Key Takeaways

  • The Computer Fraud and Abuse Act (18 U.S.C. § 1030) remains the federal government's primary weapon in cybercrime prosecutions, but the Supreme Court's landmark decision in Van Buren v. United States has fundamentally narrowed what constitutes "exceeds authorized access," giving defense counsel powerful new arguments to challenge indictments that overreach.
  • Federal cybercrime cases now routinely involve parallel civil investigations, multi-agency task forces, and cross-border evidence collection under the CLOUD Act — meaning a defense strategy must address Fourth Amendment challenges, international discovery disputes, and sentencing exposure simultaneously from day one.
  • Sentencing exposure under the CFAA can be staggering, with U.S. Sentencing Guidelines § 2B1.1 loss enhancements driving advisory ranges into double-digit years even for first-time offenders, making early loss-calculation challenges and competent guideline litigation absolutely critical to a successful defense outcome.
  • The DOJ's Computer Crime and Intellectual Property Section (CCIPS) has issued updated charging guidance as of mid-2026 that emphasizes prosecutorial discretion in cases involving security researchers, whistleblowers, and bona fide penetration testers, creating new avenues for pre-indictment advocacy and declination arguments.

In my 25 years as a federal prosecutor — and now in my second decade defending individuals and corporations against the very charges I once brought — I have watched the federal cybercrime landscape transform from a niche practice area into one of the most aggressive and technically complex prosecution environments in the entire Department of Justice. When I first handled computer intrusion cases at the U.S. Attorney's Office in the late 1990s, we were applying statutes written for telephone fraud to conduct involving dial-up modems and mainframe terminals. Today, the Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, anchors multi-defendant indictments alleging everything from ransomware deployment and cryptocurrency theft to the scraping of publicly accessible website data — conduct that many defendants genuinely believed was lawful at the time they engaged in it. The federal government now routinely charges cybercrime offenses alongside wire fraud under 18 U.S.C. § 1343, money laundering under 18 U.S.C. § 1956, and access device fraud under 18 U.S.C. § 1029, stacking counts in a manner that can produce sentencing exposure exceeding twenty or thirty years in a single indictment. For anyone facing a federal cybercrime investigation — whether you are a system administrator accused of exceeding authorized network access, a security researcher who inadvertently crossed a contractual boundary, or a business executive whose company is now the target of a multi-agency task force — the decisions you make in the first 48 hours after learning of the investigation will shape everything that follows for years to come.

What makes federal cybercrime defense uniquely demanding in July of 2026 is the convergence of three powerful forces that were not simultaneously present even five years ago. First, the Supreme Court's 2021 ruling in Van Buren v. United States, 593 U.S. ___, which held that the "exceeds authorized access" clause of § 1030(a)(2) applies only to information a defendant is not entitled to obtain — not to information obtained for an improper purpose — has continued to generate significant circuit-level litigation over its precise boundaries in cases involving employee data theft, API misuse, and terms-of-service violations. Second, the Department of Justice's Criminal Division has issued revised internal guidance through CCIPS that explicitly instructs prosecutors to consider whether a suspect's conduct involved good-faith security research, authorized penetration testing, or whistleblowing activity before seeking an indictment — a policy shift that opens meaningful doors for pre-charge advocacy but requires swift and sophisticated engagement with the government. Third, the passage of comprehensive federal data privacy legislation in late 2024 has created new statutory intersections with the CFAA, particularly around questions of what constitutes a "protected computer" when cloud services and IoT devices are involved. Each of these developments demands a defense attorney who not only knows the black-letter law of § 1030 but understands how to operationalize that knowledge in real time when agents are executing search warrants at a client's home or place of business.

I want to be direct with you about something that many law firm websites will not say plainly: federal cybercrime cases are rarely won through a single brilliant courtroom maneuver. They are won through relentless, detail-oriented pretrial litigation — motions to suppress under Federal Rule of Criminal Procedure 41, challenges to the particularity of warrant descriptions, vigorous contestation of loss calculations under U.S. Sentencing Guidelines § 2B1.1, and negotiations that exploit the government's own evolving internal guidance about what cases are truly worth prosecuting. In the sections that follow, I will walk you through the current state of CFAA defense as of mid-2026, explaining the legal doctrines that matter most right now, the procedural pressure points where federal prosecutors are most vulnerable, and the concrete steps you should be taking if you or your organization have been drawn into the federal cybercrime enforcement machinery. My perspective is informed by more than two decades on both sides of the aisle, and I will not sugarcoat the stakes: these are some of the most serious charges in the federal criminal code, and defending them requires a combination of technical literacy, constitutional law expertise, and strategic patience that many otherwise excellent criminal defense lawyers simply do not possess.

1. The Post-Van Buren Narrowing of "Exceeds Authorized Access" — And Where Prosecutors Are Still Finding Ways to Charge

When the Supreme Court handed down Van Buren in June 2021, many commentators in the defense bar declared that the "exceeds authorized access" prong of the CFAA had been effectively neutralized as a prosecutorial tool. In my experience, this optimism was both warranted and premature — warranted because the Court unequivocally rejected the broad reading that had allowed prosecutors to criminalize any use of a computer system that violated an employer's policy or a website's terms of service, but premature because creative prosecutors have adapted their charging theories in ways that often survive a motion to dismiss. The central holding of Van Buren — that an individual "exceeds authorized access" only when he or she accesses areas of a computer system, such as files, folders, or databases, to which the individual's access rights do not extend — was written by Justice Barrett in an opinion that emphasized the statute's "gates-up-or-down" logic. If the gate is open to you, you do not violate § 1030(a)(2) by walking through it, even if you do so with a forbidden purpose in mind. This represents a substantial doctrinal victory for defendants accused of violating computer use policies, acceptable use agreements, or terms of service where the underlying information was technically within the scope of their authorized system access.

However, federal prosecutors in 2026 have grown adept at recasting "exceeds authorized access" charges as "unauthorized access" charges under different CFAA subsections — or at bringing parallel charges under statutes that do not contain the same limiting language that the Supreme Court interpreted in Van Buren. For example, a prosecutor who previously might have charged an employee with exceeding authorized access to a company database under § 1030(a)(2) may now charge that same employee with accessing a different portion of the network entirely under § 1030(a)(4), framing the conduct as having been undertaken "knowingly and with intent to defraud." The distinction matters enormously because the elements of a § 1030(a)(4) violation do not turn on precisely the same authorization analysis that drove the Van Buren decision. Additionally, I have observed an increasing number of indictments that pair a narrow CFAA count with conspiracy charges under 18 U.S.C. § 371, wire fraud charges under § 1343, and — increasingly — theft of trade secrets charges under 18 U.S.C. § 1832, all of which can survive even when the CFAA count faces a serious Van Buren-based challenge. The practical lesson for defense counsel is that winning a motion to dismiss the § 1030 count may not meaningfully reduce the client's sentencing exposure if the government has built a multi-count indictment that does not depend on the "exceeds authorized access" theory to sustain multiple other felony charges.

The Department of Justice's mid-2026 charging guidance from CCIPS adds another layer to this analysis by explicitly directing prosecutors to evaluate whether the defendant's conduct involved accessing areas of a computer system that were clearly demarcated as off-limits through technical access controls — password gates, permission levels, network segmentation — rather than merely through contractual language or employee handbook provisions. This guidance, which I have successfully cited in pre-indictment correspondence with multiple U.S. Attorney's Offices this year, represents an important refinement of post-Van Buren prosecutorial practice that defense counsel should exploit aggressively during the investigatory phase. When an agent's affidavit in support of a search warrant relies heavily on terms-of-service violations rather than on evidence that the defendant bypassed an actual technical access barrier, there is now a strong argument — grounded in both Supreme Court precedent and the DOJ's own internal policy — that the case does not merit federal prosecution. Making this argument effectively requires detailed technical knowledge of the client's network architecture, precise mapping of the access controls that were actually in place, and a willingness to educate prosecutors about the difference between a contractual restriction and a genuine gate. In my practice, I have found that the sooner this education begins, the more likely it is that the government will either decline prosecution or accept a disposition that does not involve a felony CFAA conviction.

2. Fourth Amendment Terrain After the 2024 Electronic Communications Search and Seizure Amendments

One of the most significant — and, in my view, under-litigated — developments in federal cybercrime defense involves the amendments to Federal Rule of Criminal Procedure 41 that took effect in December 2024, which fundamentally altered the warrant requirements for searches of electronically stored information held outside the territorial jurisdiction of the United States. These amendments, which I have been tracking closely since they were first proposed by the Advisory Committee on Criminal Rules, effectively codify and expand the government's ability to obtain a Rule 41 warrant for remote access to computers located in foreign countries when the location of the target device has been "concealed through technological means." The practical effect is that federal agents can now obtain a single warrant from a magistrate judge in the Eastern District of Virginia or the District of Columbia that authorizes them to deploy network investigative techniques — essentially, specially crafted malware — against computers in multiple foreign jurisdictions without seeking mutual legal assistance from the host countries. This is an extraordinarily powerful investigative tool, and it raises Fourth Amendment questions that have not yet been fully resolved by the appellate courts, particularly around the particularity requirement and the means by which the government establishes probable cause to believe that a computer's location is being actively concealed.

In defending a client whose data was seized pursuant to one of these amended Rule 41 warrants, I believe defense counsel must mount a two-pronged challenge that attacks both the facial validity of the warrant application and the reasonableness of the search as executed. The facial challenge should focus on whether the government's assertion that the target device's location was "concealed through technological means" was supported by specific, non-conclusory factual allegations rather than boilerplate language about VPN usage or Tor routing. Almost every computer connected to the modern internet uses some form of network address translation or proxy service, and if the government's standard for "technological concealment" is set too low, then the amended Rule 41 warrant effectively becomes the default mechanism for all extraterritorial electronic searches — a result that I do not believe the Rule's drafters intended and that I would argue violates the principle that warrants must be supported by particularized probable cause. The execution challenge, meanwhile, should scrutinize the scope of the network investigative technique actually deployed, comparing the technical specifications described in the warrant application with the digital forensic evidence of what the government's tool actually did once it was deployed. I have retained independent digital forensic experts in multiple cases to conduct this comparison, and the results can be highly productive when the government's tool exceeded the scope of the judicial authorization — for example, by exfiltrating data from portions of the target device that were beyond the warrant's stated scope or by persisting on the device longer than the warrant permitted.

Additionally, the intersection of the CLOUD Act of 2018 and the amended Rule 41 creates a complex jurisdictional overlay that defense counsel must master in order to raise effective challenges. The CLOUD Act established a framework for bilateral executive agreements that allow U.S. law enforcement to directly request electronic evidence from service providers in signatory countries — the United Kingdom and Australia currently have operative agreements — while also giving U.S.-based providers the ability to challenge SCA warrants for data stored abroad. When a federal cybercrime investigation combines a CLOUD Act request to a cloud service provider with an amended Rule 41 warrant targeting the defendant's local devices, the defense must carefully analyze whether the government has inadvertently created a taint problem by allowing evidence obtained through the CLOUD Act process to influence the probable cause showing for the Rule 41 warrant. This is precisely the kind of complex, multi-jurisdictional suppression argument that can make the difference between a case proceeding to trial with devastating digital evidence and a case that collapses after a successful motion to suppress the central fruits of the search. In the current federal defense environment, fluency with both the CLOUD Act and the amended Rule 41 is no longer optional for competent cybercrime defense counsel — it is table stakes.

3. Sentencing Exposure and the Ongoing Battle Over Loss Calculation Under § 2B1.1

If there is one aspect of federal cybercrime defense that consistently shocks clients and their families when I first explain it, it is the sheer magnitude of sentencing exposure that can be generated by the loss calculation provisions of U.S. Sentencing Guidelines § 2B1.1. This single guideline section, which applies to the vast majority of CFAA offenses because they are classified as economic crimes, uses a loss amount table to determine the base offense level enhancement — and the table escalates with brutal speed. A loss calculation of just $40,000 triggers a six-level enhancement, while a loss of $250,000 triggers a twelve-level enhancement, and a loss exceeding $1.5 million adds sixteen levels to the base offense level. When you combine these enhancements with other adjustments for sophisticated means, use of special skill, number of victims, and obstruction of justice, a first-time offender with no criminal history can easily face an advisory Guidelines range of 97 to 121 months — essentially eight to ten years in federal prison — for conduct that involved no violence, no physical harm, and no traditional theft of tangible property. I have stood beside too many clients at sentencing hearings and watched federal district judges, bound by the advisory Guidelines framework and the mandatory factors of 18 U.S.C. § 3553(a), impose sentences that bore no rational relationship to the actual harm