Cybersecurity & Tech

The Legal Risks That Chill Good-Faith Security Research

Belen Pisaniello, Sunoo Park, Daniel R. Thomas
Tuesday, July 21, 2026, 10:02 AM
In their own words, researchers describe how anti-hacking laws push them to abandon work, stockpile flaws, or quit the field entirely.
"AI Code" (WCN 24/7, http://tinyurl.com/mr48s6p9; CC BY-NC-ND 2.0 DEED, https://creativecommons.org/licenses/by-nc-nd/2.0/)

“I sent some emails warning people of a security incident and [law enforcement] c[a]me up at me with machine guns—that kind of doesn’t seem to balance.” — Anonymous

Anti-hacking laws, such as the U.S. Computer Fraud and Abuse Act and the U.K. Computer Misuse Act, exist to combat malicious hacking and protect digital infrastructure. But paradoxically, their broad and ambiguous scope can work against that very goal. Such laws often fail to clearly distinguish between malicious hacking and good-faith research, exposing researchers to serious legal risks for essential research activities.

This exposure can create a “chilling effect,” discouraging researchers from pursuing valuable work that could improve widespread understanding of technologies that millions of people rely on every day—and shed light on the ways those technologies can fail.

Despite widespread awareness of these risks within research communities, there is little empirical evidence on the practical impacts of legal risks or on researchers’ experiences navigating them. Much of what is known in the community persists as professional “folklore” or anecdotal accounts rather than systematic research, making it difficult to understand the full landscape of legal risks and to advocate effectively for policy change.

To address this gap, our recent paper examines the legal-risk experiences of researchers in the United States and the United Kingdom. It is the most comprehensive account to date of how legal risks affect computer science researchers and their work. We heard from dozens of researchers about their firsthand encounters with legal threats, how legal risks shape research decisions, and the norms and practices surrounding legal risk. We also spoke with lawyers and other professionals who collectively have helped thousands of researchers.

A few disclaimers: We keep all our participants anonymous, do not link their quotes together, and omit detailed context around quotes, to reduce identification risk. Our analysis is qualitative, and our discussion of trends is based largely on participants’ experiences and impressions of trends. Our dataset is diverse and not comparable in a quantitative sense.

We found that research-related legal risks are serious and commonplace; for some areas, they are almost unavoidable.

As one anonymous participant put it, “You can’t really have a functional security research career without taking some level of risk; there’s just not enough legal certainty.”

These risks shape researchers’ decisions in concrete ways. We found clear evidence of “chilling effects,” with researchers describing abandoning projects, withholding disclosure of findings, or avoiding certain research areas altogether due to legal risks. That said, some researchers persevered despite the legal risks, highlighting the importance of research for keeping systems safe and secure.

One particularly alarming manifestation of these chilling effects is “stockpiling,” in which researchers discover security vulnerabilities but choose not to disclose them out of fear of legal consequences. Instead, they hold onto this information, making it a prime target for hacking, bribery, and coercion. One researcher reported being approached by a mysterious individual offering a large sum of money to buy their stockpile and their silence. They said they did not sell, but shared that:

I did think about it though, right, like holy shit, that’s life-changing money. “I could move my entire family out of the ’hood” money, right—so it was an ethical debate for me.

Anti-hacking laws may be the most prominent source of concern, but they are not the primary one researchers named. Contract law was by far the most frequently cited area of legal risk; participants told us that essential research activities often involve possible violations of the terms of service of the systems studied, some of which contain extensive and onerous limitations on independent study of the systems and reporting of research findings. Explaining the importance of studying how these systems fail, one participant said: “Adversaries who are actually adversarial will not say, ‘Oh well it says in the terms of service we can’t do this and therefore we won’t do it.’”

The next most commonly mentioned sources of risk were the U.S. Computer Fraud and Abuse Act (CFAA), the U.S. Digital Millennium Copyright Act (DMCA), defamation, the U.K. Computer Misuse Act (CMA), and fraud, in that order. The CFAA, DMCA, and CMA contain overbroad definitions of computer crime that facially appear to encompass much good-faith research activity that is essential to understand how systems work. Thanks to advocacy efforts over many years, the DMCA now has a temporary exemption for good-faith security research; while this is important progress, participants shared that the exemption is not always enough to fully allay research-related legal-risk concerns. Defamation is a concern when researchers discuss or publish negative research findings about a system, which the system owners contend are false and damage their reputation. Accusations of fraud may arise when researchers access a system without disclosing their real identity or using false information (for example, creating research accounts to test how a platform serves ads to people with different profile information), as Xiao et al.’s recent paper also discusses in more detail. Where civil (as opposed to criminal) legal risk is involved, potential risks are much broader as action can be threatened or instigated not only by prosecutors but also by disgruntled private parties (often, the subjects of the research); we heard that threats of legal action are highly disruptive and costly for researchers even where the legal basis is questionable, and even where the threat is not followed through.

The current U.S. political environment has compounded these pressures: Shifts in political climate and hostility toward the academy, especially since 2020, have heightened risks for researchers. And even where certain risks have diminished, researchers are uncertain whether those improvements will hold, since many depend on informal decisions or nonbinding guidance rather than enforceable rules. Legal threats are also growing more politically motivated, particularly in social computing research, where powerful actors have pushed back against findings they dislike. Discussing a situation where political pressure on a university led to entire research programs being shut down and researchers being laid off, one researcher told us: “I thought that was incredibly cowardly. Congressmen shouldn’t dictate research.”

The personal and emotional toll of these risks is significant. As shown in the word cloud below, fear, worry, stress, and frustration were the most commonly mentioned emotions in our interviews.

 

Researchers reported significant personal and physiological tolls stemming from the pressures of legal exposure. Some described legal risk as all-consuming, pervasively impacting their lives for a period; one participant spent many months incarcerated. On receiving legal threats over graduate school research, a participant recalled:

It was incredibly nerve-racking. I weighed myself before and after and I literally lost weight. I was unable to eat because I was so freaked out about what was going on. I kind of assumed that I was going to get sued into oblivion[.]

Participants also consistently highlighted a lack of visibility into the scope, nature, and impacts of legal risks. Even lawyers and other supporting professionals who had helped hundreds of researchers noted that they lacked a complete picture.

What motivates researchers to do this work despite these risks? While the law sometimes treats them like malicious hackers, participants’ accounts suggest quite the opposite. The most common perspective framed research as a form of public service, aimed at improving the security of widely used technologies and advancing public understanding of systems with real societal stakes. Some felt a “duty” to report vulnerabilities despite legal risks, even when their discoveries were accidental, because of the potential harm of leaving vulnerabilities unaddressed.

When legal trouble looms, researchers may turn to experienced colleagues, lawyers, or institutions—not all of whom are always helpful. While some researchers expressed skepticism about involving lawyers—worrying they would slow things down or just “say no”—most saw them as an important resource, especially when legal risks escalated. Lawyers helped researchers review writing and facilitated communication with companies or institutions. In some cases, their involvement alone was enough to deescalate legal threats. One lawyer told us:

I couldn’t say how many times I’ve had a vendor threaten a client of mine and ... our mere appearing to be like, “I don’t think so, buddy” is enough to make them go away—not always, but it is really striking[.]”

Researchers also drew a critical distinction—often learned the hard way—between personal legal counsel and institutional lawyers. One participant emphasized, “The thing you always have to remember is that [institutional lawyers] are there to protect the university. They are not there to protect the researcher.”

Experiences with institutional lawyers varied widely but were more negative than positive on balance. Some researchers described strong support from their institutions, such as protection against cease-and-desist letters or in litigation, but others said institutional lawyers undermined their interests. Researchers with experience in both academic and industry settings generally reported feeling better protected in industry.

Our findings paint a sobering picture. Legal risks are chilling the research that society needs to keep everyday digital technologies safe and accountable, leaving us dangerously exposed at a moment when Big Tech is more powerful than ever, cybersecurity threats are widely described as being at an all-time high, and the latest artificial intelligence-powered cybersecurity tools have accelerated vulnerability discovery to such a scale that humans may struggle to match.

So, what can be done? Our participants suggested several strategies and precautions available to researchers. Many emphasized thinking about legal risk early in the research process and obtaining legal advice, especially for higher-risk projects. Participants also highlighted practical precautions around data collection, such as working with publicly available data, minimizing data collection, and being aware of legal differences across jurisdictions. Some researchers discussed avoiding contracts or carefully reading terms of service, while others described anonymity measures to avoid being targeted, such as publishing research anonymously or using intermediaries during disclosure. Participants also stressed the importance of internal communication—sharing research within institutions early can help ensure support if risks later escalate. Public communication was also a key concern, since legal threats and media attacks on researchers can develop quickly and publicly.

At the same time, researchers cannot solve these problems alone. Supporting professionals stressed the importance of raising awareness of legal support resources among researchers. Institutions, conferences, companies, law enforcement, and government agencies also have important roles to play in supporting good-faith research and responding to research findings. This isn’t only about the researchers—it’s also about academic freedom, and about public safety and accountability in a world dependent on opaque digital infrastructure.

While this piece highlights some of our main findings, the paper goes further into the experiences behind them, including how researchers learn about legal risk, how they respond to threats, how lawyers and institutions can help or complicate things, and how risks differ across the U.K. and the U.S. and across different kinds of research. While we find legal-risk experiences are highly contextual, the paper also offers a range of recommendations for different stakeholders, including researchers themselves (e.g., develop a legal-risk contingency plan early), companies (e.g., consider voluntary pledges not to threaten good-faith researchers), academic publication venues (e.g., publish policies supportive of legally risky research), governments and regulators (e.g., consider enhancing support resources to intermediate research disclosure where researchers need protection), and more.

We hope that by telling some of these stories, the paper can help researchers in the short term, while also raising awareness and supporting broader change.


Belen Pisaniello is a recent graduate of New York University, where she earned a Bachelor of Arts in International Relations with a minor in Public Policy. Throughout her undergraduate career, she developed a strong foundation in research, public service, and policy through experiences in government, academia, and the nonprofit sector. She plans to attend law school and pursue a career dedicated to advancing access to justice, with particular interests in immigration law and public interest advocacy.
Sunoo Park is an Assistant Professor in Computer Science at the NYU Courant Institute, and Affiliated Faculty at the NYU School of Law. She runs the DeTaIL Lab at NYU, which engages in research in computer science and in technology law and policy, especially related to security, privacy, and transparency in digital technologies. She received her J.D. at Harvard Law School and her Ph.D. in computer science at MIT, and is a licensed attorney in New York State.
Dr. Daniel R. Thomas is a Senior Lecturer at the University of Strathclyde where he is Director of the NCSC-certified Academic Centre of Excellence in Cyber Security Research (ACE-CSR). His research interests are in measuring security, cyber-resilience, and cybercrime so that we can monitor improvement, evaluate interventions, and inform regulators. This reveals which techniques work and provides the missing economic incentives to improve security and resilience while reducing cybercrime. He also studies the legal and ethical issues involved in conducting these kinds of research.
}

Subscribe to Lawfare