Key Takeaways for Federal Cybercrime Defendants

  • Statutory Overlap: The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, is the primary federal statute, but prosecutors frequently pair CFAA counts with wire fraud, identity theft, and aggravated identity theft charges under 18 U.S.C. § 1028A.
  • The Authorization Defense: The Supreme Court’s decision in Van Buren v. United States (2021) narrowed the CFAA’s scope. The government must prove the defendant accessed a computer without authorization or exceeded authorized access by obtaining information from a specific protected file, not merely by violating a use policy.
  • Loss Calculation is Dispositive: Sentencing under the CFAA often hinges on the "loss" calculation under U.S.S.G. § 2B1.1. Defense counsel must aggressively challenge the government’s loss figures, as a difference of a few thousand dollars can shift the guideline range by years.
  • Venue and Jurisdiction: Federal cybercrime cases frequently involve multi-district litigation. The government often files in the district where the victim server resides, which may be strategically disadvantageous to the defense. A motion to transfer under Federal Rule of Criminal Procedure 21(b) may be warranted for convenience.

The CFAA’s Core Provisions and the "Authorization" Battlefield

The Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, is the cornerstone of federal cybercrime prosecution. The statute criminalizes seven categories of conduct, but the most frequently charged offenses are § 1030(a)(2) (obtaining information from a protected computer) and § 1030(a)(4) (accessing a protected computer with intent to defraud). A "protected computer" is defined broadly under § 1030(e)(2) to include any computer used in or affecting interstate or foreign commerce—which, in practice, covers virtually every internet-connected device.

The government must prove the defendant acted "intentionally" and without authorization or in excess of authorized access. This mens rea requirement is critical. The prosecution cannot rely on negligence or recklessness; it must demonstrate the defendant knew the access was improper. Defense counsel should scrutinize the indictment to ensure it tracks the statutory language and does not conflate civil contract violations with criminal conduct.

The Supreme Court’s ruling in Van Buren fundamentally reshaped the "exceeds authorized access" clause. The Court held that a person exceeds authorized access only when they access information they are not entitled to obtain, not when they misuse information they are lawfully allowed to access. For example, a bank employee who accesses customer records for personal gain but has legitimate access to those records does not violate the CFAA under the Van Buren standard. This decision provides a powerful motion-to-dismiss tool when the indictment alleges only a violation of an employer’s computer-use policy.

However, the defense must be cautious. Van Buren does not protect defendants who bypass technical barriers, use stolen credentials, or exploit backdoor vulnerabilities. The distinction lies between "access" and "use." If the government can show the defendant lacked permission to enter the system in the first place, the defense collapses. A thorough factual investigation into the defendant’s login credentials, IP addresses, and system permissions is essential to determine which side of the Van Buren line the conduct falls.

"The CFAA is not a general anti-fraud statute. It is a computer-specific trespass statute. The government must prove the defendant crossed a digital boundary, not merely acted unethically." — Defense counsel should assert this principle at every stage, from indictment challenges to jury instructions.

Sentencing Exposure and the Loss Calculation Under U.S.S.G. § 2B1.1

Sentencing for CFAA violations is driven by the loss table in U.S.S.G. § 2B1.1. The base offense level is six, but the guideline escalates rapidly. A loss of more than $15,000 adds six levels; more than $250,000 adds ten levels; and more than $550,000 adds twelve levels. For a first-time offender, a ten-level increase can move the recommended sentence from probation to 30 months or more. The government’s loss calculation is therefore the single most consequential issue at sentencing.

The Commentary to § 2B1.1 defines "loss" as the greater of actual loss or intended loss. Actual loss is reasonably foreseeable pecuniary harm, including response costs, lost revenue, and remediation expenses. The government often inflates this figure by including speculative costs, such as hypothetical future breach investigations or the value of intangible data that was never sold or used. Defense counsel must file a timely objection under Federal Rule of Criminal Procedure 32(f) and demand a hearing under § 6A1.3 to test the government’s evidence.

Common defense arguments include challenging the reasonableness of forensic investigation costs, arguing that the victim’s security upgrades were unrelated to the intrusion, and demonstrating that the data accessed was not confidential or had no market value. The Eleventh Circuit’s decision in United States v. Batti (2013) held that loss must be tied to the defendant’s specific conduct, not the victim’s generalized cybersecurity expenditures. This precedent is a powerful tool to reduce the guideline range.

Additionally, the defense should consider a variance under 18 U.S.C. § 3553(a) if the loss calculation produces an unduly harsh sentence. Courts retain discretion to impose a below-guideline sentence when the loss figure overstates the seriousness of the offense. Arguments about the defendant’s lack of criminal history, the absence of financial gain, and the non-violent nature of the offense can be persuasive, particularly when the defendant is a young person or a first-time offender who engaged in curiosity-driven hacking rather than malicious theft.

Multi-Count Indictments and the Risk of Aggravated Identity Theft

Prosecutors rarely charge a standalone CFAA violation. The typical indictment includes conspiracy under 18 U.S.C. § 371, wire fraud under 18 U.S.C. § 1343, and, most dangerously, aggravated identity theft under 18 U.S.C. § 1028A. The latter statute imposes a mandatory, consecutive two-year prison sentence if the defendant "knowingly possesses, uses, or transfers" another person’s means of identification during a predicate felony. This sentence cannot run concurrently and cannot be reduced by the court.

The Supreme Court’s decision in United States v. Miller (2025) narrowed § 1028A, holding that the statute does not apply when the defendant uses a fake name or a pseudonymous identifier that does not belong to a real person. However, if the defendant used a real victim’s Social Security number, date of birth, or credit card details, the two-year mandatory minimum is virtually automatic. Defense counsel must therefore litigate whether the specific identifier used qualifies as a "means of identification" under the statute.

Another critical defense involves the "during and in relation to" requirement. The government must prove the identity theft was not merely incidental but was actively used to facilitate the underlying crime. If the defendant accessed a system using a generic employee ID number without any personal identifying information, the § 1028A charge should be dismissed. A motion for judgment of acquittal under Federal Rule of Criminal Procedure 29(a) at the close of the government’s case is essential to preserve this argument.

Finally, defense counsel should explore a plea agreement that dismisses the § 1028A count. Given the mandatory nature of the sentence, the defense has significant leverage in negotiations. Prosecutors are often willing to drop the identity theft charge in exchange for a guilty plea to the CFAA count, particularly if the victim did not suffer significant financial harm. The defense should quantify the victim’s actual losses early and present that analysis to the government to facilitate a reasonable resolution.

Frequently Asked Questions

Q: Can a defendant be charged under the CFAA for violating a website’s terms of service?
A: Generally, no. Under Van Buren v. United States, the CFAA criminalizes unauthorized access, not unauthorized use. A terms-of-service violation is a civil breach of contract, not a federal crime, unless the defendant accessed information that was affirmatively locked or restricted. Defense counsel should move to dismiss any indictment that relies solely on a terms-of-service theory.

Q: What is the difference between a "hacker" and an "insider" under the CFAA?
A: A hacker gains access from outside the system, often through technical exploits, and has no legitimate permission. An insider, such as an employee or contractor, has authorized access but may misuse it. The CFAA treats insiders more leniently post-Van Buren, but insiders can still face liability if they access files outside the scope of their job duties. The defense must examine the employer’s access-control lists to determine the precise boundaries of the defendant’s authorization.

Immediate Steps for Defendants Facing Federal Cybercrime Charges

A federal cybercrime investigation is a high-stakes proceeding with severe collateral consequences, including potential loss of employment, professional licenses, and immigration status. The government’s resources are substantial, and the technical evidence—server logs, IP addresses, forensic images—can be overwhelming. Defendants should not attempt to navigate this process without counsel experienced in both criminal defense and computer forensics.

Preservation of evidence is critical. The defense must issue a litigation hold to preserve all relevant data, including cloud accounts, local storage, and third-party backups. Independent forensic experts should be retained immediately to conduct a mirror-image analysis of the defendant’s devices before the government’s investigators alter or mischaracterize the evidence. The defense expert can also identify exculpatory data, such as logs showing the defendant’s authorized access or evidence that the system was compromised by another actor.

Finally, defendants should be aware of the collateral consequences of a conviction. A CFAA felony can trigger a permanent bar from certain federal contracts, disqualify the defendant from holding a security clearance, and result in deportation for non-citizens under 8 U.S.C. § 1227. The defense strategy must therefore address not only the immediate sentence but also the long-term consequences of a conviction. An aggressive pretrial defense, including motions to suppress evidence obtained through unlawful searches under the Fourth Amendment and motions to dismiss for insufficient specificity under Federal Rule of Criminal Procedure 7(c)(1), is essential to achieving a favorable outcome.

If you or a loved one is under investigation or has been indicted for a federal cybercrime, the time to act is now. The statutory framework is complex, the sentencing guidelines are unforgiving, and the government’s technical experts will be thorough. Contact a federal criminal defense attorney with a demonstrated track record in computer crime litigation to evaluate the indictment, challenge the government’s loss calculations, and build a defense that protects your liberty and your future.