ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
3 AUG 2026 · 13 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: UNCATEGORIZED
DOCKET NO. 063 · THE DEFENSE DESK

Wrong Person, Right IP: Shared Wi-Fi and Misattributed Cases.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

Last Updated on: 4th August 2026, 01:33 am

The short answer is, no. An IP address is not identity. An IP address identifies an internet connection, not the person using it.

2. How Many Devices Can Use One Public IP Address?

Virtually any number of devices can share a single public IP address. Anyone connected via Wi-Fi will do so. The following examples are just the tip of the iceberg:

  • Smart Home/IoT devices (thermostats, cameras, alarms, lights, etc.)
  • Multiple computers (personal, home office, guests, etc.)
  • Multiple mobile devices (phones, tablets, watches, etc.)

3. If The IP Address is the only evidence of the connection, how can the government connect the connection to a person?

An IP address alone ordinarily cannot establish that the defendant committed the charged conduct. It needs to prove that the defendant personally committed the charged conduct.

The government can connect a person to a device, and the device to the connection, and the connection to a public IP address, and then just pretend it connected the person to the public IP address. That’s what lawyers call lying, although they sometimes use softer words like “mischaracterizing the evidence.”

4. What is the Evidentiary Value of the IP Address Alone?

None. That’s how the judge, Dennis Smith, described the evidentiary value of an IP address when presented to prove a defendant used a computer to access a restricted website to view the indecent photos of a child.

The problem is that the government and the prosecutors are trying to make a computer into a person and the IP address into identity. If they try to convince a judge that the IP address is conclusive, they’re lying to a judge about the evidentiary value of the IP address.

5. What Are the Proof Standards in Criminal, Copyright, Disciplinary, Restraining Order, and School Cases?

What Does an IP Address Actually Prove in Court?

When relying on an IP address to prove identity, prosecutors may seek to link a public IP address to a subscriber account, a router, a private LAN IP, a MAC address, and a human user. This is much more difficult than linking it to a subscriber account. Here is how the different layers of attribution function:

1. Subscriber Records

The subscriber record connects the public IP address to an account holder. Most Internet Service Providers (ISPs) issue a public IP address that identifies a connection and a subscriber account. It does not identify a human. If multiple people are utilizing the internet connection, perhaps in a family home, a workplace, or at a hotel, the subscriber record will only identify the person paying the bill.

2. Router

The router is the device that connects one or more users to the internet. Most routers share a single public IP address among multiple devices via network address translation (NAT). An IP address on a subpoena may connect the subscriber account holder to the router, and to the internet, but it does not prove that the human subscriber was the person operating the computer in question.

3. Private LAN IP

A private LAN IP is an internal identifier that the router assigns to each device on the local area network (LAN). The private LAN IP is not a public identifier, and the subscriber records will not contain any information about it.

An IP address can be assigned to different devices at different times. A router assigns local IP addresses from its pool of addresses, and it keeps track of these assignments in DHCP lease records.

A MAC address is a Media Access Control address. This is a unique hardware identifier for the device’s network interface card (NIC). Each internet-connected device has its own MAC address. However, just like the public IP address, the MAC address is not a unique identifier for the human being who is using the device.

How Can Shared Networks Identify the Wrong Subscriber?

There are many different kinds of shared Wi-Fi connections. These scenarios include:

  • Carriers that route many different subscribers behind a single public IPv4 address (this process is called “carrier-grade NAT”). Because of this, separate subscribers can’t be identified through the IP address alone. Instead, they require port numbers.
  • Mobile hotspots. These are cellular devices that share one cellular connection among nearby people who connect to the hotspot via Wi-Fi.
  • Hotel, library, university, café, and airport Wi-Fi. These networks routinely let dozens or hundreds of unrelated users onto one shared network.
  • Apartment-building Wi-Fi. Many cities have buildings where the landlord uses a single network that mixes in traffic from unrelated residents in different apartment units.
  • Household connections. This means that other family members, guests, tenants, previous residents, employees, or even former employees may have had access to the network.
  • Shared account access. Another person in the home (such as a spouse, parent, child, or domestic partner) could have legitimate access to a computer or to a social media account.
  • Exclusive network control. Government investigators have frequently used the defendant’s exclusive control over the network as a counterargument to one or more of the above possibilities. The government would argue that the defendant controls the network and has the sole ability to use it, thus implicating the defendant rather than exonerating everyone else in the house. (This argument is common in these federal cases. It ignores the fact that family members, tenants, and guests frequently have access to computers and smartphones as well as social media accounts.)
  • Evidence of access from other IP addresses and other locations. Investigators might use the IP address alone if they don’t have evidence that the suspect was connected to other IP addresses at other times and places. (The truth is that the government’s evidence of access from only one IP address may just mean that they lack evidence from other locations.)

How Do Timestamps Make IP Matches Unreliable?

1. Dynamic IP Addresses

Because an IP address for a dynamic IP shifts over time, a subscriber record that links an IP address to a subscriber does not identify anyone unless it matches the exact time and date of the event in question. But if the network connects two different subscribers behind one public IP, a timestamp is not enough.

The investigator must match the timestamp with the provider’s assignment records, taking into account time zones and daylight savings.

But this only proves the IP address was assigned to a subscriber account at the date and time of the event. To identify who is on the network, you need to match these records with the logs of the router that identify who is connected to the local network. Then you need to match those with the logs of the device that is connected to the network, the account used on that device, and a human being who controls that account.

This is called log correlation. It is a multi-layered process, and it has to be done for every single event, which may not be possible.

2. Clock Drift

Even if investigators attempt to correlate the logs, there is also the issue of clock drift. Each device’s clock is slightly different. Over time, the logs of the internet service provider, the router, and the device can get out of sync.

If investigators use a timestamp from a single device to infer evidence from others, it could lead to wrong conclusions.

3. ISP Retention

The time a subscriber assignment record is assigned to an IP address may be too short for the ISP to maintain a record of it.

Similarly, the time duration for which an ISP stores the logs of a subscriber’s connection to an IP address may be less than the time between when the alleged activity happened and when investigators sought a subscriber record.

4. NAT

A NAT table maps an internal network connection to a public port. If a home router reboots or a session expires, the NAT table will clear.

This can result in a situation where a public IP address is linked to a subscriber account, but there is no longer a NAT table record to identify the specific user or device.

Spodek Law Group, led by managing partner Todd Spodek, defends clients in federal criminal and white collar matters.

What evidence connects online activity to one person?

Because of the issue of shared Wi-Fi and the fact that an IP address is not evidence of identity, investigators have to look for other types of evidence to prove that a specific human being committed the alleged offense. This can include evidence such as:

  • Browser artifacts. The artifacts created by the defendant’s web browser, cookies, passwords, browsing history, and other data can help identify their device profile and online identity.
  • Account session records. This evidence can link an online action directly to a person’s credentials or device, even in shared-network settings.
  • Physical access evidence. Evidence indicating that only one person could have used the shared network at a certain time.
  • Biometric unlock logs. Finger-unlock and face-ID logs can help connect the use of a device to a specific person who is enrolled in those unlocking systems.
  • Camera footage. Security camera footage or even someone else’s cell phone camera may prove the defendant was at the computer at the time in question.
  • Admissions of fault. An admission by the person to have committed the alleged act.
  • Device fingerprinting. Identifying unique device characteristics can help distinguish one user from another on a shared network.
  • Network traffic analysis. Analysts can look at data such as destination IP addresses, domain names, packet sizes, and bandwidth patterns, and use that information to infer which user performed a certain online action.
  • Search and seizure evidence. Search and seizure investigations can sometimes find evidence on a person’s device (such as files, photos, or bookmarks) that correlates to the alleged online act.
  • Testimony from the accused. In some cases, the accused or their associates may provide information that corroborates their involvement.

What Alternative Explanations Should Digital Experts Test for?

When investigators pursue a case based on the match of a public IP address, they must consider and test for alternative explanations. Failure to do so can lead to false accusations against the wrong individual. These alternatives include:

  • Use of Virtual Private Networks (VPNs) and other anonymity-preserving tools like Tor. If a suspect uses a VPN, they will appear to connect from the VPN provider’s public IP address. If they use Tor, they will appear to connect from one of the Tor network’s exit nodes.
  • IP spoofing. This involves transmitting packets with a false source IP address. This can be done with a spoofing packet or by inserting a fake IP address into an application’s requests. While IP spoofing is difficult to use for full TCP connections requiring return traffic, it can still lead to errors in attribution.
  • Malware and ransomware. If an IP address is linked to a user and the user’s computer is infected with malware, then the malware may have sent packets over the internet without the user’s knowledge. The user is not responsible for the malware’s actions. In this case, the IP address would correctly link back to the user’s device but incorrectly attribute the act to the user.
  • Use of compromised accounts. This is a situation where an account was hacked by an outsider. The accounts are being used on the internet from the victim’s account, but not by the victim.
  • Malware analysis. If evidence has been gathered from the defendant’s computer, then a malware analysis can test whether the software conducted the alleged activity.
  • Spoofing and hijacking. Digital forensic experts can analyze spoofed and hijacked communications to uncover the true IP address, the spoofed IP address, and the source IP address.
  • Compromised credentials. To rule out a hacked account, a forensic expert may need to investigate logins, logins from unexpected devices, token thefts, and credential stuffing.

What Should I Preserve After a Wi-Fi Accusation?

1. Is it true that open Wi-Fi is evidence of guilt?

No. If your home Wi-Fi is open to the public, this provides no evidence to connect a public IP address specifically to you. All it proves is that your router is available to the public to send data packets.

2. What evidence should I preserve to protect myself against a public IP address allegation?

If you are facing an accusation based on an IP address, we recommend taking the steps below to preserve what you can as soon as possible. This includes:

  • Router configuration records. These records can show the existence of any guest network, any security settings (whether the Wi-Fi password was saved on another user’s device), any device logs that are available, and the MAC addresses of connected devices.
  • ISP notice. If your internet service provider has served you a notice, preserve that notice. It may provide dates or account information that is essential for defending against allegations of online identity-related offenses.
  • Repair records. To prove a person did not have possession of the computer during the alleged activity, keep all related records, including repair records, receipts for any prior sales, and communication related to third-party custody of the computer.
  • Malware-scan results. If a computer has been infected with malware or ransomware, antivirus software can show when it was infected and which files are infected. This can help corroborate an allegation that another party had control over the computer or account.
  • Communication with police, ISPs, other internet users, etc.
  • Device-usage records.
  • Any other documentation that can refute the allegations.

3. Can I rely on packet captures to prove innocence?

Unfortunately, this type of evidence is rarely available. With a few notable exceptions, most consumer routers do not have the resources to record all network traffic for later review, and the IP address logs can only show what IP address is assigned to a connection.

While live-packet data may be available at the time that a suspect is being tracked, it generally won’t be available once the investigation progresses to a search warrant and the defendant is being charged.

Legal Rules in Digital Evidence Cases

1. Establishing Innocence in a Criminal Case

It is a common misconception that in a criminal case the defendant must prove that he or she is innocent. In a criminal case, the burden is on the prosecution to prove the defendant’s guilt beyond a reasonable doubt. Defense attorneys do not need to affirmatively prove their clients’ innocence to win a case. All that is required is that they cast reasonable doubt.

The government’s use of the defendant’s IP address alone does not establish guilt. It is an investigative lead that provides insufficient evidence for any criminal charge. Even if an IP address is linked to the defendant’s account and IP address, these are circumstantial evidence that is not sufficient on its own. These may prove a link between the device and the crime, but they aren’t definitive proof of the defendant’s culpability.

Similarly, if the IP address is in the defendant’s home or on a shared-use public network such as that at a hotel, library, university, cafe, or even an open-access home router, just because of those factors, the defendant does not necessarily commit a crime. In this scenario, a factual mistake can defeat liability by negating any criminal intent.

2. Establishing Intent in Computer Offenses

The internet is part of the physical world, and it has the same rules of law that apply everywhere else. Certain online acts can potentially violate the law. In some cases, these offenses may be criminal or they may be civil.

Along with the act, intent is one of the key elements of any criminal law charge. Some computer offenses require that a defendant acted knowingly, willfully, or intentionally. In this scenario, if the government uses the IP address of a single individual to assign liability, without evidence of the actual identity of the perpetrator, this could lead to an issue with establishing intent as well.

3. Multiple Offenses and Concurrent Prosecution

One online act can lead to multiple criminal charges. For example, a single post on an internet forum may violate federal anti-threat laws, the state’s hate-speech laws, and the state’s stalking laws.

4. Establishing Interstate and Federal Jurisdiction

In many computer cases, establishing interstate and federal jurisdiction is necessary. This means prosecutors must show the IP address is from an interstate data-transmission session. With this information, they can potentially demonstrate the internet connection was between states. Once this is done, they can pursue a federal indictment against a single individual.

5. Prosecution for Online Acts Within a Single State

While it is possible to prosecute an online act by a single individual as a violation of state law, it is generally rare. A state is unlikely to prosecute a non-state resident for an online act performed entirely out-of-state unless it is a violent act such as harassment, cyberstalking, or child-abuse material.

6. Constitutional Protections

If an IP address match leads to a search warrant, then the search and seizure of computer files and other data must comply with the Fourth Amendment. If the government obtained evidence in violation of this amendment, then a suppression motion may exclude that evidence at trial.

Contact a Federal Criminal Defense Attorney

Nothing here is legal advice, and the details of your case matter. Todd Spodek and Spodek Law Group take federal criminal and white collar cases nationwide, from offices in New York, Brooklyn, Queens and Los Angeles. You can reach the firm at 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.