Phishing, Business Email Compromise & Cyber-Enabled Schemes
By the time federal agents contact you about a phishing scheme or business email compromise, the government usually has already traced the money. Wire transfers leave a record at every bank they pass through. Cloud providers keep login histories long after an account is closed or a password is changed. Federal prosecutors in the Northern District of Texas increasingly bring wire fraud, identity theft, and money laundering charges against people who never sent a phishing email themselves. This includes the employee who approved a spoofed invoice, the contractor whose credentials were stolen months earlier, or the person who agreed to move money through a personal account without asking too many questions.
How These Investigations Usually Begin
Cyber-enabled fraud cases often start with small incidents that build up over time. These incidents can include:
A bank’s compliance team notices unusual activity on a customer’s account and reports it to their internal team.
A company discovering a fraudulent invoice after payment has already been made and contacting the FBI for assistance.
A cybersecurity firm investigating a breach turning over information to law enforcement.
An individual accused of fraud providing information about other participants in exchange for leniency.
Email or cloud providers responding to requests for information and providing records under legal authority.
None of these steps requires notifying people who are eventually swept up in the investigation. Months and sometimes years can pass between the first suspicious activity report and the first knock on a door.
The Federal Statutes That Apply
Most cyber-enabled fraud prosecutions are based on a small number of overlapping statutes, rather than a single “hacking” charge:
Wire fraud under 18 U.S.C. § 1343 covers almost any scheme to defraud that involves an interstate wire, including nearly every email and electronic payment, and carries up to 20 years imprisonment per count.
The Computer Fraud and Abuse Act (18 U.S.C. § 1030) addresses unauthorized access to computers, including stolen credentials used to access a victim’s email or bank account.
Aggravated identity theft under 18 U.S.C. § 1028A applies when someone’s identifying information is used without permission during certain felonies. It carries a mandatory two-year sentence that runs on top of any other sentence, not alongside it.
Money laundering charges under 18 U.S.C. § 1956 and § 1957 often follow when stolen funds move through a second account, are converted to cryptocurrency or are wired overseas.
Conspiracy under 18 U.S.C. § 1349 allows prosecutors to charge everyone connected to a scheme with the same exposure as the person who planned it, including someone whose role was limited to a single transaction.
These statutes combine easily. One scheme can produce a wire fraud count for each fraudulent transfer, an identity theft count for each victim whose credentials were used, and money laundering counts each time the proceeds move again.
Common Fact Patterns That Lead to Charges
Federal cyber-fraud cases often follow a few common patterns:
Business email compromise: An executive’s email is compromised or spoofed, instructing an employee to transfer funds or change payment details.
Vendor invoice fraud: Criminals monitor a company’s emails and insert a fake account number into a legitimate-looking invoice, leading to payment to the wrong account.
Credential harvesting: Phishing pages collect login information that is later used to gain access to email, payroll, or bank accounts.
Money mule activity: A person allows their account to be used for fraudulent transactions, sometimes believing it is part of a legitimate job or relationship.
Romance and job scams: Victims are recruited to transfer money without fully understanding the origin.
Someone can be pulled into a federal investigation through any single point in this chain, regardless of whether they built the phishing infrastructure or simply received a wire transfer that they were told to forward.
Witness, Subject, or Target: Why the Label Matters
The Justice Department sorts people connected to an investigation into three categories. Which one applies changes everything about the case. A witness has relevant information but little or no personal exposure. A subject has engaged in conduct within the scope of the investigation, but has not yet been singled out for prosecution. A target is someone whom prosecutors already believe have substantial evidence against them. These labels can shift as the investigation develops. A person can move from being a witness to a target based on one interview or a piece of financial data that comes to light later.
How Agents Build These Cases
Federal agents and prosecutors use several tools that many people are not aware of until a case has already started:
Preservation letters and subpoenas to email and cloud service providers under 18 U.S.C. § 2703, which prevents account data from being deleted.
Suspicious activity reports and account records from banks and payment providers.
Blockchain analysis tools that track cryptocurrency transactions through wallets and exchanges even after multiple transfers.
Forensic imaging of laptops, phones, and company servers.
Proffer sessions and cooperation agreements with previous participants, who often have a strong incentive to provide information about everyone they interacted with.
Sentencing Exposure
Cyber-enabled fraud sentences are heavily driven by the total loss associated with the scheme, the number of victims, and whether sophisticated means were used, such as spoofed domains or social engineering scripts. Identity theft convictions aggravated by additional two-year sentences on top of the fraud charge. Restitution is standard and can extend beyond a person’s role if they were held accountable for losses caused by co-conspirators.
Building a Defense
Effective defense work usually begins with the same questions prosecutors try to answer: What did this person actually know and when did they know it? Some common defense strategies include:
It is challenging to determine whether the person knew or should have known that funds or credentials were linked to fraud, especially in cases of money mules and job scams.
Disputing the loss amount used to calculate sentencing exposure, which directly affects the sentencing guidelines range.
Scrutinizing whether search warrants, subpoenas, and preservation letters were properly supported and executed.
Distinguishing a person’s limited role from that of the scheme’s organizers can affect both charging decisions and sentencing.
Pursuing a decline, civil resolution, or pre-trial diversion where the facts support treating a case as an isolated incident rather than a coordinated plan.
Why Clients Choose Aaron L. Wiley, P.C.
Aaron L. Wiley has spent 18 years as an Assistant U.S. Attorney handling complex fraud and financial crimes in the Northern District of Texas. He also has earlier experience as a prosecutor in Dallas County. This background means that he has sat on the other side of investigations. He knows which evidence actually influences charging decisions, and he understands how agencies coordinate when cases involve wire fraud, identity theft and money laundering at the same time. Clients appreciate that he answers their own phone calls and walks them through each stage of the process, rather than leaving them guessing.
Talk to a Federal Defense Lawyer Before the Next Stage Starts
Cyber-enabled fraud investigations move fastest during the period before charges are filed. This is also the time when the most can be done to change the outcome. If you have received a subpoena, been contacted by federal agents, or have reason to believe your name has been involved in a business email compromise or phishing investigation, contactAaron L. Wiley, P.C. We can help you understand where the case stands and what options are available.
FAQs
Yes, this is possible. Though knowledge and intent are often the central issues in these cases, prosecutors generally must show that a person knew or was willfully blind to the fraudulent nature of the funds. That is often where the defense is built.
Phishing typically refers to a method used to steal credentials or information. Business email compromise describes a scheme where a compromised or spoofed email account tricks someone into wiring funds or changing payment details. These two often overlap in the same investigation.
Yes. Under 18 U.S.C. § 1028A, a conviction requires a consecutive two-year sentence. It cannot be reduced or served alongside the sentence for the underlying offense, which makes this charge a major factor in plea negotiations.
Timing matters. What someone does after learning about potential fraud, including whether records have been altered or kept, can affect both original charges and the possibility of additional obstruction issues.
Often, yes. Declarations, civil settlements, and negotiated plea agreements are common outcomes. This is especially true when a defense attorney becomes involved early enough to present the full context of the case before an indictment is sought.
You are not required to answer questions beyond identifying yourself. Speaking without a lawyer present carries real risks. False or inconsistent statements made to a federal agent can be charged as a separate crime, even if the underlying conduct was legal.