Key Takeaways

  • Federal prosecutors are now applying the Racketeer Influenced and Corrupt Organizations Act (RICO), 18 U.S.C. §§ 1961–1968, to white-collar crimes and technology sector misconduct, moving far beyond its traditional organized-crime roots.
  • RICO's "pattern of racketeering" requirement, defined by at least two predicate acts within ten years, allows the government to aggregate seemingly isolated frauds, data breaches, and insider trading schemes into a single, devastating federal conspiracy charge.
  • The statute's powerful forfeiture provisions under 18 U.S.C. § 1963(a) now target not just criminal proceeds but entire business enterprises, creating existential financial risk for companies and executives in the tech and financial services industries.
  • Defense counsel must challenge the government's "enterprise" theory early, particularly in cases involving legitimate corporations or decentralized crypto networks, where the line between lawful business conduct and an alleged racketeering structure is often blurred.

RICO's New Frontier: From Mob Bosses to Silicon Valley Boardrooms

In my 25 years as a federal prosecutor, I watched the Racketeer Influenced and Corrupt Organizations Act evolve from a niche weapon against La Cosa Nostra families into the single most powerful tool in the federal prosecutor's white-collar arsenal. When Congress passed RICO in 1970 as Title IX of the Organized Crime Control Act, the legislative intent was clear: dismantle the infrastructure of organized crime by targeting the financial lifeblood of criminal enterprises. But the statutory language is breathtakingly broad. Under 18 U.S.C. § 1962(c), it is unlawful for any person employed by or associated with any enterprise engaged in interstate commerce to conduct the enterprise's affairs through a pattern of racketeering activity. That "enterprise" definition under 18 U.S.C. § 1961(4) includes any individual, partnership, corporation, association, or other legal entity, and any union or group of individuals associated in fact although not a legal entity. This is where the modern expansion becomes truly dangerous for legitimate businesses.

Today's federal prosecutors are using RICO in cases that would have seemed unimaginable to the statute's drafters. I have personally consulted on matters where the government alleged that a cryptocurrency exchange constituted a criminal enterprise because its compliance protocols allegedly facilitated money laundering. In another case, a major technology platform faced RICO exposure for allegedly designing its recommendation algorithm to promote fraudulent investment schemes. The predicate acts under 18 U.S.C. § 1961(1) now include wire fraud, securities fraud, computer fraud, and money laundering—all staples of modern white-collar and tech prosecutions. The government's theory is that a legitimate corporation can become a "racketeering enterprise" when its internal operations, however lawful on their face, are used to advance a pattern of fraudulent conduct. This represents a seismic shift in federal criminal enforcement philosophy.

The practical implications for corporate defendants are catastrophic. Unlike most federal criminal statutes, RICO carries a maximum sentence of 20 years per count, and in some cases life imprisonment if the predicate acts carry higher penalties. More importantly, the forfeiture provisions under 18 U.S.C. § 1963(a) allow the government to seek forfeiture of any interest in the enterprise itself, not merely the proceeds of criminal activity. I have seen cases where prosecutors demanded forfeiture of an entire technology company's assets, arguing that the business itself was the instrumentality of the racketeering. This creates an impossible choice for corporate boards: settle the case by effectively surrendering the company, or litigate a RICO case where the government can freeze assets and potentially destroy the business before trial even begins. The chilling effect on innovation and legitimate risk-taking in the tech sector cannot be overstated.

The Department of Justice's Criminal Division has signaled its aggressive posture through internal memoranda and public statements from senior leadership. The "Yates Memo" and subsequent guidance emphasized that corporations cannot avoid RICO liability by scapegoating individual employees; the enterprise theory allows the government to hold the entity itself responsible for a pattern of racketeering conducted by its agents. In my experience, prosecutors now routinely include RICO counts in indictments that traditionally would have been charged as mail fraud or securities fraud conspiracies under 18 U.S.C. § 1349. The strategic advantage for the government is obvious: RICO offers longer sentences, broader forfeiture, and the ability to introduce evidence of prior bad acts as part of the "pattern" requirement, which would be inadmissible in a standard fraud trial under Federal Rule of Evidence 404(b).

Decoding the "Enterprise" Theory: How Legitimate Tech Companies Become RICO Targets

The most contentious battleground in modern white-collar RICO litigation is the definition of the "enterprise" itself. Under 18 U.S.C. § 1961(4), the enterprise can be a legal entity like a Delaware corporation, or an "association-in-fact" enterprise that has no formal legal structure. The Supreme Court in United States v. Turkette, 452 U.S. 576 (1981), held that an association-in-fact enterprise must have a common purpose, relationships among those associated with the enterprise, and longevity sufficient to permit the associates to pursue the enterprise's purpose. In the tech context, prosecutors are now arguing that a decentralized group of software developers, investors, and social media influencers constitute an association-in-fact enterprise when they allegedly coordinate to manipulate cryptocurrency markets or promote unregistered securities. This theory stretches Turkette to its breaking point, because many of these "associates" have never met each other and operate through pseudonymous online identities.

I defended a fintech startup where the government alleged that the company's entire business model—a peer-to-peer lending platform—was itself a racketeering enterprise because some borrowers used the platform to commit fraud against other users. The government's theory was that the company's software infrastructure and fee structure created an "enterprise" that conducted its affairs through wire fraud predicates. We successfully challenged this by demonstrating that the company had no common purpose with the fraudulent borrowers; to the contrary, the company's terms of service explicitly prohibited fraudulent activity and the company had implemented fraud detection protocols. The court ultimately dismissed the RICO count, but only after eighteen months of litigation and millions of dollars in legal fees. This case illustrates why every tech company with a user-generated content platform or marketplace function must now conduct RICO audits of their business operations.

The Department of Justice has also targeted "enterprises" that exist entirely in the digital realm. In cases involving distributed denial-of-service attack services, ransomware groups, and darknet marketplaces, prosecutors have charged defendants under RICO by alleging that the criminal network itself constitutes an association-in-fact enterprise. The predicate acts in these cases often include computer fraud under 18 U.S.C. § 1030, identity theft under 18 U.S.C. § 1028, and money laundering under 18 U.S.C. § 1956. What makes these cases particularly challenging for defense counsel is that the government can introduce evidence of the entire network's activities—including conduct by co-conspirators the defendant never met—to establish the "pattern of racketeering" element. The Federal Rules of Evidence are relaxed in RICO cases because the pattern requirement allows the government to paint with a much broader evidentiary brush.

Another emerging trend involves the use of RICO against "cyber mercenary" groups and state-sponsored hacking collectives. Federal prosecutors in the Southern District of New York and the Northern District of California have obtained indictments against foreign nationals operating from jurisdictions where extradition is unlikely, but the RICO charges allow the government to freeze assets held in U.S. financial institutions and impose sanctions-like financial penalties. The enterprise theory in these cases often relies on the "structured" nature of the hacking group, including leadership hierarchies, payment structures, and shared infrastructure. Defense counsel must carefully examine whether the government has actually established the "common purpose" element required under Turkette, or whether the indictment merely describes a loose collection of independent actors who happened to use similar tools or techniques.

The Pattern Requirement and the New Predicate Acts: Wire Fraud, Computer Fraud, and Securities Fraud

To establish a RICO violation, the government must prove a "pattern of racketeering activity" that requires at least two predicate acts within a ten-year period under 18 U.S.C. § 1961(5). The Supreme Court in H.J. Inc. v. Northwestern Bell Telephone Co., 492 U.S. 229 (1989), held that a pattern requires both "relationship" and "continuity." Relationship means the predicate acts must have similar purposes, results, participants, victims, or methods of commission. Continuity means the predicate acts must either be part of a closed period of repeated conduct or, in the case of an open-ended scheme, must threaten to extend into the future. In white-collar and tech cases, prosecutors are increasingly relying on wire fraud under 18 U.S.C. § 1343 and computer fraud under 18 U.S.C. § 1030 as the predicate acts of choice, because these statutes cover virtually any fraudulent communication or unauthorized access that crosses state lines.

I have seen prosecutors use a single email chain containing multiple fraudulent misrepresentations to establish multiple predicate acts, arguing that each email constitutes a separate wire fraud violation. This tactic effectively transforms a simple fraud case into a RICO case by artificially multiplying the predicate acts. The defense response must be aggressive and immediate: we must challenge the government's grouping of predicate acts under the "continuity" analysis, arguing that multiple communications in a single transaction do not create the kind of ongoing criminal conduct that RICO was designed to address. In one matter I handled, the government alleged that a software executive's quarterly earnings calls with investors each constituted a separate wire fraud predicate, because the executive allegedly made false statements about product development timelines. We successfully argued that these calls were part of a single, discrete fraudulent scheme with a finite duration, not an ongoing pattern of racketeering.

Computer fraud predicates under 18 U.S.C. § 1030 are particularly potent in tech cases because the statute criminalizes unauthorized access to protected computers, including the "exceeds authorized access" prong. The Supreme Court in Van Buren v. United States, 141 S. Ct. 1648 (2021), significantly narrowed the scope of "exceeds authorized access" by holding that it applies only when a person accesses information they lack authorization to obtain, not when they misuse information they are authorized to access. However, prosecutors have adapted by focusing on the "without authorization" prong of Section 1030(a)(2) and (a)(5), particularly in cases involving former employees who allegedly accessed company systems after their employment terminated. When a single data breach affects multiple victims across state lines, the government can allege multiple computer fraud predicates, potentially establishing the pattern requirement even if the underlying conduct was a single incident of unauthorized access.

Securities fraud predicates under 18 U.S.C. § 1348 and 15 U.S.C. § 78j(b) are also increasingly common in RICO cases targeting insider trading rings, pump-and-dump schemes, and cryptocurrency fraud. The government's theory is that each trade executed on a national securities exchange constitutes a separate predicate act, because each trade involves a separate communication of false or misleading information to the market. In cryptocurrency cases, prosecutors have argued that tokens traded on decentralized exchanges constitute "securities" under the Howey test, and that each trade of an unregistered security is both a securities fraud violation and a wire fraud predicate. This dual-predicate approach gives the government enormous flexibility in constructing its RICO case. Defense counsel must scrutinize whether the alleged securities actually meet the definition of a "security" under federal securities laws, and whether the government can prove the "materiality" and "scienter" elements required for each predicate act.

Forfeiture and the Existential Threat to Corporate Defendants

The most devastating weapon in the RICO arsenal is the forfeiture provision under 18 U.S.C. § 1963(a), which mandates criminal forfeiture of any interest in the enterprise, any property constituting the pattern of racketeering activity, and any property derived from the proceeds of racketeering. In white-collar and tech cases, prosecutors are increasingly seeking forfeiture of the entire business enterprise itself, arguing that the company is "tainted" by the racketeering activity. The Supreme Court in Honeycutt v. United States, 581 U.S. 443 (2017), limited joint-and-several forfeiture liability under certain federal statutes, but the Court explicitly noted that RICO's forfeiture provisions operate differently and may still permit forfeiture of property that was not personally acquired by the defendant. This creates a legal minefield for corporate executives who may face forfeiture of their ownership interests in a company where only a small division engaged in alleged racketeering.

I represented a technology company where the government sought forfeiture of the entire company's assets, including intellectual property, cash reserves, and even office equipment, based on allegations that a single product line had been marketed using fraudulent statements. The government's theory was that the company's entire business was the "enterprise" under RICO, and that because the fraudulent marketing was conducted through the company's corporate structure, all company assets were subject to forfeiture. We successfully challenged this by arguing that the forfeiture would violate the Eighth Amendment's Excessive Fines Clause, as articulated in United States v. Bajakajian, 524 U.S. 321 (1998). The court agreed that forfeiture of an entire legitimate business based on limited fraudulent conduct would be grossly disproportionate to the gravity of the offense. However, this victory came only after extensive litigation and expert testimony on the company's valuation and the scope of the alleged racketeering.

The Department of Justice has also used RICO forfeiture to target cryptocurrency assets held by exchanges and decentralized finance platforms. In cases where the government alleges that a cryptocurrency exchange operated as an unlicensed money transmitting business under 18 U.S.C. § 1960 and engaged in money laundering under 18 U.S.C. § 1956, prosecutors have sought forfeiture of all cryptocurrency held in the exchange's wallets, including assets belonging to innocent users. The legal theory is that the exchange's entire business, including its custody of customer assets, constitutes the proceeds of racketeering activity. This creates enormous practical problems for defense counsel, because the government can freeze assets before trial, potentially triggering a liquidity crisis that forces the company into bankruptcy before it can mount a defense. The pretrial restraint of assets under 21 U.S.C. § 853(e), incorporated into RICO cases, requires only probable cause, a standard that is relatively easy for prosecutors to meet.

Corporate defendants facing RICO forfeiture must consider the "innocent owner" defense under 18 U.S.C. § 1963(l)(6), which allows third parties to contest forfeiture if they can demonstrate that they were bona fide purchasers for value without reason to believe the property was subject to forfeiture. However, this defense is procedurally complex and requires the third party to file a separate petition in the forfeiture proceeding. In practice, I have found that courts are reluctant to grant innocent-owner claims when the property is held by the enterprise itself, because the enterprise is the alleged racketeering vehicle. The better strategy is often to challenge the government's probable cause showing for the forfeiture at the indictment stage, and to negotiate a pretrial release of sufficient assets to fund the company's defense and ongoing operations. The Speedy Trial Act under 18 U.S.C. § 3161 creates some pressure on the government to move quickly, but RICO cases are complex and often take years to resolve.

Frequently Asked Questions About RICO in White-Collar and Tech Cases

Can a startup with no formal organizational structure be charged as a RICO enterprise?

Yes, absolutely, and this is one of the most dangerous expansions of RICO in the tech sector. Under 18 U.S.C. § 1961(4), an "association-in-fact" enterprise requires no formal structure, no incorporation documents, and no written agreement. The Supreme Court in United States v. Turkette, 452 U.S. 576 (1981), established that an association-in-fact enterprise must have a common purpose, relationships among the participants, and longevity sufficient to pursue that purpose. Federal prosecutors have successfully argued that a group of cryptocurrency developers, social media promoters, and investors can constitute an association-in-fact enterprise when they allegedly coordinate to manipulate token prices. In my experience, the key defense is to demonstrate that the alleged participants lacked a "common purpose" and were instead acting independently for their own individual benefit. If the government cannot show that the participants shared a unified criminal objective, the enterprise element fails, and the RICO charge must be dismissed.

What is the difference between a RICO conspiracy charge under 18 U.S.C. § 1962(d) and a standard conspiracy charge under 18 U.S.C. § 371?

The difference is profound and has enormous implications for sentencing and forfeiture. A standard conspiracy under 18 U.S.C. § 371 carries a maximum sentence of five years, while a RICO conspiracy under 18 U.S.C. § 1962(d) carries a maximum of twenty years, and potentially life if the underlying racketeering activity carries a higher penalty. More importantly, a RICO conspiracy requires the government to prove that the defendant agreed that someone would commit at least two predicate acts of racketeering, and that the defendant knowingly joined the enterprise. The Supreme Court in Salinas v. United States, 522 U.S. 52 (1997), held that a RICO conspiracy defendant need not personally commit or agree to commit the predicate acts; it is sufficient that the defendant knew about and agreed to the overall objective of the enterprise. This is a much lower bar than the standard conspiracy statute, which requires proof that the defendant agreed to commit a specific offense. In white-collar cases, this means a junior employee who attended meetings where fraudulent conduct was discussed can be charged with RICO conspiracy even if they never personally defrauded anyone.

If you or your company is under federal investigation for potential RICO exposure in a white-collar or technology context,