Miju Labs

The security dossier

The terms of service bite first

The first thing that stops this business is not a criminal statute but Hack The Box's acceptable use policy, which bans training AI on its content outright — and for a Europe-based operator the sharpest criminal risk is Germany's unreformed §202c, where a researcher was convicted and fined €3,000 for using a hardcoded credential he found in a client's software.

medium confidence9 minupdated 2026-08-30law · cfaa · 202c · germany · terms of service · jurisdiction

This page and the four that follow are desk research by non-lawyers, compiled from public sources on 30 August 2026. It is not legal advice. Take counsel in every relevant jurisdiction — at minimum the company's EU seat, Germany if any German contractors, the UK and the US. The disclaimer is not repeated after this.

Ask what could stop a company that pays researchers to produce attack trajectories and sells them to frontier labs, and the answer comes back as computer-crime law. That is the wrong first answer. The first blocker is a contract nobody reads.

Hack The Box's Acceptable Use Policy, effective 1 April 2026 (HTB AUP):

In their words

"You shall not use any content from the Services… to train, evaluate, fine-tune, test, benchmark, or develop any machine learning model, artificial intelligence system, large language model."

And separately: "Do not use the Services, or any content, materials, or outputs derived from the Services, to provide external consulting, paid training, or commercial services to third parties without explicit authorisation." The same policy bans any "bot, crawler, scraper, AI agent, large language model" from accessing the service.

That is a categorical prohibition on this exact business model as applied to HTB content, and the two limbs hit it independently. It is a contract problem rather than a criminal one, which makes it more certain, not less: no intent element, no prosecutorial discretion, and a plaintiff who can simply read your marketing page.

The order of operations is inverted

Criminal exposure for producing attack data is manageable and mostly a matter of target discipline. Platform terms are a wall that arrives on day one, across the most convenient supply of practice targets, and other range operators will copy them once they notice what is happening. Assume every commercial range is closed unless you negotiate a bespoke licence — and note that Hack The Box itself builds ranges for UK AISI, so it is a competitor as well as a landlord. Build your own targets. See The oracle decides everything for what that costs.

Nobody has checked the other ranges

The AUPs of TryHackMe, Immersive Labs, RangeForce and Offensive Security's ranges could not be established here. Read each before designing a curriculum around it — an afternoon of work that could invalidate a quarter of product planning.

The US baseline, and why the DOJ policy is thinner than it looks

The CFAA, 18 U.S.C. § 1030, contains no prohibition on writing exploits, possessing them, or describing how to use them; the offence attaches to unauthorised access to someone else's machine. Production is lawful when the target is one you own or licensed, and the highest-value, lowest-risk category is published CVEs reproduced against a local instance of the vulnerable software.

The safety net most people reach for is DOJ's revised CFAA charging policy of 19 May 2022 (DOJ):

In their words

"good faith security research" means accessing a computer solely for purposes of good-faith testing, investigation, and/or correction of a security flaw or vulnerability… and where the information derived from the activity is used primarily to promote the security or safety of the class of devices, machines, or online services to which the accessed computer belongs.

Read the two adverbs. "Solely", and "used primarily to promote the security or safety." A corpus produced primarily to be sold as training data has a different primary purpose from remediating the flaw, and a prosecutor could argue commissioned corpus-production falls outside the definition entirely. No DOJ guidance or declination on for-profit corpus production could be found; the question is open [UNVERIFIED]. The policy also creates no rights, and says so: its principles "may not be relied upon to create a right or benefit, substantive or procedural, enforceable at law." It binds no state prosecutor, no civil plaintiff and no future administration (Lawfare).

DOJ's CCIPS guidance on gathering threat intelligence (February 2020) is closer to on-point for a company that commissions rather than performs: buying vulnerabilities "is not generally illegal, standing alone and without any criminal intent," but "assisting others engaged in criminal conduct can constitute the federal offense of aiding and abetting," even through otherwise lawful acts — and OFAC liability is strict, so sanctions screening of every contractor is a build-time requirement. See Paying the crowd.

Europe is where this actually gets decided

For a Europe-based operator the US analysis is background. Directive 2013/40/EU Article 7 criminalises distributing hacking tools only "with the intention that it be used to commit" an offence, "without right," and "at least for cases which are not minor" (Art. 7); Recital 17 expressly exempts mandated testing. That is not a problem on its face. The problem is that member states did not transpose the intent element faithfully.

JurisdictionStatutory position for a researcherRead for a contractor base
BelgiumArt. 62(1)-(2) of the 2019 Act as amended by the February 2023 Whistleblower Act: exemption from liability for reporters acting without fraudulent intent who notify promptly and limit action to what verification requiresThe closest thing to a real EU safe harbour
PolandCriminal Code Art. 269c exempts access "solely aimed at securing information or ICT systems," conditional on prompt notification and no harmGood; scholarship reads it narrowly
FranceArt. L.2321-4 Code de la défense — safe harbour, but only where disclosure is solely to ANSSIWorkable with a rigid disclosure channel
NetherlandsNo statutory exemption; Public Prosecution Service guidelines (2013, rev. 2018) onlyDiscretion, not a defence
Germany§202c unreformed; §202a convictions on weak factsThe sharpest risk in Europe
SpainArt. 197 bis criminalises unauthorised access regardless of intentSingled out as actively deterring disclosure
ItalyLaw Decree 105/2023 Art. 2-bis grants immunity only to police in undercover operationsNo civilian protection
PortugalProtections reportedly enacted December 2025 [WEAK] — statute reference could not be establishedDo not rely on it

Source: the Journal of Cybersecurity survey of 12 member states, the best single document on this and on the reading list at the end of Nobody prices this risk yet.

Germany: unreformed, and one conviction that should set your risk appetite

§202c StGB criminalises preparing the §202a and §202b offences by producing, obtaining, selling, supplying or distributing passwords, access codes or software whose purpose is committing such an act. As at August 2026 it remains unreformed and in effect, carrying up to a year's imprisonment; the coalition has an agreement commitment but no draft bill (TechTimes, 25 Aug 2026) [WEAK on the outlet, consistent with the academic survey].

The 2024 Federal Ministry of Justice draft would have added a new §202a(3) exempting researchers acting solely to identify a vulnerability, where access was necessary and the finding responsibly reported. It left §202c untouched, the ministry's position being that intent-based assessment suffices (Bonn DROPS analysis). The CCC's Dirk Engling argued only "obviously harmless investigations" would be protected; Lilith Wittmann made the decisive point that intent is determined at trial, so the protection on offer is "you will probably win, after two years and substantial legal costs."

Then there is Modern Solution. A programmer analysing a client's retail software found plaintext customer passwords and hardcoded database credentials exposing data on 700,000+ customers. He disclosed on 23 June 2021; the vendor denied the flaw, then took systems offline; he demonstrated it to a journalist. Police raided his home on 15 September 2021. He was convicted under §202a and fined €3,000, the court reasoning that because the database had some password protection, however weak, using the hardcoded credential counted as circumvention (Socket; The Register). The Court of Appeal confirmed the conviction and the Federal Constitutional Court rejected the constitutional complaint.

What Modern Solution establishes

Not that German courts are hostile to research, but that facts practitioners consider obviously benign can support a conviction, that any aggrieved counterparty can start the sequence with a complaint, and that the process is the punishment. The €3,000 is irrelevant; the raid and the years are the exposure.

German firms operate on the narrow-intent reading of the 2009 Bundesverfassungsgericht decision declining to strike §202c (2 BvR 2233/07 and joined cases) [WEAK — reported at [security-insider](https://www.security-insider.de/dank-verfassungsgericht-endlich-klarheit-zum-hackerparagraph-202c-stgb-a-200138/); verify the citation before relying on it]. No German industry compliance standard, BSI safe harbour or trade-association guidance was found that meaningfully de-risks this. That absence is itself a finding.

The UK reform will probably not help

CMA 1990 s.3A criminalises making, supplying or obtaining articles for use in CMA offences, and an "article" includes "any program or data held in electronic form" (CPS). For the supply limb the prosecutor weighs whether the article was developed "primarily, deliberately and for the sole purpose" of offending, whether it is widely used legitimately — and whether distribution was "to a closed and vetted list of IT security professionals or was posted openly." That last factor is the most actionable sentence in the legal record: gated distribution is itself mitigating, which turns a misuse control into a legal one. Copy Daybreak's architecture and The corpus is the target are built on it.

On 13 May 2026 the government announced CMA reform in a National Security Bill, with a statutory defence for "good-faith cyber security activity" (The Record). Reporting from 25 May 2026 says the defence would be tied to chartered status with the UK Cyber Security Council — held by about 300 people out of ~69,600 UK cyber professionals, 0.4% — and would cover only internet-facing scanning, expressly excluding PoC exploit development and agentic AI tooling (TechTimes) [WEAK — outlet, and no bill text is published, so scope cannot be established]. If that holds, the reform excludes precisely the activity this business depends on.

Contractor jurisdiction is a parameter you choose

A Belgian or Polish contractor working under a written scope has materially better statutory footing than a Spanish or German one, and the difference costs nothing at the point where you decide where to recruit. It is the variable Where the supply can legally live treats as a cost question, seen from the legal side, and it argues against concentrating supply in Germany however deep the talent pool is. See Offensive supply for where the practitioners are and Operating from Europe, selling to the US for the wider case for operating from the EU.

Two further instruments shape the customers rather than the company. The Cyber Resilience Act Article 14 imposes 24-hour early warning, 72-hour notification and 14-day final reporting on manufacturers of products with digital elements, live from 11 September 2026 (Commission); a dataset is very likely not such a product, a hosted platform or agent very likely is [UNVERIFIED — a counsel question, because it decides whether you inherit 24-hour reporting duties]. NIS2 Article 12 mandates ENISA's European vulnerability database (NIS2). Neither is a safe harbour; both create demand, because every EU manufacturer now needs vulnerability-handling capability — a market for defensive data rather than offensive.

Next: Exploits are free, uploading is an export, where exploits turn out not to be controlled but uploading a file is an export.