United States v. Gasperini

894 F.3d 482
Court of Appeals for the Second Circuit·Decided July 2, 2018·No. Docket 17-2479-cr; August Term, 2017·Published·Cited by 48 cases

Opinion

Gerard E. Lynch, Circuit Judge:

*485 Fabio Gasperini was convicted by a jury in the United States District Court for the Eastern District of New York (Nicholas G. Garaufis, Judge ) of one count of misdemeanor computer intrusion in violation of 18 U.S.C. § 1030 (a)(2)(C), a provision of the Computer Fraud and Abuse Act of 1986 ("CFAA"). Gasperini raises several challenges to his conviction. First, he contends that the statute that he was convicted of violating is unconstitutionally vague. Second, he asserts that the district court erroneously denied his motion to suppress evidence that was allegedly collected in violation of the Stored Communications Act. Third, he contends that the district court abused its discretion in allowing the government to introduce into evidence screenshots from the Internet Archive (also known as the "Wayback Machine"). Gasperini makes several other arguments, which are addressed in an accompanying summary order. Because we are not persuaded by any of Gasperini's arguments, we AFFIRM the judgment of the district court.

BACKGROUND

The evidence discussed below is taken from the trial record. Insofar as it relates to the offense of conviction, the evidence is viewed in the light most favorable to the government, and we draw all reasonable inferences in its favor. United States v. Guadagna , 183 F.3d 122 , 125 (2d Cir. 1999). As it relates to the sentencing issues discussed in the accompanying summary order, "we review the District Court's factual findings relevant to a sentencing determination for clear error." United States v. Johnson , 378 F.3d 230 , 238 (2d Cir. 2004). In order to vacate such findings, "we must view the evidence in the light most favorable to the government and nevertheless find to be impermissible the factual determinations based upon that favorably-viewed evidence." Id.

In 2014, a virus began infecting QNAP-brand devices. 1 Computer security experts who detected the virus determined that the attacker behind the virus was attempting to covertly infiltrate computers. The attacker targeted QNAP computers, which do not log external internet connections, and used an often-overlooked port to access the computers. The virus installed malware, which included several commands for the computer to execute, in hidden directories on the infected computers. Once a computer was infected, the attacker installed a "backdoor" account, which had the status of a "superprivileged user," with unrestricted access to and control over the computer's data. After creating the backdoor account, the attacker patched the initial vulnerability that had allowed him access, thereby locking out other hackers. The infected computer was then instructed to scan the internet for other computers with the same vulnerability and infect them. In this way, the attacker created what is known as a "botnet"-a network of infected computers under the attacker's control. An analysis of one of the servers used in the scheme revealed that more than 155,000 computers were infected worldwide. Many of those computers were located in the United States.

The virus's commands accomplished different tasks. One command was designed to take certain username and password files from the infected computers and copy them onto a server. Another caused the infected computer to disguise itself as a *486 human browsing the internet, and to click on certain banner advertisements. Yet another command prompted the botnet to launch coordinated attacks on certain websites, a practice known as distributed denial-of-service attacks.

United States investigators identified Gasperini, an Italian citizen, as the creator of the virus and perpetrator of the various attacks because he leased and operated several servers around the world that were used to host the malware and communicate with the infected computers. A search of Gasperini's email account also found a "test" copy of the computer virus that was initially used to infect QNAP computers, and emails from Gasperini expressly referencing several of the scripts installed on the infected computers.

Evidence later adduced at trial also linked Gasperini to a related "click fraud" scheme, in which the botnet computers were commanded to click on certain advertisements. Business records showed that several websites implicated in the scheme were registered in Gasperini's name. Additionally, Gasperini contracted with an Italian advertising company to earn money for each advertisement viewed on these websites. Finally, evidence at trial tended to show that Gasperini monitored the operation. This included emails from his servers reporting "clicks completed" and a photograph of his home computer commanding his botnet to click on an advertising banners. After his arrest in the Netherlands, Gasperini deleted the contents of his Google account, deactivated his Facebook account, and instructed someone to discard the hard drives in his home and erase others.

A grand jury charged Gasperini with felony crimes of computer intrusion with intent to defraud, for financial gain, and in furtherance of criminal acts; wire fraud conspiracy; wire fraud; and money laundering. After a seven-day jury trial, he was acquitted of all felony charges, and was convicted only of misdemeanor computer intrusion in violation of 18 U.S.C. § 1030 (a)(2)(C), a lesser-included crime within one of the computer intrusion felonies charged in the indictment. 2 At sentencing, the trial judge found that the government had proven, by a preponderance of the evidence, that Gasperini had committed the felony offenses with which he was charged. Accordingly, those crimes were considered as relevant conduct in calculating the applicable Guidelines range, resulting in a range of 63 to 78 months' incarceration, which was capped by the statutory maximum of imprisonment for one year. The district court sentenced Gasperini principally to that statutory maximum. He now appeals from that conviction. 3

DISCUSSION

I. Vagueness

The statute under which Gasperini stands convicted punishes anyone who "intentionally accesses a computer without authorization ... and thereby obtains ...

Free access — add to your briefcase to read the full text and ask questions with AI

United States v. Gasperini, 894 F.3d 482 (2d Cir. 2018).

894 F.3d 482 (United States v. Gasperini) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

United States v. Runner
143 F.4th 146 (Second Circuit, 2025)
Pietrangelo v. Refresh Club, Inc
District of Columbia, 2023
Weinhoffer v. Davie Shoring
23 F.4th 579 (Fifth Circuit, 2022)
People v. Potts
2021 IL App (1st) 161219 (Appellate Court of Illinois, 2021)
United States v. Daniel Harris
991 F.3d 552 (Fourth Circuit, 2021)
United States v. Dickens, Cruz
Second Circuit, 2020
United States v. Casey Dill
Second Circuit, 2020
United States v. Doka
Second Circuit, 2020
Horn v. Med. Marijuana, Inc.
383 F. Supp. 3d 114 (W.D. New York, 2019)
Patriot Grp. v. Fustolo (In re Fustolo)
597 B.R. 1 (D. Massachusetts, 2019)
State v. Brown
302 Neb. 53 (Nebraska Supreme Court, 2019)
Sims, Christian Vernon
569 S.W.3d 634 (Court of Criminal Appeals of Texas, 2019)
United States v. Monroe
350 F. Supp. 3d 43 (D. Rhode Island, 2018)
United States v. Loera
333 F. Supp. 3d 172 (E.D. New York, 2018)
Disney Enters., Inc. v. Sarelli
322 F. Supp. 3d 413 (S.D. Illinois, 2018)