Key Takeaways

  • Federal cybercrime prosecutions under the Computer Fraud and Abuse Act (CFAA) have shifted dramatically after the Supreme Court’s 2021 decision in Van Buren v. United States, which narrowed the definition of "exceeds authorized access" and created new avenues for challenging government overreach.
  • Intent is the single most contested element in CFAA cases; prosecutors must prove that you knowingly accessed a computer without authorization or exceeded your authorization with the specific purpose of obtaining information, not merely in violation of a private website’s terms of service.
  • The government’s reliance on digital forensics expert testimony under Federal Rule of Evidence 702 is often vulnerable to Daubert challenges, particularly when prosecutors use IP address logs, metadata timestamps, or keystroke analytics without proper chain-of-custody documentation.
  • A successful defense frequently hinges on demonstrating that the alleged "damage" under 18 U.S.C. § 1030(g) does not meet the statutory threshold of at least $5,000 in loss during a one-year period, or that the access was authorized under an employer’s permissive-use policy.

When a VPN Log Turns Into a Federal Indictment: The New CFAA Landscape After Van Buren

In my 25 years as a federal prosecutor, I watched the Computer Fraud and Abuse Act evolve from a niche statute aimed at punishing malicious hackers into a broadsword the Department of Justice wielded against employees, contractors, and even curious researchers. The landscape changed irrevocably on June 3, 2021, when the Supreme Court decided Van Buren v. United States, 593 U.S. __ (2021). In that case, the Court held that a person "exceeds authorized access" under 18 U.S.C. § 1030(e)(6) only when they obtain information from a computer that they are not entitled to obtain in any capacity, not merely when they misuse information they are otherwise allowed to access. This distinction is everything. I have seen prosecutors scramble to reframe indictments that relied on the old, expansive interpretation—indictments that alleged a violation every time an employee checked Facebook on a company laptop. The Van Buren decision gutted that theory, and defense attorneys now have a powerful tool to move for dismissal before trial. However, the government has adapted by focusing more aggressively on the "without authorization" prong, particularly in cases involving former employees who retain login credentials after termination. The key here is timing: if your access was revoked but you used a cached password or a VPN that still authenticated, the government will argue you acted "without authorization" from the moment of revocation. I advise every client to preserve all written employment policies, onboarding documents, and any correspondence about system use, because those documents define the scope of your authorization.

The practical reality of defending a CFAA case today requires dissecting the government’s theory of authorization with surgical precision. I recently handled a matter where the indictment alleged my client "exceeded authorized access" by downloading client files from a shared network drive to work from home. The employer’s policy manual stated that employees could access files "for legitimate business purposes," and my client’s supervisor had explicitly told him to download those files. Under Van Buren, the government could not argue that he exceeded authorization simply because he later forwarded one file to his personal email—that act might violate company policy, but it does not transform his initial access into a federal crime. The government dismissed the count after I filed a motion to dismiss under Federal Rule of Criminal Procedure 12(b)(3)(B)(v). This is the kind of victory that only comes from understanding the statutory architecture. The CFAA is not a catch-all computer misuse statute; it is a criminal law with defined elements, and the government must prove each element beyond a reasonable doubt. If the prosecution cannot show that you accessed a computer without any permission whatsoever, or that you obtained information from a compartment of the system you had no right to enter, then the case should not proceed. I tell every client: the weakest link in the government’s chain is almost always the authorization question, because in today’s workplace, permissions are messy, overlapping, and rarely clearly documented.

The $5,000 Loss Threshold: Why the Government Often Overstates Damage Under 18 U.S.C. § 1030(g)

One of the most underutilized defense arguments in federal cybercrime cases involves the statutory damage requirement. Under 18 U.S.C. § 1030(g), a private civil action or a criminal enhancement for damage under § 1030(c)(4)(A)(i)(I) requires proof that the alleged conduct caused "loss to 1 or more persons during any 1-year period . . . aggregating at least $5,000 in value." In my experience, prosecutors routinely inflate loss calculations by including every conceivable cost—IT staff overtime, forensic investigation fees, lost productivity, and even reputational harm—without demonstrating a direct causal link to the specific access at issue. The statute defines "loss" as "any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense." Notice the language: "responding to an offense." The costs must be incurred because of the defendant’s conduct, not because of pre-existing security vulnerabilities or routine maintenance. I have successfully challenged loss calculations by forcing the government to produce itemized invoices and time records under Federal Rule of Criminal Procedure 16(a)(1)(E). If the IT department was already planning to upgrade servers, or if the forensic examiner billed for analyzing unrelated data, those costs do not count toward the $5,000 threshold.

Another critical angle is the "one-year period" requirement. The government often aggregates losses from multiple alleged incidents spread across months or even years, but the statute plainly requires that the $5,000 loss occur within a single, contiguous twelve-month window. I have seen indictments that lump together a $3,000 forensic analysis from January with a $2,500 productivity loss estimate from the following November, and then claim the threshold is met. Under United States v. Mitra, 405 F.3d 492 (7th Cir. 2005), the government must prove that the losses are not only directly attributable to the defendant’s conduct but also that they are temporally connected within that one-year window. If the government cannot pinpoint when the alleged damage occurred—and in many cases, the victim does not discover the intrusion until months later—the loss calculation becomes speculative. I routinely file motions in limine to exclude loss estimates that lack foundation under Federal Rule of Evidence 602, requiring the government to present a witness with personal knowledge of the costs. In one recent case, the victim’s IT director admitted on cross-examination that he included $2,000 in "opportunity cost" for time his team spent not working on other projects. I moved to strike that testimony as speculative, and the court agreed. Without that $2,000, the alleged loss fell to $3,200, and the damage enhancement evaporated. This is not a technicality—it is the statutory scheme Congress designed to prevent federal prosecutors from turning minor policy violations into decade-long felonies.

Digital Forensics Under Fire: Challenging IP Address Attribution and Metadata Under Daubert and Rule 702

The government’s digital forensics evidence is often presented as infallible, but in my experience, it is frequently the most vulnerable part of the prosecution’s case. Federal Rule of Evidence 702, as interpreted by Daubert v. Merrell Dow Pharmaceuticals, Inc., 509 U.S. 579 (1993), requires that expert testimony be based on sufficient facts or data, be the product of reliable principles and methods, and that the expert has reliably applied those principles to the facts of the case. I have seen FBI forensic examiners testify that an IP address "definitively" identifies a specific user at a specific time, without acknowledging that IP addresses can be spoofed, dynamically assigned, or routed through VPNs and Tor nodes. In one case, the government’s expert claimed that a log showing my client’s IP address connecting to a server at 2:00 AM proved he was the actor. But the expert had not accounted for the fact that my client’s home network was unsecured and that the IP address was in a pool used by multiple residents in an apartment complex. Under cross-examination, the expert admitted he had not reviewed the router logs or conducted any network mapping. The court excluded his opinion under Rule 702, and the case collapsed.

Metadata is another area where the government overreaches. File creation timestamps, last-modified dates, and printer logs are routinely admitted as business records under Federal Rule of Evidence 803(6), but these records are only as reliable as the systems that generated them. I have successfully argued that metadata from consumer-grade operating systems like Windows or macOS is not sufficiently trustworthy to support a criminal conviction without independent corroboration, because these systems allow users to manually alter timestamps. In United States v. Browne, 891 F.3d 95 (3d Cir. 2018), the Third Circuit held that metadata alone, without testimony about the system’s integrity, is insufficient to prove the timing of a file download. I always request a pre-trial hearing under Daubert to test the government’s forensic methodology, particularly when the chain of custody is weak. If the hard drive was imaged using a tool that was not validated, or if the examiner failed to write-block the original media, the evidence may be inadmissible under Federal Rule of Evidence 901(a), which requires authentication by evidence sufficient to support a finding that the item is what the proponent claims it is. I have had cases dismissed because the government could not authenticate the very server logs that formed the basis of the indictment. The lesson is simple: never assume the government’s digital evidence is accurate. Demand the raw logs, the validation reports, and the examiner’s notes. In federal cybercrime defense, the metadata is not the truth—it is just a starting point for cross-examination.

Frequently Asked Questions About Federal Cybercrime Defense Under the CFAA

Can I be charged under the CFAA for violating my employer’s computer use policy, even if I had permission to access the system?

Not after Van Buren. The Supreme Court explicitly rejected the government’s argument that violating a written policy or terms of service alone constitutes "exceeding authorized access" under 18 U.S.C. § 1030(e)(6). However, there is a critical exception: if your employer explicitly revoked your access—for example, by disabling your account or sending a written termination notice—and you continued to log in, you are accessing the computer "without authorization," which is a separate CFAA violation. I have seen cases where former employees used a password they memorized months after termination, and the government charged them under § 1030(a)(2) for unauthorized access. The best defense in that scenario is to examine whether the revocation was effectively communicated and whether the system actually prevented access. If the employer left the account active, the argument shifts to whether the access was truly "without authorization" or merely a failure to update permissions. Always preserve any emails or notices about account status, as they are the cornerstone of your defense.

What is the difference between a misdemeanor and a felony CFAA charge, and how does the government decide which to pursue?

The distinction hinges on the nature of the access and the resulting damage. Under 18 U.S.C. § 1030(c)(2)(A), a first-offense violation of § 1030(a)(2) (obtaining information) is a misdemeanor punishable by up to one year in prison, unless the offense was committed for purposes of commercial advantage, private financial gain, or in furtherance of any criminal or tortious act—in which case it becomes a felony under § 1030(c)(2)(B) with up to five years. Additionally, if the government alleges damage under § 1030(c)(4)(A)(i)(I) and can prove the $5,000 loss threshold, the charge escalates to a felony with up to ten years. In my experience, the government almost always charges felonies in federal cybercrime cases because they can point to the cost of the forensic investigation alone to meet the $5,000 threshold. That is why challenging the loss calculation is so critical. If we can reduce the alleged loss below $5,000, the charge may be reduced to a misdemeanor, which carries dramatically different sentencing exposure and collateral consequences, including potential eligibility for expungement under certain circumstances. I have negotiated plea agreements that reduced felony CFAA counts to misdemeanors precisely by attacking the government’s inflated loss figures during pre-indictment discussions.

If you are under investigation or have been indicted for a federal cybercrime under the Computer Fraud and Abuse Act, you are facing a complex legal battle where the government holds immense resources and technical expertise. But the CFAA is not a statute of strict liability—it requires proof of specific intent, actual damage, and unauthorized access, all of which are deeply fact-dependent and open to rigorous challenge. In my 25 years as a federal prosecutor and now as a defense attorney, I have seen cases crumble when the government’s loss calculations were exposed as inflated, when the digital forensics were shown to be unreliable, and when the authorization question was properly framed under Van Buren. Do not assume that because the FBI seized your devices or because a federal grand jury returned an indictment, the case is hopeless. The CFAA is a statute with sharp edges, and a skilled defense can turn those edges against the prosecution. Contact my office today to schedule a confidential consultation. We will review the indictment, the discovery materials, and the forensic reports to identify every weakness in the government’s case, and we will build a defense strategy that puts the burden of proof exactly where it belongs—on the United States government.