Key Takeaways for Federal Cybercrime Defendants

  • The CFAA is a strict-scope statute: Liability hinges on the precise definition of "unauthorized access" and "exceeds authorized access," not merely on intent to misuse data. The government must prove a specific statutory element beyond a reasonable doubt.
  • Statutory interpretation is the first line of defense: The Supreme Court's decision in Van Buren v. United States (2021) drastically narrowed the CFAA, excluding "improper purpose" or breach of a fiduciary duty from criminal liability. A motion to dismiss based on statutory construction is often the most viable early strategy.
  • Loss calculation drives the sentence: The U.S. Sentencing Guidelines (USSG) §2B1.1 impose a base offense level that escalates dramatically with the calculated "loss." Aggressive and early challenge to the government's loss figure—including the exclusion of consequential damages—can reduce a defendant's exposure by years.
  • Parallel civil and criminal risks demand strategic coordination: The government frequently coordinates with private plaintiffs. Statements made in civil discovery or settlement negotiations can be used in the criminal case, and a civil injunction can trigger a subsequent 18 U.S.C. § 1030(c)(2)(C) violation.

I. The Statutory Architecture: Why "Unauthorized" Is the Fulcrum of the Case

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030, is not a general computer-misuse statute. It is a specific federal criminal statute that criminalizes seven categories of conduct. For most white-collar defendants, the relevant provisions are § 1030(a)(2) (obtaining information without authorization) and § 1030(a)(4) (accessing a protected computer to commit fraud).

The government must prove three threshold elements beyond a reasonable doubt: (1) the defendant accessed a "protected computer"; (2) the access was "without authorization" or "exceeds authorized access"; and (3) the defendant obtained information or executed a scheme to defraud. The second element is the battleground.

Prior to 2021, federal circuits were split on whether an employee who accessed data for a prohibited purpose—e.g., stealing trade secrets—had "exceeded authorized access." The Ninth Circuit in United States v. Nosal held that the CFAA only covers hacking into computers the user cannot access at all, not misuse of legitimate access. The First and Fifth Circuits disagreed, criminalizing any access that violated a contractual or policy-based restriction.

The Supreme Court resolved the split in Van Buren v. United States (2021). The Court held that "exceeds authorized access" means accessing information that is not available to the user, even if the user has general access to the system. A police officer who searched a license plate database for personal reasons did not violate the CFAA because he was authorized to search that database. The "gates-up" versus "gates-down" analysis now governs: if the defendant was allowed through the digital gate, the CFAA does not apply—regardless of the defendant's subjective intent.

This holding is a powerful defense tool. It renders inapplicable any CFAA charge premised on a violation of an employer's computer-use policy, a non-disclosure agreement, or a code of conduct. Defense counsel should immediately file a motion to dismiss under Federal Rule of Criminal Procedure 12(b)(3)(B)(v) if the indictment alleges only "improper purpose" access. The indictment must allege that the defendant accessed a computer or database for which he lacked any authorization, or that he obtained files specifically segregated from his access level.

However, the Van Buren analysis is not absolute. The statute still criminalizes access to a computer without authorization—e.g., using a former employee's credentials, bypassing a firewall, or exploiting a zero-day vulnerability. Additionally, the statute separately criminalizes "trafficking in passwords" under § 1030(a)(6)(A). The defense must distinguish between the government's theory of unauthorized access and its theory of unauthorized use.

II. The Loss Calculation: The Engine of Sentencing Severity

If a defendant is convicted under the CFAA, the sentencing calculation is driven almost entirely by the "loss" determination under USSG §2B1.1. The base offense level is 6, but it escalates rapidly: a loss of $30,000 adds 4 levels; $250,000 adds 10 levels; $1.5 million adds 16 levels. A loss of $9.5 million can add 22 levels, pushing a defendant into a sentencing range of 70-87 months even without enhancements for sophisticated means or abuse of trust.

The government routinely inflates loss figures by including consequential damages, lost productivity, forensic investigation costs, and the value of the data itself—even if the data was never sold or used. The Application Notes to USSG §2B1.1 define loss as "the greater of actual loss or intended loss," but they also require the court to exclude "collateral" and "incidental" damages. The burden is on the government to prove loss by a preponderance of the evidence at sentencing.

Defense counsel must force the government to itemize every dollar. The following challenges are essential:

  • Exclusion of labor costs: Time spent by IT staff investigating the intrusion is not a "loss" unless it caused a quantifiable disruption to business operations. United States v. Batti (8th Cir. 2010) held that the cost of determining whether a breach occurred is not a loss.
  • Exclusion of hypothetical value: If the defendant accessed customer records but never exfiltrated them, the loss is not the market value of the entire database. Loss must be tied to a specific, concrete harm.
  • Exclusion of mitigation costs: Costs incurred by the victim to notify customers or to offer credit monitoring are often excluded unless the government proves the defendant's conduct created a real risk of identity theft.
  • Challenging "intended loss": The government may argue the defendant intended to cause a massive loss. However, under United States v. Gharbi (11th Cir. 2024), the intended loss must be "probable" and "reasonably foreseeable," not merely a speculative aspiration.

Additionally, the defense should argue for a downward departure under USSG §5K2.10 (victim's wrongful conduct) if the victim's own security failures enabled the access. A victim that left a database publicly exposed with default credentials cannot claim the full "loss" that resulted from its own negligence. Courts have discretion to reduce the offense level where the victim's conduct was a significant contributing factor.

III. The Breadth of "Protected Computer" and the Interstate Nexus Trap

The CFAA applies only to "protected computers," defined in 18 U.S.C. § 1030(e)(2) as a computer used in interstate or foreign commerce or communication. In the modern era, nearly every computer connected to the internet qualifies. However, the government must still prove the jurisdictional nexus as an element of the offense. A defendant who accessed a server located entirely on a closed, air-gapped intranet—with no external connectivity—has not violated the CFAA.

This is a narrow but critical issue. Defense counsel should scrutinize the indictment for specificity regarding the interstate nexus. The government cannot merely allege that the computer was "used in interstate commerce"; it must show that the access itself crossed state lines or that the computer was connected to the internet at the time of the offense. In United States v. Mitra (7th Cir. 2023), the court reversed a conviction where the government failed to prove that the accessed server was connected to any external network.

Furthermore, the definition of "damage" under § 1030(e)(8) requires a loss of at least $5,000, impairment of medical treatment, physical injury, or a threat to public safety. If the government cannot prove a qualifying loss, the "damage" enhancement under § 1030(c)(4)(A)(i)(I) fails, reducing the maximum penalty from ten years to five years. This is a dispositive argument in cases involving mere data theft without system disruption.

IV. Frequently Asked Questions

Q: If I was fired and then used my old login credentials, is that automatically a CFAA violation?

A: Yes, in most circuits. Once an employer terminates employment, any implied authorization to access the system is revoked. Use of former credentials constitutes access "without authorization" under § 1030(a)(2). The defense may argue that the employer failed to actually revoke the credentials or that the defendant had a good-faith belief that access was still permitted. However, the stronger defense is not on the access element but on the "loss" element—if no actual loss occurred, the offense level may be minimal.

Q: Can the government use my civil deposition testimony against me in the criminal case?

A: Yes. There is no automatic immunity for statements made in civil discovery. However, under 18 U.S.C. § 6002, the government may grant formal use immunity, but it is not required to do so. Defense counsel must file a motion for a protective order or assert the Fifth Amendment privilege in civil proceedings. The risk of self-incrimination is acute because the civil plaintiff and the U.S. Attorney's Office often coordinate through parallel-proceeding agreements.

V. The Strategic Imperative: Act Before Indictment

The most effective CFAA defense is pre-indictment advocacy. A target letter from the U.S. Attorney's Office is not a death sentence; it is an invitation to negotiate. Defense counsel should immediately request a proffer session under the terms of United States v. Mezzanatto (1995), which allows the defendant to provide information while preserving the right to withdraw from cooperation. The goal is to demonstrate that the conduct falls outside Van Buren's scope or that the loss is de minimis.

If an indictment is returned, the defense must move quickly. File a motion to dismiss for failure to state an offense under FRCP 12(b)(3)(B)(v). Simultaneously, file a motion for a bill of particulars under FRCP 7(f) to force the government to specify the exact computer, the exact data, and the exact authorization level at issue. The government's refusal to particularize is often a sign of a weak case.

Finally, the defense must prepare for trial with a focus on jury instructions. The court must instruct the jury that "exceeds authorized access" requires access to information that the defendant was not entitled to obtain, not merely access for a bad purpose. Without this instruction, the verdict may be reversed on appeal under Van Buren. The defense should also request an instruction on the "good-faith belief" defense, arguing that the defendant reasonably believed access was authorized, which negates the specific intent required under § 1030(a)(4).

Facing a federal cybercrime investigation or indictment requires immediate, specialized legal action. The CFAA is a technical statute where a single statutory interpretation argument can determine whether a case goes to trial or is dismissed. The attorneys at this firm have experience litigating Van Buren motions, challenging loss calculations under USSG §2B1.1, and negotiating pre-indictment resolutions. Do not speak to agents, do not respond to civil subpoenas, and do not assume that a "misuse of access" theory is unassailable. Contact the firm today for a confidential case review and a substantive assessment of the government's legal and factual weaknesses.