 6, 2011.
The immediate consequence was contained: JSTOR received all downloaded files from Swartz's hard drives and declined to pursue civil action against him. JSTOR issued a statement after his death noting that they had considered the matter closed. MIT declined to take a position on the prosecution despite repeated requests from Swartz's legal team and from members of Congress - a stance the MIT report commissioned after his death described as "institutional neutrality" that some criticized as passive complicity in an aggressive prosecution.
The CFAA and the Indictment
The Computer Fraud and Abuse Act was passed in 1986 and amended several times since, most significantly in 1994, 1996, and 2001. Its core prohibition is against accessing a computer "without authorization" or "in excess of authorized access." The original target was clearly malicious intrusion: the legislative history references hackers breaking into government and financial systems. But the law's language is broad enough that it has been interpreted to criminalize a wide range of conduct that involves computers and some violation of terms of use.
The Swartz prosecution hinged on whether using MIT's network to access JSTOR for purposes beyond what MIT or JSTOR intended constituted "unauthorized access" or access "in excess of authorized access." His attorneys argued that he had legitimate network access (MIT's open network policy allowed any campus visitor to connect) and legitimate JSTOR access (MIT's campuswide license made JSTOR accessible to anyone on MIT's IP range). The prosecution argued that his automated bulk downloading violated JSTOR's terms of service and that MIT's network policies did not authorize the kind of automated scraping he was conducting - and that violating terms of service is sufficient to constitute criminal "unauthorized access" under the CFAA.
The original indictment in July 2011 charged four felony counts. In September 2012, a superseding indictment added nine additional counts, for a total of 13 felony charges: wire fraud (2 counts), computer fraud (5 counts), and unlawfully obtaining information from a protected computer (5 counts) and recklessly damaging a protected computer (1 count). The additional charges dramatically increased the potential maximum sentence.
The timing of the superseding indictment - shortly after Swartz and his legal team had rejected a plea deal that would have required him to plead guilty to all 13 counts and serve six months in federal prison - was interpreted by many observers as prosecutorial pressure. US Attorney Carmen Ortiz's office did not publicly explain the decision to add counts after plea negotiations failed.
The Technical Reality
What Swartz actually did, stripped of legal framing, was run an automated script that downloaded files from a website using network access he was permitted to have. The technique - a Python or curl-based scraper iterating through JSTOR article URLs - required no exploitation of security vulnerabilities, no credential theft, no bypassing of authentication systems. The laptop in the network wiring closet was hidden, which suggested intent to conceal, but the access was technically straightforward.
The comparison his supporters drew, repeatedly, was to the treatment of actual hackers. Gary McKinnon, who broke into 97 US military and government computers including Pentagon and NASA systems and caused millions of dollars in damage, was never extradited from the UK to face the charges the US sought. Albert Gonzalez, who stole 170 million credit and debit card numbers and was responsible for the largest identity theft case in US history at the time, received 20 years. The proposition that downloading academic articles should carry a potential sentence commensurate with these cases was, to critics, a reductio ad absurdum of the CFAA's scope.
His Death and Aftermath
Aaron Swartz died by suicide on January 11, 2013, two years after his arrest and two months before his trial was scheduled to begin. He was 26.
The immediate reaction in the internet freedom and programming communities was grief combined with outrage directed at the prosecution. His family released a statement calling his death "the product of a criminal justice system rife with intimidation and prosecutorial overreach." Lawrence Lessig, who had been his mentor, called it "a great loss to the internet." Tim Berners-Lee tweeted that the internet was in mourning.
The prosecution was widely criticized by legal scholars, technology advocates, and members of Congress in the months that followed. Representative Zoe Lofgren introduced "Aaron's Law," a proposed amendment to the CFAA that would explicitly exclude terms-of-service violations from the definition of "unauthorized access." Aaron's Law has been introduced multiple times in Congress and has not passed.
MIT commissioned an independent review of its handling of the case, led by Hal Abelson. The Abelson report, released in 2013, concluded that MIT had neither assisted nor opposed the prosecution but had declined multiple opportunities to signal to prosecutors that it considered the matter resolved, which could have reduced prosecutorial pressure. The report stopped short of concluding that MIT's neutrality was wrong, but noted that it had consequences.
US Attorney Carmen Ortiz defended the prosecution publicly, stating that her office had offered a plea deal and that the charges were appropriate. Assistant US Attorney Stephen Heymann, who led the prosecution, was reported to have told Swartz's attorneys that he would push for a six-month prison sentence only if Swartz pleaded guilty to all 13 felony counts - accepting a permanent felony record that would have severely limited his future employment options. Heymann was later reported to have faced an internal DOJ review but received no formal discipline.
CFAA Reform: What Changed and What Didn't
The Swartz case generated the most sustained public debate about CFAA reform since the law's passage. The specific issue he raised - that terms-of-service violations should not constitute federal computer crime - achieved partial judicial resolution in Van Buren (2021), but the broader problems with the law's scope remain.
The law still permits prosecutors to stack charges: each instance of downloading a file is potentially a separate count. It still provides no proportionality requirement between the harm caused and the severity of charges. It still lacks a clear definition of "authorization" that distinguishes between technical access controls and use policies. The chilling effect on security researchers - who routinely access systems in ways that could be characterized as "without authorization" depending on the system owner's interpretation - remains significant. The practice of "bug bounty" programs and responsible disclosure frameworks exists in part to provide cover for exactly this kind of access.
The most lasting legacy of the case may be less legal than cultural: it became the reference point for conversations about prosecutorial overreach in computer crime cases and about the structural disconnect between a 1986 law and the reality of how the internet works. Every subsequent case where CFAA charges were applied to conduct that looked more like policy violation than malicious hacking invoked Swartz's name. In the security community, his death and the circumstances surrounding it became a permanent part of the argument for CFAA reform.