Guy Cuomo, operating under the alias John Monaco, ran a skip-tracing business alongside a partner that provided place-of-employment information to third parties. To obtain this data, Cuomo and his employees impersonated debtors by creating fraudulent accounts on state unemployment insurance websites, such as ny.gov. They used the debtors' names and Social Security numbers to bypass identity verification gates, accessing private mainframe records to determine where the debtors worked. This information was then sold to customers for profit. Cuomo was convicted in the Northern District of New York on multiple counts, including conspiracy to commit computer fraud, accessing a protected computer without authorization, aggravated identity theft, and misuse of Social Security numbers. He received a 45-month prison sentence and three years of supervised release, which he appealed.
The Second Circuit addressed three primary categories of appeal. First, regarding the Computer Fraud and Abuse Act (CFAA), the court rejected Cuomo's argument that accessing a public website meant he had authorization. Citing Van Buren v. United States, the court explained that the CFAA distinguishes between accessing a computer system and accessing specific areas within it. The state website served as an interface to a protected mainframe computer containing private data. The court found that the state's requirement for a valid Social Security number and address to access employment records constituted a 'gate' based on authentication. By impersonating debtors to bypass this gate, Cuomo accessed the computer without authorization. Second, on the Social Security Act charges, the court clarified that the statute prohibits falsely representing a Social Security number with intent to deceive. The court held that the intent to deceive a government entity or system satisfies the statute; it is not necessary to prove that a specific human official was actually misled. Third, regarding aggravated identity theft, the court distinguished the Supreme Court's decision in Dubin v. United States. In Dubin, the use of a patient's name was ancillary to the fraud. Here, the court found that the use of the debtors' identities was central to the fraud, as the entire scheme relied on impersonating the victims to gain access to restricted data. Finally, on sentencing, the court affirmed the leadership enhancement. The record showed Cuomo was the president of the operating company, managed employees, and supervised the skip-tracing operations, satisfying the criteria for a four-level increase under the Sentencing Guidelines.
The judgment is affirmed without modification, leaving Cuomo subject to the 45-month imprisonment term and three years of supervised release. The decision reinforces that using false credentials to bypass authentication gates on government websites to access private data constitutes a federal computer crime, even if the public-facing portal appears open. It also clarifies that identity theft convictions under the Social Security Act do not require proof of a specific human victim being deceived, only the intent to deceive the system or entity.
Podcast (federal-narrative-summaries): Play in new window | Download
