BuiltWithNOF
50pixels09

CASWELL BELL & HILLISON LLP
FRESNO, CALIFORNIA

June 2008 p1 p106

COMPUTER FRAUD AND ABUSE ACT UPDATE

The federal Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030,  is most closely associated with criminal prosecutions brought by the Department of Justice.  But the CFAA also provides for a civil cause of action for anyone who suffers damage or loss because of a violation of the statute.

Click here to review the statute:

iStock_June_2008A civil lawsuit gives the wronged party more control and may provide a quicker fix.  By means of such a lawsuit, the victim can retrieve stolen data, enjoin illegal access to data, and even get compensatory damages for the theft and destruction of data.

The CFAA applies to all companies and all computers that are connected to the Internet. Potentially, there are multiple, distinct types of violations of the statute that could support a civil action. 

On a recurring issue in such cases – whether the defendant had authorization for his actions – the courts look at several factors:

  • Whether the defendant was an agent of the plaintiff;
  • Whether an employment contract, such as may have been embodied in company rules and policies, was breached; and
  • Whether the defendant’s use of the computer exceeded normal use that was expected by the plaintiff

Recent Court Decisions
A real estate business was allowed to proceed with a civil action against a former employee for violations of the CFAA.  In violation of his employment contract, the employee decided to quit and start a competing business.  Before he returned the company’s laptop, he deleted all of the data in it, including data that would have revealed his misconduct.  Knowing that “deleted” files can be retrieved, he erased the incriminating data by loading into the laptop a secure-erasure program.

All of this, if proven in court, violated the CFAA as “transmission” of a program that damaged the computer (defined to include files in the computer), and as intentionally accessing the computer without authorization.  Although the employee had not yet left his job when he installed the program, by law any authorization he might have had evaporated as soon as he violated the duty of loyalty to his employer.

In another case brought under the CFAA, a tour company secured an injunction against a competing company run by one of its former employees.  The ex-employee improperly used confidential information from his former employer to enable his new company to glean pricing data from his former employer’s website, so that his new enterprise could effectively undercut those prices.

Although the website was open to anyone, the unauthorized use of the confidential information, combined with the use of a “scraper” software program, violated the CFAA.  On top of the injunction, the plaintiff could recover, as a compensable “loss” under the CFAA, the thousands of dollars it had paid in computer consultant fees for diagnostic work after the defendant’s conduct was discovered.

© Caswell Bell & Hillison LLP          Attorneys and Lawyers, Fresno, California

[August 2008] [July 2008] [June 2008] [May 2008] [April 2008] [March 2008] [Feb 2008] [Jan 2008] [Dec 2007] [Nov 2007] [Oct 2007] [Sept 2007] [August 2007] [July 2007] [June 2007] [May 2007] [April 2007] [March 2007] [Feb 2007] [Jan 2007] [Dec 2006] [Nov 2006] [Oct 2006] [Sept 2006] [August 2006] [June 2006] [May 2006] [April 2006] [March 2006] [Feb 2006] [Jan 2006] [Dec 2005] [Nov 2005] [Oct 2005] [Sept 2005]