Leaked documents show the FBI never charged the hacker in the Matthew Keys case, despite knowing his identity for at least two years
Kim Zetter / Wired :
Context & Ripple Effects
The Matthew Keys prosecution has always rested on an odd division of labor: as Motherboard's deep dive on the case explained, federal prosecutors charged Keys under computer-hacking laws for passing along credentials, while the person who actually used them sat outside the indictment. The leaked documents now show the FBI had identified that hacker for at least two years without ever filing charges.
That gap fits a pattern visible elsewhere in this coverage: the government identified a former CIA employee as a Vault 7 leak suspect yet could not bring charges either, even as the FBI demonstrated real attribution muscle in other cases by tracing the Twitter hackers through a leaked OGUsers forum database and platform records.
First-order effects
- The actual intruder in the Keys case faces no legal exposure despite a known identity, leaving Keys to bear the full weight of a prosecution built on conduct adjacent to the hack rather than the hack itself.
- Kim Zetter's leaked-document reporting hands defense counsel and critics of the CFAA charging strategy documentary evidence that prosecutors pursued one defendant while declining to charge another they had already named.
Second-order effects
- Prosecutors face harder questions in future hacking cases about who gets indicted — the pattern of identifying suspects without charging them (Vault 7, and now the Keys case) invites challenges that attribution alone does not equal prosecutable evidence.
- The FBI's contrast is stark for observers of its methods: it can assemble charges from forum dumps and Coinbase records in the Twitter-hacker case, so its failure to act on a known identity in the Keys case looks like choice or evidentiary weakness rather than incapacity.
Third-order effects
- If the identify-but-don't-charge pattern holds alongside aggressive charging of facilitators under hacking statutes, cyber enforcement settles into a structure where legal jeopardy tracks prosecutorial convenience more than proximity to the intrusion itself.
- Sustained reliance on leaks and unredacted filings to expose these decisions — from the Lavabit target confirmation to today's documents — points toward court paperwork becoming the primary accountability mechanism for FBI cyber operations.
The trend: US cyber enforcement is splitting into high-capability attribution paired with selective prosecution, where knowing a hacker's identity no longer guarantees charges will follow.