ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
2 AUG 2026 · UPDATED 20 AUG 2026 · 15 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: UNCATEGORIZED
DOCKET NO. 591 · THE DEFENSE DESK

Attribution Defenses: Proving Someone Else Used the Device.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

Q: An IP address connects me to the internet. That means the prosecutors have a record of me committing the crime, right?

A: No. An IP address identifies a network connection to the Internet. It identifies the device making the connection, but not who is using the device.

Q: But the prosecutors say that a criminal login used my account credentials. They can use that to prove that I was the one behind the computer, can’t they?

A: No. Credentials prove that a person logged into your account, not that the person logged in was you.

Q: Will it be up to my defense lawyer to prove that it wasn’t me?

A: No. In criminal cases, it’s up to the prosecutors to prove every element of the crime beyond a reasonable doubt. Your lawyer can challenge the prosecutors’ evidence, but your lawyer doesn’t have to prove your innocence.

Q: What kind of evidence do you need to prove coordination between a defendant and their co-defendant?

A: That will depend on the specifics of each case. However, evidence of coordination will often include messages discussing targets, scripts, or the timing of posts. In some cases, it can even be as simple as two people operating a computer from the same house.

Q: What is the computer fraud law in Pennsylvania?

A: In Pennsylvania, computer crimes are governed by Chapter 76 of the Pennsylvania Crimes Code, and 18 Pa.C.S. § 7611 defines the offense of unlawful use of a computer. A separate statute, 18 Pa.C.S. § 4106, defines the offense of access device fraud. An access device is anything with data, such as a card, code, account number, or PIN, that authorizes access to real or electronic funds. Under Pa.C.S. § 4106, access device fraud is a state offense that requires a person to knowingly use an unauthorized or invalid access device.

Does owning the device prove I sent the message?

Q: Does owning the device or the account prove that I committed the crime?

A: Ownership is not a defense in all circumstances. For example, if you use your computer or smartphone to commit a crime, owning the device is not a defense. However, device ownership is not a replacement for evidence showing that you committed the offense. Your device ownership, account control, and authorship of the transaction or message are all separate attribution questions.

Q: Can my account credentials prove that I committed the crime?

A: No. A named account holder is not always the account operator. Even if a transaction was made using your account, prosecutors must show that you also committed the act.

Q: Will a mistaken identity defense prove my innocence?

A: The mistaken identity defense can be used to challenge a defendant’s liability. If a defendant wins on this defense, it means the defendant did not commit the offense. However, the mistaken identity defense can also be used to challenge a defendant’s liability. If a jury accepts the mistaken identity defense, it may find that the defendant is not liable even though it may think the defendant was involved in the criminal act.

Q: What is the mistaken identity defense?

A: A mistaken identity defense is available when it makes sense to use it. These defenses are based on the defendant’s lack of identity, authorization, knowledge, or intent. Each of these are different defenses that require different evidence.

Q: What is an attribution timeline?

A: The government uses attribution timelines to prove a defendant committed the crimes it is prosecuting. As a result, a defendant’s lawyer should scrutinize the evidence behind these timelines. When necessary, the government’s timestamps should be compared with the defendant’s alibi records to see if they match up.

What evidence can show someone else used my device?

Q: How can we prove that a computer or phone belongs to another person?

A: When available, DHCP lease records can show that a device’s MAC address was associated with a specific internal IP address. This information can then be used to identify the owner of the account.

Q: How can we prove that the accused did not commit the crime?

A: In cases involving MFA accounts, MFA logs can be used to show which MFA factor approved a particular account session. This can be used to show that the defendant was not the individual who committed the crime.

Q: How can we prove that the accused was not using their cell phone during a particular time?

A: Cell-site records can be used to corroborate the location of the phone at a specific time. If the accused was at a different location at the time the suspected criminal activity took place, this can serve to prove the defendant did not commit the crime.

Q: How can we use records from stores and restaurants to corroborate a defendant’s alibi?

A: Point-of-sale records can be used to corroborate the location of a defendant at a specific time. If a defendant was in public during the time of the digital activity in question, then the defendant was unlikely to be using the computer or phone to commit the crime.

Q: How can we use delivery records to protect a client against attribution?

A: Delivery records can be used to show who received the goods associated with a particular online transaction. This information can be used to suggest that a third party committed the crime.

Q: How can we use surveillance video to help our clients fight criminal charges?

A: Surveillance video can help establish a defendant’s whereabouts at a specific time. The video can then be used to corroborate or defeat the presumption that the defendant was in possession of a computer or phone.

Q: When available, what role do biometric unlock logs play in attribution cases?

A: Biometric unlock logs establish who is in possession of a computer or phone at a specific time. This information can then be used to prove or defeat allegations of criminal liability.

Q: How does malware lead to a successful attribution defense?

A: Malware can compromise the security of a computer or phone. In attribution cases, evidence of malware can be used to explain account activity that was performed without the account owner’s knowledge.

How do we preserve digital logs before they disappear?

Q: When does it make sense to send a preservation letter?

A: A preservation letter is important to send as soon as possible before routine business-record deletion occurs. If the government wants to preserve business surveillance footage, then business surveillance footage may need to be preserved as well.

Q: Do ISPs preserve logs of online activities?

A: ISPs have retention windows for their logs. If a subpoena, a court order, or a warrant is not served before the retention window expires, then the record of the suspect’s online activity can be lost forever.

Q: What can we find in cloud audit logs?

A: Cloud audit logs contain logins, IP addresses, device identifiers, dates, and times. They can be used to help establish a timeline of activity, or they can be used to identify the specific devices used during the criminal transaction.

Q: How can we establish a SIM-swap theory?

A: To help establish a SIM-swap theory, we subpoena mobile carrier records that show changes to the subscriber identity module (SIM) card associated with the phone. This information can prove that the suspect was not in control of the phone, and can lead to a successful attribution defense.

Q: What additional evidence can we obtain during our independent defense investigation?

A: During our independent defense investigation, we can subpoena records the government either overlooked or failed to pursue. This allows us to ensure that our clients’ defense efforts are supported by the most complete records available.

Q: What is the danger of deleting information from computers or smart devices after learning about an investigation?

A: Deleting information from computers or smart devices after learning about an investigation or criminal charges can serve to support obstruction of justice or tampering charges. In these cases, the information can often be found in cloud backups, mirror sites, or other sources that the government can subpoena or search.

Q: What constitutes a crime in the context of an investigation into attribution?

A: Providing false statements to federal agents is a crime. Even if a device or account is linked to a particular suspect, the act of lying to federal agents can lead to criminal liability. According to 18 U.S.C. § 1001, individuals and entities can face penalties for providing false information to federal agents.

If you are facing this situation, Spodek Law Group handles federal criminal defense matters nationwide, from offices in New York and Los Angeles.

What if roommates, employees, or strangers had access?

Q: What if the device was used at home?

A: If a device was used at home, family members and roommates may have used it. Both family members and roommates can gain physical access to the device in order to execute a transaction using the user’s account. A successful attribution defense can remove any presumption that the user committed the crime.

Q: What if the device was used at work?

A: Use of workplace terminals can also lead to attribution defense. If employees are not required to log in, the evidence may not show who used the computer to commit the crime. If login records exist, then any evidence that multiple individuals share an account or that a third party used an individual’s login can also lead to a successful attribution defense.

Q: What if the defendant borrowed the phone or computer for a few minutes?

A: Borrowing a phone or computer for a few minutes is not uncommon. If the owner or renter of the computer or phone did not commit the crime, this is another important issue to address during an attribution defense.

Q: What if the digital activity was traced to a customer’s IP address at a restaurant or hotel?

A: In a public setting, like a restaurant or hotel, an IP address identifies a network, not the specific patron. An IP address also doesn’t show the identity of the specific device the owner used to access the wireless network.

Q: What if the accused did not know the person who used their computer, smartphone, or account?

A: When a guest or employee is in possession of the computer, smartphone, or account, they may gain access through a variety of methods. Password storage on devices such as computers or smartphones can allow a guest or employee to gain access.

Q: What is a physical-access timeline?

A: A physical-access timeline is evidence showing who can gain access to the computer or phone at specific times. As a result, physical-access timelines are frequently used to disprove allegations of criminal liability.

Q: What is a remote-access timeline?

A: A remote-access timeline is evidence of connections from a remote computer or phone to a specific target. As a result, remote-access timelines are frequently used to disprove allegations of criminal liability.

Q: What if the accused, the co-defendant, and other individuals have the same IP address?

A: Shared Wi-Fi networks can result in several people having the same IP address. This can happen at hotels, restaurants, offices, and other public or workplaces. As a result, an IP address can serve to link several individuals to the same connection.

Which forensic artifacts show who used the device?

Q: What can user profiles tell us?

A: Digital devices, including computers and smartphones, use user profiles that record specific user preferences. Many applications allow the use of multiple user profiles, while most devices only allow one user profile at a time. If a user profile is configured to a specific account, any activity may be attributed to the owner of that account.

Q: How can autofill artifacts help in attribution cases?

A: Most modern web browsers allow users to save their profile information. This information is then presented as a suggestion when a user enters information in certain types of forms. These autofill artifacts are unique to a particular user identity and can help identify who executed a particular online transaction.

Q: What information is contained in operating-system event logs?

A: Operating-system event logs record computer activities such as logons, unlocks, shutdowns, and application launches. This information can help prove that an account owner was active at the time a particular criminal activity took place.

Q: What information is contained in application databases?

A: In addition to OS event logs, application databases store application-specific data such as messages, session identifiers, and local timestamps. Application databases often store time-stamped evidence that can serve as a digital fingerprint.

Q: Can these databases be omitted in digital-forensics reports?

A: Yes. Application databases are frequently omitted due to incomplete extractions. As a result, the application data available to the forensic examiner may be incomplete or misrepresented.

Q: How can mismatched time zones result in inaccuracies in the digital timeline?

A: Mismatched time zones can lead to an incorrect digital timeline. If the computer or phone is configured to the wrong time zone, any time-stamped data will be recorded incorrectly.

Q: What information should be included in the digital-forensics discovery request?

A: Digital-forensics discovery requests should include all relevant information. This should include:

  • The extraction report;
  • The hash value of the forensic image;
  • The date and time of the image;
  • The tool, the version of the tool, and the script used to capture the image;
  • The forensic report;
  • The forensic report’s annex (if any);
  • The audit logs;
  • The examiner’s handwritten notes;
  • The examiner’s computer-generated notes;
  • All search terms used in the forensic analysis;
  • Information regarding all files and locations searched;
  • The forensic image itself.

How can a defense lawyer test the police’s attribution tools?

Q: What do reverse IP lookups identify?

A: Reverse IP lookups identify the subscriber to the network connection. The subscriber does not necessarily identify the individual who used the device to commit the crime. For example, the subscriber may not have used the internet on that day, and the subscriber may not have used the computer.

Q: What are the pitfalls of geofence evidence?

A: When using geofence evidence, it will be important to scrutinize the location accuracy and capture parameters. Even if a specific device was within the geofence, a device owner is not always the individual who committed the crime.

Q: How do you evaluate conclusions made with blockchain analytics?

A: With blockchain analytics, it is first important to understand how the software arrived at its conclusion. This often involves analyzing the underlying assumptions made about transaction clustering. Additionally, transactions identified as being made to or from a wallet attributed to the defendant’s wallet must be supported by separate transaction records.

Q: What can payment processor records provide?

A: Payment processor records can be used to connect online transactions to funding sources, delivery addresses, and other third parties. These records are obtained by subpoena to show how transaction details correlate with the suspected crime.

Q: What is network address translation (NAT)?

A: Network address translation (NAT) allows multiple devices on the same local network to access a website through one public IP address. When using NAT, a single IP address can serve as evidence against several individuals.

Q: What if you used a public Wi-Fi network?

A: Shared Wi-Fi networks can lead to a single IP address serving as evidence for multiple transactions. However, if multiple other transactions use the same IP, it could be that a shared network, a VPN, a proxy server, or even compromised credentials served to conceal the criminal’s identity.

Q: Can you implement a malware theory?

A: For a successful malware theory, the defense must have logs, artifacts, and other evidence that support the theory of malware installation. An expert should be available to explain how the malware compromised the computer or phone and caused unauthorized activity.

Q: Can you implement a remote-access theory?

A: For a successful remote-access theory, the defense should have logs showing a remote session and identify the computer or phone from which the connection was made. Without showing which remote computer or phone accessed the target computer or phone, it will be much harder to prove the device owner is not the perpetrator.

How is evidence showing another user was involved able to be introduced as evidence at trial?

Q: Does a defendant have a constitutional right to introduce evidence of a third person’s guilt in a criminal trial?

A: In Holmes v. South Carolina, the Supreme Court addressed the limits of a defendant’s ability to exclude evidence showing someone else is responsible for a crime. While a defendant has no absolute right to introduce evidence of another person’s guilt, this evidence is admissible when a defendant is unable to meet the elements of their defense.

Q: What is the role of an expert in attribution cases?

A: A forensic expert can evaluate a defendant’s digital files to identify the specific forensic artifacts showing who used a particular device to access a particular account, and who executed a particular transaction or message. Using this evidence, the forensic expert can challenge the government’s claims with a data-driven argument.

Q: Does digital evidence need to be authenticated in criminal cases?

A: Digital evidence needs to be authenticated. The authentication requirement in criminal cases has been detailed in a series of federal cases such as USA v. United States Postal Service, USA v. Johnson, and USA v. Miller. Most digital evidence presented at trial in criminal cases will need to meet the authentication requirements.

Q: What are the federal rules regarding digital evidence certification?

A: Along with the authentication requirement, federal rules of evidence (the Federal Rules of Evidence, or “FRE”) contain certification and hearsay rules for electronic evidence. For example:

  • FRE 902(13) provides rules for the certification of electronic-process records;
  • FRE 902(14) provides rules for the certification of data copied from electronic devices;
  • FRE 803(6) contains a business-records hearsay exception that the government may rely upon to admit certain types of electronic evidence.

Q: What do chain-of-custody defects affect?

A: While mistakes regarding the chain of custody can have various consequences, their typical effect is to cast doubt on the evidence’s reliability and evidentiary weight. In most cases, a chain-of-custody defect will not affect admissibility.

Q: Are screenshots or platform messages that are stored on a device admissible in trial?

A: No. Screenshots and platform messages must be authenticated before they can be used at trial. If prosecutors are relying upon screenshots or platform messages to prove a defendant committed a crime, then your lawyer should demand the authentication of the screenshots or platform messages.

Get Advice on Your Situation

If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.