Virginia Computer Crimes Act

Va. Code Title 18.2, Ch. 5, Art. 7.1 (§§ 18.2-152.2 et seq.) — Trial & Preliminary-Hearing Cheatsheet

1. Part I — Building Blocks (cite, don't charge alone)

These three sections supply definitions and reach that every charging offense in Part II depends on. They are not standalone charges. Most contested issues at a computer-crime hearing turn on "uses," "without authority," or what counts as "property."

§ 18.2-152.2 — Definitions

Definitional — supplies terms for the entire Article.

  • "Uses" a computer/network A person uses a computer when he attempts to cause or causes it to perform or stop performing operations. The attempt is built in — no completed operation needed for the "use" element.
  • "Without authority" The person knows or reasonably should know he has no right, agreement, or permission, or acts in a manner knowingly exceeding the right/permission given. This is the hook for the insider / exceeds-authorized-access theory (e.g., an employee with login rights who accesses data outside his job).
  • "Property" Expressly includes real property; computers and networks; financial instruments, computer data, programs, and software; and computer services. Reaches property whether tangible or intangible, human- or machine-readable, in transit between or within computers, or stored on paper or any device. Intangible data and data in transit are property.
  • "Computer" A device that accepts digital information and manipulates it by a sequence of instructions. Excludes simple calculators, automated typewriters, fax machines, and narrow single-purpose preprogrammed devices.
  • "Computer services" Computer time or services, including data processing, Internet, email, and message services, and data stored in connection with them.
  • "Computer network" / "network" Two or more computers connected by a network; "network" covers transmission facilities, switches, routers, and similar interconnected equipment.
  • "Owner" Owner/lessee of a computer or network, or owner/lessee/licensee of data, programs, or software — broader than title ownership.
  • "Person" Includes individuals, partnerships, associations, corporations, and joint ventures.

§ 18.2-152.8 — Property Capable of Embezzlement

Definitional — enables larceny/embezzlement theories.

For purposes of § 18.2-95, § 18.2-96, § 18.2-108, and § 18.2-111 (grand/petit larceny, receiving stolen goods, embezzlement), personal property subject to those crimes includes computers and networks; financial instruments; computer data, programs, and software (tangible or intangible, human- or machine-readable, in transit, or stored on any device or paper); and computer services.

§ 18.2-152.11 — Article Not Exclusive

Charging-strategy provision.

This Article does not preclude any other criminal-law provision that applies to the same transaction or course of conduct, unless that provision is clearly inconsistent with the Article.

2. Quick Grade & Threshold Index

SectionGrade Summary
§ 18.2-152.3Computer fraud — Class 5 felony if ≥ $1,000; else Class 1 misd.
§ 18.2-152.3:1Spam — Class 1 misd.; Class 6 felony at volume/revenue thresholds or minor-assist.
§ 18.2-152.4Computer trespass — Class 1 misd.; Class 6 felony for infrastructure target, $1,000 damage, >5 computers, or malicious A.8.
§ 18.2-152.5Computer invasion of privacy — Class 1 misd.; Class 6 felony on prior conviction, sale/distribution, or use in another crime.
§ 18.2-152.5:1Gather identifying info by deception — Class 6 felony; Class 5 felony on sale/distribution or use in another crime.
§ 18.2-152.6Theft of computer services — Class 1 misd.; Class 6 felony if ≥ $2,500.
§ 18.2-152.7Personal trespass by computer — Class 3 felony (malicious) / Class 6 felony (unlawful).
§ 18.2-152.7:1Harassment by computer — Class 1 misd.
§ 18.2-152.7:2Scheme / false representations (no benefit) — Class 1 misd.
§ 18.2-152.14Computer as instrument of forgery — grade follows underlying forgery offense (§ 18.2-168 et seq.).
§ 18.2-152.15Encryption to further crime — Class 1 misd. (separate and distinct offense).

Felony class maxima (§ 18.2-10): Class 3 — 5 to 20 yrs + up to $100,000; Class 5 — 1 to 10 yrs (or jury/court may set ≤12 mo. / $2,500); Class 6 — 1 to 5 yrs (or ≤12 mo. / $2,500). Class 1 misdemeanor — up to 12 months / $2,500 (§ 18.2-11). Confirm current penalty ranges before relying on them.

3. § 18.2-152.3 — Computer Fraud

Class 5 felony / Class 1 misdemeanor by value.

Elements — Prove Each BRD

  1. Use of a computer or computer network (includes attempt to cause an operation — § 18.2-152.2)
  2. Without authority (§ 18.2-152.2 definition; reaches exceeding-authority insiders); and
  3. the defendant thereby (a) obtained property or services by false pretenses, (b) embezzled or committed larceny, or (c) converted the property of another.
GradeTrigger / When It Applies
Class 5 felonyValue of property or services obtained is $1,000 or more.
Class 1 misdemeanorValue is less than $1,000.

Proof / Evidence Notes

  • Value is usually the contested element. The $1,000 line is the current felony threshold (raised from $200 via the 2018/2020 larceny amendments — older files may cite $200). Line up a valuation witness and document the basis (market value, replacement cost, value of services obtained).
  • "Property" and "services" are broad (§ 18.2-152.2); pair with § 18.2-152.8 so intangible data supports the larceny/embezzlement predicate.
  • Pick your theory in the charging document — false pretenses vs. larceny/embezzlement vs. conversion carry different proof. False pretenses needs a false representation of a present/past fact that induced the transfer; embezzlement needs entrustment; conversion needs wrongful exercise of dominion.
  • Tie "without authority" to concrete proof of the permission's scope (credentials, policy, TOS) and where the defendant exceeded it.
  • Consider stacking under § 18.2-152.11 (parallel false-pretenses / grand larceny) and § 18.2-152.15 (encryption) where applicable.

Key Virginia Case Law

Commonwealth v. Wallace Rec. No. 240138 (Va. Nov. 21, 2024) (published order), rev'g Wallace v. Commonwealth, 79 Va. App. 455 (2024) (en banc), Va., 2024

binding

Depositing forged checks at one's own bank ATM is computer fraud — general permission to use a device does not authorize using it for an unpermitted purpose. The Supreme Court reversed the en banc Court of Appeals and reinstated the convictions "for the reasons stated in the dissenting opinion" below. (3 Justices dissented.) Only the second time the Supreme Court construed § 18.2-152.3. ⚠️ "An ATM is a computer" is NOT a flat rule. The en banc majority assumed it without deciding; Callins, J. would have held this ATM is not a computer; and the controlling dissent held this ATM qualifies but not every ATM — a cash-only stand-alone unit may fall inside § 18.2-152.2's exceptions for devices "dedicated to a specific task."

⚠️ cite the Supreme Court order — the en banc CoA opinion at 79 Va. App. 455 is REVERSED; its dissent at 476–84 is the law

DiMaio v. Commonwealth 46 Va. App. 755, 2005

binding

Construes the computer-fraud/computer-trespass interplay; useful on what the Commonwealth must show for value and on the misdemeanor/felony line.

A.V. ex rel. Vanderhye v. iParadigms, LLC 562 F.3d 630, 4th Cir., 2009

persuasive federal

Civil VCCA decision (§§ 152.3, 152.6, 152.12); persuasive, not binding, but reads "any damages" broadly and discusses the false-pretenses theory.

Common Defenses & Rebuttals

Defense attackProsecution response
"He had permission to use the computer/account, so not 'without authority.'"Per Commonwealth v. Wallace, Rec. No. 240138 (Va. Nov. 21, 2024) — ⚠️ the Supreme Court order, which REVERSED the en banc Court of Appeals at 79 Va. App. 455 — general permission to use a device does not authorize using it for an unpermitted/fraudulent purpose; build the record on the scope of permission and the purpose of the access.
"The Commonwealth can't prove value ≥ $1,000."Concede the misdemeanor if needed but present valuation proof (market/replacement value, value of services); value affects grade, not guilt of the base offense.
"No property was 'obtained' — only data was viewed/copied."§ 18.2-152.2 and § 18.2-152.8 define property to include intangible data and make data capable of larceny/embezzlement; tie to the chosen theory (false pretenses/larceny/conversion).

4. § 18.2-152.3:1 — Spam / Unsolicited Commercial Email

Class 1 misdemeanor / Class 6 felony by volume or revenue.

Elements — Subsection A (Base Misdemeanor)

A.1 — Falsified routing

  1. Use of a computer or computer network
  2. With intent to falsify or forge email transmission or routing information
  3. In connection with transmitting spam (unsolicited commercial email — § 18.2-152.2) through or into an EMSP's network or its subscribers

A.2 — Falsification software

Knowingly sells, gives, distributes, or possesses with intent to distribute software that (i) is primarily designed to falsify routing info, (ii) has only limited other commercial use, or (iii) is marketed for that falsification purpose.

GradeTrigger / When It Applies
Class 1 misdemeanorBase violation of A.1 or A.2.
Class 6 felony (B)A.1 violation where volume exceeds 10,000 recipients/24 hrs, 100,000/30 days, or 1,000,000/year; OR revenue from one transmission exceeds $1,000 or total revenue to any EMSP exceeds $50,000.
Class 6 felony (C)Knowingly hiring, employing, using, or permitting a minor to assist in a subsection-B spam violation.

Proof / Evidence Notes

  • Header/routing forensics drive this charge. Preserve full message headers; establish the falsification or forgery of transmission/routing data, not merely that email was unwanted.
  • "Spam" excludes commercial email to a recipient with whom the sender has an existing business or personal relationship (§ 18.2-152.2) — anticipate that defense.
  • For the felony, the volume/revenue thresholds are elements; prove them with EMSP logs, recipient counts within the defined time windows, and financial records tying revenue to the transmissions.
  • Note the parallel civil remedy in § 18.2-152.12(B)–(C) (statutory damages per message/day); relevant if a victim EMSP is involved.

Common Defenses & Rebuttals

Defense attackProsecution response
"Statute is unconstitutionally overbroad (per Jaynes)."Distinguish the current "commercial" text from the "bulk" version Jaynes struck; the messages here are commercial and routing information was forged — conduct at the core of a properly narrowed statute. Be prepared to brief it.
"Recipient had an existing business/personal relationship, so it isn't 'spam.'"§ 18.2-152.2 excludes such email; rebut with proof there was no prior relationship and messages were unsolicited and commercial.
"No falsification — the headers were merely inaccurate."Prove intent to falsify/forge transmission or routing info with header forensics and EMSP records; intent is the gravamen of A.1.

5. § 18.2-152.4 — Computer Trespass

Class 1 misdemeanor / Class 6 felony by aggravator.

Enumerated Acts — Prove at Least One

  1. Temporarily/permanently remove, halt, or disable data, programs, or software from a computer/network
  2. Cause a computer to malfunction (regardless of duration)
  3. Alter, disable, or erase data, programs, or software
  4. Effect creation/alteration of a financial instrument or electronic funds transfer
  5. Use a computer/network to cause physical injury to property of another
  6. Make/cause an unauthorized copy (any form) of data, programs, or software
  7. [Subdivision 7 repealed]
  8. Install, cause to be installed, or collect information through keystroke-logging software capturing all/most keystrokes of another
  9. Install software on another's computer to (i) take control so it can damage another computer, or (ii) disable/disrupt its ability to share or transmit data to other computers or devices
GradeTrigger / When It Applies
Class 1 misdemeanorBase computer trespass.
Class 6 felonyTarget computer used exclusively by/for (i) the Commonwealth or any VA local government/agency, or (ii) a provider of telephone, oil, electric, gas, sewer, wastewater, or water service to the public.
Class 6 felonyDamage to another's property valued at $1,000+ caused by an act done with malicious intent.
Class 6 felonyWith malicious intent, installs software in violation on more than five computers of another.
Class 6 felonyViolates subdivision A.8 (keystroke logging) with malicious intent.

Proof / Evidence Notes

  • Subsection C carves out a lot. No liability for contract/license terms or EMSP anti-spam measures; for monitoring a minor or a person with a disability/mental impairment (§ 51.5-40.1); for a parent/guardian monitoring a minor's computer use, lawfully copying data, or denying access; or for activity a reasonable user should expect from a hardware/software provider, ISP, or telecom/cable operator, or that law requires/authorizes. The parental-monitoring and provider-expectation carve-outs are common defenses.
  • Pin down which mental-state path you're on: malicious intent vs. intentionally deceptive means + without authority. The felony aggravators (critical-infrastructure target, $1,000 damage, >5 computers, A.8) generally require malicious intent — plead it.
  • For the infrastructure felony, prove the target computer was exclusively used by/for the protected entity — establish with custodian testimony about the system's dedicated use.
  • For the >5-computers felony, count the devices and tie each to a malicious installation; for the $1,000-damage felony, document repair/replacement/loss valuation.

Key Virginia Case Law

DiMaio v. Commonwealth 46 Va. App. 755, 2005

binding

Departing employee took/deleted employer files. Misdemeanor computer trespass does NOT require proof of property damage — damage valuation matters only for the felony grade. Useful on the misdemeanor/felony divide and on the "without authority" of a departing insider.

Several enumerated theories (esp. A.8 keystroke logging, A.9 control/disruption software) have limited published Virginia appellate construction. Where state authority is thin, federal CFAA (18 U.S.C. § 1030) decisions are sometimes cited as persuasive on "without authority"/"exceeds authorized access," but are not binding — frame them as such.

Common Defenses & Rebuttals

Defense attackProsecution response
"No property damage, so no crime."Per DiMaio, damage is not an element of misdemeanor trespass; it only elevates to felony. The act + required mental state suffices for the misdemeanor.
"This falls under the parental-monitoring or provider-expectation carve-out (subsection C)."Show the facts fall outside the carve-outs — not a parent/guardian of a minor, or conduct beyond what a reasonable user would expect from a provider; subsection C is narrow and fact-specific.
"He acted without malice and with authority."Establish the alternative mens rea path — intentionally deceptive means + without authority — which does not require malice (malice is needed only for certain felony aggravators).

6. § 18.2-152.5 — Computer Invasion of Privacy

Class 1 misdemeanor / Class 6 felony aggravators.

Elements — Prove Each BRD

  1. Use of a computer or computer network
  2. The defendant intentionally examines without authority
  3. Employment, salary, credit, or other financial or identifying information relating to another person, as defined in clauses (iii)–(xiii) of § 18.2-186.3(C)

Incorporated identifying information under § 18.2-186.3(C), clauses (iii)–(xiii): (iii) social security number; (iv) driver's license number; (v) bank account numbers; (vi) credit or debit card numbers; (vii) personal identification numbers (PIN); (viii) electronic identification codes; (ix) automated or electronic signatures; (x) biometric data; (xi) fingerprints; (xii) passwords; or (xiii) any other numbers or information that can be used to access a person's financial resources, obtain identification, or obtain money, credit, loans, goods, or services.

Note: clauses (i) name and (ii) date of birth are deliberately NOT incorporated — those two alone do not satisfy the element.

GradeTrigger / When It Applies
Class 1 misdemeanorBase offense (subsection B).
Class 6 felony (C)Prior conviction under this section or substantially similar law of another state or the U.S.
Class 6 felony (D)Defendant sells or distributes the information to another.
Class 6 felony (E)Defendant uses the information in the commission of another crime.

Proof / Evidence Notes

  • The "after he knows/should know" timing is the heart of the offense. Build the record that defendant continued viewing once authority ended (e.g., after termination, after a warning, after opening a file plainly outside his role).
  • Exception (subsection F). Does not apply to collecting info reasonably needed to (i) protect security of/diagnose/repair a computer, service, or business, or (ii) determine whether user is licensed/authorized to use specific software or service. Anticipate the "IT/security" defense.
  • Match the data examined to a specific incorporated clause; if it's only name + DOB, the element fails.

Key Virginia Case Law

Ramsey v. Commonwealth 65 Va. App. 694, 2015

binding

Police dispatcher ran VCIN/database inquiries on individuals for non-criminal-justice reasons. Court of Appeals affirmed multiple § 152.5 convictions: she acted "without authority" because her dispatcher duties gave no reason to access the data and a warning appeared each time. Holds it is the unauthorized access that violates the statute, regardless of later use. Adopts the federal CFAA "exceeds authorized access" framework.

Plasters v. Commonwealth Rec. No. 1870-99-3, 2000 Va. App. LEXIS 473 (Va. Ct. App. June 27, 2000) (unpublished), Va. App., 2000

persuasive

Police dispatcher ran VCIN inquiries for non-criminal-justice purposes: four § 18.2-152.5 convictions affirmed, a fifth reversed on the Commonwealth's concession that out-of-state access was unproved. "The evidence must establish the offender viewed the information after she knew or should have known she was unauthorized to do so." Unpublished; Ramsey found its reasoning persuasive.

unpublished, followed in Ramsey

Common Defenses & Rebuttals

Defense attackProsecution response
"I had login access, so I had authority."Per Ramsey, authorized credentials are not authority to view data outside one's job purpose; use warnings, policies, and the absence of a job-related need to show he knew or should have known he exceeded authority.
"I only glanced — I didn't 'examine' it."The statute defines examination as reviewing the information AFTER he knows he lacks authority; prove continued review past that point (e.g., running multiple queries, drilling into records).
"It was for security/diagnostics (subsection F)."Rebut with proof the access was not reasonably needed for security, repair, or license verification — the exception is limited to those purposes.

7. § 18.2-152.5:1 — Gather Identifying Info by Deception

Class 6 felony / Class 5 felony aggravators — the phishing/pretexting statute.

Elements — Prove Each BRD

  1. The defendant (other than a law-enforcement officer under § 9.1-101 acting in official duties)
  2. uses a computer to obtain, access, or record
  3. through material artifice, trickery, or deception
  4. any identifying information as defined in clauses (iii)–(xiii) of § 18.2-186.3(C) (same list as § 152.5)
GradeTrigger / When It Applies
Class 6 felonyBase offense (subsection A).
Class 5 felony (B)Defendant sells or distributes the information to another.
Class 5 felony (C)Defendant uses the information in the commission of another crime.

Proof / Evidence Notes

  • This is the phishing/pretexting statute. The gravamen is deception (a spoofed site, fake login, false pretext) used to harvest the data. Distinguish from § 18.2-152.5, which targets unauthorized examination without the artifice element.
  • Prove the artifice/trickery/deception with specificity — the deceptive mechanism is what elevates this to a baseline felony.
  • Same incorporated clause list as § 152.5; name + DOB alone do not suffice.
  • Watch overlap with identity-theft (§ 18.2-186.3 itself) and computer fraud — § 18.2-152.11 permits parallel charging.

Common Defenses & Rebuttals

Defense attackProsecution response
"No artifice/trickery — the data was voluntarily provided."The deceptive mechanism is the element; prove the spoofed site/false pretext that induced disclosure. Genuinely voluntary, informed disclosure defeats the charge — distinguish it factually.
"The data isn't covered identifying information."Match the data to a specific clause (iii)–(xiii) of § 18.2-186.3(C); name + DOB alone do not suffice, but SSN, account/card numbers, PINs, passwords, biometric data, etc. do.
"My client is law enforcement acting officially."The exemption is limited to a § 9.1-101 officer in performance of official duties; rebut if outside that scope.

8. § 18.2-152.6 — Theft of Computer Services

Class 1 misdemeanor / Class 6 felony by value.

Elements — Prove Each BRD

  1. The defendant willfully
  2. obtained computer services (computer time, data processing, Internet, email, message services, or data stored in connection therewith — § 18.2-152.2)
  3. without authority.
GradeTrigger / When It Applies
Class 1 misdemeanorBase offense.
Class 6 felonyTheft of computer services valued at $2,500 or more. NOTE: this threshold is $2,500 — NOT the $1,000 line used in § 152.3. Do not conflate.

Proof / Evidence Notes

  • Mind the $2,500 felony line. It is distinct from the $1,000 computer-fraud threshold. Value the services obtained (e.g., usage logs, bandwidth/compute metering, subscription value) and document the methodology.
  • "Willfully" is the mental state — prove intent, not accident or authorized use that merely exceeded an informal expectation.
  • Establish lack of authority concretely (no account, revoked credentials, circumvented paywall/license).

Construed mainly in the civil VCCA context — see A.V. ex rel. Vanderhye v. iParadigms, LLC, 562 F.3d 630 (4th Cir. 2009) (§ 152.6 alongside § 152.3). Limited published Virginia criminal appellate construction located; verify before charging.

Common Defenses & Rebuttals

Defense attackProsecution response
"Use wasn't willful — it was inadvertent or believed authorized."Prove willfulness with evidence of circumvention (cracked credentials, bypassed paywall, knowledge access was cut off).
"The Commonwealth can't value the services at $2,500."Concede the misdemeanor if necessary; for the felony, value with usage/metering data and subscription/market rates. Note the threshold is $2,500, not $1,000.

9. § 18.2-152.7 — Personal Trespass by Computer

Class 3 felony (malicious) / Class 6 felony (unlawful) — rarely charged.

Elements — Prove Each BRD

  1. The defendant uses a computer or computer network
  2. to cause physical injury to an individual (a person, not property — contrast § 18.2-152.4(A)(5))
GradeTrigger / When It Applies
Class 3 felonyCommitted maliciously.
Class 6 felonyDone unlawfully but not maliciously.

Proof / Evidence Notes

  • Physical injury to a person is the line. Separates this from computer trespass (§ 152.4, injury to property). Think medical-device tampering, industrial/SCADA manipulation causing bodily harm, or altering systems that control physical safety.
  • Malice drives the grade — a Class 3 felony is a serious exposure; develop intent evidence (planning, motive, awareness that injury would result).
  • Prove causation between the computer use and bodily injury with medical and technical evidence.

Common Defenses & Rebuttals

Defense attackProsecution response
"The injury was to property, not a person."If harm is to property, the correct charge is § 18.2-152.4(A)(5), not § 152.7; make sure the evidence shows physical injury to an individual.
"No malice — at most negligence."Malice drives the Class 3 grade; if malice is doubtful, the unlawful-but-not-malicious Class 6 felony remains. Develop intent/foreseeability-of-injury evidence.
"The computer use didn't cause the injury."Establish the causal chain from the computer operation to bodily harm with technical and medical proof.

10. § 18.2-152.7:1 — Harassment by Computer

Class 1 misdemeanor.

Elements — Prove Each BRD

  1. The defendant, with intent to coerce, intimidate, or harass any person
  2. uses a computer or computer network to communicate
  3. (a) obscene, vulgar, profane, lewd, lascivious, or indecent language; (b) any suggestion or proposal of an obscene nature; or (c) a threat of any illegal or immoral act.

Proof / Evidence Notes

  • Specific intent is the core — intent to coerce, intimidate, or harass. Preserve the full communications and surrounding context (frequency, prior contact, response to requests to stop) to prove intent rather than mere offensive speech.
  • Be alert to First Amendment limits. "Profane/indecent" language untethered from a true threat or obscenity may raise overbreadth/as-applied challenges. The statute was amended in 2020 and 2022; confirm the current text and any narrowing construction.
  • Identify the actual sender — account attribution, IP/device evidence, authorship — a frequent contested issue.
  • Cross-reference § 18.2-427 (obscene/threatening communications), which is similarly worded and shares the obscenity-test construction.

Key Virginia Case Law

Barson v. Commonwealth 284 Va. 67, 726 S.E.2d 292 (2012), Va., 2012

binding

⚠️ CONVICTION VACATED, and by the Supreme Court of Virginia — not, as this sheet formerly said, affirmed by the Court of Appeals. The CoA en banc had abandoned Allman's § 18.2-372 definition of "obscene" for a dictionary definition; applying that broader standard to conduct already past "retroactively criminalized his conduct" and violated due process. Barson's emails, "as offensive, vulgar and disgusting as their language may have been, did not meet the standard of obscenity that prevailed in Virginia at the time they were sent."

Airhart v. Commonwealth Rec. No. 1219-05-2 (Va. Ct. App. Jan. 16, 2007) (unpublished), Va. App., 2007

binding

⚠️ REVERSED AND DISMISSED — the opposite of what this sheet formerly said. The evidence was insufficient to prove the communication was obscene: the words had explicit sexual connotations but "were used to express anger, contempt and disgust and were not used in an erotic sense," so they did not appeal to the prurient interest. The court expressly did not reach the intent element or the prior-bad-act issue, and decided no vagueness or overbreadth challenge at all.

Common Defenses & Rebuttals

Defense attackProsecution response
"The statute is vague/overbroad under the First Amendment."⚠️ This sheet no longer cites authority that the statute survives facial attack — the case formerly named here decided no constitutional challenge at all (see Annotated Authority). What IS settled is that the "obscene" prong is cabined by the § 18.2-372 test: Barson, 284 Va. 67 (2012), VACATED a conviction because the Court of Appeals had widened it. Anchor the charged language to constitutionally proscribable categories (true threats, obscenity), and find current authority before arguing facial validity.
"This was protected, if offensive, speech."Tie the communication to a threat of an illegal/immoral act or obscene material, plus the specific intent to coerce/intimidate/harass shown by context (frequency, prior contact, refusal to stop).
"My client wasn't the sender."Prove authorship/attribution with account, IP, device, and content evidence.

11. § 18.2-152.7:2 — Scheme Involving False Representations

Class 1 misdemeanor — targets malicious hoaxes, not fraud for gain.

Elements — Prove Each BRD

  1. The defendant acts without intent to receive any direct or indirect benefit
  2. maliciously sends an electronically transmitted communication
  3. containing a false representation intended to cause another to spend money; and
  4. the false representation actually causes that person to spend money (result element).

Proof / Evidence Notes

  • Prove the result: the victim actually spent money because of the false representation. Establish reliance and causation, plus the expenditure.
  • "Maliciously" is required — develop intent to cause the victim loss/expense.

Enacted in 2020; no published Virginia appellate construction was located. Plead and prove strictly to the statutory text — especially the unusual "no direct or indirect benefit" element and the result element (victim actually spent money). Verify before the hearing.

Common Defenses & Rebuttals

Defense attackProsecution response
"My client sought a benefit — so this statute doesn't fit."If true, this section fails (requires NO benefit) — but that points toward computer fraud (§ 18.2-152.3); charge in the alternative under § 18.2-152.11.
"The victim didn't actually spend money."The expenditure is a result element; prove the victim spent money and that the false representation caused it (reliance + causation).
"No malice."Develop intent to cause loss/expense — e.g., a hoax designed to make the victim pay for something illusory.

12. § 18.2-152.14 — Computer as Instrument of Forgery

Grade follows the underlying forgery offense (§ 18.2-168 et seq.) — bridge statute, not a standalone charge.

What It Does

Creating, altering, or deleting computer data that would constitute forgery if done on a tangible document under the forgery article (§ 18.2-168 et seq.) is deemed forgery. The absence of a tangible writing is not a defense where a creation/alteration/deletion of computer data was involved in lieu of a tangible instrument.

How to Charge

Charge the substantive forgery offense from Article 1 of Chapter 6 (e.g., forgery of a writing, § 18.2-172; forging public records, § 18.2-168) and use § 18.2-152.14 to defeat the "no tangible writing" defense. Grade and elements come from the underlying forgery statute charged.

Proof / Evidence Notes

  • Prove every element of the predicate forgery offense — a writing/instrument of apparent legal efficacy, a false making or material alteration, and (for uttering) intent to defraud — substituting the data act for the tangible writing.
  • Establish the data act (creation, alteration, or deletion) forensically: what was changed, by whom, when, and that it carried apparent legal significance.
  • Confirm the current elements of the specific forgery section you charge before the hearing — this cheatsheet does not reproduce the forgery article.

Common Defenses & Rebuttals

Defense attackProsecution response
"There was no tangible forged writing."§ 18.2-152.14 expressly removes that defense — a creation/alteration/deletion of computer data in lieu of a tangible instrument is forgery.
"The data altered had no legal significance."Prove the data, if tangible, would be a writing of apparent legal efficacy under the predicate forgery statute.
"No intent to defraud."Intent to defraud is imported from the predicate forgery offense; prove it as you would in a tangible-document forgery case.

13. § 18.2-152.15 — Encryption Used in Criminal Activity

Class 1 misdemeanor — separate and distinct offense; add-on count.

Elements — Prove Each BRD

  1. The defendant willfully uses encryption
  2. to further any criminal activity.

"Encryption" = enciphering intelligible data into unintelligible form, or deciphering unintelligible data into intelligible form.

Proof / Evidence Notes

  • Prove (a) use of encryption, (b) willfulness, and (c) a nexus to furthering specific criminal activity. Not mere possession of encrypted data or routine/incidental encryption.
  • Tie the encryption to the criminal purpose with forensic evidence (encrypted containers tied to the offense, timing, statements, concealment behavior).

No published Virginia appellate decision construing § 18.2-152.15 has been located — it is rarely charged and almost always paired with a predicate offense. Be prepared to argue the "willfully…to further" nexus from first principles and the statutory text. Verify before the hearing.

Common Defenses & Rebuttals

Defense attackProsecution response
"Encryption was routine/incidental, not used to further a crime."Prove the willful nexus — encryption deployed to conceal or advance the specific predicate offense, shown by timing, content, and concealment behavior. Default device encryption alone is insufficient.
"This is just the same conduct as the predicate — double counting."The statute makes it expressly separate and distinct from the predicate; it is a permissible additional count, not a lesser-included.

14. § 18.2-152.12 — Civil Relief & Damages (reference only)

Civil — not a criminal charge. Why a prosecutor keeps this handy: Provides a private civil cause of action for any person whose property or person is injured by an Article violation — including any computer-trespass act in § 18.2-152.4(A)(1)–(8) regardless of malicious intent. Damages include lost profits and costs of suit.

  • Spam-specific statutory damages (subsections B–C). Injured persons/EMSPs may elect statutory damages in lieu of actual damages, plus attorney fees — context for § 152.3:1 matters and for victim restitution discussions.
  • Subsection D. Lets the court protect the secrecy/security of the computer systems and trade secrets and the privacy of non-party complainants during proceedings — useful framing for protective-order requests touching sensitive systems.
  • Subsection F. Sets the limitations period by cross-reference to § 8.01-40.1 and the long-arm provision (§ 8.01-328.1) for spam injuries — worth knowing when coordinating with victims.

15. Pre-Trial Checklist — Day of Court

  • Charging document correct — statute, section, and subsection identified; theory of fraud/embezzlement/conversion specified if charging § 152.3
  • Value threshold confirmed and documented § 152.3: $1,000 felony line (not $200). § 152.6: $2,500 felony line (not $1,000). Prepare valuation witness and basis.
  • Definitional building blocks ready — § 152.2 definitions pleaded and proof mapped to each term
  • § 152.8 invoked if intangible data is the 'property' — anticipate the 'not real property' defense
  • 'Without authority' proof locked in — permissions scope document, TOS, employment policy, access logs, warning screens
  • Digital forensic expert (if needed) subpoenaed and qualified
  • Chain of custody for digital evidence documented — imaging, hash values, storage, access log
  • Email/routing headers preserved in native format (spam and harassment cases)
  • For § 152.3:1 (spam) — EMSP logs, recipient counts, revenue records pulled; Jaynes issue briefed
  • For § 152.4 (trespass) — mental state pinned down (malicious vs. deceptive means + without authority); infrastructure target documentation ready if felony
  • For § 152.5 (invasion of privacy) — identifying data matched to specific § 18.2-186.3(C) clause (iii)–(xiii); timing of unauthorized access documented
  • For § 152.7 (personal trespass) — medical evidence secured; causation chain from computer act to bodily injury established
  • For § 152.7:1 (harassment) — complete communications preserved with metadata; sender attribution evidence ready
  • For § 152.14 (computer forgery) — predicate forgery statute identified and its elements mapped; data act established forensically
  • For § 152.15 (encryption) — encryption tied to predicate offense by timing, content, and concealment behavior
  • Stacking analysis done under § 152.11 — double-jeopardy/Blockburger same-elements review for sentencing
  • Civil remedy under § 152.12 reviewed if victim EMSP or other civil plaintiff is involved
  • Discovery complete and disclosed
  • Brady/Giglio review done
  • Carve-outs screened (§ 152.4(C) — parental monitoring, provider expectation, law-authorization exceptions)
  • Plea cutoff and terms locked in

16. Key Cases — One-Line Holdings

Commonwealth v. Wallace Rec. No. 240138 (Va. Nov. 21, 2024) (published order), rev'g 79 Va. App. 455 (2024) (en banc), Va., 2024

binding

General permission to use a device does not authorize use for an unpermitted purpose. Key authority on "without authority" for § 152.3. ⚠️ Cite the Supreme Court order, not the en banc Court of Appeals opinion, which it reversed; and "an ATM is a computer" is qualified, not flat.

DiMaio v. Commonwealth 46 Va. App. 755, 2005

binding

Misdemeanor computer trespass (§ 152.4) does NOT require property damage; damage matters only for the felony grade. Also construes § 152.3 value/misdemeanor line.

Ramsey v. Commonwealth 65 Va. App. 694, 2015

binding

Unauthorized access is the § 152.5 violation regardless of later use; adopts CFAA "exceeds authorized access" framework for insiders.

Jaynes v. Commonwealth 276 Va. 443, 2008

binding

Prior "unsolicited bulk email" version of § 152.3:1 held facially unconstitutional; current "commercial" version narrower — verify enforceability before charging.

Barson v. Commonwealth 284 Va. 67, 726 S.E.2d 292 (2012), Va., 2012

binding

⚠️ § 152.7:1 conviction VACATED by the Supreme Court of Virginia on due process grounds — the Court of Appeals had widened "obscene" beyond § 18.2-372 and applied the wider test retroactively.

Airhart v. Commonwealth Rec. No. 1219-05-2 (Va. Ct. App. Jan. 16, 2007) (unpublished), Va. App., 2007

binding

⚠️ § 152.7:1 conviction reversed and dismissed for insufficient proof that the language was obscene under § 18.2-372. It decided no constitutional challenge.

A.V. ex rel. Vanderhye v. iParadigms, LLC 562 F.3d 630, 4th Cir., 2009

persuasive federal

Civil VCCA (§§ 152.3, 152.6, 152.12); persuasive on damages breadth and false-pretenses theory.

Plasters v. Commonwealth Rec. No. 1870-99-3, 2000 Va. App. LEXIS 473 (Va. Ct. App. June 27, 2000) (unpublished), Va. App., 2000

persuasive

Early application of exceeds-authority theory to a government-database insider (VCIN); four counts affirmed, one reversed for want of proof of out-of-state access. Followed in Ramsey.

unpublished

17. Annotated Authority

Annotated authority — research layer, not printed on the PDF

Broadrick v. Oklahoma 413 U.S. 601, 615, U.S., 1973

A statute is facially overbroad only if it "punishes a 'SUBSTANTIAL' AMOUNT OF PROTECTED FREE SPEECH, JUDGED IN RELATION TO THE STATUTE'S PLAINLY LEGITIMATE SWEEP."

Practical value: The test the Commonwealth lost under in Jaynes. Substantial overbreadth is "NOT A TEST OF THE CONSTITUTIONALITY of a statute, but a policy related to the REMEDY flowing from a successful facial challenge" — so arguing that most applications would be constitutional does not save the statute.

Lund v. Commonwealth 217 Va. 688, 232 S.E.2d 745, Va., 1977

"Where an item HAS NO MARKET VALUE, its ACTUAL VALUE must be shown."

Practical value: The starting point for valuing data, source code or computer time — none of which has a market price in the ordinary sense. ⚠️ NOTE FOR THE FRAUD SHEET: Lund is a VALUATION case. The three annotations that formerly cited it on `fraud` (credit-card transactions, intent to defraud in forgery, pecuniary loss) were all wrong and were stripped.

Dunn v. Commonwealth 222 Va. 704, 705, 284 S.E.2d 792, 792, Va., 1981

Value may be proved by TRADITIONAL ACCOUNTING PRINCIPLES — starting with the ORIGINAL COST and then factoring in DEPRECIATION OR APPRECIATION.

Practical value: The most workable route for business records and software: get the purchase or development cost and the depreciation schedule.

Kern v. Commonwealth 2 Va. App. 84, 88, 341 S.E.2d 397, 399-400, Va. Ct. App., 1986

Value may be established by an EXPERT'S OPINION.

Practical value: Where the item is genuinely technical — a database, a customer list, proprietary code — the expert route is usually cleaner than accounting.

Walls v. Commonwealth 248 Va. 480, 482, 450 S.E.2d 363, 364, Va., 1994

"[T]he OPINION TESTIMONY OF THE OWNER of personal property is COMPETENT AND ADMISSIBLE on the question of the value of such property, REGARDLESS OF THE OWNER'S KNOWLEDGE OF PROPERTY VALUES." A non-expert, non-owner may also testify provided the witness has sufficient knowledge of the value.

Practical value: The cheapest route to value, and the one most often overlooked: the business owner can simply testify, and the defence cannot exclude him for lacking valuation expertise.

Crowder v. Commonwealth 41 Va. App. 658, 664 n.3, 588 S.E.2d 384, 387 n.3, Va. Ct. App., 2003

Value may be established by a LAY OPINION of the property's FAIR MARKET VALUE.

Practical value: Completes the four routes DiMaio collects — lay opinion, expert opinion, accounting principles, and owner testimony.

DiMaio v. Commonwealth 46 Va. App. 755, 621 S.E.2d 696, Va. Ct. App., 2005

Convictions AFFIRMED for computer fraud, computer trespass, embezzlement and attempted extortion (§§ 18.2-152.3, 18.2-152.4, 18.2-111, 18.2-59). Collects the FOUR ROUTES TO PROVING VALUE. And a point counsel CONCEDED at oral argument: Code § 18.2-152.4 DOES NOT REQUIRE PROOF THAT PROPERTY WAS DAMAGED for a MISDEMEANOR conviction.

Practical value: The single most useful case on the sheet. The value routes matter because computer-crime charges are graded by value, and the no-damage-required point disposes of the commonest defence to misdemeanor computer trespass. ⚠️ There are TWO DiMaio decisions — this Court of Appeals judgment at 46 Va. App. 755, and a later Supreme Court decision at 272 Va. 531. Check which one a brief is citing.

Jaynes v. Commonwealth (Court of Appeals) 48 Va. App. 673, 634 S.E.2d 357, Va. Ct. App., 2006

AFFIRMED the convictions under § 18.2-152.3:1 — and was REVERSED by the Supreme Court.

Practical value: Superseded. Do not cite it for anything; it is here so that a brief relying on it can be recognised as out of date.

Jaynes v. Commonwealth 276 Va. 443, 666 S.E.2d 303, Va., 2008

⛔ THE ANTI-SPAM STATUTE IS FACIALLY UNCONSTITUTIONAL. On rehearing, the Supreme Court REVERSED the Court of Appeals and VACATED all three convictions: Code § 18.2-152.3:1 "PROHIBITS THE ANONYMOUS TRANSMISSION OF ALL UNSOLICITED BULK E-MAILS INCLUDING THOSE CONTAINING POLITICAL, RELIGIOUS OR OTHER SPEECH PROTECTED BY THE FIRST AMENDMENT", and under strict scrutiny is "NOT NARROWLY TAILORED" to the interests advanced. "Reversed and final judgment." Jurisdiction WAS proper — using AOL's servers was the "immediate result" of his acts — so the case failed on the First Amendment, not on venue.

Practical value: DO NOT CHARGE § 18.2-152.3:1. A successful facial overbreadth challenge "precludes the application of the affected statute IN ALL CIRCUMSTANCES" — this is not a limiting construction. The sheet's verify banner already flags the invalidity; this is the holding behind it.

Ramsey v. Commonwealth 65 Va. App. 694, 780 S.E.2d 624, Va. Ct. App., 2015

Convictions AFFIRMED under § 18.2-152.5. An offender acts "WITHOUT AUTHORITY" when he "knows or reasonably should know that he has NO RIGHT, AGREEMENT, OR PERMISSION or acts in a manner KNOWINGLY EXCEEDING such right, agreement, or permission" (§ 18.2-152.2), and "EXAMINATION" means reviewing another's identifying information "AFTER THE TIME AT WHICH the offender knows or should know that he is without authority to view" it.

Practical value: The insider case — an employee with legitimate system access who looks at records she has no business seeing. Authority is not all-or-nothing: EXCEEDING permission is enough, and the offence begins at the moment she knows she should stop.

Commonwealth v. Wallace Rec. No. 240138 (Va. Nov. 21, 2024) (published order), Va., 2024

"[T]here is REVERSIBLE ERROR in the judgment of the Court of Appeals. FOR THE REASONS STATED IN THE DISSENTING OPINION OF THE EN BANC COURT OF APPEALS, see Wallace v. Commonwealth, 79 Va. App. 455, 476-84 (2024), the Court REVERSES the judgment of the en banc Court of Appeals and AFFIRMS the circuit court's final judgment." Chief Justice Goodwyn, with McCullough and Russell, JJ., DISSENTED for the reasons in the en banc MAJORITY. Ordered published in the Virginia Reports.

Practical value: ⚠️ CITE THIS ORDER, NOT THE COURT OF APPEALS OPINION. A prosecutor who shepardises "Wallace, 79 Va. App. 455" and reads the majority will find a holding that a bank customer using her own ATM is NOT "without authority" — which is exactly wrong, because that opinion was reversed. The law is in the DISSENT at 476-84. The controlling reasoning (Athey, J., with Humphreys and Beales, JJ.): the 2005 amendments removed the "intent to obtain property by false pretenses" element from § 18.2-152.3 and put a MENS REA into "without authority" — one acts without authority "when he KNOWS OR REASONABLY SHOULD KNOW that he has no right, agreement, or permission OR ACTS IN A MANNER KNOWINGLY EXCEEDING such right." Wallace HAD permission to use the ATM, so the only question was whether she knowingly exceeded it, and she did by using it to obtain money by false pretences.

Wallace v. Commonwealth (en banc, REVERSED) 79 Va. App. 455, 471-76 (2024) (en banc), Va. Ct. App. (en banc), 2024

⚠️ REVERSED BY THE SUPREME COURT OF VIRGINIA — recorded here so it is not cited by mistake. The en banc majority held that "[a] person who uses a computer for a fraudulent purpose DOES NOT AUTOMATICALLY use it 'without authority'", that the inquiry "lies in looking at WHETHER THE SPECIFIC COMPUTER OPERATIONS PERFORMED WERE AUTHORIZED", and that "Wallace's operations were, in fact, authorized". It reversed her computer-fraud convictions. CALLINS, J., CONCURRING, would have gone further and held THIS ATM IS NOT A COMPUTER at all under § 18.2-152.2 — the "best and narrowest ground".

Practical value: Worth reading precisely because it is the defence's brief, already written by nine judges. Two arguments to expect: that the specific operations performed were authorized, and that the ATM is a "specialized computing device" preprogrammed for a narrow range of functions and therefore outside the definition. The answer to both is the Supreme Court's order.

Brewer v. Commonwealth 71 Va. App. 585, 592, Va. Ct. App., 2020

The 2005 General Assembly "broadly redefined" a "computer" in the VCCA to mean a "device[] that accept[s] information in digital or similar form and manipulate[s] it for a result based on a sequence of instructions" — § 18.2-152.2 — while EXCLUDING basic devices "dedicated to a specific task" requiring "minimal end-user or operator intervention", such as simple calculators, automated typewriters and fax machines.

Practical value: The exclusions are the live issue, not the definition. Whether a device is "dedicated to a specific task" is where a cash-only ATM, a card reader or a point-of-sale terminal will be attacked, and the Wallace dissent expressly left that open.

Barson v. Commonwealth 284 Va. 67, 726 S.E.2d 292, Va., 2012

CONVICTION VACATED ON DUE PROCESS GROUNDS. The Court of Appeals en banc had departed from its own decision in ALLMAN — which applied § 18.2-372's statutory definition of "obscene" — and substituted a DICTIONARY definition, then affirmed under the wider test. That was retroactive: "Barson's emails, AS OFFENSIVE, VULGAR AND DISGUSTING AS THEIR LANGUAGE MAY HAVE BEEN, DID NOT MEET THE STANDARD OF OBSCENITY THAT PREVAILED IN VIRGINIA AT THE TIME THEY WERE SENT. His conviction under a broader standard of obscenity that RETROACTIVELY CRIMINALIZED HIS CONDUCT violated his constitutional right to due process of law."

Practical value: ⚠️ THIS SHEET SAID THE COURT OF APPEALS AFFIRMED. It did — and was REVERSED. The operative rule for charging is that "obscene" in § 18.2-152.7:1 carries the § 18.2-372 meaning, which requires an appeal to the PRURIENT INTEREST IN SEX. Abusive, humiliating and sexually explicit language is not enough. The facts show the scale needed to fail anyway: 87 emails in fourteen days and hundreds more over six months, and still no obscenity.

Airhart v. Commonwealth Rec. No. 1219-05-2 (Va. Ct. App. Jan. 16, 2007) (unpublished), Va. Ct. App., 2007

REVERSED AND DISMISSED. Applying § 18.2-372 through Allman to a § 18.2-152.7:1 prosecution, the court held the evidence insufficient to prove the communication OBSCENE: although the words "had explicit sexual connotations, THEY WERE USED TO EXPRESS ANGER, CONTEMPT AND DISGUST AND WERE NOT USED IN AN EROTIC SENSE", so they did not appeal to the prurient interest. "Because we reverse on this issue, WE DO NOT ADDRESS APPELLANT'S OTHER ISSUES RAISED" — the intent element and a prior-bad-act ruling.

Practical value: ⚠️ THE SHEET DESCRIBED THIS AS "the leading authority upholding the harassment-by-computer statute against constitutional attack." IT IS NOT. It is an unpublished REVERSAL on the obscenity element, and it decided NO constitutional question — the court said in terms that it was not reaching the other issues. A prosecutor citing it for facial validity would be citing a case the defence should be citing. What it is good for: the anger-not-eros distinction, which is the line most § 18.2-152.7:1 charges actually turn on.

Allman v. Commonwealth 43 Va. App. 104, 596 S.E.2d 531, Va. Ct. App., 2004

Held that the statutory definition of obscenity in § 18.2-372 applies to a prosecution under § 18.2-427 for obscene telephone calls, on the premise that the Code of Virginia "constitutes a SINGLE BODY OF LAW and other sections can be looked to" for meaning. The General Assembly supplied no definition of "obscene" for either the telephone or the computer statute.

Practical value: The root of the rule that reaches § 18.2-152.7:1 through Airhart and Lofgren. ⚠️ READ THE CAPTION: Allman is a TELEPHONE case under § 18.2-427, not a computer case. It governs here only because the two statutes use parallel language and the Code is read as one body.

Plasters v. Commonwealth Rec. No. 1870-99-3, 2000 Va. App. LEXIS 473 (Va. Ct. App. June 27, 2000) (unpublished), Va. Ct. App., 2000

A part-time police dispatcher, trained and certified on VCIN, used it to obtain confidential personal information for non-criminal-justice reasons. FOUR § 18.2-152.5 convictions AFFIRMED; a FIFTH REVERSED because the Commonwealth conceded it had not proved she accessed a terminal in West Virginia. "The evidence must establish the offender viewed the information AFTER SHE KNEW OR SHOULD HAVE KNOWN SHE WAS UNAUTHORIZED to do so."

Practical value: The insider case, and the training records are the proof — Plasters had been certified twice, the second time with "the highest possible grade", which is how the Commonwealth showed she knew the limits. Subpoena the VCIN certification file. ⚠️ The reversed count is the warning: prove WHERE the terminal was. Ramsey found this reasoning persuasive; it remains unpublished.