Prosecution of Cyber and Cyber-Enabled Offenses

FederalAgency guidance

Ask Donna

How this section applies to your facts.

DOJ Justice Manual › Title 9: Criminal › 9-50.000 - CHIP Guidance › Justice Manual § 9-50.201

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

CHIP AUSAs have primary responsibility for cyber crimes, defined as cases where a computer or network is the target of criminal action (

e.g.

, computer intrusions, data breaches, damage to computers, ransomware and digital extortion, botnets, denial of service attacks, and the use or dissemination of malware). CHIP AUSAs' responsibilities can also include the investigation and prosecution of cyber-enabled crimes, specifically:

crimes where online platforms or digital assets are central to the commission of the offense (

e.g.

, investigations of bulletproof hosting, counter antivirus services, and darknet or online criminal markets; investigations into criminal digital asset exchanges, mixers, tumblers, stablecoin or token issuers, or other decentralized finance (DeFi) platforms (including instances in which the provider or platform is a target of, or a victim in, the investigation); crimes targeting digital asset service providers or other DeFi platforms; and digital asset theft and fraud schemes); and

crimes in which a computer, electronic device, and/or the internet is used to harass, threaten, stalk, extort, coerce, cause fear to, or intimidate an individual.

When charging cyber and cyber-enabled crimes, CHIP AUSAs frequently charge offenses under 18 U.S.C. § 1030, the Computer Fraud and Abuse Act. Pursuant to

JM 9-48.000

, AUSAs shall consult with CCIPS with respect to decisions to charge a case under 18 U.S.C. § 1030. Other statutes used to charge the offenses described above include, but are not limited to, 18 U.S.C. §§ 1028, 1028A, 1029 (identity theft and access device fraud), 2261A (cyber stalking), 2511 (illegal interception of electronic communications in violation of Title III of the Omnibus Safe Streets and Crime Control Act), and conspiracy statutes applicable to those sections. U.S. Attorneys have flexibility about what charges are appropriate for a particular case

e, but are not limited to, 18 U.S.C. §§ 1028, 1028A, 1029 (identity theft and access device fraud), 2261A (cyber stalking), 2511 (illegal interception of electronic communications in violation of Title III of the Omnibus Safe Streets and Crime Control Act), and conspiracy statutes applicable to those sections. U.S. Attorneys have flexibility about what charges are appropriate for a particular case. When a non-cyber offense charge or disposition has been approved, it is particularly important that the CHIP AUSA appropriately enter the case into CaseView as a cyber case (

JM 3-16.110

), and that the CHIP AUSA accurately reflects his or her time in USA-5 as cyber work (

JM 3-16.120

).

When determining which cyber and cyber-enabled crimes to prioritize, CHIP AUSAs should generally give priority to cyber and cyber-enabled crimes that endanger the health or safety of the public, including those crimes involving critical infrastructure. A denial-of-service or ransomware attack on a hospital’s computer network is an example of a computer crime with serious public health implications. To protect the economic safety of the public, USAOs should prioritize investigations and prosecutions of ransomware (or other cyber intrusions that involve economic extortion, such as data breaches used as a means of extortion). Those efforts should include outreach to the public and industry to prevent these attacks from succeeding in the first place and efforts to try to address those attacks as they are happening.

mic safety of the public, USAOs should prioritize investigations and prosecutions of ransomware (or other cyber intrusions that involve economic extortion, such as data breaches used as a means of extortion). Those efforts should include outreach to the public and industry to prevent these attacks from succeeding in the first place and efforts to try to address those attacks as they are happening.

Additionally, CHIP AUSAs should work to prevent and respond to unlawful cyber intrusions involving our elections. As an initial matter, responsibility over elections in each district belongs to the District Election Officer (“DEO”), as designated by the U.S. Attorney in that district. But CHIP AUSAs should assist the DEO, in coordination with their federal agency partners, to engage in outreach to state and local election officials throughout their district in advance of federal elections to help identify, report, and stop cyber intrusions. CHIP prosecutors should also work with, and through, the DEO during the election (including on election day and other dates when voters are registered, votes are cast, or votes are tabulated) to address any cyber incidents should they occur (in consultation with the Public Integrity Section).

[added August 2023] [cited in

JM 9-50.102

]

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.