Go to integrated search
contact us

Copyright SJKP LLP Law Firm all rights reserved

Credit Card Fraud Defense: What Turns Card Use into a Federal Case



Federal credit card fraud is often charged as access device fraud under 18 U.S.C. § 1029. The statute covers physical cards, account numbers, PINs, codes, and other means of account access. Credit card fraud defense therefore turns on the subsection charged, federal jurisdiction, authorization, intent, statutory thresholds, and evidence tying the transaction to the defendant.


1. What Is Federal Credit Card Fraud?


Federal credit card fraud generally involves knowing and fraudulent production, use, trafficking, possession, or misuse of an access device.

The term “access device” is broader than a physical card. 18 U.S.C. § 1029 covers account numbers, PINs, codes, electronic identifiers, and other means of account access capable of obtaining money, goods, services, or value.

The statute also distinguishes counterfeit access devices from unauthorized devices. Unauthorized devices can include lost, stolen, expired, revoked, canceled, or fraudulently obtained access devices.

A case involving broader financial misconduct may also intersect with white collar crime allegations.



2. What Makes Credit Card Fraud a Federal Case?


Section 1029 requires the charged offense to affect interstate or foreign commerce; the amount of alleged loss alone does not determine federal jurisdiction.

Payment-card networks and banking channels frequently cross state lines and can supply the required federal nexus. Online transactions, interstate merchant activity, or account processing through financial institutions may also become relevant depending on the facts.

A large disputed charge is therefore not automatically federal. Conversely, conduct involving a relatively modest amount can fall within federal jurisdiction if the charged subsection and interstate-commerce requirement are satisfied.



3. The Exact Section 1029 Charge Controls the Defense


Section 1029 contains several distinct offenses, so the required conduct, thresholds, and potential penalties depend on the subsection charged.

Common § 1029 ChargeStatutory RequirementMaximum Imprisonment for a First Offense
§ 1029(a)(1)Producing, using, or trafficking in a counterfeit access device with intent to defraud10 years
§ 1029(a)(2)Using or trafficking unauthorized devices and obtaining $1,000 or more within one year10 years
§ 1029(a)(3)Possessing 15 or more counterfeit or unauthorized access devices with intent to defraud10 years
§ 1029(a)(4)Producing, trafficking in, controlling, or possessing device-making equipment15 years
§ 1029(a)(5)Using devices issued to others to obtain $1,000 or more within one year15 years

§ 1029(a)(1)

  • Statutory RequirementProducing, using, or trafficking in a counterfeit access device with intent to defraud
  • Maximum Imprisonment for a First Offense10 years

§ 1029(a)(2)

  • Statutory RequirementUsing or trafficking unauthorized devices and obtaining $1,000 or more within one year
  • Maximum Imprisonment for a First Offense10 years

§ 1029(a)(3)

  • Statutory RequirementPossessing 15 or more counterfeit or unauthorized access devices with intent to defraud
  • Maximum Imprisonment for a First Offense10 years

§ 1029(a)(4)

  • Statutory RequirementProducing, trafficking in, controlling, or possessing device-making equipment
  • Maximum Imprisonment for a First Offense15 years

§ 1029(a)(5)

  • Statutory RequirementUsing devices issued to others to obtain $1,000 or more within one year
  • Maximum Imprisonment for a First Offense15 years

A qualifying offense committed after a prior § 1029 conviction can carry a statutory maximum of 20 years. These figures are statutory maximums, not predictions of the sentence in a particular case.

The advisory federal sentencing guidelines can account for factors such as loss, victims, device-making equipment, authentication features, role in the offense, obstruction, acceptance of responsibility, and criminal history. Restitution and forfeiture may create additional financial exposure.


The $1,000 Threshold Must Be Calculated under the Charged Subsection

Sections 1029(a)(2) and (a)(5) generally require at least $1,000 in aggregate value during the applicable one-year period.

Transaction dates, declined charges, attribution, and whether the defendant actually obtained anything of value can affect the calculation. Later refunds, reversals, or merchant credits require separate analysis because they do not necessarily erase value previously obtained for purposes of the statutory threshold.

Section 1029(a)(1), by contrast, does not impose the same $1,000 element for counterfeit access-device conduct.

Fifteen Devices Can Mean Fifteen Account Numbers

A § 1029(a)(3) charge generally requires knowing possession of at least 15 counterfeit or unauthorized access devices with intent to defraud.

Investigators do not necessarily need 15 pieces of plastic. Account numbers or qualifying codes stored in a spreadsheet, photograph, messaging application, cloud account, or database can potentially count as separate access devices.

That makes device identification important. Each item attributed to the defendant should be tested against the statutory definition, possession evidence, and alleged fraudulent intent.


4. Authorization and Fraudulent Intent Require Separate Proof


Proof that a card belonged to another person does not, by itself, establish that its use was unauthorized or undertaken with intent to defraud.

Authorization disputes can arise in families, businesses, employment relationships, shared accounts, purchasing arrangements, and recurring-payment settings. Messages, prior transactions, account practices, merchant records, and the scope of any permission may change the factual picture.


Possession of Card Data Does Not Automatically Establish Intent

The presence of account information on a device is different from proof that the defendant knowingly possessed it for a fraudulent purpose.

Prosecutors may rely on circumstantial evidence such as multiple account numbers, card-making equipment, resale activity, false identification, or communications about purchases. The defense can test how each fact connects to the individual defendant.

Shared phones, computers, cloud accounts, and messaging applications can create attribution questions. Digital evidence should show more than where information was found; it should also be examined for who accessed, controlled, created, or used it.


5. Can Digital Evidence Be Challenged or Suppressed?


Digital evidence should be examined for the legal basis of the search, warrant scope, attribution, forensic methodology, authentication, preservation, and chain of custody.

Federal card investigations may involve phones, computers, cloud accounts, payment applications, IP logs, location data, and account records. A warrant should be reviewed for probable cause and particularity, while warrantless collection requires its own legal basis.

A defect does not automatically result in suppression. Good-faith rules and other doctrines may affect the remedy. Evidence that was unlawfully obtained, inadequately authenticated, or incorrectly attributed may nevertheless be subject to appropriate challenge.



6. Aggravated Identity Theft Can Add Consecutive Prison Exposure


A § 1029 case can carry additional exposure if prosecutors charge aggravated identity theft under 18 U.S.C. § 1028A.

Section 1028A generally imposes a consecutive two-year term when a defendant knowingly transfers, possesses, or uses another person's means of identification without lawful authority during and in relation to a qualifying predicate felony. Access device fraud can qualify as a predicate offense.

Cases involving another person's identifying information should therefore be analyzed separately from the underlying identity theft issues.


Dubin Limits Incidental Uses of Identification

The mere appearance of another person's identifying information in a fraudulent transaction does not automatically establish aggravated identity theft.

In Dubin v. United States, the Supreme Court rejected an expansive interpretation of § 1028A. The use of another person's identification must have the required relationship to what makes the predicate conduct criminal.

That distinction can matter where identification appears only as an incidental part of billing, payment processing, or another transaction.

Prosecutors Must Also Prove Knowledge That the Identity Belonged to a Real Person

Section 1028A also requires proof that the defendant knew the means of identification belonged to another actual person.

The Supreme Court established that knowledge requirement in Flores-Figueroa v. United States, 556 U.S. 646 (2009). A defense should therefore address both questions: whether the defendant knew the identifying information belonged to a real person and whether its use satisfies the relationship required by Dubin.


7. Other Federal Fraud Charges May Accompany Section 1029


Federal prosecutors may combine access device charges with wire fraud, bank fraud, conspiracy, or identity-related offenses arising from the same transactions.

Wire fraud under 18 U.S.C. § 1343 may apply when interstate wire communications further a qualifying scheme to obtain money or property through deception.

Bank fraud under 18 U.S.C. § 1344 addresses qualifying schemes involving financial institutions or property under their custody or control. Section 1344 carries a statutory maximum of 30 years.

Related wire and mail fraud allegations should be evaluated independently. The government must establish the elements of each offense rather than treating § 1029 as proof of every related fraud count.



8. How Federal Credit Card Fraud Investigations Develop


Federal investigations often combine transaction records and digital evidence to determine who obtained, controlled, or used the disputed account information.

The U.S. Secret Service has statutory investigative authority for § 1029 offenses. The FBI, Postal Inspection Service, or other federal agencies may participate when allegations overlap with bank fraud, mail fraud, organized activity, or other federal offenses.

Investigators may examine:

  • Issuer and merchant transaction records.
  • IP addresses and login histories.
  • Device identifiers and payment-app data.
  • Phones, computers, and cloud storage.
  • ATM and retail surveillance footage.
  • Shipping and delivery information.
  • Card-making or encoding equipment.
  • Cash withdrawals and resale transactions.
  • Communications among alleged participants.

Evidence that a fraudulent transaction occurred should be separated from evidence identifying who caused it.



9. How to Build a Credit Card Fraud Defense


A credit card fraud defense should test each statutory element against the transaction history, authorization evidence, and digital attribution.

Key issues include:

  • Federal nexus: Can prosecutors establish the required effect on interstate or foreign commerce?
  • Authorization: What evidence shows whether use was permitted at the relevant time?
  • Intent: What supports an intent to defraud rather than mistake or misunderstanding?
  • Device status: Does each number, credential, or card satisfy § 1029?
  • Thresholds: Can the required $1,000 amount or 15-device count be proven?
  • Attribution: What ties the defendant to the purchase, withdrawal, account, or digital device?
  • Possession: Was card data knowingly controlled or merely present on a shared system?
  • Knowledge of a real person: If § 1028A is charged, can prosecutors satisfy Flores-Figueroa?
  • Identity use: Does the alleged use satisfy Dubin?
  • Search and seizure: Was digital evidence obtained and authenticated through legally supportable procedures?

The analysis should remain transaction-specific. Several disputed purchases do not necessarily involve identical authorization, evidence, or participants.



10. Practical Pitfalls in Credit Card Fraud Defense


Early assumptions about authorization, account ownership, and digital evidence can make an access-device case harder to evaluate accurately.

Common problems include:

  • Assuming a physical card must exist. Account numbers and qualifying codes can constitute access devices.
  • Ignoring statutory thresholds. The $1,000 and 15-device requirements are elements of particular charges.
  • Treating a cardholder's denial as the entire authorization record. Prior communications and transaction practices may matter.
  • Accepting digital attribution without examining access history. Shared accounts, devices, and networks can complicate attribution.
  • Deleting messages or transaction data after learning of an investigation. Relevant records should be preserved once scrutiny is reasonably foreseeable.
  • Offering speculative explanations for unfamiliar transactions. Statements may later be compared against detailed financial and digital records.
  • Assuming every identity-related allegation supports § 1028A. Both the Flores-Figueroa knowledge requirement and Dubin relationship must be evaluated.


11. Frequently Asked Questions


Federal credit card fraud liability depends on the charged subsection, federal nexus, authorization, intent, transaction value, and evidence connecting the defendant to the conduct.


Yes. An access device can include an account number, PIN, code, or other qualifying means of account access.

No. Section 1028A has separate requirements. Prosecutors must establish the required identity use, knowledge that the identification belonged to another actual person, and the necessary relationship to a qualifying predicate offense.

08 Sep, 2026


The information provided in this article is for general informational purposes only and does not constitute legal advice. Prior results do not guarantee a similar outcome. Reading or relying on the contents of this article does not create an attorney-client relationship with our firm. For advice regarding your specific situation, please consult a qualified attorney licensed in your jurisdiction.
Certain informational content on this website may utilize technology-assisted drafting tools and is subject to attorney review.

Online Consultation
Phone Consultation