Social Media

Showing posts with label Computer Fraud and Abuse Act. Show all posts
Showing posts with label Computer Fraud and Abuse Act. Show all posts

Monday, September 10, 2012

Handling of Trade Secrets


Businesses often store proprietary information in automated systems, and it is much easier to pilfer proprietary information.  It can be done with a few keystrokes.  In a commendable burst of foresight, in 1986 Congress saw this problem looming on the horizon and enacted the Computer Fraud and Abuse Act (“CFAA”), 18 USC §1030.  The CFAA was designed principally to prevent outsiders from hacking into computer systems and not to prevent theft by employees.  However, depending on the circumstances, the CFAA can also cover theft by corporate employees.  The statue makes it a crime to intentionally access a computer “without authorization” or to “exceed authorized access” to obtain information on the computer.  The CFAA is a criminal law, and, although the general rule is that criminal laws do not create private causes of action, in the CFAA Congress expressly created a private cause of action, allowing a private party to obtain compensatory damages and injunctive relief.


Recently, the U.S. Court of Appeals for the 4th Circuit decided a case applying the CFAA in a civil action involving an employee’s alleged theft of trade secrets. WEC Carolina Energy Solutions, LLC v. Miller, et al., 4th Cir. No. 11-1201 (26 July 2012).  The defendant, Miller, was an employee of the plaintiff, WEC, and WEC authorized Miller to access WEC’s computers.  WEC alleged that Miller transferred the company’s trade secrets from the company’s computers to a competitor.  WEC alleged, inter alia, that Miller violated the CFAA.  The case presented the following issue: If a company authorizes an employee to access the company’s computers and to access the information on the computers, and if the employee, acting within the scope of his authorization, transfers information to a competitor, does the employee violate the CFAA?  The Court acknowledged that there are two conflicting decisions in other courts reaching opposite conclusions. Int’l Airport Ctrs., LLC v. Citrin, 440 F.3d 418 (7th Cir. 2006); United States v. Nosal, 676 F.3d 854 (9th Cir. 2012)(en banc).  

In WEC, the Fourth Circuit Court focused on the “plain language of the statute, seeking first and foremost to implement congressional intent,” saying that the words of the statute should be given their ordinary, contemporary and common meaning.  The Court noted that because the statute has criminal penalties the Court must strictly construe the statue applying the so-called “rule of lenity,” rejecting interpretations not strictly warranted by the text.  The Court concluded that based on the ordinary and common meaning of “authorization,” an employee is authorized access to a computer when the employer approves his admission to that computer.  Thus, an employee accesses a computer without authorization only if he gains admission to that computer without the employer’s approval.  Similarly, the Court concluded that an employee “exceeds authorized access” when he has approval to access the computer, but uses his access to obtain or alter information that falls outside the bounds of his approved access.  For example, if the employee accesses files that are outside the scope of his authorization.  According to the Fourth Circuit, the CFAA does not reach the improper use of information validly accessed.  For example if the employer authorizes the employee to access the information, and the employee then improperly uses the information by transferring the information to a competitor, the employee has not violated the CFAA.

The WEC decision does not leave employers without remedies for the theft of trade secrets.  Employers can still sue for violation of state trade secrets laws, breach of fiduciary duty, and, depending on the facts, fraud.  However, in cases like the WEC case, employers cannot sue for violation of the CFAA.

Author John Polk is Special Counsel at the D.C. regional business law firm of Berenzweig Leonard, LLP.  He can be reached at jpolk@berenzweiglaw.com.

Tuesday, August 21, 2012

Employee’s Access of Company Computers Was Not Unauthorized

In the case of WEC Carolina Energy Solutions LLC v. Miller, employee Miller had access to his employer WEC’s computer files.  Miller accessed WEC’s files using his valid log-in rights, but then downloaded information in order to help another company compete against WEC.  WEC found out what Miller did and sued him for, among other claims, violation of the federal Computer Fraud and Abuse Act (CFAA).


The CFAA is often invoked by companies to sue employees who steal confidential information for use by competitors.  The law applies when someone accesses a computer without authorization, or when someone exceeds the level of authorized access to a computer.  So a big question faced by appellate courts in recent years is whether it is a violation of the CFAA if an employee uses his valid access to his employer’s computer files to download confidential information in order to compete against the company.

There is a split among the nation’s federal appellate courts on this issue, with some jurisdictions such as the 7th Circuit saying the above case is a violation of the CFAA because the access by the employee is being done to the company’s detriment, and therefore by definition is not authorized by the company.  But Miller’s case arose in the 4th Circuit, which covers Virginia, Maryland, West Virginia and the Carolinas.  The 4th Circuit opined that Miller did not violate the CFAA because he had valid log-in rights to WEC’s computer system at the time he logged on to download the confidential information.  According to the court, WEC has other tort claims it can bring against Miller, just not a claim under the CFAA.

Given the split among the federal appellate courts on this issue, it is likely to end up before the United States Supreme Court for final resolution, so stay tuned.

Declan Leonard is managing partner of Washington, DC business law firm Berenzweig Leonard, LLP.  He can be reached at DLeonard@BerenzweigLaw.com.