United States v. Andrew Auernheimer, 748 F.3d 525 (3d Cir. 2014) was decided by the United States Court of Appeals for the Third Circuit on April 11, 2014 (No. 13-1816). The Third Circuit reversed the district court's venue determination and vacated Auernheimer's conviction on both counts. That the data described roughly 4,500 New Jersey residents was a circumstance, not conduct, and could not supply venue. The court resolved the appeal on venue alone and did not reach the other CFAA questions the case raised.
The question before the court
Where is a computer intrusion offence committed for venue purposes when the defendants, the servers they queried and the recipient of the data were all in different states, and none of them in the charging district?
The governing rule
Article III, § 2, cl. 3 requires trial in the state where the crime was committed; the Sixth Amendment and Federal Rule of Criminal Procedure 18 repeat the guarantee. Where Congress has not prescribed a venue rule, the court must find the locus delicti from the nature of the crime and the location of the acts constituting it, separating 'essential conduct elements', which can support venue, from 'circumstance elements', which cannot. Continuing offences may be tried where begun, continued or completed, 18 U.S.C. § 3237(a), and conspiracy venue lies wherever a co-conspirator committed an act in furtherance. The counts were conspiracy under 18 U.S.C. § 371 to violate 18 U.S.C. § 1030(a)(2)(C) with the § 1030(c)(2)(B)(ii) enhancement for an offence committed in furtherance of a state-law violation (N.J. Stat. Ann. § 2C:20-31(a)), and identity fraud under 18 U.S.C. § 1028(a)(7). The Government bears the burden of proving venue by a preponderance.
How the court applied it
The court parsed § 1030(a)(2)(C) into four elements and identified two of them as conduct: accessing without authorization and obtaining information. Neither happened in New Jersey. Spitler ran the account slurper from San Francisco, Auernheimer helped from Fayetteville, Arkansas, and the AT&T servers they queried sat in Dallas and Atlanta. The Government's fallback was the felony enhancement, which required that the CFAA offence be committed in furtherance of a state violation. The court analysed the New Jersey computer crime statute the same way and found its conduct elements — unauthorised access and disclosure of data or personal identifying information — equally absent from the state: no computer was accessed there, and the only disclosure proved was to a Gawker reporter whom no evidence placed in New Jersey. Nor did the article publish any New Jersey resident's address. Each of the four overt acts alleged in the indictment — writing the slurper, deploying it, emailing victims, and passing the list to Gawker — occurred elsewhere or was unproved as to location. Venue was analysed separately for the identity fraud count, with the same result: neither the use of other people's ICC-IDs nor the transfer to Gawker was shown to have any New Jersey locus.
What the court concluded
The Third Circuit reversed the district court's venue determination and vacated Auernheimer's conviction on both counts. That the data described roughly 4,500 New Jersey residents was a circumstance, not conduct, and could not supply venue. The court resolved the appeal on venue alone and did not reach the other CFAA questions the case raised.
From the opinion
- “The statute's plain language reveals two essential conduct elements: accessing without authorization and obtaining information.” — Part III.A, breaking down 18 U.S.C. § 1030(a)(2)(C) for the locus delicti inquiry.
- “New Jersey was not the site of either essential conduct element.” — Part III.A, immediately after locating the defendants in California and Arkansas and the AT&T servers in Texas and Georgia.
- “Venue in criminal cases is more than a technicality; it involves "matters that touch closely the fair administration of criminal justice"” — Opening paragraph, quoting United States v. Johnson, 323 U.S. 273, 276 (1944), before the court notes this is especially true of computer crimes.
Why it matters for cyber conflict
The decision insists that a computer offence is located where the defendant acted and where the machine he entered sits, not where the affected people happen to live — a constraint that bites hard when an intrusion's effects are scattered across many jurisdictions, as they routinely are in cross-border operations. It marks the limit of effects-based reasoning in a criminal forum, even as effects-based reasoning grows in the civil and international law of cyber operations.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: United States v. Andrew Auernheimer on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on International Law · All case notes · Peer-reviewed scholarship