Research: Hacker Cases, Legal Controversies, and Misunderstood Incidents
From: Lurk More
Contents 82 sections
Research compiled for Lurk More (Book 3). Relevant to Ch. 11 (When Trolling Learned to Code), Ch. 13 (Anonymous – The Full Story), Ch. 18 (Hackers and Trolls – The Overlap Nobody Admits), and the broader “correcting the record” thesis of the book.
The through-line: the legal system’s response to hacking was consistently disproportionate, the media narratives were consistently oversimplified, and the digital native community’s understanding of these cases is fundamentally different from the public understanding. The book’s position is not “hackers did nothing wrong” – it’s that the punishment rarely fit the crime, the story told to the public rarely matched the facts, and the infrastructure built to fight government overreach was itself created by government overreach.
1. Aaron Swartz
The Person They Prosecuted
Aaron Hillel Swartz (November 8, 1986 – January 11, 2013). Not a random script kiddie. Not a malicious actor. One of the most productive technologists of his generation:
- Age 12: Created The Info Network, a user-generated encyclopedia that won the ArsDigita Prize.
- Age 14: Became a member of the working group that authored the RSS 1.0 web syndication specification. Fourteen years old, co-authoring the spec that would power podcasting and blog distribution.
- Creative Commons: Helped develop the technical architecture for Creative Commons licensing – the infrastructure that lets people share creative work legally.
- web.py: Developed the Python web framework web.py.
- Reddit: Co-owner and developer of Reddit. Sold to Conde Nast in 2006. A 19-year-old who built a platform that would become one of the most visited sites on the internet.
- Demand Progress: Founded in 2010. Led the grassroots campaign against SOPA/PIPA, the internet censorship bills. Demand Progress boiled down the bills into simple language and organized massive public opposition. The bills died. This was arguably the internet’s most successful political campaign to that date.
- Open Library, SecureDrop: Contributed to the Internet Archive’s Open Library and the whistleblower submission system later adopted by major newsrooms.
This is the person the federal government decided to make an example of.
What He Actually Did (Technically)
Between late September 2010 and early January 2011, Swartz downloaded approximately 4.8 million articles from JSTOR – about 80% of the entire database – using MIT’s computer network. (Source)
The technical method:
- MIT’s campus network was famously open – a point of institutional pride. Guest access was freely given.
- Swartz connected a laptop to the MIT network using a guest account. The
laptop ran a Python script named
keepgrabbing.pythat automated downloading articles from JSTOR. - When MIT and JSTOR blocked his access (by MAC address, then by IP range), he switched approaches – registering under the name “Gary Host” (G. Host – ghost) and eventually placing the laptop in an unlocked, unmarked wiring closet in Building 16’s basement.
- He periodically retrieved the laptop to offload downloaded articles, then replaced it. Security cameras captured him covering his face with a bicycle helmet.
- Total data: approximately 70 gigabytes, 98% from JSTOR.
Key technical fact: He accessed JSTOR through MIT’s authorized institutional subscription. He did not “hack” JSTOR in any conventional sense. He did not crack passwords, exploit vulnerabilities, or bypass authentication. He downloaded articles at a rate that exceeded what JSTOR’s terms of service allowed, using an authorized network connection.
JSTOR’s Own Position
This is the detail that makes the prosecution indefensible:
- JSTOR settled the matter with Swartz civilly. He paid $1,500 in damages and $25,000 in attorneys’ fees.
- Swartz returned all downloaded articles.
- JSTOR explicitly told the U.S. Attorney’s Office they had no further interest in the matter and did not want to press charges.
- JSTOR publicly stated their preference that Swartz not be prosecuted. (Source)
The “victim” of the crime said “we don’t want this prosecuted.” The federal government prosecuted anyway.
The Prosecution: Carmen Ortiz and Stephen Heymann
U.S. Attorney Carmen Ortiz and Assistant U.S. Attorney Stephen Heymann pursued the case aggressively:
- Original indictment (July 2011): 4 felony counts.
- Superseding indictment (September 2012): Expanded to 13 felony counts, including wire fraud, computer fraud, unlawfully obtaining information from a protected computer, and recklessly damaging a protected computer. (Source)
- Maximum penalty: Up to 35 years in prison, $1 million in fines, three years of supervised release, asset forfeiture, and restitution.
The plea bargain negotiations reveal the prosecution’s stance:
- Prosecutors offered a plea deal: plead guilty to all 13 charges, serve 4 months in prison.
- When Swartz rejected that deal, prosecutors warned future offers would be less attractive.
- Two days before Swartz’s death, the offer was: plead guilty to all 13 charges, serve 6 months in prison.
- Prosecutors refused any deal that did not include prison time and a guilty plea on all 13 counts, even after learning Swartz had battled depression.
Heymann handled all negotiations with Swartz’s attorneys. Heymann had a documented history of aggressively prosecuting internet-related cases.
MIT’s Role
MIT adopted a position of institutional “neutrality”:
- MIT did not request that federal charges be brought.
- MIT was not consulted about appropriate charges or punishment.
- MIT did not issue any public statements for or against Swartz.
- MIT cooperated with the prosecution by providing evidence when requested.
The Abelson Report (July 2013), led by MIT Professor Hal Abelson, reviewed MIT’s role. The investigation interviewed approximately 50 people and reviewed about 10,000 pages of documents (Source). Key findings:
- MIT did not target Swartz and did not seek prosecution.
- However, MIT’s “neutrality” meant it never intervened on Swartz’s behalf, never asked the government to drop the case, and never publicly acknowledged the disproportionality of the charges.
- MIT “missed the wider background” – failed to recognize who Swartz was and what the case represented.
Aaron Swartz’s father, Robert Swartz, called MIT’s claimed neutrality a fiction – arguing that neutrality between a federal prosecutor and an individual defendant is not neutrality at all.
The Mental Health Dimension
Swartz had a documented history of depression. In 2007, he blogged about his “depressed mood” with painful eloquence: “You feel as if streaks of pain are running through your head, you thrash your body, you search for some escape but find none.”
His ex-girlfriend Taren Stinebrickner-Kauffman noted depression was “something he was always dealing with,” often triggered by chronic stomach problems and migraines. Friends had worried about his mental health and suggested he seek counseling long before his arrest.
The federal prosecution compounded this. Facing 35 years, $1 million in fines, and a permanent felony record – for downloading academic papers that the “victim” didn’t want prosecuted – Swartz was under extraordinary pressure.
Death and Aftermath
On January 11, 2013, Aaron Swartz was found dead in his Brooklyn apartment. He was 26 years old.
His father’s statement: Aaron was “pushed to his death by the government.”
Tim Berners-Lee’s tribute: The inventor of the World Wide Web delivered a eulogy at Swartz’s funeral on January 15, 2013, calling Swartz “an elder” of the computer and information community. “I have not met anyone else so ethical,” Berners-Lee said. “He knew by writing code he could change the world.” (Source)
The #PDFTribute: In the days following his death, academics and researchers worldwide began posting their own papers online for free using the hashtag #PDFTribute – making Aaron’s point about open access in the most direct way possible.
The Internet’s Own Boy: A 2014 documentary about Swartz’s life and case, directed by Brian Knappenberger, screened at Sundance.
The federal government dropped all pending charges against Swartz after his death.
Aaron’s Law
In direct response to the Swartz case, Representative Zoe Lofgren drafted “Aaron’s Law” to reform the CFAA:
- First introduced in the 113th Congress by Lofgren and Senator Ron Wyden.
- Reintroduced with co-sponsor Senator Rand Paul (bipartisan, bicameral).
- Key provisions: breaches of terms of service would not be automatic CFAA violations; “access without authorization” would be defined as circumventing technological or physical controls (passwords, encryption, locked doors); penalties would be proportional; prosecutors could not inflate sentences by stacking multiple CFAA charges.
Aaron’s Law was reintroduced in April 2015 (Source) with the explicit acknowledgment that “the CFAA didn’t fix itself.” (Source)
It never passed. Despite bipartisan support, despite the circumstances that prompted it, despite widespread expert agreement that the CFAA was broken – Congress never enacted meaningful reform.
The Broader Argument
The research Swartz downloaded was overwhelmingly publicly funded. American taxpayers funded the research through federal grants. The researchers were not paid by JSTOR for their work. JSTOR’s service was providing access to publicly funded knowledge – behind a paywall.
Swartz’s position, articulated in his 2008 “Guerilla Open Access Manifesto”: knowledge produced with public money should be publicly available. The fact that downloading publicly funded research from an academic database could result in 35 years in federal prison is the indictment – not of Swartz, but of the system.
2. Kevin Mitnick
The Myth
The most dangerous hacker in the world. A digital terrorist who could launch nuclear missiles by whistling into a telephone. So dangerous he had to be kept in solitary confinement to prevent him from accessing a phone.
The Reality
A social engineer with extraordinary skills and insatiable curiosity who never profited financially from his intrusions, never caused documented physical harm, and never came close to anything involving nuclear weapons.
The Actual Charges and Conviction
Mitnick was charged with 14 counts of wire fraud, 8 counts of possession of unauthorized access devices, interception of wire or electronic communications, unauthorized access to a federal computer, and causing damage to a computer.
In 1999, he pled guilty (plea bargain) to:
- 4 counts of wire fraud
- 2 counts of computer fraud
- 1 count of illegally intercepting a wire communication (Source)
What he actually did: social engineering (manipulating people into providing access), copying proprietary software source code (from companies including Motorola, NEC, Nokia, Sun Microsystems, and Fujitsu), and unauthorized access to computer systems. He never used his intrusions for financial profit. He never destroyed data. He was driven by intellectual curiosity about telephone systems and computer security.
The Damages Discrepancy
Prosecutors claimed losses of hundreds of millions of dollars and sought $1.5 million in restitution. The judge ordered $4,125 in “token restitution” – an implicit acknowledgment that the claimed damages were inflated beyond recognition. (Source)
The John Markoff / Tsutomu Shimomura Narrative
The public story of Mitnick’s capture was told primarily through:
- “Takedown” (1996) by Tsutomu Shimomura and John Markoff (New York Times reporter) – presented Shimomura as the heroic security researcher who tracked down and caught the world’s most dangerous hacker.
The counter-narratives:
“The Fugitive Game” by Jonathan Littman – alleged journalistic impropriety by Markoff, who covered the case for the New York Times while never interviewing Mitnick, and questioned the legality of Shimomura’s involvement. Littman exposed conflicts of interest: book advances, movie deals, and speaking fees that Shimomura and Markoff received by cooperating with the FBI.
“Ghost in the Wires” (2011) by Kevin Mitnick – Mitnick’s own account. Alleges that Assistant US Attorney Kent Walker made a secret arrangement to provide Shimomura with confidential trap-and-trace information and confidential material from Mitnick’s FBI file, allowing Shimomura to intercept Mitnick’s communications without a warrant. The book was a New York Times Bestseller. “Takedown” was poorly reviewed.
The Nuclear Missiles Myth
This is not exaggeration. A federal prosecutor told a judge that Mitnick could “start a nuclear war by whistling into a pay phone” – implying he could dial into NORAD via a payphone and communicate with modems by whistling to launch nuclear missiles.
The judge did not recognize this as absurd. Instead, special restrictions were placed on Mitnick’s custody. He was placed in solitary confinement partly on the basis of this claim.
The Pre-Trial Detention
- 4.5 years of pre-trial detention – before conviction, before trial.
- 8 months in solitary confinement – based partly on the nuclear missiles claim.
- Total prison time: 5 years. U.S. District Judge Mariana Pfaelzer sentenced him to 46 months in federal prison plus 22 months for violating the terms of his 1989 supervised release. (Source)
- Released January 21, 2000.
- Conditions of release: initially barred from using computers or the internet.
The Free Kevin Movement
The Free Kevin movement, championed by 2600: The Hacker Quarterly and its publisher Emmanuel Goldstein, argued that Mitnick’s punishment was wildly disproportionate. “Free Kevin” bumper stickers became iconic in hacker culture.
The core argument: Mitnick’s crimes – curiosity-driven social engineering and unauthorized copying of software – were treated as though he were a terrorist. The media narrative (world’s most dangerous hacker, nuclear missiles, existential threat) drove law enforcement response out of all proportion to his actual conduct. The judge’s restitution order of $4,125 vs. the prosecution’s claimed damages in the hundreds of millions tells the entire story.
The Transformation
After prison, Mitnick became a security consultant. He ran Mitnick Security Consulting, LLC and became chief hacking officer and co-owner at KnowBe4, a security training company. He became one of the most sought-after cybersecurity speakers in the world.
The man the government said was too dangerous to touch a telephone became one of the most respected figures in the security industry.
Death
Kevin Mitnick died of pancreatic cancer on July 16, 2023, at age 59, at a hospital in Pittsburgh, Pennsylvania. His wife, Kimberley Mitnick, was pregnant with their first child at the time of his death.
3. The CFAA – The Worst Law in Technology
Origin: WarGames Panic (1983-1986)
The movie “WarGames” (1983) depicts a teenager who accidentally hacks into NORAD and nearly starts World War III. After President Ronald Reagan watched the film at Camp David, he asked the Chairman of the Joint Chiefs of Staff whether the plot was possible.
Six anti-hacking bills began working through Congress. Clips from WarGames were screened in committee hearings and described as “a realistic depiction of the kind of threat” being legislated against. A 1983 congressional hearing on computer security opened with a clip of the main character hacking a school computer to change his grade.
The resulting legislation – the Computer Fraud and Abuse Act of 1986 – became the primary federal anti-hacking law (Source). A law written in response to a fictional movie about a teenager became the tool used to prosecute real people for decades.
The “Exceeds Authorized Access” Problem
The CFAA prohibits intentionally accessing a computer “without authorization” or “in excess of authorization.” The law never defines what “without authorization” means.
This vagueness is not a minor technical problem. It is the central defect of the law. Under broad interpretations:
- Violating a website’s Terms of Service could be a federal crime.
- Sharing your Netflix password could be a federal crime.
- Lying about your age on Facebook could be a federal crime (Facebook’s ToS requires truthful biographical information).
- Using a work computer for personal email could be a federal crime.
- Incrementing a number in a URL could be a federal crime (the weev case).
Orin Kerr, Berkeley Law Professor, has spent much of his career documenting these absurdities. His 2003 NYU Law Review article “Cybercrime’s Scope: Interpreting ‘Access’ and ‘Authorization’ in Computer Misuse Statutes” (Source) was later cited by the Supreme Court. Kerr illustrated the law’s absurdity with a personal example: lying about where you live on your Facebook profile violates Facebook’s terms, which under some court interpretations means you are committing a federal crime every time you log in.
Tim Wu, law professor and author of “The Master Switch,” called the CFAA “the worst law in technology,” “the most outrageous criminal law you’ve never heard of,” and “a nightmare for a country that calls itself free.” (Source)
Van Buren v. United States (2021)
The Supreme Court finally narrowed the CFAA – 35 years after it was enacted.
The case: Nathan Van Buren, a former police sergeant, was caught in an FBI sting using his valid credentials to look up license plate information in a police database in exchange for money. He had authorized access to the database. The question was whether using authorized access for unauthorized purposes violated the CFAA.
The ruling (June 3, 2021): In a 6-3 opinion written by Justice Amy Coney Barrett, the Court held that the CFAA’s “exceeds authorized access” provision is a “gates-up-or-down inquiry.” Either you have authorized access to that part of the computer system, or you don’t. If you have access, there is no CFAA violation, regardless of your purpose. (Source)
Justice Barrett cited Orin Kerr’s scholarship. The ruling resolved a 4-3 circuit split that had persisted for years.
What it didn’t fix: Van Buren narrowed the law but did not address the fundamental “without authorization” question. The CFAA remains overly broad, and Congress has not enacted comprehensive reform.
The weev Case
Andrew “weev” Auernheimer and Daniel Spitler discovered in June 2010 that AT&T’s website would automatically display an iPad owner’s email address when queried with a URL containing a matching ICC-ID (SIM card identifier). No login was required. No password was bypassed. No encryption was broken. AT&T had published the data on the open web. Spitler wrote a script that iterated through ICC-IDs and collected 114,000 email addresses.
Auernheimer was convicted under the CFAA and sentenced to 41 months in federal prison for what amounted to incrementing a number in a URL and accessing data AT&T had placed on an unauthenticated public website. (Source)
In April 2014, the Third Circuit reversed the conviction – but on venue grounds (the case should not have been brought in New Jersey), not on the merits of the CFAA charge. (Source) The fundamental question of whether accessing publicly available data on an unauthenticated website constitutes “unauthorized access” was never definitively resolved.
The Aaron Swartz Prosecution (CFAA Application)
Swartz was charged under the CFAA for downloading academic articles through an authorized network connection at a rate that exceeded terms of service. Thirteen felony counts. Up to 35 years. The “victim” didn’t want to prosecute. (See Section 1 above.)
The EFF’s Position
The Electronic Frontier Foundation has been the most consistent institutional critic of the CFAA:
- Called it “the worst law in technology.”
- Documented its use against journalists, security researchers, and ordinary internet users.
- Supported Aaron’s Law reform efforts.
- Filed amicus briefs in Van Buren and Auernheimer.
- Warned against proposed expansions that would make the law broader and more punitive.
- Supported DOJ’s 2022 policy update limiting CFAA prosecutions for security research, while noting it “does not go far enough.”
Why It Hasn’t Been Fixed
Despite decades of criticism from technologists, legal scholars, civil liberties organizations, and bipartisan congressional sponsors – despite Aaron Swartz’s death, despite Van Buren, despite the weev case – the CFAA has never been comprehensively reformed.
Proposed reforms (Aaron’s Law) have been introduced and reintroduced. They have never passed. The law enforcement lobby opposes narrowing the statute. Congress has, if anything, proposed expansions.
A law inspired by a fictional movie, written before the World Wide Web existed, remains the primary federal tool for prosecuting computer-related offenses in 2026.
4. The Hacker Crackdowns (1990)
Operation Sundevil
On May 9, 1990, the United States Secret Service announced Operation Sundevil, a nationwide crackdown on “illegal computer hacking activities.”
The scale: Raids in approximately 15 cities – Cincinnati, Detroit, Los Angeles, Miami, Newark, Phoenix, Pittsburgh, Richmond, Tucson, San Diego, San Jose, San Francisco, and others. Seizure of 42 computer systems and 23,000 floppy disks. (Source)
The result: 3 arrests. Three. From 15 cities, 42 seized computer systems, and a massive federal operation, the government produced three arrests. The operation is now widely regarded as a public relations stunt – a display of force intended to signal that the government was taking hacking seriously, regardless of whether any serious crimes were being committed.
The Steve Jackson Games Raid
On March 1, 1990, armed Secret Service agents accompanied by Austin police and a civilian telephone company “expert” raided the offices of Steve Jackson Games, a tabletop role-playing game publisher in Austin, Texas.
What they seized: Three company computers, over 300 floppy disks, and the manuscript for GURPS Cyberpunk, a role-playing game sourcebook.
Why: The Secret Service asserted that GURPS Cyberpunk was a “handbook for computer crime.” It was a role-playing game sourcebook. A work of fiction for a game about fictional characters in a fictional cyberpunk setting.
The actual connection: An employee of Steve Jackson Games, Loyd Blankenship (known in the hacker community as “The Mentor,” author of “The Hacker Manifesto”), ran a BBS called “Illuminati” on the company’s equipment. The BBS had hosted a copy of the BellSouth E911 document (see Craig Neidorf case below). The Secret Service used this connection to justify seizing the entire company’s equipment.
The damage: Steve Jackson Games was told that neither the company nor the GURPS Cyberpunk manuscript was the target. Yet the Secret Service kept the equipment. The seizure delayed publication of the game by six weeks. Unable to ship product on time, the company held an emergency meeting with their CPA firm and laid off 8 people out of a staff of 17.
The lawsuit: Steve Jackson Games, Inc. v. United States Secret Service went to trial in 1993 in the Western Texas District Court. The result was a disaster for the Secret Service. The court awarded Steve Jackson Games over $300,000 in fees and damages. The judge accused the Secret Service of not knowing the relevant statutes, having no grounds to accuse the entire company, and being “sloppy” in their procurement of warrants. (Source)
The Craig Neidorf / Phrack Case
In February 1990, Craig Neidorf (known as “Knight Lightning”), editor of the hacker newsletter Phrack, was arrested and charged with fraud and interstate transportation of stolen property. The alleged crime: publishing a BellSouth document about the Enhanced 911 system in Phrack.
BellSouth’s claim: The document was proprietary and worth $79,449.
What the trial revealed: On the fourth day of trial (July 27, 1990), the case was dismissed (Source). The defense demonstrated:
- The document was not source code but a memorandum.
- It contained nothing useful for breaking into systems.
- More damaging information about BellSouth’s 911 system was already publicly available.
- The exact document could be ordered from BellSouth by phone for $13.
The government claimed a document was worth $79,449 and prosecuted a young man under federal fraud statutes. The same document could be purchased for $13 by calling BellSouth’s own ordering department. The case collapsed because the prosecution had never checked.
The Electronic Frontier Foundation’s first major legal case was supporting Neidorf’s defense through First Amendment motions.
The Legion of Doom / Masters of Deception Rivalry
The Legion of Doom (LOD), founded by “Lex Luthor,” was active from the 1980s to early 2000s, most prominently 1984-1991. The Masters of Deception (MOD) was a splinter group formed after Mark Abene (“Phiber Optik”) was expelled from LOD in 1989.
The “Great Hacker War” (1990-1992) consisted of both sides attacking each other across Internet, X.25, and telephone networks. MOD members would ring LOD members’ home phones at all hours, switch their phone service randomly, and listen in on their calls.
The war ended when LOD member Erik Bloodaxe called the FBI on his rivals. The FBI and Secret Service served warrants on several MOD members.
The Founding of the EFF
The Electronic Frontier Foundation was founded in July 1990 by three people enraged by the crackdowns:
- Mitch Kapor – entrepreneur (Lotus 1-2-3)
- John Gilmore – civil rights activist and Sun Microsystems engineer
- John Perry Barlow – Grateful Dead lyricist and essayist
The EFF was founded in direct response to Operation Sundevil and the Steve Jackson Games raid (Source). The pattern: government overreaction to perceived hacking threats produced the exact organization that would fight government overreach in digital rights for the next 35+ years.
Bruce Sterling’s “The Hacker Crackdown” (1992)
Bruce Sterling’s nonfiction book remains the definitive account of this period. It covers Operation Sundevil, the Steve Jackson Games raid, the Neidorf trial, the LOD/MOD rivalry, and the founding of the EFF. It profiles Emmanuel Goldstein (2600 publisher), Gail Thackeray (Arizona assistant attorney general), Mitch Kapor, and John Perry Barlow.
In 1994, Sterling released the entire book for free on the internet – a fitting coda to a book about the tension between information control and information freedom.
The book is available via Project Gutenberg. (Source)
5. The Silk Road Sentencing
Ross Ulbricht’s Double Life
Ross William Ulbricht, a physics graduate from the University of Texas at Dallas with a master’s in materials science from Penn State, created and operated the Silk Road anonymous marketplace between 2011 and 2013 under the pseudonym “Dread Pirate Roberts.”
Silk Road operated as a Tor hidden service, using Bitcoin for transactions. It facilitated the sale of drugs, with the site taking a commission on each transaction. The site also had rules – no child pornography, no weapons of mass destruction, no stolen credit cards.
The Conviction
Ulbricht was convicted in February 2015 on seven federal counts:
- Distributing narcotics
- Distributing narcotics by means of the internet
- Conspiring to distribute narcotics
- Engaging in a continuing criminal enterprise (the “kingpin” statute, typically reserved for leaders of major drug trafficking organizations – carries mandatory minimum of 20 years)
- Conspiring to commit computer hacking
- Conspiring to traffic in false identity documents
- Conspiracy to commit money laundering
The Sentence
On May 29, 2015, U.S. District Judge Katherine B. Forrest sentenced Ulbricht to two life sentences plus 40 years, without the possibility of parole, to be served concurrently. He was also ordered to forfeit $183,961,921. (Source)
He was a first-time, non-violent offender. He was 31 years old.
Sentencing Comparisons
- Joaquin “El Chapo” Guzman, leader of the Sinaloa Cartel, responsible for thousands of murders, torture, and massive drug trafficking: life plus 30 years. Ulbricht’s sentence was arguably harsher.
- Every other prosecuted Silk Road defendant received sentences ranging from 17 months to 10 years. The largest drug sellers on the platform got 3-10 years. All of them are already out of prison.
- Average federal sentence for drug offenses: approximately 6 years.
- Ulbricht’s sentence of effective life-without-parole for a first-time, non-violent offense was, by any comparative measure, extraordinary.
The Murder-for-Hire Allegations
The most damaging allegation against Ulbricht was that he attempted to hire hitmen to kill people who threatened the operation of Silk Road. These charges were:
- Filed in a separate indictment in Maryland.
- Never brought to trial.
- Never tested by a jury.
- In 2018, U.S. Attorney Robert Hur filed a motion to dismiss the Maryland charges.
Critically, the murder-for-hire allegations were intertwined with the corrupt federal agents (see below). The “hitman” Ulbricht allegedly hired was, in some instances, a corrupt DEA agent who faked the deaths and pocketed the money.
Despite never being tried or convicted on murder-for-hire charges, the allegations were used:
- To deny Ulbricht bail.
- To influence public perception and media coverage.
- To influence the sentencing judge toward maximum severity.
The Corrupt Federal Agents
Two of the federal agents investigating Silk Road were themselves criminals:
Carl Force IV (DEA Special Agent):
- Created unauthorized fake online identities during the investigation.
- Extorted Ulbricht by posing as a corrupt government employee selling inside information about the investigation.
- Posed as a hitman and accepted payment from Ulbricht.
- Faked the death of a target.
- Stole Bitcoin from Silk Road accounts.
- Charges: Extortion, money laundering, obstruction of justice.
- Sentence: 78 months (6.5 years). (Source)
Shaun Bridges (Secret Service Special Agent):
- Used credentials of a Silk Road moderator-turned-informant to steal approximately $820,000 in Bitcoin from Silk Road.
- Later stole additional Bitcoin that had been seized by the government.
- Charges: Money laundering, obstruction of justice.
- Sentence: 71 months (approximately 6 years). (Source)
The sentencing disparity: The corrupt federal agents who stole money, committed extortion, obstructed justice, and compromised a federal investigation received sentences of 6-6.5 years. The person they were investigating received life without parole.
The trial problem: The corruption of Force and Bridges was never mentioned at Ulbricht’s trial. The investigation into their misconduct was kept secret. Ulbricht’s defense team was not informed. He later unsuccessfully argued that this secrecy denied him a fair trial.
The Free Ross Movement
Ulbricht’s mother, Lyn Ulbricht, launched the “Free Ross” campaign, which gathered over 600,000 petition signatures. The movement drew support from libertarian politicians, prison reform advocates, and the cryptocurrency community.
Trump’s Pardon (January 2025)
On January 21, 2025, President Donald Trump granted Ulbricht a full and unconditional pardon (Source). Trump had promised the pardon at the 2024 Libertarian National Convention, telling the audience he would commute the sentence on his first day in office. (Source)
Ulbricht was released after serving approximately 12 years.
The pardon was explicitly political – Trump secured Libertarian Party support by promising Ulbricht’s release. Whether that makes it more or less just is a question the reader can answer for themselves.
The Futility Argument
After Silk Road was shut down, successor dark web markets appeared immediately:
- Silk Road 2.0 launched shortly after.
- AlphaBay rose in late 2014, eventually becoming larger than Silk Road ever was, with over 40,000 vendors and 350,000+ listings.
- Hansa operated alongside AlphaBay.
- In 2017, Operation Bayonet (FBI, Europol, Dutch police) shut down both AlphaBay and Hansa. Users immediately migrated to Dream Market and others.
- This cycle has continued through 2026.
The drug markets continued. The war on drugs continued. The only thing Ulbricht’s life sentence accomplished was making an example of one person while changing nothing about the underlying market dynamics.
6. Julian Assange and WikiLeaks
Early WikiLeaks (2006-2010): The Legitimate Phase
WikiLeaks was founded in 2006 by Julian Assange. In its early years, it functioned as a genuine whistleblowing platform:
- Kenya (2007-2009): Published material about extrajudicial killings and corruption. Won the 2009 Amnesty International Media Award.
- Iceland (2009): Published internal documents from Kaupthing Bank showing that suspiciously large sums were loaned to bank owners and large debts written off, contributing to understanding of the 2008-2012 Icelandic financial crisis. Kaupthing’s lawyers threatened legal action.
- Various: Published classified documents from multiple governments, exposing corruption, human rights abuses, and corporate malfeasance.
During this period, WikiLeaks was broadly celebrated by journalists, civil liberties organizations, and digital rights advocates.
“Collateral Murder” and the Manning Leaks (2010)
On April 5, 2010, WikiLeaks released “Collateral Murder” – 39 minutes of classified US military gunsight footage from a July 12, 2007 helicopter strike in Baghdad. (Source)
What the video showed: US Apache helicopter crews firing on a group of people and killing at least 18, including two Reuters journalists (Saeed Chmagh and Namir Noor-Eldeen). The crew can be heard laughing at casualties. A van that arrived to rescue the wounded was also fired upon; two children inside were wounded.
Reuters had previously requested the footage through a Freedom of Information Act request. The request was denied. The video was provided to WikiLeaks by Chelsea Manning, a US Army intelligence analyst.
Manning also provided WikiLeaks with:
- The Afghan War Diary (75,000+ classified documents)
- The Iraq War Logs (nearly 400,000 classified documents)
- 251,287 US diplomatic cables (“Cablegate”)
Manning was arrested in 2010, sentenced to 35 years, and served 7 years before President Obama commuted her sentence. (Source)
The 2016 Election and the DNC/Podesta Emails
This is where the narrative becomes complicated:
- In July 2016, WikiLeaks published emails hacked from the Democratic National Committee.
- Throughout October 2016, WikiLeaks released the Podesta emails (from Clinton campaign chairman John Podesta) in daily tranches – 33 batches between October 7 and November 7 (election day).
- Multiple US intelligence agencies concluded that the emails were provided to WikiLeaks by Russian intelligence (GRU).
- The Senate Intelligence Committee found “significant evidence” that WikiLeaks was “knowingly collaborating with Russian government officials” in summer 2016. (Source)
Assange’s stated motivation: He timed the DNC release to coincide with the Democratic National Convention. The New York Times reported he believed Clinton had pushed for his indictment and regarded her as a “liberal war hawk.”
The Roger Stone connection: Trump adviser Roger Stone claimed contact with Assange (later clarifying “through an intermediary”). Stone emailed Jerome Corsi to “get to Assange at Ecuadorian Embassy in London and get the pending WikiLeaks emails.” In August 2016, Stone predicted publicly that “it will soon be Podesta’s time in the barrel.” The Mueller investigation found evidence Stone knew in advance about the releases but lacked “sufficient evidence” to prosecute.
The Swedish Sexual Assault Allegations
August 2010: Swedish prosecutors issued an arrest warrant based on allegations of rape and molestation by two women.
September 2010: The warrant was initially withdrawn due to insufficient evidence, then a higher prosecutor reopened the investigation. Assange left Sweden for the UK.
June 2012: Assange breached bail and took refuge in Ecuador’s embassy in London, claiming political asylum. Granted asylum in August 2012.
August 2015: Statute of limitations expired on three of the allegations.
May 2017: Swedish chief prosecutor rescinded the arrest warrant, calling it impossible to serve while Assange was in the embassy.
November 2019: After Assange was removed from the embassy, Sweden reopened then dropped the investigation, stating the evidence was “not strong enough to bring charges” due in part to the passage of time.
The allegations were never resolved by trial. Supporters called them a pretext for extraditing Assange to the US. Critics noted that dismissal was not exoneration. Both positions contain truth. The ambiguity is the point.
UK Imprisonment (2019-2024)
On April 11, 2019, Ecuador withdrew Assange’s asylum and invited police into the embassy. Assange was arrested.
He spent 1,901 days in HM Prison Belmarsh (described as “Britain’s Guantanamo”):
- Confined to his cell 23 hours per day.
- One hour of recreation, conducted indoors.
- Lost approximately 15 kilograms of weight.
- UN Special Rapporteur on Torture Nils Melzer concluded Assange was experiencing “psychological torture.”
The Plea Deal (June 2024)
On June 25, 2024, Assange pleaded guilty to a single count of conspiracy to obtain and disclose classified US national defense documents under the Espionage Act of 1917. The plea was entered in Saipan, Northern Mariana Islands (US territory in the Pacific – chosen because Assange refused to enter the continental US).
Sentence: Time served. Assange flew to Australia the same day. (Source)
He was the first publisher charged under the Espionage Act who entered a plea. The original indictment had included 17 counts of violating the Espionage Act plus a conspiracy charge, carrying up to 175 years in prison.
Press Freedom Implications
The Assange prosecution raised questions that remain unresolved:
- If publishing classified material provided by a source is a crime, every investigative journalist who has ever worked with leaked classified documents is potentially guilty.
- The New York Times, the Washington Post, the Guardian, and Der Spiegel all published material from the Manning leaks. None were charged.
- Reporters Without Borders stated Assange “would have been the first publisher to be tried under the US Espionage Act,” setting “a deeply alarming precedent.” (Source)
The Digital Native’s Complicated View
The honest assessment acknowledges all of the following simultaneously:
- WikiLeaks’ early work was genuine, important whistleblowing that exposed real abuses.
- The “Collateral Murder” video showed the public something the military wanted hidden, and the public had a right to see it.
- Assange made terrible personal choices – the 2016 timing was suspicious at best and actively harmful at worst.
- The prosecution was at least partially political.
- Publishing classified material is something newspapers do regularly; the Espionage Act charge against a publisher is genuinely dangerous for press freedom.
- The Russian coordination question has never been fully resolved.
- Seven years of imprisonment (embassy + Belmarsh) for publishing is disproportionate by any measure.
All of these things can be true at the same time. Anyone claiming the Assange case is simple is selling something.
7. The Whistleblower Cases: Drake, Binney, Klein
The Argument These Cases Make
The standard response to Edward Snowden is: “He should have used proper channels.” These three cases demonstrate what happens when you use proper channels.
Thomas Drake – The NSA Whistleblower Who Did Everything Right
Background: Thomas Drake was a senior executive at the NSA. He discovered that the NSA had abandoned a cheaper, more effective, and more privacy-protective surveillance program called ThinThread in favor of a far more expensive, less effective, and more invasive program called Trailblazer. Trailblazer cost billions and didn’t work. ThinThread cost a fraction and did work but had built-in privacy protections the NSA didn’t want.
What he did (the proper channels):
- Reported internally to his superiors at the NSA.
- Reported to the NSA Inspector General.
- Reported to the Defense Department Inspector General.
- Reported to both the House and Senate Congressional intelligence committees.
- Did all of this in accordance with whistleblower protection laws.
Nothing happened. The waste, mismanagement, and constitutional violations continued.
Then what happened: In 2006, Drake began providing unclassified information to a reporter at The Baltimore Sun, leading to articles exposing NSA waste and the ThinThread/Trailblazer debacle.
The government’s response:
- November 2007: FBI agents raided Drake’s home.
- April 2010: A federal grand jury issued a 10-count indictment: 5 counts of violating the Espionage Act, 1 count of obstruction of justice, and 4 counts of making false statements to the FBI.
- Maximum penalty: 35 years in prison.
The collapse: After a 60 Minutes episode about the case aired in May 2011, the government dropped all 10 original charges and agreed to seek no jail time. Drake pled guilty to a single misdemeanor – misusing the agency’s computer system. (Source)
The judge’s response: U.S. District Judge Richard D. Bennett called the government’s conduct “unconscionable” – charging a defendant with crimes carrying 35 years in prison, then dropping everything on the eve of trial. He sentenced Drake to one year of probation and 240 hours of community service. (Source)
The man who went through every proper channel, who followed whistleblower law to the letter, was rewarded with an FBI raid, an Espionage Act indictment, and years of legal torment – for being right about government waste and constitutional violations.
William Binney – The NSA Crypto-Mathematician
Background: William Binney served as Technical Director at the NSA for over 30 years. He was one of the key developers of ThinThread – the surveillance program that actually worked while protecting privacy.
What he did: Binney resigned from the NSA on October 31, 2001 – appalled by the agency’s failure to prevent 9/11 and its subsequent adoption of mass warrantless surveillance. In 2002, he and colleagues (Kirk Wiebe, Ed Loomis, and Diane Roark) filed a formal complaint with the Department of Defense Inspector General alleging waste, fraud, and mismanagement.
The government’s response:
- After the New York Times published its December 2005 expose on NSA warrantless wiretapping, the FBI opened a leak investigation.
- The four individuals who had filed the 2002 Inspector General complaint were targeted as suspects – despite not being sources for the article.
- In early July 2007, a dozen FBI agents armed with rifles conducted an unannounced early-morning raid on Binney’s home. One agent reportedly aimed his weapon at Binney while Binney was in the shower.
- Binney was never charged with any crime. (Source)
Binney’s assessment: the raids were “retribution for our complaint against the NSA for corruption, fraud, waste, and abuse.” The leak investigation was used as a “pretext.”
Mark Klein – The AT&T Technician
Background: Mark Klein was a communications technician at AT&T for over 22 years, from 1981 to 2004. In 2003, he was assigned to connect circuits carrying internet data to optical “splitters” at AT&T’s central office at 611 Folsom Street, San Francisco.
What he discovered: The splitters made a copy of all data passing through AT&T’s fiber-optic backbone and delivered it into a secret, secure room – Room 641A – that was operated by the NSA. The room contained a Narus STA 6400, a device designed to intercept and analyze internet communications at very high speeds. Similar splitters were installed in AT&T facilities in other cities.
This was, effectively, real-time mass surveillance of the entire American internet backbone.
What he did: In early 2006, Klein brought over 100 pages of authenticated AT&T schematic diagrams and tables to the Electronic Frontier Foundation. The EFF used this evidence to file two lawsuits: Hepting v. AT&T (a class-action on behalf of AT&T customers) and Jewel v. NSA. (Source)
What happened: Klein was not prosecuted. He was the rare whistleblower who went directly to a civil liberties organization rather than through “proper channels” or to the press, and whose evidence was used in civil litigation rather than published in a newspaper. This may be why he avoided the fate of Drake and Binney.
Mark Klein died in March 2025 at age 79.
The Implication for Snowden
These three cases created the context for Edward Snowden’s decision:
Snowden himself explained: “No one was willing to risk their jobs, families, and possibly even freedom to go through what [Thomas Andrews] Drake did.”
Drake’s assessment: “Snowden carefully saw what happened to me and others, and it was clear… there was no other recourse.”
Binney: “I think he saw and read about what our experience was, and that was part of his decision-making.”
The “proper channels” argument collapses under the weight of these cases. Drake used every proper channel available and was rewarded with an Espionage Act indictment. Binney filed proper complaints and was rewarded with an armed FBI raid. The system demonstrated, repeatedly, that proper channels are mechanisms for identifying and punishing whistleblowers, not for addressing their concerns.
The counterargument: Drake and Binney didn’t flee to Russia. They stayed, faced the legal system, and ultimately were vindicated (Drake’s charges collapsed; Binney was never charged). Snowden’s critics argue this shows the system works – eventually. The counterargument to the counterargument is that “eventually, after years of legal torment, the charges were dropped” is not the same as “the system worked.”
8. The Jeremy Hammond Case
Who He Was
Jeremy Hammond was a self-described anarchist-communist from Chicago with a long history of political hacking. He identified as fighting “against centralized state authority” and “exploitative corporations,” seeking to build “leaderless collectives based on free association, consensus, mutual aid, self-sufficiency.”
He had a shoulder tattoo of an anarchy symbol with the words “Freedom, equality, anarchy.” He migrated from the liberal wing of the Democratic Party to Black Bloc anarchism as a teenager and was an avid reader of CrimethInc material.
The Stratfor Hack
In December 2011, Hammond (associated with AntiSec, a merger of Anonymous and LulzSec operations) hacked Stratfor, a private intelligence firm based in Austin, Texas. Stratfor described itself as providing “geopolitical intelligence” to corporate and government clients – critics called it a “private intelligence firm” conducting surveillance on activists and journalists.
What was taken:
- 60,000 credit card numbers
- $700,000 in fraudulent charges (using the stolen cards for donations to charitable organizations)
- 5 million internal emails, subsequently published by WikiLeaks
The emails revealed Stratfor’s intelligence-gathering methods, including monitoring of activists, and its relationships with government agencies and corporations.
The Sabu Informant Angle
Hector Xavier Monsegur, known as “Sabu,” was the leader of LulzSec. What Hammond and other Anonymous/LulzSec members did not know was that Sabu had been secretly arrested by the FBI on June 7, 2011, and had immediately begun working as a government informant. (Source)
What the FBI knew and enabled:
- Monsegur was cooperating with the FBI throughout the Stratfor hack.
- The FBI was aware of the hack as it happened.
- Monsegur provided Hammond with an FBI-owned server to exfiltrate the stolen emails and documents.
- Hammond alleges that Sabu “was used by his handlers to facilitate the hacking of targets of the government’s choosing – including numerous websites belonging to foreign governments.”
- Sabu reportedly distributed stolen access credentials for Brazilian government servers to Anonymous participants.
Hammond’s position: “I would not have carried out the breach of Stratfor’s systems without the involvement of Sabu.”
The entrapment question: Hammond’s defense argued that the FBI, through Sabu, actively directed and facilitated the hacking – providing targets, infrastructure, and encouragement. This raises fundamental questions about entrapment: when a government informant provides the server, identifies the target, and encourages the operation, who is really responsible?
The government’s response has been largely one of silence. Hammond’s attorney noted that “proof is only in the form of failure of government to deny.”
The Judge and the Conflict of Interest
The case was assigned to Chief U.S. District Judge Loretta Preska. Hammond’s defense discovered that Judge Preska’s husband, Thomas Kavaler, was a Stratfor client – his email address and password were among those compromised in the hack. Kavaler was a partner at Cahill Gordon & Reindel, where Judge Preska had previously worked. (Source)
Hammond’s attorneys filed a recusal motion arguing the conflict of interest was “clear cut.”
Judge Preska denied the recusal motion, arguing that her husband was not a “victim” because his email was already publicly available on his firm’s website. She further stated that granting recusal would “only encourage supporters of this defendant – or other defendants – to allege unsubstantiated conflicts of interest.”
She then sentenced Hammond to the maximum: 10 years in federal prison.
The Sentence
On November 15, 2013, Hammond was sentenced to 10 years in federal prison (the statutory maximum under his plea agreement) plus 3 years of supervised release. (Source)
The Argument
The Hammond case raises questions that the legal system has not answered:
Entrapment: If an FBI informant provides the target, the infrastructure (an FBI-owned server), and the encouragement, at what point does the government become a co-conspirator rather than an investigator?
Judicial conflict of interest: When a judge’s spouse is a client of the hacked company, the appearance of impartiality – regardless of actual bias – is compromised beyond repair.
Political motivation vs. legal outcome: Hammond’s stated motivation was exposing private intelligence surveillance of activists and journalists. The legal system treated this identically to how it would treat financially motivated cybercrime. Whether political motivation should matter is a genuine question with no easy answer.
Informant-directed operations: Sabu, while working for the FBI, directed Anonymous members to hack foreign government websites. The FBI used a hacker to create more hackers, then prosecuted the hackers it created. This is not a novel law enforcement tactic, but its application in the digital context raises particular concerns.
Cross-Cutting Themes
Disproportionality
| Case | Offense | Sentence |
|---|---|---|
| Aaron Swartz | Downloading academic papers (victim didn’t want prosecution) | Facing 35 years; died before trial |
| Kevin Mitnick | Social engineering, copying software (no financial gain) | 5 years, including 4.5 pre-trial and 8 months solitary |
| Ross Ulbricht | Operating online marketplace (first offense, non-violent) | Life without parole (pardoned after 12 years) |
| Jeremy Hammond | Hacking private intelligence firm (FBI-directed) | 10 years (maximum) |
| Carl Force | Extortion, theft, obstruction of justice (corrupt DEA agent) | 6.5 years |
| Shaun Bridges | $820K Bitcoin theft, obstruction (corrupt Secret Service) | ~6 years |
| Thomas Drake | Whistleblowing through proper channels | Indicted under Espionage Act; pled to misdemeanor |
The corrupt federal agents who stole money and obstructed justice received shorter sentences than the hackers they investigated. The whistleblower who followed every rule was treated worse than the agencies that broke the law.
The Pattern of Government Overreaction Creating Its Own Opposition
- Operation Sundevil and the Steve Jackson Games raid –> founding of the EFF
- The Neidorf prosecution –> first EFF legal case
- The Mitnick prosecution –> Free Kevin movement, hacker rights awareness
- The Swartz prosecution –> Aaron’s Law proposals, open access movement
- Drake/Binney treatment –> directly influenced Snowden’s approach
- Ulbricht’s sentence –> Free Ross movement, Trump pardon
Every disproportionate government action produced an organized response that advanced digital rights further than the original “crime” ever threatened to undermine security.
The CFAA as Enabling Statute
The CFAA appears in nearly every case:
- Swartz: 13 CFAA-based felony counts for downloading papers.
- Weev: CFAA conviction for incrementing a URL (overturned on venue).
- Hammond: CFAA charges for the Stratfor hack.
- Mitnick: Pre-CFAA, but the same legal framework.
A law inspired by a movie, written before the web existed, with undefined core terms, has been the primary mechanism for every overreach documented in this chapter.
Media Narrative vs. Reality
In every case, the public understanding was shaped by a simplified narrative that diverged from the facts:
- Swartz: “Hacker broke into MIT” vs. “downloaded papers through authorized network access; victim didn’t want prosecution.”
- Mitnick: “World’s most dangerous hacker” vs. “social engineer who never profited and whose restitution was $4,125.”
- Ulbricht: “Drug kingpin” vs. “first-time non-violent offender sentenced more harshly than actual cartel leaders.”
- Assange: “Traitor” or “hero” vs. “complicated person who did both important and harmful things.”
- Drake: “Leaker” vs. “whistleblower who exhausted every legal channel.”
Source URLs
Aaron Swartz
- JSTOR evidence archive: https://docs.jstor.org/
- MIT Abelson Report: https://swartz-report.mit.edu/
- United States v. Swartz: https://en.wikipedia.org/wiki/United_States_v._Swartz
- “The Internet’s Own Boy” (2014 documentary)
- EFF on Aaron Swartz: https://www.eff.org/deeplinks/2014/08/aaron-swarts-work-internets-own-boy
Kevin Mitnick
- “Ghost in the Wires” by Kevin Mitnick (2011)
- “Takedown” by Tsutomu Shimomura and John Markoff (1996)
- “The Fugitive Game” by Jonathan Littman (1997)
CFAA
- Van Buren v. United States, 593 U.S. ___ (2021)
- Orin Kerr, “Cybercrime’s Scope” (2003), NYU Law Review
- Tim Wu, “Fixing the Worst Law in Technology,” The New Yorker
- EFF CFAA reform page: https://www.eff.org/issues/cfaa
- Aaron’s Law: https://lofgren.house.gov/media/press-releases/lofgren-wyden-paul-introduce-bipartisan-bicameral-aaron-s-law-reform-computer
Hacker Crackdowns
- “The Hacker Crackdown” by Bruce Sterling (1992), available via Project Gutenberg
- Steve Jackson Games case archive: https://www.sjgames.com/SS/
- Craig Neidorf / United States v. Riggs
Silk Road
- United States v. Ulbricht, SDNY
- DOJ press releases on Carl Force and Shaun Bridges sentencing
- Free Ross campaign: https://freeross.org/
Julian Assange
- DOJ plea deal announcement (June 2024)
- Reporters Without Borders: https://rsf.org/en/wikileaks-publisher-julian-assange-finally-freed
- Senate Intelligence Committee report on 2016 election interference
Whistleblowers
- PBS Frontline interviews with Drake and Binney
- Government Accountability Project: https://whistleblower.org/
- EFF on Mark Klein and Room 641A
Jeremy Hammond
- FBI sentencing announcement (November 2013)
- “How an FBI informant orchestrated the Stratfor hack” (Daily Dot)
- Democracy Now coverage of Judge Preska recusal denial
Prefer RSS? Subscribe here.