Key Takeaways for Federal Cybercrime Defendants
  • The Computer Fraud and Abuse Act (18 U.S.C. § 1030) is a federal statute with seven distinct subsections, each carrying different penalties up to 20 years for repeat offenders; the specific charge dictates the entire defense posture.
  • The government must prove "intentional" access without authorization or in excess of authorization, but recent Supreme Court precedent in Van Buren v. United States (2021) has narrowed the scope of what constitutes "exceeds authorized access," creating a powerful motion-to-dismiss tool.
  • Loss calculation under USSG § 2B1.1 is the single most critical sentencing battleground; a $5,000 loss threshold triggers felony exposure, and sophisticated means enhancements can double the offense level.
  • Early engagement with Rule 16 discovery and Rule 41 search warrant challenges is essential—many CFSA cases collapse when the government cannot authenticate its own digital evidence or when forensic images were obtained through defective warrants.

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030, remains the primary federal weapon against unauthorized computer access. A conviction under this statute carries severe consequences, including lengthy prison terms, substantial fines, and mandatory restitution. The statute's complexity—coupled with rapidly evolving case law—demands a rigorous, technical, and proactive defense from the very first interview.

Defendants facing CFAA charges should understand that this is not a typical white-collar defense. The government's case is built on digital artifacts: logs, IP addresses, metadata, and forensic images. The defense must be equally technical, challenging the integrity of that evidence while simultaneously attacking the statutory elements. The following analysis outlines the critical components of a modern CFAA defense.

Deconstructing "Authorization" Post-Van Buren: The New Gatekeeping Defense

The CFAA criminalizes two distinct forms of access: (1) accessing a computer without authorization, and (2) accessing a computer with authorization but exceeding the authorized scope. For years, prosecutors stretched the "exceeds authorized access" prong to cover any violation of a website's terms of service or a company's computer usage policy. That era ended with the Supreme Court's decision in Van Buren v. United States, 593 U.S. 374 (2021).

In Van Buren, the Court held that a person "exceeds authorized access" only when they access information they are not entitled to obtain—not when they access information for an improper purpose. The Court adopted a "gates-up-or-down" approach: if the user has permission to access the specific files or database, the access is authorized regardless of the user's subjective intent. This decision gutted the government's ability to criminalize policy violations.

Defense counsel must immediately scrutinize the indictment to determine whether the charged conduct rests on a Van Buren-violative theory. If the government alleges that the defendant accessed files they were permitted to access but did so for a prohibited reason (e.g., stealing trade secrets to benefit a competitor), the indictment is legally insufficient. A motion to dismiss under Federal Rule of Criminal Procedure 12(b)(3)(B)(v) should be filed, arguing that the indictment fails to state an offense as a matter of law.

However, the defense must be careful. Van Buren does not protect the defendant who bypassed technical barriers, used stolen credentials, or exploited a known vulnerability. The distinction between "without authorization" and "exceeds authorized access" remains critical. The former involves no permission at all; the latter involves permission to some data but not other data. The defense should move to compel the government to specify, with particularity, which exact data files the defendant was prohibited from accessing.

Strategic Note: A Van Buren motion is not merely a pre-trial formality. It forces the government to articulate its theory of unauthorized access. If the theory is "the defendant violated the employee handbook," the case is over. If the theory is "the defendant used a credential to enter a server room they were never granted access to," the defense must pivot to a factual challenge regarding the scope of that credential.

Loss Calculation and the USSG § 2B1.1 Trap: Battling the Government's Numbers

No aspect of a CFAA case is more consequential than the loss calculation. Under 18 U.S.C. § 1030(c)(4)(A)(i)(I), a felony conviction requires either (a) a loss exceeding $5,000, (b) access affecting a financial institution, (c) a threat to public health or safety, or (d) access to a government computer. In practice, most federal prosecutions rely on the $5,000 loss threshold. Once that threshold is crossed, the Sentencing Guidelines calculate the offense level based on the total loss under USSG § 2B1.1.

The government frequently inflates loss figures to include speculative costs: lost productivity, forensic investigation fees, brand damage, and hypothetical future losses. Defense counsel must challenge every dollar. The Guidelines define "loss" as the greater of the actual loss or the intended loss, but the loss must be reasonably foreseeable. The commentary to § 2B1.1 explicitly excludes "costs incurred by the victim in attempting to restore the computer system" unless those costs are "necessary" and "directly related" to the offense.

A rigorous loss challenge requires a forensic accounting expert. The defense should demand, under Rule 16(a)(1)(E), all underlying documentation supporting the government's loss figure. This includes time sheets from IT personnel, invoices from forensic vendors, and any internal cost-allocation memos. Frequently, these documents reveal that the "loss" includes routine maintenance, unrelated security upgrades, or overtime pay that would have been incurred regardless of the alleged offense.

The sentencing stakes are enormous. A loss of $5,001 triggers a base offense level of 6 under USSG § 2B1.1(a)(2). A loss of $550,000 increases the offense level by 14 points. Additionally, the government often seeks a two-level "sophisticated means" enhancement under § 2B1.1(b)(18)(C), arguing that the defendant used advanced techniques to conceal the offense. This enhancement is frequently inappropriate in cases involving simple password guessing or basic SQL injection—techniques that are not "especially complex or especially intricate."

  • Challenge the "actual loss" calculation: Demand proof that every dollar claimed was actually paid or actually lost, not merely estimated.
  • Attack the "intended loss" theory: If the defendant could not have plausibly achieved the alleged intended loss, the court must reject the government's speculative figure.
  • Litigate the "sophisticated means" enhancement: The government must prove the conduct was "especially complex" relative to typical offenses of the same type—not merely that the defendant used a computer.
  • File a pre-trial motion to determine loss: Under Rule 12(b)(3)(B)(v), the defense can seek a pre-trial ruling that the loss does not exceed $5,000, which would eliminate felony exposure entirely.

Defense counsel should also scrutinize the government's choice of charging subsection. A violation of § 1030(a)(2)(C) (obtaining information from a protected computer) carries a lower maximum penalty than § 1030(a)(4) (access with intent to defraud). If the government indicted under (a)(4) but the evidence only supports (a)(2)(C), a motion to dismiss or a jury instruction on the lesser-included offense is appropriate.

Forensic Evidence Challenges: The Rule 41 and Rule 16 Battleground

CFAA cases are won or lost on the admissibility of digital evidence. The government typically obtains evidence through a Rule 41 search warrant authorizing the seizure of computers, servers, or cloud accounts. Defense counsel must obtain the warrant application and affidavit immediately. Suppression motions under Rule 12(b)(3)(C) should be filed where the warrant lacked probable cause, failed to describe the items to be seized with particularity, or was executed in an overbroad manner.

A critical issue arises with the particularity requirement. Many warrants authorize the seizure of "all electronic devices" and "all digital media" from a premises, which courts often find impermissibly overbroad. The Fourth Amendment requires that warrants describe the items to be seized with sufficient specificity to prevent a general, exploratory search. If the government conducted a forensic examination of a device beyond the scope of the warrant's authorized data categories, the exclusionary rule may apply.

Beyond suppression, the defense must challenge the government's forensic methodology under Daubert. The government will present an FBI Computer Analysis Response Team (CART) examiner or a private forensic expert to testify about the evidence. The defense must retain its own expert to review the forensic images, the hash values, the chain of custody, and the examination logs. Common errors include improper write-blocking, failure to preserve metadata, and the use of outdated forensic tools that produce unreliable results.

Under Rule 16(a)(1)(F), the government must produce any expert witness summary that will be used at trial. The defense should move to compel the production of the examiner's raw notes, the validation reports for the software used, and the complete chain of custody documentation. If the government cannot produce these items, a motion in limine to exclude the expert's testimony should be filed.

Another powerful defense tool is the "attorney's eyes only" review of the seized data. The defense may need to review the actual data on the seized devices to determine whether the defendant had authorization to access certain files. Courts frequently grant protective orders under Rule 16(d)(1) that allow defense counsel and experts to review the data while protecting the victim's proprietary information. This review often reveals that the "victim" had no reasonable expectation of privacy in the data at issue, or that the data was publicly accessible, thereby defeating the "protected computer" element.

Frequently Asked Questions

Q: If the company's terms of service prohibited the defendant's actions, does that automatically mean the defendant violated the CFAA?

No. Under Van Buren, a violation of a terms-of-service agreement does not, by itself, constitute "exceeding authorized access." The government must prove the defendant accessed files or data that were off-limits, not merely that the defendant used authorized access for an improper purpose. The defense should move to dismiss any indictment that relies solely on a policy violation theory.

Q: Can the government use the CFAA to prosecute an employee who downloads client lists before leaving to work for a competitor?

Potentially, yes, but only if the employee accessed a specific database or folder that was explicitly restricted. If the employee had routine access to the client list as part of their job duties, the Van Buren "gates-up" analysis applies: the access was authorized, and the government cannot criminalize the employee's intent. The prosecution would instead need to pursue trade secret theft under the Economic Espionage Act (18 U.S.C. § 1831) or a breach of fiduciary duty theory, which carry different elements and burdens.

Q: What is the most common mistake defendants make before consulting counsel?

Speaking with law enforcement agents without an attorney present. Federal agents are trained to elicit statements that can later be used to establish "intent" or "knowledge." Even a benign statement like "I thought I had permission" can be used to argue the defendant knew the access was unauthorized. The Fifth Amendment right to remain silent is absolute; defendants should invoke it and immediately seek counsel.

Immediate Action Required: The Defense Must Begin Now

A CFAA charge is a serious, life-altering event, but it is not a foregone conclusion. The defense must act immediately to preserve evidence, challenge the government's legal theories, and prepare for sentencing mitigation. Delays are fatal—warrants become stale, witnesses become unavailable, and the government's loss calculations become entrenched. The firm's approach is comprehensive: attack the statute's elements, challenge the forensic evidence, and negotiate from a position of technical strength. Any individual facing a CFAA investigation or indictment should retain experienced federal criminal defense counsel immediately. The time to act is before the government locks in its narrative—not after.