Introduction
Login credentials have quietly become one of the main lines of defense for personal privacy, corporate data, and even government systems. Most people would think nothing of giving someone your password to a streaming service or allowing a co-worker access to a shared database. But the laws have not kept up with the informality of modern-day access. When a seemingly innocent exchange crosses the threshold between a violation of terms of service and a felony, the law quickly finds itself in search of clarification.
How Intent Shapes the Legal Risk
Whether sharing a password lands someone in civil or criminal trouble depends a lot on context — who’s involved, what was accessed, and why. Legal scholars generally sort these situations into a few rough categories.
Streaming and subscription accounts:
Giving a Netflix or news subscription to a loved one is typically a civil matter between the consumer and the company, not a crime. Companies can sue people who share an account, but it’s uncommon for the issue to escalate to the point of involving prosecutors.
Workplace and ex-employee access:
The stakes rise sharply once corporate systems are involved. A common flashpoint is a former employee who still has, or borrows, working credentials after leaving a job and uses them to look at company files, client records, or financial data.
Fraud and government systems:
The most serious cases involve passwords obtained or shared to commit fraud, break into government networks, or get around multi-factor authentication through social engineering. Here the credential isn’t just misused access — it’s a tool in a larger criminal scheme.
What Counts as Authorization
Two ideas do most of the work in these cases. Access is authorized when the entity that actually owns or manages the system has granted it explicitly. And that permission can end abruptly — a person gets fired, or a company rewrites its policy, and any further use of old credentials becomes unauthorized, even if nothing about the login itself has changed.
How Different Countries Handle It?
There’s no standalone “password sharing law” anywhere, as far as the sources reviewed here show. Prosecutors instead reach for broader computer-crime and trespass statutes, and how those get applied varies a fair amount by country.
United States — the Computer Fraud and Abuse Act
Federal prosecutors in the US lean on the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, which makes it illegal to access a protected computer “without authorization” or to exceed authorized access. The case that’s usually cited here is United States v. Nosal, where the Ninth Circuit found that someone could be criminally liable under the CFAA for using a current employee’s password to get into a company database after his own access had been formally cut off. It didn’t matter that the employee gave up the password willingly — the employer had withdrawn permission from the person actually logging in, and that was enough to make it a federal crime.
India — the Information Technology Act, 2000
India treats misused login credentials as a form of identity theft rather than a minor lapse. Two provisions of the IT Act come up most often.
Section 66C. Anyone who fraudulently or dishonestly uses someone else’s electronic signature, password, or other unique identifying feature can face up to three years in prison and a fine.
Section 43. Helping someone access a secure system without the owner’s permission can bring civil damages, and depending on the facts, criminal charges as well.
United Kingdom — the Computer Misuse Act 1990
The UK relies on the Computer Misuse Act 1990. Section 1 makes it an offense to cause a computer to perform a function with intent to secure unauthorized access to a program or data. Under this framework, being handed a password by a third party doesn’t protect the recipient if they know full well that the actual owner of the system never agreed to let them in. The Crown Prosecution Service tends to frame these cases around unauthorized modification and basic cyber trespass.
Why Businesses Care So Much
As for enterprises, shared user credentials may introduce a security risk. The modern regulatory environment, such as the GDPR in the EU, and HIPAA in the US, holds enterprises accountable for ensuring controlled access to data by all users, and having an audit trail available if required. Shared credentials present a risk in this area since they can make auditing significantly more difficult, and, in the case of a breach, it may not be possible to identify exactly which user was responsible for a security violation. That loss of accountability is a big reason so many companies now have zero-tolerance policies on password sharing, and why those internal rules often end up feeding directly into civil lawsuits or criminal referrals after a data breach.
Building a Defense
Defending against these charges usually comes down to intent. If someone can show they genuinely believed their access was permitted — because they’d been allowed in before, or company policy was vague about it — that can undercut the criminal-intent requirement that statutes like the CFAA depend on.
Where This Is Headed
As authentication moves away from plain passwords toward biometrics, passkeys, and zero-trust systems that continuously check identity, the legal questions will probably shift too. Instead of asking whether a string of characters was handed over, courts may increasingly ask whether someone deliberately worked around an identity check to fool an automated system.
Bottom Line
Sharing a password is a line, one that runs between a quotidian transgression and a felony, and which one falls on which side is determined by what one is sharing and the reason why. Handing a relative your streaming login isn’t likely to get you prosecuted; using an old coworker’s credentials to get into a corporate database after you’ve been let go is a different story. Until such time as legislation catches up to reality, the safest assumption, as far as the courts are concerned, is the one they keep coming back to: that the right to control access to something belongs to whomever owns it, period.

