HR-3278-119
Referred to the Committee on the Judiciary, and in addition to the Committee on Foreign Affairs, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Sponsored by Pat Fallon (R-TX)
What it does
This bill would add a penalty tier to the federal computer fraud statute (18 U.S.C. 1030) requiring a fine and imprisonment of at least 30 years or life for any offense that involves critical infrastructure, as defined in the USA PATRIOT Act. It would also require the President to impose sanctions on foreign persons who knowingly access or try to access critical infrastructure to harm U.S. national security or the safety of U.S. citizens and permanent residents. Sanctions would include blocking assets, revoking visas, and barring entry, with a renewable 180-day national security waiver.
Who benefits
Operators and customers of power grids, water systems, pipelines, hospitals, and communications networks, if the penalties deter attacks. Federal prosecutors, who would gain a severe charging tool and added plea leverage. National security agencies, which would get a mandatory sanctions mechanism against foreign hackers. Communities that depend on essential services and could be harmed by a successful attack.
Who is hurt
Defendants convicted under any part of section 1030 where the offense involves critical infrastructure, including low-level or non-malicious violators, who would face a 30-year mandatory minimum with no judicial discretion. Security researchers and penetration testers who could face exposure if their access is deemed unauthorized. Federal courts and the Bureau of Prisons, which would bear higher sentencing and incarceration burdens. Foreign persons, and U.S. entities dealing with them, who would face asset blocking and IEEPA penalties under a lower 'should have known' standard.
Supporters argue
Supporters argue that attacks on the grid, water systems, and hospitals can endanger thousands of lives and that current section 1030 penalties are too low to deter state-backed and criminal hackers. They contend a high mandatory minimum signals the seriousness of these offenses, and that the sanctions provision gives the executive a firm tool against foreign actors, with a waiver that preserves diplomatic flexibility. They point to attacks such as the Colonial Pipeline ransomware incident as evidence that the threat is real.
Opponents argue
Opponents argue that the bill's 30-year mandatory minimum applies to any offense that 'involves' critical infrastructure, a broad term covering many sectors, so minor or non-destructive violations could draw sentences comparable to murder. They contend mandatory minimums remove judicial discretion, raise Eighth Amendment proportionality concerns, and have not been shown to deter cyber offenders who often operate abroad. They also warn that the 'should have known' sanctions standard and the effects on security researchers are overbroad.
Constitutional context
The Eighth Amendment's ban on cruel and unusual punishment is the main issue, since courts review mandatory sentences for proportionality; Harmelin v. Michigan (1991) upheld a mandatory life sentence for drug possession, setting a very deferential standard for adult non-capital sentences. Sanctions rely on Congress's foreign affairs and commerce powers and on IEEPA, while the 'should have known' standard and asset blocking raise Fifth Amendment due process questions.
Checks and balances
The bill shifts sentencing power from judges to Congress and prosecutors through the mandatory minimum, and gives the President mandatory sanctions authority; checks include a 180-day waiver with notice to congressional committees, a 10-day advance notice requirement for regulations, and judicial review of convictions and sanctions.
Historical precedent
Congress previously raised Computer Fraud and Abuse Act penalties in the USA PATRIOT Act of 2001, and the Cybersecurity Enhancement Act of 2002 added life imprisonment where an offense knowingly or recklessly causes death, though neither set a 30-year mandatory minimum for infrastructure-related offenses generally.