Cybercrime DB

Cyberstalking Prosecutions and Landmark Court Verdicts

Federal law sets a high bar for prosecution, leaving millions of victims without recourse.

Editorial team · · 11 min read
Cover illustration for “Cyberstalking Prosecutions and Landmark Court Verdicts”
cybercrime arrests and convictions · October 6, 2026 · 11 min read · 2,396 words

Federal cyberstalking law has a specific, narrow job: it defines what counts as a crime worth the government's time, and it sets the bar high enough that most harassment never clears it. This piece walks through that bar, the cases that have cleared it, and the gaps that remain even after a Supreme Court ruling and a brand-new statute tried to patch them.

What 18 U.S.C. § 2261A requires prosecutors to prove

The federal cyberstalking statute, 18 U.S.C. § 2261A, covers electronic conduct when it crosses state lines or touches any facility of interstate commerce. The internet always counts, so that part of the test is rarely the sticking point. What actually narrows the pool of cases is the next requirement: prosecutors have to show a pattern, not a single ugly message. One bad text doesn't trigger federal jurisdiction. A sustained course of conduct does.

From there, prosecutors need one of two outcomes. Either the victim was placed in reasonable fear of death or serious bodily injury, or the conduct caused substantial emotional distress. That second standard isn't limited to the direct target, either. It also reaches the victim's immediate family, spouse, and intimate partner, so if a campaign terrorizes someone's parents or partner alongside the victim herself, it still fits inside the statute.

Federal prosecutors tend to reserve their limited bandwidth for cases that cross state or international borders, involve especially serious threats, or come bundled with other federal charges. Most single-state harassment gets handled by state prosecutors instead, and state cyberstalking statutes vary a lot in how they define intent and harm; the exact same conduct can look like a felony in one state and a misdemeanor, or nothing, in another.

One gap the statute hasn't caught up with: smart home abuse. Connected cameras, smart locks, thermostats that reveal when someone's home. All of it can be turned into a surveillance and control system, and none of it necessarily produces a threatening message anyone can point to in court. If there's no clear, documented threat, the intent requirement becomes hard to satisfy even when the victim is being monitored around the clock.

The narrow federal prosecution record despite a vast victim population

When the federal government brings a cyberstalking case, it wins the overwhelming majority of the time, but it brings very few cases to begin with. Across the entire decade from 2010 to 2020, the number of federal cyberstalking cases filed was small, a canyon-sized gap even though millions of people experience cyberstalking every single year in the United States.

Part of the explanation is reporting. Only a minority of victims ever report cyberstalking to police in the first place, and that reluctance isn't irrational. It tracks a reasonable skepticism that law enforcement will actually do anything with the report once it's filed.

The deeper issue sits further upstream than any individual victim's decision to call the police. Most law enforcement agencies simply lack the specialized training to investigate cyberstalking well: tracing accounts, preserving digital evidence, understanding how VPNs and anonymous platforms work. The bottleneck isn't conviction rates; it's case intake. Cases that never get properly investigated never reach a prosecutor's desk, and those cases never appear in any win-rate statistic.

One pattern does show up clearly in the cases that do make it to federal court: current or former intimate partners make up the largest share of offender-victim relationships. That reflects the real offender profile, but it also reflects something more practical. A known relationship gives investigators a starting point, a name, a motive, a timeline. Stranger stalking, by comparison, often leaves investigators with nothing but a screen name and a VPN exit node in another country.

The Florence case: a technically sophisticated offender in federal court

James Florence Jr. spent a decade at a federal research laboratory, and he held a government security clearance. He used that same technical fluency to run a 16-year harassment campaign against more than a dozen Massachusetts women, starting as early as 2008. On July 23, 2025, U.S. District Judge Richard G. Stearns sentenced him to nine years in prison and 10 years of supervised release.

Florence built more than 60 accounts across numerous platforms, used to impersonate, intimidate, and abuse women he knew personally, including two who were minors when the abuse began. He posted thousands of fake, AI-generated, and photoshopped sexually explicit images, paired with victims' real names, home addresses, and driver's license photos, and he actively encouraged strangers to sextort them.

Florence's technical fluency is what let his campaign last 16 years. Florence used VPN services to mask his location, posted through anonymous overseas "revenge porn" sites that sit outside easy U.S. jurisdiction, and routed communication through encrypted foreign email providers that simply don't answer U.S. legal process. These are the exact tools enterprise security teams worry about when a hacker crew goes quiet mid-breach. Florence used the same playbook to vanish between messages.

He pleaded guilty in April 2025 to seven counts of cyberstalking and one count of possession of child pornography. Nine years is a steep sentence by federal cyberstalking standards, and the length of the campaign, the premeditation, and the sheer number of victims explain why.

The Saunders and Bonnell cases: lower-severity federal cyberstalking prosecution

Federal cyberstalking prosecution doesn't require a 16-year campaign or an MIT résumé. Shorter, messier harassment campaigns reach federal court too, and the sentences scale down to match.

Jonas D. Saunders, 22, of Vernal, Utah, was sentenced on June 4, 2026, in federal court in Lincoln, Nebraska. U.S. District Judge Susan M. Bazis gave him 24 months in prison, with no parole available in the federal system, followed by three years of supervised release, for one count of cyberstalking and one count of using a telecommunications device to abuse, threaten, and harass. The trigger was almost absurdly small: Saunders saw that a former university acquaintance had started a new relationship, and that set off a campaign in February 2025 that included threats on Instagram and X, repeated phone calls, hiring a so-called "hacker" to break into her accounts, mass-emailing her entire university's student population with her contact information, building a website designed to degrade her, and threatening her family and boyfriend directly. It only stopped once police in two different jurisdictions got involved.

Caleb Bonnell, 20, of Bringhurst, Indiana, got 36 months in prison and two years of supervised release from U.S. District Judge Cristal C. Brisco after pleading guilty to cyberstalking. Between September and December 2025, prosecutors said he sent hundreds of unwanted texts, contacted the victim's school directly, messaged her classmates on social media, posted threats online, and escalated to "swatting," filing false reports designed to send armed police to the victim's home.

Laying these two cases side by side reveals a pattern. Conduct that spreads across multiple platforms and reaches into a victim's university, school, family, and friend group consistently clears the federal threshold, even when the whole campaign runs for only months. Duration matters for sentencing length. Duration doesn't gate whether the case gets charged federally.

AI-generated imagery and the Take It Down Act in cyberstalking law

Accessible AI image generators created a new kind of harm almost overnight: synthetic sexually explicit images of real, identifiable people, built without their knowledge or consent. For years, the law simply hadn't caught up. Victims of this specific harm had no direct federal remedy until 2025.

The Take It Down Act changed that by putting teeth into a notice-and-removal system. Platforms covered by the law have to investigate and take down flagged material within 48 hours of notice, and they have to make a real effort to catch duplicates and reposts, not just the single file that got reported. Violations are treated as unfair or deceptive trade practices under the FTC Act, which carries civil penalties per violation. Before enforcement kicked in, the FTC sent compliance-reminder letters to 15 major named platforms. After enforcement began, it sent warning letters to 12 unnamed "nudify" websites that hadn't gotten the message.

James Strahler II, 37, of Columbus, Ohio, became the first person in the country convicted under the Take It Down Act for publishing digital forgeries. He was sentenced on September 8, 2026, to 180 months, 15 years, in prison. His case wasn't limited to AI fakes. It also involved real sexually explicit imagery, threats of violence against numerous victims, and more than 24 AI platforms along with more than 100 AI web-based models found installed on his phone, all used alongside phone calls, voicemails, text messages, and web postings to run a sustained harassment operation.

The law has real limits: it doesn't touch the AI tools themselves, so building the software that generates this imagery remains completely legal. It requires platforms to remove flagged content only after it has been reported, by which point it may have already spread. And its scope is confined to "intimate" imagery or content meant to cause harm, which leaves a lot of AI-enabled harassment, including conduct that doesn't involve explicit images, outside the statute. These are the gaps the next legislative round will need to close.

Counterman v. Colorado's effect on the mental-state requirement in cyberstalking prosecutions nationwide

The Supreme Court's ruling in Counterman v. Colorado changed what prosecutors have to prove about a defendant's state of mind, and the change runs through every case discussed so far. Courts now have to establish that the defendant recklessly disregarded the threatening nature of their own communications. That's a subjective standard, focused on what the defendant actually understood, rather than the older objective "reasonable person" test, which asked only whether a typical listener would have felt threatened.

Justice Elena Kagan wrote the majority opinion and didn't dodge the trade-off at the center of it. A subjective standard makes prosecuting genuinely dangerous communication harder. An objective standard risks punishing speech the speaker never intended as threatening, chilling protected expression in the process. The Court picked the subjective standard, and prosecutors nationwide now have to build a case about what was going on in a defendant's head, not just document the messages and the damage they caused.

Professor Mary Anne Franks of George Washington Law School put the criticism in the sharpest terms available: "The more deluded the stalker, the more protected the stalking." That line lands directly on cases where an offender insists, and maybe even believes, that the conduct was harmless, turning a delusion into something close to a legal shield.

Digital rights groups including the Electronic Frontier Foundation and the ACLU had pushed the Court toward this outcome, arguing that an objective standard convicts people based on how speech lands rather than what the speaker meant, and that this risk chills legitimate expression across the internet. Justice Barrett dissented, joined by Thomas, focused on what the ruling does to victims and to restraining-order enforcement going forward. Thomas also dissented separately, aiming his criticism at the majority's reliance on New York Times v. Sullivan. The ruling didn't settle the argument. It just moved the argument into every future cyberstalking trial.

Across the cases in this piece, nobody is struggling to notice that harassment is happening. The hard part is proving who did it, and the offenders with the most technical skill have access to the exact same evasion tools that make enterprise security investigations difficult.

VPNs routed through jurisdictions that ignore U.S. legal process. Encrypted foreign email providers. Anonymous offshore hosting. Networks of sockpuppet accounts spread across platforms. AI-generated synthetic media muddying the evidence trail further. These are the tools of enterprise-level threat actor campaigns, borrowed wholesale by individual stalkers, and untangling them takes the same cross-source correlation work that enterprise threat hunters do every day.

Courts also lean toward commercially validated forensic tools over open-source alternatives, mostly because there's no standardized validation framework for the open-source options. That means even when investigators land on a likely suspect, the chain of evidence that got them there can still be challenged in court.

Florence's case shows how this plays out. His use of encrypted offshore services, learned and refined over a career in defense-adjacent IT work, meant the email trail by itself led nowhere. Investigators said that with a service like Proton Mail, there's no way to trace who's actually on the other end of the account. Without a separate investigative thread, pulled from somewhere other than the email itself, that trail goes cold.

Threat intelligence platforms built to correlate activity across sources have become one of the main tools for cutting through false flags and multi-account evasion schemes. The approach pairs human analysts with machine-speed correlation, a model already reshaping enterprise threat hunting, and it applies just as directly to cyberstalking investigations. Security vendors building tools for this kind of cross-source attribution work, whether for enterprise threat intelligence or for law-enforcement-adjacent forensics, are increasingly showing up in federal case records, giving the whole field a concrete evidentiary track record.

Where the law still falls short

Trace the line from early, overreaching prosecutions under broad computer-crime law to Strahler's conviction under the brand-new Take It Down Act, and the law has clearly moved forward. But stack these cases next to each other and the gaps left behind are just as clear as the progress.

Counterman created a mental-state requirement that's hardest to satisfy in exactly the cases where the offender poses the most danger: the ones who've convinced themselves, genuinely or conveniently, that their conduct was never threatening.

The Take It Down Act addresses AI-generated intimate imagery, but only reactively and only within a narrow lane. Platforms act when someone reports content, not before. The AI tools used to create that content stay legal to build and distribute. And AI-facilitated harassment that doesn't fit the "intimate imagery" definition, the mass emails, the fake websites, the swatting calls, sits outside the statute's reach.

Smart home surveillance remains the clearest unresolved gap of all. A stalker who locks a victim out of her own thermostat or watches her through a camera she bought for her own safety hasn't necessarily sent a single threatening message, and without that message, the intent standard that 18 U.S.C. § 2261A and Counterman both demand becomes very hard to satisfy. The law has built real tools for real harm. What it hasn't built yet is a way to reach the harm that never says a word.

Sources

  1. District of Massachusetts
  2. District of Nebraska
  3. Southern District of Ohio
  4. Cyberstalking: A Growing Challenge for the U.S. Legal System

More in cybercrime arrests and convictions