Cyber Crime: CFAA Penalties, Stacked Charges, and Forfeiture

Federal cyber crime laws and penalties center on the Computer Fraud and Abuse Act, but prosecutors rarely stop there. A single hacking or online fraud case can pull in wire fraud, identity theft, access device fraud, and electronic surveillance statutes, with prison exposure that runs from one year at the low end to life imprisonment when someone dies as a result of the attack. Asset forfeiture, mandatory consecutive sentences, and civil suits from victims stack on top of the prison term.

The Computer Fraud and Abuse Act

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. 1030, is the federal government’s primary tool for prosecuting computer offenses. It reaches unauthorized access, data theft, intentional damage to systems, and computer-based extortion. Its jurisdictional hook is broad: any computer used in or affecting interstate or foreign commerce or communication qualifies as a “protected computer,” including computers outside the United States if the conduct affects U.S. commerce.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers In practice that captures nearly every laptop, server, phone, and cloud instance in commercial use.

The statute is divided into seven subsections. The provisions charged most often are (a)(2) unauthorized access to obtain information, (a)(4) fraud through unauthorized computer use, (a)(5) intentionally causing damage to a protected computer, and (a)(7) threats and extortion demands, which is the provision used against ransomware operators. A separate provision, (a)(1), targets unauthorized access to restricted government data tied to national defense or foreign relations and carries steeper penalties.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers

CFAA Prison Exposure by Offense

Sentencing under the CFAA depends on which subsection applies, whether the conviction is a first or repeat offense, and how much financial loss or damage resulted. The ceilings escalate sharply for repeat offenders, and one subsection reaches life imprisonment.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers

  • Unauthorized access to obtain information: up to 1 year for a basic first offense. The maximum rises to 5 years if the offense was committed for financial gain, to further another crime, or if the value of the information exceeded $5,000. A repeat conviction carries up to 10 years.
  • Computer fraud: up to 5 years for a first offense, up to 10 years for repeat offenders.
  • Intentional damage to a protected computer: up to 10 years for a first offense, up to 20 years for a subsequent conviction. If the damage knowingly or recklessly causes death, the sentence can run to any term of years or life.
  • Extortion and ransomware threats: up to 5 years for a first offense; a repeat conviction doubles the ceiling to 10 years.
  • Accessing restricted government data: up to 10 years for a first offense, up to 20 years for a second.

The life-imprisonment provision is the outer boundary of CFAA exposure. If someone intentionally transmits malicious code that damages a protected computer and a person dies as a result, the statute authorizes any term of years up to life. A ransomware attack that shuts down hospital systems and leads to a patient’s death is the scenario Congress had in mind.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers

When Using a Computer You Are Allowed to Use Becomes a Crime

The Supreme Court narrowed the CFAA in Van Buren v. United States (2021). The Court held that someone “exceeds authorized access” only when they reach files, folders, or databases their permissions do not cover. Using an authorized computer for an unauthorized purpose does not violate the statute. A contrary reading, the Court wrote, “would attach criminal penalties to a breathtaking amount of commonplace computer activity.”2Supreme Court of the United States. Van Buren v. United States (2021)

The practical line: an employee who checks social media on a work computer against company policy is not committing a federal crime. That same employee who logs into a restricted customer database they have no permission to view is.

Charges Prosecutors Stack on Top of the CFAA

Most federal cyber prosecutions carry more than one count. Several companion statutes match or exceed the CFAA’s ceilings, and one of them adds mandatory prison time on top of whatever else is imposed.

Wire Fraud

Wire fraud under 18 U.S.C. 1343 covers any scheme to defraud that uses electronic communications, which captures phishing, business email compromise, and cryptocurrency fraud. The maximum is 20 years in prison. If the fraud targets or affects a financial institution, the ceiling rises to 30 years and the fine can reach $1 million.3Office of the Law Revision Counsel. 18 US Code 1343 – Fraud by Wire, Radio, or Television

Identity Theft and Aggravated Identity Theft

Base identity theft under 18 U.S.C. 1028 covers producing, transferring, or using someone else’s identifying information for fraud. Penalties range from 5 years for a basic offense up to 15 years when the fraud involves a government-issued ID or when the offender obtains $1,000 or more in value. Identity theft that facilitates drug trafficking or a violent crime reaches 20 years, and a terrorism connection carries up to 30 years.4Office of the Law Revision Counsel. 18 US Code 1028 – Fraud and Related Activity in Connection With Identification Documents, Authentication Features, and Information

Aggravated identity theft under 18 U.S.C. 1028A is where most data-breach defendants accumulate serious time. Using someone else’s identity during specified felonies, including computer fraud, wire fraud, and mail fraud, triggers a mandatory 2-year prison sentence that runs consecutively to the sentence for the underlying crime. It cannot be reduced or served concurrently. If the predicate offense is terrorism-related, the consecutive add-on is 5 years.5Office of the Law Revision Counsel. 18 USC 1028A – Aggravated Identity Theft

Access Device Fraud

Stolen credit card numbers, cloned debit cards, compromised account credentials, and hacked PINs all qualify as “access devices” under 18 U.S.C. 1029. First offenses carry up to 10 or 15 years depending on the conduct; repeat offenders face up to 20 years. Conspirators are subject to up to half the maximum for the underlying offense, and property used in the crime is subject to forfeiture.6Office of the Law Revision Counsel. 18 US Code 1029 – Fraud and Related Activity in Connection With Access Devices

Wiretap Act and Stored Communications Act

The Wiretap Act at 18 U.S.C. 2511 criminalizes intentionally intercepting electronic communications in transit, which covers packet sniffers, man-in-the-middle attacks, and keystroke loggers. The maximum is 5 years.7Office of the Law Revision Counsel. 18 USC 2511 – Interception and Disclosure of Wire, Oral, or Electronic Communications Prohibited The Stored Communications Act at 18 U.S.C. 2701 covers unauthorized access to communications sitting on a server rather than moving across a wire, such as breaking into an email provider and reading stored messages. A first offense committed for financial gain or to further another crime carries up to 5 years; repeat offenses reach 10 years.8Office of the Law Revision Counsel. 18 US Code 2701 – Unlawful Access to Stored Communications

Cyberstalking

Federal cyberstalking under 18 U.S.C. 2261A criminalizes using the internet or any electronic communication service to engage in conduct that places a person in reasonable fear of death or serious injury, or that causes substantial emotional distress. The interstate element is satisfied by virtually all internet-based harassment. Sentences are set under the domestic violence sentencing provisions and vary with the harm caused.9Office of the Law Revision Counsel. 18 USC 2261A – Stalking

Forfeiture and Civil Liability

Federal law lets the government seize property connected to cyber crime. Under 18 U.S.C. 981, any real or personal property that constitutes or is derived from the proceeds of computer fraud (Section 1030) or access device fraud (Section 1029) is subject to civil forfeiture.10Office of the Law Revision Counsel. 18 US Code 981 – Civil Forfeiture Cryptocurrency wallets, bank accounts, and vehicles traceable to the offense can be taken before a criminal conviction. For defendants who profited from the conduct, forfeiture often exceeds any fine.

The CFAA also creates a private right of action. Individuals and businesses harmed by covered conduct can sue for compensatory damages and injunctive relief, but the claim must involve at least $5,000 in loss over a one-year period (or meet one of the other qualifying factors), and the suit must be filed within 2 years of the act or the discovery of the damage. Damages for losses below the threshold are limited to economic losses, and the statute explicitly excludes claims based on negligent hardware or software design.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers

How Long the Government Has to Charge You

Most CFAA prosecutions fall under the general 5-year federal criminal statute of limitations, measured from the last criminal act. Cases involving major fraud exceeding $1 million against the federal government can extend to 7 years. Civil claims under the CFAA carry the shorter 2-year window from the act or its discovery.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers

State Charges and Overlap With Federal Prosecution

Every state has its own computer crime statute, typically labeled computer trespass, unauthorized computer access, or electronic data tampering. Felony-level computer crimes in most states carry sentences that can reach 5 to 10 years for serious offenses involving significant loss or damage, with fines scaled to the value stolen or the damage caused. Some states impose enhanced penalties for offenses against critical infrastructure or healthcare systems. State limitations periods for computer felonies generally run 2 to 5 years, and some states start the clock at discovery rather than the date of the offense, which matters when an intrusion goes undetected for months.

Federal and state prosecutors sometimes pursue the same conduct, though they usually coordinate. Federal charges dominate when the crime crosses state lines, involves large sums, or targets federal systems; state charges tend to cover localized offenses where perpetrator and victim are in the same jurisdiction. Because the internet’s architecture involves interstate commerce almost by default, federal jurisdiction attaches in most cyber cases, and a business server holding out-of-state customer data is enough to bring the CFAA’s “protected computer” definition into play.1Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers