Report on the Investigation into Russian Interference in the 2016 Presidential Election · 2019

Section 1030 Computer-Intrusion Conspiracy

Section 1030 Computer-Intrusion Conspiracy

Background

On July 13, 2018, a federal grand jury in the District of Columbia returned an indictment charging Russian military intelligence officers from the GRU with conspiring to hack into various U.S. computers used by the Clinton Campaign, DNC, DCCC, and other U.S. persons, in violation of 18 U.S.C. §§ 1030 and 371 (Count One); committing identity theft and conspiring to commit money laundering in furtherance of that hacking conspiracy, in violation of 18 U.S.C. §§ 1028A and 1956(h) (Counts Two through Ten); and a separate conspiracy to hack into the computers of U.S. persons and entities responsible for the administration of the 2016 U.S. election, in violation of 18 U.S.C. §§ 1030 and 371 (Count Eleven). Netyksho Indictment.1277 The Office provided a more detailed explanation of the charging decision in this case in meetings with the Office of the Acting Attorney General before the indictment. As of this writing, all 12 defendants remain at large.

The Netyksho indictment alleges that the defendants conspired with one another and with others to hack into the computers of U.S. persons and entities involved in the 2016 U.S. presidential election, steal documents from those computers, and stage releases of the stolen documents to interfere in the election. Netyksho Indictment ¶ 2. The indictment also describes how, in staging the releases, the defendants used the Guccifer 2.0 persona to disseminate documents through WikiLeaks. On July 22, 2016, WikiLeaks released over 20,000 emails and other documents that the hacking conspirators had stolen from the DNC. Netyksho Indictment ¶ 48. In addition, on October 7, 2016, WikiLeaks began releasing emails that some conspirators had stolen from Clinton Campaign chairman John Podesta after a successful spearphishing operation. Netyksho Indictment ¶ 49.

176

One witness told the Office at one point that the initial release of Podesta emails on October 7 may have come at the behest of, or in coordination with, Roger Stone, an associate of candidate Trump. As explained in Volume I, Section III.D.1.d, supra, phone records show that Stone called Jerome Corsi on October 7, after Stone received a call from the Washington Post. The Washington Post broke a story later that day about a video recording of Trump speaking about women in graphic terms. According to some of Corsi's statements to the Office [Redacted: (b) (3)] Stone said that he had learned about the imminent release of that tape recording, and it was expected to generate significant negative media attention for the Campaign. Corsi told investigators that Stone may have believed from their prior dealings that Corsi had connections to Julian Assange, WikiLeaks's founder, and that Stone therefore asked Corsi to tell Assange to start releasing the Podesta emails immediately to shift the news cycle away from the damaging Trump recording. Although Corsi denies that he actually had access to Assange, he told the Office at one point that he tried to bring the request to Assange's attention via public Twitter posts and by asking other contacts to get in touch with Assange. The investigation did not establish that Corsi actually took those steps, but WikiLeaks did release the first batch of Podesta emails later on the afternoon of October 7, within an hour of the publication of the Washington Post's story on the Trump tape.

Charging Decision As to WikiLeaks, Julian Assange, and Roger Stone

Given WikiLeaks's role in disseminating the hacked materials, and the existence of some evidence that Stone played a role in coordinating the October 7 release of the Podesta materials, this Office considered whether to charge WikiLeaks, Assange, or Stone as conspirators in the computer-intrusion conspiracy under Sections 1030 and 371.1278 The Office also considered, but ruled out, charges on the theory that the post-hacking sharing and dissemination of emails could constitute trafficking in or receipt of stolen property under the National Stolen Property Act (NSPA), 18 U.S.C. §§ 2314 and 2315. The statutes comprising the NSPA cover "goods, wares, or merchandise," and lower courts have largely understood that phrase to be limited to tangible items since the Supreme Court's decision in Dowling v. United States, 473 U.S. 207 (1985). See United States v. Yijia Zhang, 995 F. Supp. 2d 340, 344-48 (E.D. Pa. 2014) (collecting cases). One of those post-Dowling decisions—United States v. Brown, 925 F.2d 1301 (10th Cir. 1991)—specifically held that the NSPA does not reach "a computer program in source code form," even though that code was stored in tangible items (i.e., a hard disk and in a three-ring notebook). Id. at 1302-03. Congress, in turn, cited the Brown opinion in explaining the need for amendments to 18 U.S.C. § 1030(a)(2) that "would ensure that the theft of intangible information by the unauthorized use of a computer is prohibited in the same way theft of physical items [is] protected." S. Rep. 104-357, at 7 (1996). That sequence of events would make it difficult to argue that hacked emails in electronic form, which are the relevant stolen items here, constitute "goods, wares, or merchandise" within the meaning of the NSPA. The theory of prosecution would be that these actors were liable as late joiners in an already existing conspiracy. See United States v. Bridgeman, 523 F.2d 1099, 1107 (D.C. Cir. 1975) ("A defendant can join a conspiracy at any time, and can properly be convicted though he was not in the conspiracy at its inception."); see also United States v. Scott, 64 F.3d 377, 381 (8th Cir. 1995) ("[E]ven if defendant joined the conspiracy relatively late, played only a minor role, and was unaware of some aspects of the conspiracy, he was legally responsible as a co-conspirator for all acts carried out in furtherance of the conspiracy."). In particular, although it did not participate in the hacking itself, WikiLeaks would be liable for ensuring a market for and maximizing the value of the stolen materials—much as someone who holds himself out as a "fence" may be found to have joined a conspiracy to traffic in stolen goods, see United States v. Hess, 691 F.2d 984, 988 (11th Cir. 1982), and an individual who launders drug money can be a member of a drug-trafficking conspiracy when such laundering activities are "integral to the success" of the overall trafficking venture, see United States v. Orozco-Prada, 732 F.2d 1076, 1080 (2d Cir. 1984). See also, e.g., United States v. Tarantino, 846 F.2d 1384, 1396-97 (D.C. Cir. 1988); United States v. Dela Espriella, 781 F.2d 1432, 1436 (9th Cir. 1986). Stone might similarly be liable under these cases if he too was integral to the computer-intrusion conspiracy's success by ensuring that the stolen materials had their maximum impact upon dissemination.

177

The Office determined, however, that it did not have admissible evidence that was probably sufficient to obtain and sustain a Section 1030 conspiracy conviction of WikiLeaks, Assange, or Stone. See Justice Manual § 9-27.200. The foregoing theory of conspiracy liability depends on proof of an agreement, see Iannelli v. United States, 420 U.S. 770, 777 (1975), whether express or "tacit," see United States v. Willson, 708 F.3d 47, 54 (1st Cir. 2013) (observing that conspiracy may be proved through "a tacit agreement shown from an implicit working relationship") (internal quotation marks omitted). It would also require evidence of knowledge on the part of the putative conspirator that the criminal objective of the conspiracy has not yet been completed. Cf. Rosemond v. United States, 572 U.S. 65, 78-80 (2014). (discussing role of "foreknowledge" in aiding-and- abetting liability). A "fence" who had no advance knowledge of the plan to steal the goods he disposes of, for example, is generally not liable for conspiring to steal those goods. See United States v. Solomon, 686 F.2d 863, 876 (11th Cir. 1982); United States v. McGann, 431 F.2d 1104, 1106-07 (5th Cir. 1970). Here, a late-joiner theory would require that the conspirator knew that the computer intrusions that comprise the Section 1030 violation were ongoing, or expected to continue, at the time that he or she joined the conspiracy.

With respect to WikiLeaks and Assange, this Office determined the admissible evidence to be insufficient on both the agreement and knowledge prongs. As to agreement, many of the communications between the GRU officers and WikiLeaks-affiliated actors occurred via encrypted chats. Although a conspiracy is often inferred from the circumstances, see Iannelli, 420 U.S. at 777 n.10, the lack of visibility into the contents of these communications would hinder the Office's ability to prove that WikiLeaks was aware of and intended to join the criminal venture comprised of the GRU hackers. Similar problems of proof existed as to knowledge. While the investigation developed evidence that the GRU's hacking efforts in fact were continuing at least at the time of the July 2016 WikiLeaks dissemination, see Netyksho Indictment ¶¶ 32, 34, the Office did not develop sufficient admissible evidence that WikiLeaks knew of—or even was willfully blind to—that fact. Cf. Global-Tech Appliances, Inc. v. SEB S.A., 563 U.S. 754, 769-70 (2011) (recognizing that willful blindness can be used to prove the knowledge element of an offense). And absent sufficient evidence of such knowledge, the government could not prove that WikiLeaks (or Assange) joined an ongoing hacking conspiracy intending to further or facilitate additional computer intrusions. See United States v. Piper, 35 F.3d 611, 615 (1st Cir. 1994) (conspiracy defendant must have "an intent to effectuate the commission of the substantive offense"); see also Ingram v. United States, 360 U.S. 672, 678 (1959) ("Without the knowledge, the intent cannot exist.") (internal quotation marks and citation omitted).

178

The Office determined that it could not pursue a Section 1030 conspiracy charge against Stone for some of the same legal reasons. The most fundamental hurdles, though, are factual ones.1279 Some of the factual uncertainties are the subject of ongoing investigations that have been referred by this Office to the D.C. U.S. Attorney's Office. As explained in Volume I, Section III.D.1, supra, Corsi's accounts of his interactions with Stone on October 7, 2016 are not fully consistent or corroborated. Even if they were, neither Corsi's testimony nor other evidence currently available to the Office is sufficient to prove beyond a reasonable doubt that Stone knew or believed that the computer intrusions were ongoing at the time he ostensibly encouraged or coordinated the publication of the Podesta emails. Stone's actions would thus be consistent with (among other things) a belief that he was aiding in the dissemination of the fruits of an already completed hacking operation perpetrated by a third party, which would be a level of knowledge insufficient to establish conspiracy liability. See State v. Phillips, 82 S.E.2d 762, 766 (N.C. 1954) ("In the very nature of things, persons cannot retroactively conspire to commit a previously consummated crime.") (quoted in Model Penal Code and Commentaries § 5.03, at 442 (1985)).

The Office's determination that it could not charge WikiLeaks or Stone as part of the Section 1030 conspiracy was also informed by the constitutional issues that such a prosecution would present. Under the Supreme Court's decision in Bartnicki v. Vopper, 532 U.S. 514 (2001), the First Amendment protects a party's publication of illegally intercepted communications on a matter of public concern, even when the publishing parties knew or had reason to know of the intercepts' unlawful origin. Id. at 517-518. Any effort by WikiLeaks to invoke Bartnicki would raise an initial question whether, as a foreign actor, WikiLeaks is entitled to claim the protections of the First Amendment. Compare DKT Mem'l Fund Ltd. v. Agency for Int'l Dev., 887 F.2d 275, 284 (D.C. Cir. 1989) (stating that "aliens beyond the territorial jurisdiction of the United States are generally unable to claim the protections of the First Amendment"), with Lamont v. Postmaster General, 381 U.S. 301, 305 (1965) (invalidating a statute based on the First Amendment rights of the addressees to whom the material was directed); id. at 308 (Brennan, J., concurring). But assuming that a First Amendment defense is available to WikiLeaks (or that Stone raised one), a court could conclude that Bartnicki's holding applies equally to actors such as WikiLeaks and Stone on the ground that they published or caused the publication of previously hacked materials, without participating directly "in the initial illegality" of the computer intrusions, see 532 U.S. at 529.

The government might be able to distinguish Bartnicki on the ground that, under the late-joiner principles of conspiracy law described above, WikiLeaks and Stone were complicit in the computer intrusions. That contention would succeed only if qualifying as a conspirator under late-joiner principles establishes sufficient participation under Bartnicki, a question that the decision itself does not resolve. Regardless, success would also depend upon evidence of WikiLeaks's and Stone's knowledge of ongoing or contemplated future computer intrusions—the proof that is currently lacking. The absence of evidence as to knowledge, in short, would both hinder the government's ability to prove conspiracy liability and also potentially provide a First Amendment defense. Therefore, the Office did not seek charges against WikiLeaks, Assange, or Stone for participating in the computer-intrusion conspiracy alleged in Count One of the Netyksho indictment.

179