Federal Ransomware Charges: Extortion and Computer Crimes.
What is ransomware? Ransomware is a type of malicious software (malware) that encrypts a victim’s data on a computer or other digital device and then demands payment in exchange for the decryption key. The ransom is usually demanded in cryptocurrency to protect the anonymity of the attackers.
The Computer Fraud and Abuse Act (CFAA)
While a number of federal statutes can potentially be implicated by ransomware attacks, the primary statute used in federal criminal prosecutions is the Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. § 1030. This is a sweeping statute that covers a wide range of cybercrimes, and ransomware attacks commonly trigger a few of its most heavily-cited provisions.
Section 1030(a)(5)
Section 1030(a)(5) is one of the most commonly cited provisions of the CFAA. Section 1030(a)(5) prohibits knowingly causing the transmission of a program, information, code, or command to a protected computer and, as a result, intentionally causing damage without authorization to that computer. The CFAA defines “damage” as any impairment to the integrity or availability of data, a program, a system, or information.
Section 1030(a)(4)
Section 1030(a)(4) of the CFAA also offers the potential for federal prosecution in ransomware cases. This section prohibits accessing a protected computer without authorization, or exceeding authorized access, with intent to defraud and thereby obtain anything of value.
Section 1030(a)(7)
Finally, section 1030(a)(7) of the CFAA prohibits transmitting a communication in interstate or foreign commerce containing a threat to damage a protected computer with the intent to extort or obtain money or other things of value, in exchange for not causing such damage. Similar to section 1030(a)(4) of the CFAA, the intent to extort is the central issue at hand. While prosecutors are often able to rely on this section in ransomware cases, it is generally less helpful for securing a conviction than relying on section 1030(a)(5) or section 1030(a)(4).
Why does digital evidence so often leave ransomware attribution uncertain?
Which federal agencies are involved in ransomware investigations and prosecutions?
Ransomware investigations are typically conducted by the FBI, which relies on a team of digital forensics investigators and cryptocurrency tracing experts to identify and track ransomware attackers. Due to the anonymity offered by the internet and cryptocurrency, the FBI often works closely with foreign law-enforcement agencies to identify, track, and apprehend ransomware perpetrators, and to seize any cryptocurrency ransoms. Once an investigation is complete and leads to criminal charges, the case is passed to the U.S. Department of Justice for prosecution.
What does a federal ransomware investigation entail?
A federal ransomware investigation can take many forms, and this often depends on the scope of the attack and how it was carried out. An investigation can involve an analysis of the ransomware’s malicious code, an investigation of the network used to transmit the ransomware, or both. If a ransomware attack was carried out against a government entity or critical infrastructure, the FBI may also use other tools at its disposal to track the origin of the attack, which are tools that are not available for most civil investigations.
What are some types of digital evidence in federal ransomware cases?
In federal ransomware cases, digital evidence can be incredibly vast. It can include:
- IP addresses
- Cryptocurrency wallet addresses
- Online aliases and usernames
- Domain registration information
- Search logs
- Browser history
- Metadata from photos, videos, and documents
- Social media posts and other information
- Network data
- Device ID numbers
Why is digital evidence not always conclusive for attribution?
Digital evidence is powerful evidence in a federal ransomware case. It can often show that a defendant’s computer was involved in the ransomware attack; but, it does not necessarily show that the defendant was the one using their computer. This is a key limitation of digital evidence, and it is why ransomware investigations often leave attribution uncertain. For example, having a defendant’s IP address is not conclusive evidence that the defendant was the one using the computer connected to the network that emitted the ransomware to its target. Similarly, cryptocurrency wallets do not have names attached to them, and online aliases and usernames are relatively easy to spoof. In many cases, prosecutors rely on this circumstantial evidence to support their case, but it rarely offers proof beyond a reasonable doubt required to support a conviction.
When do prosecutors add fraud, laundering, and attempt charges to CFAA counts?
Section 1030(b) (Attempts and Conspiracies)
In addition to the core ransomware prohibitions, Section 1030(b) of the CFAA criminalizes any attempt or conspiracy to commit violations of Section 1030(a). Thus, if a federal criminal investigation is underway, federal prosecutors can use Section 1030(b) to support criminal charges even when the evidence does not conclusively show the defendant was the one who actually carried out the attack. We can evaluate the strength of the government’s case based on its use of a federal ransomware statute, and this includes scrutinizing its use of Section 1030(b) in some cases.
Other Charges That Ransomware Conduct May Trigger
Ransomware conduct can often lead to multiple federal charges, and ransomware attacks that generate civil lawsuits can trigger numerous charges for criminal defendants as well. Some examples of additional charges that are often filed in federal ransomware cases include federal charges for:
- Identity theft
- Conspiracy
- Wire fraud (18 U.S.C. § 1343)
Money Laundering and Related Charges
We can also anticipate money laundering charges in cases that involve cryptocurrency ransoms, particularly if the alleged attackers shifted cryptocurrency across wallets in order to hide their identities. Federal prosecutors can pursue money-laundering charges under statutes such as 18 U.S.C. §§ 1956 and 1957, sometimes in conjunction with CFAA charges; the Anti-Money Laundering Act of 2020 amended the federal anti-money-laundering framework. Along with money laundering charges, federal prosecutors can pursue other charges in cases that involve cryptocurrency ransoms as well. Among others, these charges include those that relate to tax evasion, illegal-money transmissions, and money transfers to foreign accounts.
Section 1030 Statutory Loss Provisions
Along with these additional charges, federal prosecutors can utilize the statutory loss provisions found in Section 1030 of the CFAA as well. In ransomware cases, the definition of loss is somewhat ambiguous, so defendants will need to challenge the government’s use of these provisions to impose harsher criminal penalties. Under 18 U.S.C. § 1030(c)(4)(A)(i)(I), a loss of at least $5,000 during a one-year period is one of several alternative circumstances that can trigger a higher penalty for certain § 1030(a)(5)(B) offenses.
How can a defendant attack intent, authorization, attribution, and sentencing proof?
Challenging the Government’s Proof of Intent
The CFAA’s ransomware prohibitions generally require proving that the defendant’s conduct was “knowing” or “intentional,” or, at times, had the specific “intent to defraud.” Intent is a subjective concept, and when it is an essential element of a criminal charge, it can open the door for a variety of defense strategies. It also can leave room for doubts about the government’s case to exist, which we can leverage in order to protect you during the legal process.
Challenging the Government’s Proof of Lack of Authorization
Much of the law under the CFAA centers on unauthorized computer access. In federal ransomware cases, unauthorized access can present an issue in a number of ways. For example, if a defendant is an employee or contractor who had access to the computer system at issue, the dispute may center on whether the defendant lacked authorization in general, or whether the defendant’s access “exceeded” their granted authorization. In either case, demonstrating a lawful right to access the computer system can open the door to various defenses as well.
Challenging the Government’s Proof of Attribution
Proving attribution in federal ransomware cases is often an uphill battle for federal prosecutors. To do so, prosecutors must show that it was the defendant who actually carried out the alleged computer crimes. But, as we have discussed, in most cases, this is a matter of circumstantial evidence. While cryptocurrency tracing and other investigative tools have provided law enforcement officers with new means of tracking the alleged perpetrators of ransomware attacks, these tools still leave room for doubt.
Challenging the Collection of Digital Evidence
While digital evidence is important in federal ransomware investigations and prosecutions, evidence that was collected in violation of the Constitution’s Fourth Amendment cannot be used against defendants in court. By thoroughly investigating how digital evidence was collected and used to build your case, we can help you challenge the government’s evidence. If a federal judge agrees that the evidence was collected in violation of your constitutional rights, the evidence may be suppressed at trial.
Challenging the Proof for Statutory Penalties
Finally, defendants can challenge the proof for statutory penalties. Federal criminal cases involving computer crimes are particularly complex, and the evidence used to establish a defendant’s criminal liability often also supports the application of statutory penalties. If the government’s evidence is weak, it can offer an additional opportunity to avoid criminal sentencing as well.
Speak With a Federal Defense Lawyer
If you are dealing with any part of what this article describes, the next step is a conversation with a lawyer who handles these cases. Spodek Law Group is a second generation criminal defense firm practicing since 1976, representing clients nationwide from offices in New York, Brooklyn, Queens and Los Angeles. Call 888 348 8028 to speak with our team.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196