Cybercrime DB

Financial Penalties and Restitution Orders in Cybercrime Sentencing

Courts impose restitution orders that defendants cannot realistically repay.

Editorial team · · 9 min read
Cover illustration for “Financial Penalties and Restitution Orders in Cybercrime Sentencing”
cybercrime arrests and convictions · October 7, 2026 · 9 min read · 2,125 words

Cybercrime sentencing looks like a black box from the outside, but it runs on six inputs a court can point to every time: how much money was lost, how many victims got hit, how sophisticated the attack was, whether the defendant has a record, what the defendant's motive was, and whether the defendant cooperated once caught. Those six variables do the real work in both criminal sentencing and civil damages, and the same factors that stretch a prison sentence also stretch the dollar amount a defendant ends up owing.

Loss amount carries the most weight of the six. Courts treat the dollar figure as the cleanest stand-in for harm, and that single number is why restitution orders in some cases climb into the tens or even hundreds of millions of dollars. Victim count works as a multiplier on top of that: a scheme that hurts ten thousand people reads as a bigger societal wound than one that hurts ten, even if the total dollar loss is similar, and courts move sentences and financial exposure up accordingly.

Sophistication tells a judge something about intent, not just technical skill. A defendant who builds custom tools, launders proceeds through multiple layers, or times an attack to avoid detection has shown planning, and courts read that planning as aggravating, not neutral. Motive shapes the outcome too, though more at the edges: crimes committed for straightforward financial gain draw harsher treatment than conduct that looks careless or opportunistic, and when espionage or terrorism enters the picture, penalties can run straight to the statutory ceiling.

None of these six variables float free, though. They get fed into a legal structure built specifically to turn them into numbers, and that structure, not the variables themselves, is what sets the actual floor and ceiling a defendant faces.

The statutory architecture that sets the penalty ceiling and floor

The Computer Fraud and Abuse Act is the statute most people picture when they hear "cybercrime law," but it was never built to work alone. It sits alongside wire fraud law, identity theft law, and money laundering law, and prosecutors routinely charge several of these together. The combination, not any single statute, sets the real penalty range a defendant walks into court facing.

The CFAA itself, codified at 18 U.S.C. § 1030(a), covers seven separate categories of offense, running from basic computer trespassing (think unauthorized access with no real harm done) up to accessing a computer for purposes of espionage. The penalties scale with the offense: as little as a year behind bars at the low end, and life in prison at the top end, reserved for conduct that knowingly or recklessly causes death through intentional damage to a computer system. The CFAA also does double duty on the financial side. Subsections 1030(i) and (j) allow forfeiture of property tied to a violation, and subsection 1030(g) gives victims their own civil cause of action. One act of hacking can trigger criminal punishment, mandatory restitution, civil forfeiture, and a private lawsuit, all from the same conduct.

The Identity Theft Enforcement and Restitution Act, signed into law in 2008 as P.L. 110-326, added muscle to this structure. It amended the CFAA and, specifically, 18 U.S.C. §3663(b), tightening restitution rules for identity theft victims and closing loopholes defendants had used to dodge repayment.

Then prosecutors stack other statutes on top. Wire fraud alone carries up to 20 years in federal prison, rising to 30 years when a financial institution is involved. Aggravated identity theft adds a mandatory two years, served consecutively after the underlying sentence. Prosecutors combine these charges with CFAA counts specifically to maximize leverage in cases involving banks or large groups of victims, and that's why a cybercrime case built on a single intrusion can carry exposure that looks disproportionate to the hack itself when you only look at one charge at a time.

The United States Sentencing Commission is the body that takes all of this, statutes plus the six variables from loss amount to cooperation, and turns it into the Sentencing Guidelines judges use at the bench. Judges don't start from a blank page. They start from a calculation: that calculation produced $25.6 billion in total fines and restitution ordered in fiscal year 2025 alone, the Commission's own numbers show.

Diagram: The Stacking Penalty Structure Behind a Single Cybercrime Charge. Visualizes: Visualize how a single act of hacking can trigger four separate financial and criminal consequences that stack on top of each other: criminal punishment (CFAA…

How restitution is calculated, mandatory regardless of ability to pay

Restitution sits apart from the rest of the penalty structure because of one rule: the Mandatory Victims Restitution Act bars courts from considering whether a defendant can actually pay. A fine can be reduced or waived for someone with no money. Restitution cannot. The amount tracks the harm done to victims, full stop on the logic, regardless of what the person sitting at the defense table could realistically earn in a lifetime.

Property connected to a CFAA violation, whether it was derived from the crime or used to carry it out, is subject to confiscation on top of this. And where restitution applies, it isn't optional for the judge. There's no discretion to waive it for an indigent defendant the way there is with a fine. The math runs entirely off the victim's loss. Restitution orders in cybercrime cases routinely land far above anything the defendant could repay even with decades of wage garnishment.

Restitution and fines are also separate line items that stack. A court can order both at once: restitution to the victim, a fine to the government, on top of whatever prison term applies. The total financial liability compounds fast, and the sentencing court's failure to weigh ability to pay doesn't make the debt disappear. It just moves downstream, into the years after sentencing, where it becomes someone else's problem to collect.

Why restitution orders rarely translate into actual victim recovery

The design that makes restitution track harm instead of means is the same design that makes a large share of restitution orders impossible to collect. A court can order a defendant to pay a large sum to victims, and that number is legally binding, but legally binding and collectible are two different things when the defendant has no assets, no income stream, and years left on a prison sentence.

For the defendant, an unpaid restitution balance doesn't just sit quietly on the books. It accrues interest, it extends the terms of supervised release, and it can trigger further consequences long after the prison sentence itself ends. In practice, this turns restitution into something closer to an open-ended second punishment than a repayment plan. The person owes money they will likely never finish paying, and the terms follow them well past the original sentence.

This collection gap is the strongest card proportionality reformers hold. If restitution exists to compensate victims, and the money demonstrably isn't reaching them in full, then a rule built to ignore ability to pay is failing the one test it was designed to pass. That failure is also what pushed federal prosecutors toward a different tool entirely for getting money back to victims.

Asset forfeiture as the more effective financial recovery track

Faced with restitution orders that look impressive on paper and collect poorly in practice, the DOJ has leaned harder on asset forfeiture, especially forfeiture of seized cryptocurrency, as the tool that actually gets money back into victims' hands. Restitution hasn't been scrapped or replaced. Forfeiture just works faster, because it can grab assets before a defendant has the chance to spend, hide, or launder them away.

The results back that up. The DOJ's Asset Forfeiture Program has returned more than $12 billion to crime victims since 2000. In fiscal year 2024 and the opening stretch of fiscal year 2025, hundreds of millions of dollars moved back to victims of human trafficking, romance fraud, business email compromise schemes, and cryptocurrency theft.

Seizing a crypto wallet is not the same thing as putting cash in a victim's pocket the next day, though. Recovered assets move through a legal pipeline, with claims processes and court approval, before any of it reaches the people who were harmed. That pipeline takes time, and anyone offering to speed up the return of seized crypto for an upfront fee is running a scam, not a service.

Forfeiture has become the system's own workaround for a restitution mechanism that routinely fails to collect. It's a parallel track, not a fix for restitution itself, and that distinction matters once you start asking whether the overall framework is actually achieving what it claims to.

What recent sentences reveal about the framework in practice

Recent sentences show the same six variables producing wildly different dollar outcomes depending on what's being measured, loss, victims, sophistication, or offense type, but the pattern holds: loss amount and victim scale drive the number more than anything else.

Keonne Rodriguez and William Lonergan Hill, the CEO and CTO behind the Samourai Wallet cryptocurrency mixing service, were sentenced in November 2025 to five and four years in prison respectively. Their service facilitated more than $237 million in illegal transactions, money tied to drug trafficking, darknet markets, cyber-intrusions, fraud, sanctioned jurisdictions, murder-for-hire schemes, and a child exploitation website. The case shows how loss aggregated across many different categories of underlying crime compounds total exposure, even when the defendants weren't the ones running the drug ring or the murder-for-hire scheme directly.

Christina Marie Chapman, sentenced in July 2025 out of Arizona, received 102 months in prison for a scheme that placed foreign-linked remote workers inside more than 300 American companies. The scheme involved identity theft affecting roughly 70 U.S. citizens. Here, victim count and a national security angle both pushed the sentence upward, even though the scheme's financial loss figure wasn't the headline number driving the outcome.

Putting the two cases side by side makes the variables from the opening section stop looking abstract. Aggregated loss across offense categories produced one outcome. Victim count paired with motive produced another. The inputs are consistent even when the final numbers aren't.

United States

The ruling reclassified restitution under the MVRA, and the Court got there by reading the statute's own language closely. The MVRA calls restitution a "penalty" for a criminal "offense." It applies only to criminal defendants. It gets imposed at sentencing, right alongside prison time and fines. Every feature the Court pointed to marks restitution as punishment rather than compensation, and that's the basis for the ruling.

The immediate effect is narrow and specific: the government can no longer go back and increase interest or extend payment deadlines on restitution orders that are already in place, because doing that after the fact would mean increasing a criminal punishment retroactively. The ruling reclassifies restitution. It does not strike down the MVRA, and mandatory restitution itself remains fully in place.

What the ruling does open up is a constitutional argument that didn't exist in this form before. If restitution counts as criminal punishment, the Eighth Amendment's Excessive Fines Clause comes into play, and lawyers can challenge the MVRA's flat refusal to consider ability to pay under what's called the anti-ruination principle: the idea that a financial penalty shouldn't wipe out someone's entire ability to earn a living. The National Association of Criminal Defense Lawyers has described the ruling as a clear rejection of what it calls the "legal fiction" that restitution was ever a civil remedy dressed up as something separate from punishment.

None of this is settled law yet. The ruling changes the constitutional ground defendants can argue on. It hasn't yet changed how restitution orders get calculated or enforced day to day.

The unresolved tension between deterrence logic and proportionality in cybercrime financial penalties

The real disagreement in cybercrime sentencing is whether a mandatory system that ignores ability to pay, built around harm rather than means, actually deters crime and compensates victims, or whether it mostly produces numbers that look tough in a press release and do little else.

The deterrence argument holds that penalties have to be severe precisely because so much cybercrime crosses borders, hides behind anonymity, and simply never results in an arrest. For the small number of offenders who do get caught, the logic says, the penalty has to be heavy enough to account for everyone who got away with it.

The proportionality argument points straight at the collection numbers. The U.S. Sentencing Commission's FY 2025 Annual Report puts total fines and restitution ordered at $25.6 billion in a single year, inside a system that struggles to collect anywhere near that much. If the money doesn't get collected, the deterrent value of ordering it in the first place is, at best, unproven. That gap between what courts order and what victims actually see is the live fault line running through cybercrime sentencing today, actively argued over by courts, legislators, and defense lawyers, and not one anybody has closed.

Diagram: Ordered vs. Collected: The $25.6 Billion Restitution Gap. Visualizes: Show the contrast between two numbers that define the core tension in cybercrime financial penalties: $25.6 billion in total fines and restitution ordered by federal…

Sources

  1. Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute
  2. IRS-CI reveals top 10 cases of 2025
  3. NACDL - CFAA Cases

More in cybercrime arrests and convictions