TECH Signal 301
Cop who used police system to snoop for info on crook pals sentenced for Computer Misuse Act offenses
A former Merseyside police officer received a suspended 12-month prison sentence after being convicted of Computer Misuse Act and Data Protection Act offenses for conducting unauthorized searches on police systems and relaying sensitive investigation details while maintaining undisclosed relationships with criminals.
This case confirms that authorized system users who access data without a legitimate purpose can be criminally convicted under the CMA, even without proven financial gain or demonstrable harm. For teams operating access-controlled databases, it highlights that insider misuse detection remains a hard problem, Hughes's unauthorized queries went undetected for years, and that audit logs can eventually serve as prosecution evidence.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Hughes was convicted on eight counts of unauthorized computer access under the CMA 1990 and three counts under the DPA 2018, for queries spanning 2016 to 2019 and information relayed between 2019 and 2021.
The court found no evidence that Hughes profited from or deliberately passed information to criminal enterprises, yet convictions on all counts still stood.
Despite receiving training on handling police information and declaring inappropriate relationships, Hughes concealed his decade-long ties to criminals, which the CPS called central to proving his access had no legitimate purpose.
THE CLUSTER