I. The Statutory Framework
The federal wire fraud statute, codified at 18 U.S.C. § 1343, provides in relevant part that “[w]hoever, having devised or intending to devise any scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice, shall be fined under this title or imprisoned not more than 20 years, or both.”1
The statute was enacted in 1952 as a complement to the mail fraud statute (18 U.S.C. § 1341), which dates to 1872. Together, they constitute what the Supreme Court has described as the federal government’s “first line of defense” against fraud. The wire fraud statute differs from its mail fraud counterpart only in the medium of transmission: where mail fraud requires use of the postal service, wire fraud requires use of interstate wire, radio, or television communications. The elements, the penalties, and the interpretive framework are otherwise identical.
The Supreme Court has distilled the elements of wire fraud into three requirements. In Neder v. United States, 527 U.S. 1 (1999), the Court held that the government must prove: (1) a scheme or artifice to defraud, (2) involving a material misrepresentation, and (3) use of interstate wire communications in furtherance of the scheme.2 The penalty for each count is imprisonment of up to twenty years. Where the scheme affects a financial institution, the penalty increases to thirty years and the fine to one million dollars per count.
Wire fraud is the most versatile weapon in the federal criminal arsenal. The Department of Justice charges it more frequently than virtually any other substantive offense. In fiscal year 2023, the United States Sentencing Commission reported that fraud offenses constituted the second-largest category of federal cases sentenced, with wire fraud the most commonly charged variant.3 The statute has been applied to schemes involving insider trading, health care billing, identity theft, government contract fraud, Ponzi schemes, and the theft of trade secrets.
It has never been applied to the act of clicking a checkbox on a website. The reason is not statutory.
II. The Representation
The phrase “I have read and agree to the Terms and Conditions” is not a button label. It is a declarative statement. It contains two factual assertions, joined by the conjunction “and”: first, that the person making the statement has read the terms and conditions; and second, that the person agrees to them.
The first assertion is a statement of historical fact. It describes a completed action: the reading of a specific document. It is either true or it is not. The person either read the document or did not.
The second assertion is a statement of present intent: the person agrees to be bound by the terms described in the document they claim to have read. This assertion is logically dependent on the first. One cannot meaningfully agree to terms one has not read, any more than one can ratify a treaty one has not seen or endorse a candidate whose platform is unknown. The agreement, if genuine, presupposes the reading. If the reading did not occur, the agreement is built on a false foundation.
The legal significance of this representation is not academic. In ProCD, Inc. v. Zeidenberg, 86 F.3d 1447 (7th Cir. 1996), Judge Frank Easterbrook held that “shrinkwrap” license terms are enforceable contracts, establishing the principle that a user who manifests assent to terms is bound by them.4 This principle was extended to “clickwrap” agreements in a series of cases that now forms the bedrock of online contract law. The Second Circuit, in Specht v. Netscape Communications Corp., 306 F.3d 17 (2d Cir. 2002), drew the critical distinction: a “clickwrap” agreement, in which the user must affirmatively click a button indicating assent, is enforceable precisely because the user has manifested assent. A “browsewrap” agreement, in which terms are merely posted without requiring a click, may not be.5
The entire framework of digital contract enforcement therefore depends on a single factual predicate: that the person who clicked “I have read and agree” actually read and agreed. If this predicate is false, the contractual foundation is fraudulent. If it is true, approximately 230 million American adults have read and understood the Terms and Conditions of every service they have ever used.
One of these propositions must be correct. We have data on which one it is.
III. The Falsity
In 2020, Jonathan A. Obar and Anne Oeldorf-Hirsch published a study titled “The Biggest Lie on the Internet” in Information, Communication & Society. The researchers recruited 543 university students and asked them to join a fictitious social networking service called NameDrop. The service came with a privacy policy and terms of service that the participants were required to review before joining.6
The terms of service contained two “gotcha clauses.” The first stated that NameDrop would share all user data with the National Security Agency. The second stated that users agreed to provide their first-born child as payment for access to the service.
Of the 543 participants, 98 percent did not notice either clause. Seventy-four percent skipped the privacy policy entirely by selecting a “quick join” option. Among those who did access the terms of service, the average reading time was 51 seconds. At a standard adult reading rate of 250 to 280 words per minute, the document should have required 15 to 17 minutes to read. The participants spent less than a minute. The majority then clicked “I agree.”
The Obar and Oeldorf-Hirsch study was not an outlier. In 2017, the Deloitte Global Mobile Consumer Survey reported that 91 percent of consumers accept legal terms and conditions without reading them. Among consumers aged 18 to 34, the figure was 97 percent.7 In 2019, the Pew Research Center found that only 9 percent of American adults report that they always read a company’s privacy policy before agreeing to it. Thirty-six percent said they never do.8
In 2008, Aleecia M. McDonald and Lorrie Faith Cranor of Carnegie Mellon University calculated the aggregate cost of reading every privacy policy an average American internet user encounters. The result, published in I/S: A Journal of Law and Policy for the Information Society, was approximately 244 hours per year: roughly thirty full working days devoted exclusively to the reading of legal documents governing one’s use of the internet. The researchers estimated that if every American internet user actually read every privacy policy, the national economic cost in lost productivity would be approximately $781 billion per year.9
The statement “I have read the Terms and Conditions” is false when made by approximately 91 percent of the Americans who make it. This is not a disputed claim. It is not an inference drawn from ambiguous data. It is the finding of peer-reviewed research conducted at multiple universities and corroborated by the largest professional services firm in the world. The people clicking the checkbox know they did not read the document. The companies publishing the document know the people did not read it. The courts enforcing the contracts formed by the checkbox know the people did not read it. The only entity that treats the representation as true is the legal system that governs the consequences of making false representations by wire.
IV. The Wire
The third element of wire fraud requires that the defendant “transmit or cause to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice.”
When a user clicks “I have read and agree to the Terms and Conditions,” the click generates an HTTP POST request. This request is transmitted from the user’s device through a series of routers, switches, and fiber-optic cables to a server operated by the service provider. The server may be located in a different state. In 2024, Amazon Web Services, Microsoft Azure, and Google Cloud collectively operated data centers in more than 30 U.S. states and over 60 countries. A user in California clicking “I agree” on a website hosted on cloud infrastructure in Virginia has transmitted a signal by means of wire communication in interstate commerce.
The Supreme Court has interpreted the wire transmission element broadly. In Schmuck v. United States, 489 U.S. 705 (1989), the Court held that the wire communication need not be the central feature of the fraud. It need only be “incident to an essential part of the scheme.”10 In Pereira v. United States, 347 U.S. 1 (1954), the Court held that use of the wires need only be “reasonably foreseeable” to the defendant.11 A person who submits a false statement through an online form, knowing that the form will be transmitted over the internet, has caused a wire transmission in interstate commerce as a matter of law.
The click of “I agree” is not an incidental use of the wires. It is the use. The wire transmission carries the false representation itself. The signal that arrives at the server contains, as its substantive content, the assertion that the user has read and agrees to the terms. The wire is not merely the medium by which the scheme operates. The wire carries the lie.
V. The Scheme
Wire fraud requires a “scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises.” The Supreme Court has interpreted “property” expansively. In Carpenter v. United States, 484 U.S. 19 (1987), the Court held that intangible property rights, including confidential business information, constitute “property” within the meaning of the fraud statutes.12
The user who clicks “I have read and agree” without reading obtains something of value: access to a digital service. The service may be a social media platform, an email provider, a streaming service, a cloud storage system, or a software application. These services have measurable economic value. The average revenue per user for major technology platforms ranges from approximately $10 to $50 per year. The aggregate revenue of the U.S. digital services industry exceeds $500 billion annually. Access to these services is conditioned on the representation. Without the click, access is denied. The user obtains access by making a representation the user knows to be false.
In Kelly v. United States, 590 U.S. 391 (2020), the Supreme Court narrowed the scope of wire fraud by holding that the scheme must aim to obtain “money or property.”13 The defendants in Kelly, who orchestrated the “Bridgegate” lane closures on the George Washington Bridge, were convicted of wire fraud for diverting Port Authority resources, but the Court unanimously reversed, holding that the object of the scheme was regulatory power, not money or property. The fraud must “target” property, not merely “involve” it.
The terms-and-conditions scheme does not encounter this limitation. The user’s objective is to obtain access to a service: a form of intangible property with measurable economic value. The false representation is the mechanism by which that property is obtained. The scheme targets the property directly. Every HTTP POST request that carries an unread “I have read” assertion is a wire transmission in furtherance of a scheme to obtain property by false pretenses.
VI. Materiality
In Neder v. United States, the Supreme Court held that materiality is an implied element of the federal fraud statutes. A statement is material if it has “a natural tendency to influence, or [is] capable of influencing, the decision of the decisionmaking body to which it was addressed.” The Court drew this formulation from the common law of fraud and from the definition codified in the federal false statements statute at 18 U.S.C. § 1001.14
The representation “I have read and agree to the Terms and Conditions” is the most material statement in digital commerce. Without it, the transaction does not occur. The service provider conditions access on the click. The legal enforceability of the resulting contract depends on the click. The entire downstream relationship between user and provider: the right to terminate the account, the right to modify the terms, the right to collect and monetize user data, the right to resolve disputes through binding arbitration, all depends on the legal fiction that the user made an informed, voluntary assent to the contract’s provisions.
Courts have repeatedly held that the click is what makes the contract enforceable. In Sgouros v. TransUnion Corp., 817 F.3d 1029 (7th Cir. 2016), the Seventh Circuit evaluated whether a user who clicked “I accept” was bound by terms that included an arbitration clause. The court held that the user was bound because the clickwrap interface “presented the user with the terms and required the user to click ‘I accept’ before proceeding.”15 The enforceability turned on the representation. If the representation is false, if the user did not actually read or understand the terms before clicking, the foundation on which the court relied is fraudulent.
The statement is not merely capable of influencing the decision of the service provider. It is the decision. No click, no access. No reading, no valid click. No valid click, no enforceable contract. The materiality element is not at issue. It is the load-bearing wall of the entire structure.
VII. The Knowledge Element
Wire fraud requires specific intent. The government must prove that the defendant acted “knowingly and with intent to defraud.” This distinguishes wire fraud from negligent misrepresentation or innocent mistake: the defendant must know that the representation is false and must make it with the purpose of obtaining something of value.
The average American internet user clicks “I have read and agree to the Terms and Conditions” knowing that the statement is false. This is not an assumption. It is the central finding of the Obar and Oeldorf-Hirsch study. The participants did not accidentally skip the terms. They chose to skip them. The “quick join” option was a deliberate selection. The 51-second reading time for a 17-minute document was not an honest effort that fell short. It was a conscious decision not to read, followed by an affirmative assertion that one had.
The Deloitte survey confirms the intentionality. Respondents who reported that they do not read terms of service did not claim that they tried and failed. They acknowledged that they chose not to. The behavior is not inadvertent. It is systematic, premeditated, and repeated across dozens of services per year, for years on end, by hundreds of millions of adults.
Moreover, the knowledge is effectively universal. Every internet user over the age of approximately fourteen understands that the “I have read” checkbox is a formality. Internet culture has acknowledged this understanding explicitly. The phrase “I agree to the Terms and Conditions” has been described as “the biggest lie on the internet” in peer-reviewed academic literature, by researchers at York University and the University of Connecticut, for over a decade.16 A person who clicks the checkbox cannot credibly claim ignorance of its falsity. The cultural context forecloses the defense.
VIII. The Scale
The Pew Research Center reports that approximately 95 percent of American adults use the internet.17 With an estimated adult population of 258 million, this yields approximately 245 million internet-using adults in the United States. Each of these individuals routinely encounters terms-of-service agreements when installing applications, creating accounts, updating software, and accessing websites that require registration.
A conservative estimate of the number of “I have read and agree” clicks per American internet user per year is ten. This accounts for new app installations, service registrations, and terms updates, and it deliberately excludes the dozens of cookie consent and privacy policy interactions that accompany routine browsing. At ten clicks per user across 245 million users, the annual volume of representations is approximately 2.45 billion.
If 91 percent of those representations are false, as the Deloitte data indicates, then approximately 2.23 billion false representations are transmitted by means of interstate wire communication each year in the United States. Each transmission constitutes a separate count of wire fraud under 18 U.S.C. § 1343. Each count carries a maximum penalty of twenty years’ imprisonment.
The aggregate maximum sentence for one year of American terms-and-conditions fraud is 44.6 billion years of imprisonment. This exceeds the age of the observable universe, which is approximately 13.8 billion years, by a factor of three.
The Federal Bureau of Prisons operates 122 institutions with a combined capacity of approximately 131,000 beds.18 Assuming every existing bed were vacated and repurposed exclusively for Terms of Service offenders, and assuming an average sentence of five years, the Bureau of Prisons would require approximately 85,000 years to process the backlog generated by a single calendar year of clicking.
The United States Sentencing Commission processes approximately 64,000 cases per year across all federal offenses. At that throughput, adjudicating one year of terms-and-conditions violations would take approximately 34,800 years. By the time the courts finished sentencing the 2026 violators, it would be the year 36,826, and approximately 77 trillion additional violations would have accumulated in the interim.
IX. Conclusion
The elements are not ambiguous. The statute prohibits obtaining property by means of false representations transmitted by wire. The checkbox is a representation. The representation is false. The falsity is knowing. The wire is the internet. The property is the service. The materiality is absolute: without the click, the transaction does not occur, and without the reading, the click is a lie.
Approximately 245 million Americans commit this offense with the regularity of brushing their teeth. They do it before checking their email in the morning. They do it while installing software at their desks. They do it while downloading games on their children’s tablets. They do it while their phones update overnight. Each click is a count. Each count is a felony. Each felony carries twenty years.
The Department of Justice employs approximately 10,000 attorneys across 94 United States Attorneys’ offices and its Washington headquarters. It has prosecuted wire fraud in every conceivable context: a man who sold counterfeit Super Bowl tickets, a woman who submitted fraudulent insurance claims, a hedge fund manager who fabricated investment returns, a government official who steered contracts to a relative. It has secured convictions for wire fraud based on a single email, a single phone call, a single fax transmission.
It has never indicted a person for clicking a checkbox.
The checkbox says “I have read and agree.” The user has not read. The user clicks anyway. The click crosses state lines. A service is obtained. A false statement was the instrument of its obtaining. This is the textbook definition of the offense. It is committed 2.23 billion times per year. It has been committed, by the most conservative accounting, approximately 30 billion times since the iPhone App Store opened in 2008 and made checkbox-clicking a daily American ritual.
The statute of limitations for wire fraud is five years. The exposure is cumulative. Every American adult who has used the internet in the last five years has committed wire fraud. Most have committed it hundreds of times. All of them knew, at the moment they clicked, that they had not read the document they were swearing they had read.
The Department of Justice has not opened a file. The Federal Bureau of Investigation has not assigned a case number. The United States Attorneys have not convened a grand jury. Two hundred and forty-five million Americans continue to commit a federal felony every time they install an app, create an account, or update their software, secure in the knowledge that the most commonly committed crime in American history is the one the government has decided not to see.
The checkbox is still there. It still says “I have read.” They still have not.
Ergo.
Sources
- 18 U.S.C. § 1343, Wire Fraud, as amended. law.cornell.edu ↑
- Neder v. United States, 527 U.S. 1 (1999). supreme.justia.com ↑
- United States Sentencing Commission, “Annual Report and Sourcebook of Federal Sentencing Statistics,” Fiscal Year 2023. ussc.gov ↑
- ProCD, Inc. v. Zeidenberg, 86 F.3d 1447 (7th Cir. 1996). law.justia.com ↑
- Specht v. Netscape Communications Corp., 306 F.3d 17 (2d Cir. 2002). law.justia.com ↑
- J.A. Obar and A. Oeldorf-Hirsch, “The Biggest Lie on the Internet: Ignoring the Privacy Policies and Terms of Service Policies of Social Networking Services,” Information, Communication & Society, vol. 23, no. 1, 2020, pp. 128–147 (originally presented at TPRC 44, 2016). ssrn.com ↑
- Deloitte, “2017 Global Mobile Consumer Survey: US Edition,” 2017. deloitte.com ↑
- Pew Research Center, “Americans and Privacy: Concerned, Confused, and Feeling Lack of Control Over Their Personal Information,” November 15, 2019. pewresearch.org ↑
- A.M. McDonald and L.F. Cranor, “The Cost of Reading Privacy Policies,” I/S: A Journal of Law and Policy for the Information Society, vol. 4, no. 3, 2008, pp. 543–568. kb.osu.edu ↑
- Schmuck v. United States, 489 U.S. 705 (1989). supreme.justia.com ↑
- Pereira v. United States, 347 U.S. 1 (1954). supreme.justia.com ↑
- Carpenter v. United States, 484 U.S. 19 (1987). supreme.justia.com ↑
- Kelly v. United States, 590 U.S. 391 (2020). supreme.justia.com ↑
- Neder, 527 U.S. at 16, quoting Kungys v. United States, 485 U.S. 759, 770 (1988), and citing 18 U.S.C. § 1001. ↑
- Sgouros v. TransUnion Corp., 817 F.3d 1029 (7th Cir. 2016). law.justia.com ↑
- Obar and Oeldorf-Hirsch, cited above at note 6. The phrase “the biggest lie on the internet” originates with this paper and has been widely adopted in subsequent academic and popular discourse. ↑
- Pew Research Center, “Internet/Broadband Fact Sheet,” updated January 2024. pewresearch.org ↑
- Federal Bureau of Prisons, “Statistics,” accessed August 2026. bop.gov ↑