Federal access device fraud — the formal name for most credit card and account fraud cases — is prosecuted under a single, far-reaching statute that turns possession of cards, account numbers, or card-making equipment into a felony. If federal agents are asking about credit cards, account numbers, skimmers, or stolen account data, bring a credit card fraud lawyer into the case before you answer a single question — these prosecutions rise and fall on intent and on precise statutory thresholds. At Elizabeth Franklin-Best, P.C., we defend access device fraud cases nationwide as part of our federal fraud defense practice.
The governing statute, 18 U.S.C. § 1029, was enacted to combat credit card fraud and has grown to reach a wide range of conduct — counterfeit cards, unauthorized account numbers, device-making equipment, and electronic account data. Because the statute defines “access device” so broadly, conduct that a defendant may not have viewed as serious can carry years of federal prison exposure.
This defense work is built on a substantial federal record. Our principal attorney, Elizabeth Franklin-Best, has handled more than 330 federal proceedings, including over 100 appeals, and is admitted to the United States Supreme Court and all twelve federal courts of appeals. She holds a 2026 “Best Lawyer” designation in Appellate Practice from Best Lawyers in America and a 2026 Chambers USA ranking for Litigation: White-Collar Crime & Government Investigations. In a § 1029 case we start where the statute does — with the exact subsection charged, its thresholds, and whether the government can prove the knowing, fraudulent intent it demands. If you are facing an access device or credit card fraud investigation or charge, we invite you to schedule a paid, one-hour initial consultation.
Table of Contents

Access Device Fraud: Quick Answer
| Question | Answer |
|---|---|
| What is access device fraud? | A federal crime under 18 U.S.C. § 1029 covering the fraudulent production, use, trafficking, or possession of credit cards, account numbers, and other “access devices.” |
| What must the government prove? | That the defendant acted knowingly and with intent to defraud, engaged in conduct described in one of the statute’s subsections, and that the offense affected interstate or foreign commerce. |
| What penalties can apply? | Depending on the subsection, a first offense carries up to 10 or 15 years in federal prison; repeat offenses can carry up to 20 years, plus fines. |
| Is intent required? | Yes. The statute requires both knowledge and a specific intent to defraud. Innocent or unknowing possession is not a crime. |
| How do we take on these cases? | Our firm defends § 1029 investigations and prosecutions nationwide; representation starts with a paid, one-hour initial consultation booked online. |
Key Takeaways
- Access device fraud is governed by 18 U.S.C. § 1029, the broad federal statute behind most credit card and account fraud prosecutions.
- An “access device” is defined expansively — cards, plates, codes, account numbers, electronic serial numbers, PINs, and other means of account access.
- The statute reaches counterfeit access devices, unauthorized access devices, device-making equipment, and electronic account data.
- Two thresholds recur: trafficking or using devices to obtain $1,000 or more in a one-year period, and possessing fifteen or more counterfeit or unauthorized devices.
- Every subsection requires that the defendant act knowingly and with intent to defraud.
- Penalties depend on the subsection — up to 10 or 15 years for a first offense, and up to 20 years for repeat offenses.
- The offense must affect interstate or foreign commerce to be a federal crime.
- Prosecutors routinely stack aggravated identity theft (18 U.S.C. § 1028A) onto § 1029 counts, but Dubin v. United States confines that mandatory two-year add-on to cases where identity misuse is at the crux of the offense.
- SIM-swap and account-takeover schemes are a current federal charging priority, typically combining § 1029 with wire fraud and identity theft counts.
- Because these cases turn on intent and on statutory thresholds, the precise charge must be analyzed closely.
What Is Access Device Fraud?
Access device fraud is the federal term for what most people call credit card fraud. Congress enacted 18 U.S.C. § 1029 in 1984 to combat a rising tide of credit card and account fraud, supplementing earlier consumer-credit laws and broadening federal jurisdiction over these offenses. As payment technology evolved, the statute’s reach grew with it.
The breadth of the statute comes from its definition of “access device.” Under § 1029, an access device is any card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other telecommunications service, equipment, or instrument identifier, or other means of account access that can be used to obtain money, goods, services, or anything of value, or to initiate a transfer of funds. In plain terms, the statute reaches far beyond a physical credit card — a stolen account number, a captured PIN, or a batch of electronic card data can all be access devices.
The statute distinguishes between a counterfeit access device — one that is forged, fictitious, altered, or a counterfeit component — and an unauthorized access device — one that is lost, stolen, expired, revoked, canceled, or obtained with intent to defraud. The label matters, because different subsections target different conduct and different categories of device.
How Access Device Fraud Is Charged
Section 1029 contains a series of subsections, each describing distinct conduct. The most commonly charged include:
- § 1029(a)(1) — Counterfeit access devices. Knowingly and with intent to defraud producing, using, or trafficking in one or more counterfeit access devices.
- § 1029(a)(2) — Unauthorized access devices. Knowingly and with intent to defraud trafficking in or using one or more unauthorized access devices during a one-year period and obtaining anything of value aggregating $1,000 or more during that period.
- § 1029(a)(3) — Possession of fifteen or more devices. Knowingly and with intent to defraud possessing fifteen or more devices that are counterfeit or unauthorized access devices.
- § 1029(a)(4) — Device-making equipment. Knowingly and with intent to defraud producing, trafficking in, or controlling device-making equipment — for example, card embossers and encoders.
- § 1029(a)(5) — Transactions with another’s account. Knowingly and with intent to defraud effecting transactions with access devices issued to another person, obtaining $1,000 or more in value during a one-year period.
The statute also reaches trafficking in or possessing account-data and scanning equipment, and the solicitation of others to provide account information. In addition, access device cases are frequently charged together with aggravated identity theft, wire fraud, bank fraud, and conspiracy, which can add significant exposure.
Applied Insight: The subsection charged drives everything — the conduct element, the thresholds, and the penalty range. A § 1029(a)(3) possession count rises or falls on the count of fifteen; a § 1029(a)(2) count depends on the $1,000 aggregation. Reading the indictment against the exact statutory text is the first, essential step in the defense.
What the Government Must Prove
Although the conduct element varies by subsection, two requirements run through the entire statute. First, the offense must affect interstate or foreign commerce — the jurisdictional hook that makes the conduct a federal crime. Second, and most importantly, the defendant must have acted knowingly and with intent to defraud.
The intent requirement is demanding. Federal courts have explained that “intent to defraud” under § 1029 means acting with the conscious purpose of deceiving — a culpable state of mind distinct from mere knowledge. The government must prove the defendant not only knew what was in their possession or what they were doing, but acted with the purpose of committing fraud.
That distinction creates real defense opportunities. A person who unknowingly possessed account data, who did not realize a card or number was counterfeit or unauthorized, who held items without any fraudulent purpose, or who was unaware of the contents of a device or a file may lack the intent the statute requires. Where the government’s proof of purpose is thin — for example, where it relies on possession alone — the intent element is a central battleground.
The Statutory Thresholds
Two numerical thresholds appear repeatedly in § 1029 cases, and both are genuine, litigable elements rather than technicalities.
The $1,000 aggregation applies to charges under § 1029(a)(2) and (a)(5). The government must prove that the value obtained through the charged conduct totaled at least $1,000 within a one-year period. Where the proof of value is uncertain, contested, or falls short of the threshold within the relevant period, that is a defense to the charge.
The fifteen-device threshold applies to possession charges under § 1029(a)(3). The government must prove the defendant knowingly and with intent to defraud possessed fifteen or more counterfeit or unauthorized access devices. The count of qualifying devices, and whether each truly meets the statutory definition, can be vigorously contested — not every item the government characterizes as an “access device” necessarily qualifies.
Applied Insight: In possession cases, the defense often examines each item the government counts. Whether a particular number, card, or piece of data actually meets the statutory definition of a counterfeit or unauthorized access device — and whether it was truly possessed with fraudulent intent — can move the count below fifteen and reshape, or defeat, the charge.
Penalties for Access Device Fraud
Penalties under § 1029 depend on the subsection charged. For a first offense, the most commonly charged subsections — including counterfeit access devices, unauthorized access devices, and possession of fifteen or more devices — carry up to 10 years in federal prison. Other subsections, including those involving device-making equipment and transactions with another person’s account, carry up to 15 years for a first offense. Repeat offenses can carry up to 20 years. Substantial fines apply across the board.
The exposure often grows because of related charges. Access device cases are frequently paired with aggravated identity theft, which adds a mandatory, consecutive two-year term to certain underlying felonies, and with wire fraud, bank fraud, and conspiracy counts. The combination can transform what appears to be a single § 1029 charge into a multi-count indictment with serious aggregate exposure.
The actual sentence is driven by the advisory United States Sentencing Guidelines, and in access device cases U.S.S.G. § 2B1.1 makes the loss amount the dominant input, with further enhancements tied to the number of victims and the means used. Two features of the loss rules deserve close attention. First, a special rule sets a floor of $500 per counterfeit or unauthorized access device — with a $100-per-device floor for certain telecommunications identifiers — so a stack of cards or account numbers produces a guideline loss figure even if nothing was ever charged to the accounts. Second, effective November 1, 2024, Amendment 827 wrote the intended-loss rule into the text of § 2B1.1 itself, which lets the government press a loss theory built on what it claims a defendant intended to obtain rather than what was actually taken.
Those rules make the device count enormously consequential — and the count can be attacked. In United States v. Onyesoh, 674 F.3d 1157 (9th Cir. 2012), the Ninth Circuit vacated a sentence because the government never proved that expired credit card numbers were actually usable; an item that cannot obtain anything of value does not satisfy the statutory definition. Most other circuits have declined to impose that usability requirement: in United States v. Carver, 916 F.3d 398 (4th Cir. 2019), the Fourth Circuit held that the government need not show each device was currently functional, only that it was “in principle the sort of thing that people use to obtain money,” reasoning that the statute’s coverage of expired, revoked, and canceled cards would be meaningless under a strict usability rule. The law of the charging district therefore shapes how far this argument runs. Loss calculation and device-count challenges are frequently where the most sentencing ground is gained. Restitution and forfeiture are standard in these cases.
Aggravated Identity Theft After Dubin
The single most dangerous companion charge in an access device case is aggravated identity theft under 18 U.S.C. § 1028A. Because § 1029 sits within the chapter of the criminal code that § 1028A lists as a predicate, prosecutors can add a § 1028A count whenever they allege that a defendant used another person’s means of identification — a name, an account number, a card — during the access device offense. Each § 1028A count carries a mandatory two-year sentence that must run consecutively to the underlying fraud sentence, and that mandatory term is a powerful plea-bargaining lever for the government.
The Supreme Court cut that practice back in Dubin v. United States, 599 U.S. 110 (2023). Dubin holds that a defendant “uses” another person’s means of identification under § 1028A only when that misuse is at the crux of what makes the conduct criminal — not when someone else’s identifying information is merely an ancillary feature of a billing or payment method. The decision rejected the government’s sweeping reading, under which nearly every fraud involving a real person’s account could trigger the two-year add-on.
The early appellate returns show both the power and the limits of the decision. In United States v. Omotayo, 132 F.4th 181 (2d Cir. 2025), the Second Circuit threw out a § 1028A conviction because a real person’s name on a backup invoice was never a “key mover” in the wire fraud — ancillary paperwork is not identity theft. The same court’s decision in United States v. Constantinescu, 147 F.4th 299 (2d Cir. 2025), affirmed § 1028A convictions in an ATM-skimming case, holding that stolen debit card numbers and PINs are themselves means of identification. The dividing line matters enormously in access device cases: where cloned cards or hijacked account credentials are the scheme itself, the add-on remains squarely in play; where a person’s identifying information merely appears in the paperwork, it does not.
For access device defendants, Dubin matters in two ways. Where the alleged fraud centers on misrepresenting goods or services — and a real account number is simply how payment moved — a motion to dismiss or an instruction fight on the § 1028A count is now viable. And where the government has stacked multiple § 1028A counts to manufacture mandatory time, Dubin arguments can reshape the entire negotiating posture of the case. We analyze every § 1028A count against Dubin at the outset; the issue is developed further on our aggravated identity theft defense page.
SIM-Swap and Account-Takeover Prosecutions
A growing share of modern § 1029 prosecutions involves no plastic at all. In a SIM-swap scheme, as the government describes it, an offender persuades or bribes a mobile carrier — or exploits its reset procedures — to move a victim’s phone number onto a SIM card the offender controls. Once the number moves, text-message verification codes for banking, email, and cryptocurrency accounts flow to the offender, who can then reset passwords and drain accounts. Account-takeover cases follow a similar pattern using phished or purchased credentials.
These cases fit § 1029 because the statute’s definition of access device expressly includes electronic serial numbers, mobile identification numbers, and other telecommunications identifiers — a phone number tied to a victim’s accounts can itself be the charged device. The typical indictment pairs § 1029 counts with wire fraud, aggravated identity theft, and sometimes computer fraud and money laundering counts, and the Secret Service and FBI cyber task forces lead most of these investigations. Because stolen cryptocurrency is so often the target, our cryptocurrency fraud defense page addresses the digital-asset side of these prosecutions in depth.
SIM-swap cases present distinctive defense issues. Attribution is often the central fight: the government must connect a specific person to the swap, and IP logs, device identifiers, and cooperator testimony all carry weaknesses worth probing. Carrier insiders, group chats, and online handles complicate the question of who did what. Valuation and forfeiture of volatile cryptocurrency raise their own disputes. And Dubin challenges to stacked § 1028A counts apply with full force here, because the government’s theory often treats every intercepted code as a fresh identity-theft offense.
Defenses to Access Device Fraud Charges
Access device cases vary enormously in their facts, and results can never be promised. Still, a recognizable set of defense themes runs through § 1029 litigation, and fitting them to the government’s evidence is where strategy begins:
- Lack of intent to defraud. The defendant did not act with the conscious purpose of committing fraud — the demanding mental state the statute requires.
- Lack of knowledge. The defendant did not know a card, number, or file was counterfeit or unauthorized, or was unaware of what a device or account contained.
- Below the threshold. The proof fails to establish $1,000 in value within a one-year period, or fewer than fifteen qualifying devices were possessed.
- The item is not an “access device.” A challenged item does not meet the statutory definition of a counterfeit or unauthorized access device.
- Insufficient interstate commerce nexus. The government cannot establish that the offense affected interstate or foreign commerce.
- Mere presence or possession. Possession near, or shared access to, items controlled by others does not by itself establish a defendant’s knowing, fraudulent possession.
- Search and seizure challenges. Evidence obtained through an unlawful stop, search, or device extraction may be suppressed.
- Sentencing and loss challenges. Even where conviction is likely, contesting the device count and loss can sharply reduce exposure.
The right combination depends entirely on the facts and the evidence. Our role is to test the government’s proof element by element, scrutinize how the evidence was gathered, and press every legitimate defense — during the investigation, in pretrial motions, at trial, and on appeal.
How Access Device Investigations Begin
Access device fraud investigations arise in several ways. The United States Secret Service has long-standing jurisdiction over financial and access device crimes and frequently leads these cases, often alongside the FBI and Postal Inspectors. A traffic stop that uncovers cards or a skimmer, a merchant’s fraud report, a bank’s referral, a cooperating witness, or an investigation into a data breach or a card-trafficking forum can each be the starting point.
The early steps matter. Preserve your rights at the first sign of contact: you are not required to explain items found in your possession or to consent to searches of your phone, computer, or accounts. Anything said to investigators can be used to supply the intent the statute requires. If you are stopped, served with a subpoena, or contacted by agents, decline to give informal explanations and consult experienced federal defense counsel before proceeding.
Why Work With Elizabeth Franklin-Best, P.C.
Access device fraud cases reward defense lawyers who read the statute precisely, who understand its subsections and thresholds, and who scrutinize both the intent evidence and the way the government’s evidence was gathered. The difference between a defensible case and a damaging one often lies in those details.
Elizabeth Franklin-Best, our principal attorney, wrote Reversing Your Criminal Conviction and is admitted to practice before the U.S. Supreme Court and all twelve federal courts of appeals, appearing pro hac vice in district courts nationwide. Her practice spans federal trial defense, a nationwide post-conviction docket, and an appellate bench that has produced more than 100 circuit appeals — reach that matters when a § 1029 device count or loss ruling needs to be preserved for appeal, not just argued once. Christopher Zoukis, our Managing Director, adds a working command of federal sentencing and the Bureau of Prisons to the exposure questions that dominate § 1029 cases. From the first agent contact through trial, sentencing, and appeal, we handle access device and credit card fraud matters at every stage.
No defense firm can guarantee how a case ends, and we will never pretend otherwise. What you can count on from us is element-by-element scrutiny of every § 1029 count, straight answers about where your case stands, and a strategy built around the specific subsection, thresholds, and evidence in your indictment. To put that analysis to work, schedule a paid, one-hour initial consultation.
Talk With a Credit Card Fraud Defense Lawyer
Between the statutory tiers, the $500-per-device loss floor, and the threat of stacked § 1028A counts, a credit card fraud prosecution can escalate from a single charge into years of mandatory exposure with startling speed. Early, statute-focused defense work is the counterweight. To review your circumstances confidentially with our team, book your paid, one-hour initial consultation now.
Access Device Fraud FAQs
What is access device fraud?
Access device fraud is the federal crime, under 18 U.S.C. § 1029, of fraudulently producing, using, trafficking in, or possessing credit cards, account numbers, and other “access devices.” It is the statute behind most federal credit card and account fraud prosecutions.
What counts as an “access device”?
An access device is defined broadly as any card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other means of account access that can be used to obtain money, goods, services, or anything of value, or to initiate a transfer of funds.
What is the difference between a counterfeit and an unauthorized access device?
A counterfeit access device is forged, fictitious, altered, or a counterfeit component. An unauthorized access device is one that is lost, stolen, expired, revoked, canceled, or obtained with intent to defraud. Different subsections of § 1029 target different categories.
What penalties does access device fraud carry?
Penalties depend on the subsection. A first offense for counterfeit devices, unauthorized devices, or possession of fifteen or more devices carries up to 10 years; subsections involving device-making equipment or another person’s account carry up to 15 years. Repeat offenses can reach 20 years.
What is the fifteen-device threshold?
Under § 1029(a)(3), it is a crime to knowingly and with intent to defraud possess fifteen or more counterfeit or unauthorized access devices. The count of qualifying devices is a real element, and whether each item meets the statutory definition can be contested.
What is the $1,000 threshold?
For charges under § 1029(a)(2) and (a)(5), the government must prove the defendant obtained at least $1,000 in value within a one-year period through the charged conduct. Where the proof of value falls short within the relevant period, that is a defense to the charge.
Does the government have to prove intent?
Yes. Every subsection of § 1029 requires that the defendant act knowingly and with intent to defraud. Courts have described intent to defraud as a conscious purpose to deceive — a demanding mental state. Innocent or unknowing possession is not a crime.
Can I be charged just for possessing account numbers or card data?
Possession can be charged, but only where the government proves the items were counterfeit or unauthorized access devices and that they were possessed knowingly and with intent to defraud. Unknowing possession, or possession without fraudulent purpose, lacks the required intent.
What is a skimmer, and how does it relate to these charges?
A skimmer is a device that captures the data stored on a payment card’s magnetic strip. Skimmers and card-encoding equipment can be charged as device-making equipment under § 1029(a)(4), a subsection that carries up to 15 years for a first offense.
Is access device fraud charged with other crimes?
Often. Access device fraud is frequently charged together with aggravated identity theft — which adds a mandatory, consecutive two-year term to certain felonies — and with wire fraud, bank fraud, and conspiracy. These combinations can substantially increase total exposure.
What are common defenses to access device fraud?
Common defenses include lack of intent to defraud, lack of knowledge that an item was counterfeit or unauthorized, falling below the $1,000 or fifteen-device threshold, an item that is not actually an “access device,” and challenges to how evidence was searched and seized. The right approach depends on the facts.
What should I do if I am stopped or contacted about credit card fraud?
You are not required to explain items in your possession or to consent to searches of your phone, computer, or accounts. Decline to give informal explanations, preserve your rights, and contact experienced federal defense counsel before proceeding. Early statements can supply the intent the statute requires.
What is a SIM-swap charge?
A SIM-swap charge alleges that someone moved a victim’s phone number onto a SIM card they controlled — usually to intercept text-message security codes and take over bank, email, or cryptocurrency accounts. Federal prosecutors typically charge SIM swapping under § 1029 alongside wire fraud and aggravated identity theft counts.
Does Dubin v. United States help in a credit card fraud case?
Often, yes. Dubin v. United States limits aggravated identity theft under § 1028A to cases where the misuse of another person’s identity is at the crux of the offense. When an account number was merely how payment moved, a stacked § 1028A count — and its mandatory two-year consecutive sentence — may be vulnerable to challenge.
How much does it cost to talk with your firm about an access device case?
We meet new clients through a paid, one-hour initial consultation booked on our online scheduling page. That hour lets us hear the facts, review any charging documents you have, and give you a candid early read on the statute’s thresholds and your realistic options.

