Showing posts with label employee misconduct. Show all posts
Showing posts with label employee misconduct. Show all posts

Tuesday, April 8, 2014

WI governor signs revenge porn and social media privacy bills into law; privacy bill raises questions

(Update 1: Included link and excerpt from Rep. Sargent's Op-Ed when the bill was introduced, and further comments - to provide some context)

Governor Scott Walker of Wisconsin signed 62 bills into law today, including SB223 (relating to social media privacy) and SB367 (revenge porn).

A full list of the bills he signed can be found here: At a glance: List of 62 bills Gov. Walker signed, and regarding the two bills mentioned above:
Senate Bill 223 – prohibits employers, educational institutions and landlords from requesting or requiring passwords or other protected access to personal internet accounts of students, employees, and tenants. Viewing, accessing and using information from internet accounts, including social media, in the public domain is allowed. Senator Glenn Grothman (R-West Bend) and Representative Garey Bies (R-Sister Bay) authored the bill which unanimously passed the Senate and passed the Assembly on a voice vote; it is Act 208.
Senate Bill 367 – modernizes Wisconsin’s law relating to disseminating private images and expands protections for victims who have their private images distributed without their consent. Senator Leah Vukmir (R-Wauwatosa) and Representative John Spiros (R-Marshfield) authored the bill which passed both the Senate and the Assembly on a voice vote; it is Act 243. 
I criticized the original revenge porn bill proposal in Wisconsin (see: Wisconsin's "revenge porn" bill goes too far. Hypos to ponder and why the legislature should look to Professor Franks ); specifically, I labeled the original proposal as overbroad because the bill did not include a scienter requirement. In the final bill, after a substitute amendment was adopted, the statutory text has been narrowed with just such a requirement. The bill signed into law requires "knowledge":
942.09 (3m) (a) Whoever does any of the following is guilty of a Class A misdemeanor: 
1. Posts, publishes, or causes to be posted or published, a private representation if the actor knows that the person depicted does not consent to the posting or publication of the private representation. 
2. Posts, publishes, or causes to be posted or published, a depiction of a person that he or she knows is a private representation, without the consent of the person depicted.
The social media privacy bill signed by the governor will surely be lauded by privacy advocates as a win for individual autonomy (and freedom from employer/educational institution snooping). But, I find the exceptions to the bill much more intriguing and noteworthy than the protections most will focus on. Particularly, the interesting carve-outs in bold:
(2) Restrictions on employer access to personal Internet accounts.  
   (a) Except as provided in pars. (b), (c), and (d), no employer may do any of the       following:
1. Request or require an employee or applicant for employment, as a condition of employment, to disclose access information for the personal Internet account of the employee or applicant or to otherwise grant access to or allow observation of that account.
2. Discharge or otherwise discriminate against an employee for exercising the right under subd. 1. to refuse to disclose access information for, grant access to, or allow observation of the employee's personal Internet account, opposing a practice prohibited under subd. 1., filing a complaint or attempting to enforce any right under subd. 1., or testifying or assisting in any action or proceeding to enforce any right under subd. 1. 
3. Refuse to hire an applicant for employment because the applicant refused to disclose access information for, grant access to, or allow observation of the applicant's personal Internet account. 
   (b) Paragraph (a) does not prohibit an employer from doing any of the following:

2. Discharging or disciplining an employee for transferring the employer's proprietary or confidential information or financial data to the employee's personal Internet account without the employer's authorization.
3. Subject to this subdivision, conducting an investigation or requiring an employee to cooperate in an investigation of any alleged unauthorized transfer of the employer's proprietary or confidential information or financial data to the employee's personal Internet account, if the employer has reasonable cause to believe that such a transfer has occurred, or of any other alleged employment-related misconduct, violation of the law, or violation of the employer's work rules as specified in an employee handbook, if the employer has reasonable cause to believe that activity on the employee's personal Internet account relating to that misconduct or violation has occurred. In conducting an investigation or requiring an employee to cooperate in an investigation under this subdivision, an employer may require an employee to grant access to or allow observation of the employee's personal Internet account, but may not require the employee to disclose access information for that account.
 So, an employer may not require you to provide access to your personal Internet account on a whim or a hunch. But, if the employer can point to an Acceptable Use Policy, text in an employee handbook, or can establish reasonable cause to believe employment-related misconduct, the employer can require such access. Sure, you don't have to provide your login/password, but in subsection 3, above, you could be required to grant access (whatever that means).

The social media bill's carve-outs sound a lot like CFAA cases of late, and also general social media prying lawsuits as well. How, then, is this bill a boon for employee/student privacy? Also, if my employer requested I grant access to a personal account, as part of an "investigation," I would almost assuredly deny that request, absent a subpoena. I am very curious how these exceptions will be used by employers going forward.

Update 1: 

Rep. Sargent wrote an Op-Ed in the Milwaukee Journal Sentinel when she proposed the bill (with other representatives). See here: Bipartisan bill protects social media accounts

Later, after the bill made it out of the Senate on a 33-0 vote, Sargent issued a press release. See here: Social Media Protection Bill Passes Senate on a 33-0 Vote. An interesting quote from the release:
I’m pleased that this common sense, bi-partisan legislation advanced further through the legislative process today.  It makes sense that personal internet accounts should be given the same, 4th Amendment protections as other aspects of our daily lives.  People have a reasonable expectation of privacy when interacting with their friends and family on Facebook or other sites. An employer, university, or landlord should not have access to private communications on social media sites. As technology evolves, so must our legislative efforts to protect our citizen’s privacy. The current generation will write the laws on social media.  We must do it carefully and with respect for all parties involved.
There should, in my opinion, be an asterisk (*) after that paragraph, noting that the exceptions may indeed swallow a large chunk of the well-intentioned proposal. If the bill's intent was to prevent forced disclosure of account credentials, then the text should have narrowly reflected that (considering, to wit, that the exceptions do not require providing credentials, but merely providing/granting access). Further, just as some courts have attempted to bring TOS/Acceptable Use Policies/Employee Handbooks within the ambit of CFAA liability, this bill allows varying employer-defined standards to dictate whether an employee must grant access to a social media/personal email account.

Hypo: If an employee handbook states no surfing the internet for personal reasons (or updating social media) during work hours and there is "reasonable cause" to believe that a violation occurred - must the employee grant access to the account to prove otherwise? How is that giving personal internet accounts "4th Amendment protections...[similar to those in] other aspects of our daily lives?" What if the employee refuses to grant access - is that grounds for termination?

More fundamentally, though, is this question: now that the bill has become law, who benefitted more from its enactment: employers, or employees?

Wednesday, August 21, 2013

New CFAA Complaints - Civil employee disloyalty cases dominate, reinforcing shift away statute's anti-hacking genesis

Cybercrime Review will now be posting, on an ongoing basis, new complaints alleging CFAA violations. This serves two purposes: (1) to make our readers aware of new cases that may be worth following, and (2) to provide a survey of how CFAA litigation has evolved as courts have grappled with the scope and purpose of the statute.

August filings of note:

91. Based on this initial research, Burns and Smith further investigated Defendants' actions prior to and following their resignations. 
92. Burns and Smith quickly discovered additional emails on Clinton Rubin's computer systems and network evidencing Defendants' efforts to divert the Company's valuable confidential, proprietary, and trade secret information, including, but not limited to, Clinton Rubin's financial statements; schedules and related information; business plans and strategy documents; business documents; customer information; contact lists; marketing documents, qualification documents, and sales and marketing information; client planning documents, work products, deliverables and other client information; resumes; affiliation, joint venture and alliance information and contracts; association and membership information; contracts including, but not limited to, client Non-Disclosure Agreements and Confidentiality Agreements, Master Services Agreements, Statements of Work, Subcontractor Agreements and other contractual documents made on behalf of Clinton Rubin; Clinton Rubin account information and passwords; and other Clinton Rubin confidential information, intellectual property, and client owned information. 
93. For example, in an email to Defendant Solak and Sandow, Defendant Pickens wrote the following: “Same with this. Stealing other people's stuff was effective in kindergarten and is effective now!”
... 
129. Defendants, prior to withdrawing, regularly accessed Clinton Rubin's computers, computer network, computer systems, computer files, electronic files and/or email accounts without authorization and/or in a manner that exceeded their authorization. 
130. Defendants also utilized Clinton Rubin's computers, computer network, computer files, computer systems, electronic files and/or email accounts to give instructions to a third-party to obtain Clinton Rubin's information for an improper purpose. 
131. Clinton Rubin's computers, computer network, computer systems, computer files, electronic files and/or email accounts that were used and/or accessed by Defendants prior to and following their withdrawal qualify as “protected computers” under the CFAA, 18 U.S.C. § 1030(e), because they are used in or affecting interstate or foreign commerce or communication. 
132. Without authorization and/or in a manner that exceeded their authorization, Defendants knowingly accessed, or caused another person to knowingly access on their behalf, Clinton Rubin's computers, computer network, computer systems, computer files, electronic files and/or email accounts with the intent to defraud and/or misappropriate Clinton Rubin's valuable confidential, proprietary, and trade secret information, including, but not limited to, Clinton Rubin's intellectual property, customer lists, financial data, marketing data, and client owned data, by forwarding, or causing another person to forward, such information to their personal email accounts in violation of the CFAA, corporate policy and their fiduciary duties as Members of Clinton Rubin. 
133. As a result of Defendants' actions and/or the actions Defendants caused to occur, Defendants furthered their intended fraud and/or misappropriation and obtained Clinton Rubin's valuable confidential, proprietary, and trade secret information and/or caused an impairment to the integrity and/or availability of Clinton Rubin data, programs, systems, or information, including, but not limited to, Clinton Rubin's intellectual property, customer lists, financial data, marketing data, and client owned data which carry a value in excess of $5,000. 
134. Defendants' conduct and/or the conduct Defendants cause to be conducted involved interstate or foreign commerce or communication. 
135. Defendants' conduct and/or the conduct Defendants cause to be conducted constituted a serious breach of loyalty owed to Clinton Rubin as former Members by accessing and misappropriating Clinton Rubin's valuable and protected information for their own personal gain and against the interest of Plaintiff. 
136. In an attempt to disguise their fraud and/or misappropriation, Defendants, with full knowledge and motive to do so, attempted to and did in fact delete relevant emails reflecting their misappropriation of Clinton Rubin's valuable trade secret information and diversion of business opportunities from Clinton Rubin to their newly founded competing venture. 
137. Through Defendants' unlawful access, copying, and alteration of Plaintiffs valuable confidential, proprietary, and trade secret information, Defendants furthered their intended fraud and/or misappropriation of Clinton Rubin's valuable trade secret information. 
138. Defendants' actions violate the CFAA and have caused Clinton Rubin damage. 
139. Plaintiff has no adequate remedy at law and will continue to suffer substantial and immediate irreparable harm unless Defendants are immediately enjoined pursuant to 8 U.S.C. § 1030(g) (“Any person who suffers damage or loss by reason of a violation of this section may maintain a civil action against the violator to obtain compensatory damages and injunctive relief or other equitable relief.”).
15. Following the formation of SOUTH VALLEY BIOLOGY CONSULTING, LLC, its owners and members embarked on a scheme to recruit and hire Plaintiffs staff biologists, and to illegally acquire Plaintiffs confidential work product and intellectual property in order to gain a competitive advantage over Plaintiff. As a result, Defendants NINA E. HOSTMARK, MICHAEL V. PHILLIPS, and PAUL ROSEBUSH left the employ of Plaintiff and joined SOUTH VALLEY BIOLOGY CONSULTING, LLC. 
16. Following the departure of NINA E. HOSTMARK, MICHAEL V. PHILLIPS, and PAUL ROSEBUSH, Plaintiffs managers discovered that its work product and intellectual property, in the form of original copies of its biological reconnaissance data and reports, were missing from the company's files, and that electronic copies of such data and reports had been removed and/or copied from the company's computers. 
17. Soon thereafter, several of Plaintiff's clients advised that existing contracts with Plaintiff were being terminated and given to SOUTH VALLEY BIOLOGY CONSULTING, LLC, and that future work involving biology reconnaissance and reporting would be performed by SOUTH VALLEY BIOLOGY CONSULTING, LLC. These clients include, but are not necessarily limited to Berry Petroleum, Aera Energy, Macpherson Oil, Co., Plains Pipeline, and Occidental. 
18. Around the same time, it was also discovered by Plaintiff that significant portions of Plaintiff's confidential work product and intellectual property relating to biological studies and reports completed by Plaintiff were being utilized by Defendants and incorporated into the reports of SOUTH VALLEY BIOLOGY CONSULTING, LLC, all without the permission of Plaintiff. Data, analysis and report narratives published by SOUTH VALLEY BIOLOGY CONSULTING, LLC, including typographical errors, were identical to the data, analysis and report narratives prepared by Plaintiff. 
19. Plaintiff has also learned that, during 2012 and 2013, the web site and promotional materials for SOUTH VALLEY BIOLOGY CONSULTING, LLC contained copies of confidential work product created by Plaintiff; and that Plaintiffs former employees named in this complaint, now owners, members or employees of SOUTH VALLEY BIOLOGY CONSULTING, LLC were claiming responsibility for, and ownership of, such confidential work product and intellectual property generated by Plaintiff.
...
21. Plaintiff alleges that Defendants NINA E. HOSTMARK, MICHAEL V. PHILLIPS and PAUL ROSEBUSH within the last two years preceding the filing of this complaint each intentionally, illegally, and without authorization, removed Plaintiffs confidential work product and intellectual property from Plaintiffs computers prior to their leaving Plaintiffs employ. 
22. Plaintiff alleges that Defendants NINA E. HOSTMARK, MICHAEL V. PHILLIPS and PAUL ROSEBUSH each intentionally, illegally, and without authorization, transmitted the confidential work product and intellectual property to SOUTH VALLEY BIOLOGY CONSULTING, LLC and to Defendants JAMES W. JONES, JR. and JASON H. KANG in person or by e-mail transmission. 
23. Plaintiff alleges that Defendants NINA E. HOSTMARK, MICHAEL V. PHILLIPS and PAUL ROSEBUSH, while they were still employed by Plaintiff, intentionally, illegally, and without authorization, communicated by e-mail with existing clients of Plaintiff for the purpose of soliciting such clients and for the purpose of diverting the work covered by Plaintiffs contracts with the existing clients to the benefit of SOUTH VALLEY BIOLOGY CONSULTING, LLC. 
24. At all times, the removal, copying and transmission of confidential work product and intellectual property, and the e-mail communications with competitors, were performed without the knowledge, authorization or consent of Plaintiff. 
25. As a direct and proximate result of the illegal and unauthorized use of Plaintiff's computers by Defendants NINA E. HOSTMARK, MICHAEL V. PHILLIPS and PAUL ROSEBUSH, Plaintiff has sustained economic damages exceeding $5,000.00 over the last one-year period in the form of lost current and future income, has required Plaintiff to expend resources to investigate the adequacy of its computer security systems, and required Plaintiff to expend resources to replace the work product and intellectual property illegally removed from Plaintiffs computers.
1. Pearson is a former Area Manager and Branch Manager for XTRA. This action arises largely out of Pearson's misappropriation of XTRA's confidential, competitively-valuable and trade secret information in connection with his recent resignation from XTRA on July 3, 2013, and his subsequent employment with XTRA's direct competitor, Premier Trailer Leasing, Inc. (“Premier”). 
2. By mid-June 2013, and while Pearson was in active discussions with Premier's President and Vice President to join Premier, Pearson (a) improperly downloaded and copied onto an unapproved HP v125w USB portable electronic device (the “HP Device”) and/or (b) improperly e-mailed to his personal e-mail address, confidential, competitively-valuable and trade secret information pertaining to XTRA's business. Pearson's misconduct continued after he received his June 28, 2013 offer letter from Premier, and further continued after he signed and dated Premier's offer letter on July 1, 2013. Pearson, however, did not tell XTRA he was resigning until July 3, 2013, and his improper copying and downloading of XTRA's confidential and competitively-valuable information onto the HP Device continued until July 3, 2013 - which was his last day of employment at XTRA. 
3. As Branch Manager for XTRA's Allentown, Pennsylvania office, Pearson had no legitimate reason to e-mail to his personal e-mail address or to download and transfer XTRA's confidential information onto the portable HP Device in connection with his departure or possible departure from XTRA and his plan to join Premier. On July 3, 2013, for example, Pearson improperly copied onto his HP Device detailed confidential and trade secret information pertaining to XTRA's business in Chicago, Louisville and Memphis, even though he was Branch Manager only for Allentown. In short, Pearson on information and belief was improperly accessing, downloading, copying onto the HP Device and/or e-mailing to his personal e-mail address significant confidential, competitively valuable and trade secret information of XTRA in order to help him and Premier.
...
121. Pearson's conduct described above violates the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. § 1030. Pearson's conduct, at a minimum, violates 18 U.S.C. § 1030(a)(2)(C). 
122. XTRA's XTRALink, databases and servers, as well as Pearson's XTRA company laptop, are “computers” and “protected computers” under 18 U.S.C. § 1030(e)(1) and (2).
123. Pearson was not authorized to access XTRA's XTRALink, databases or servers or his XTRA laptop computer in order to review, download or copy XTRA's confidential, proprietary, competitively valuable or trade secret information to help Premier and/or to help him compete after he joined Premier. Pearson also was not authorized to access XTRA's XTRALink, databases or servers or Pearson's XTRA laptop computer in order to e-mail any such information to his personal e-mail address for such purposes. 
124. Pearson acted without authorization and/or in excess of his authorization in accessing XTRA's XTRALink, databases and servers, and/or Pearson's XTRA laptop computer, in order to review, download or copy and/or e-mail to his personal e-mail address, XTRA's confidential, proprietary, competitively valuable or trade secret information to help Premier and/or to help him compete after he joined Premier. 
125. Pearson's conduct described above has caused XTRA damage and loss. XTRA's damage and loss include, but are not limited to, (a) expenses, fees and costs incurred to uncover and determine the extent of Pearson's computer-related misconduct; and (b) damages and/or losses in an amount not yet determined resulting from the impairment of the integrity of the data and/or information pertaining to Pearson's computer-related misconduct. Such damages and/or losses are already well in excess of $5,000.


Monday, March 4, 2013

CFAA read narrowly by another court; misuse by employee is not "unauthorized access"

In Advanced Aerofoil Techs., AG v. Todaro, No. 11 Civ 9505 (S.D.N.Y. Jan. 30, 2013), a federal district court held that employee misuse of access granted by an employer cannot sustain a cause of action under the Computer Fraud and Abuse Act (CFAA) for "unauthorized access." The court essentially withdrew terms of service violations from the ambit of the CFAA, as some other federal courts have done. The decision was based on a survey of recent holdings, as well as an appeal to the legislative intent of the CFAA.

(The Complaint and Memo/Order are embedded, below, for reference.)

The case is a typical theft of IP/trade secrets/etc. case, where former employees are sued for misappropriating such information after switching to a competitor (or startup). Advanced Aerofoil Techs (AAT) alleged that the defendants "developed and began to execute a scheme whereby they would form a venture to compete with Plaintiffs, [by] using Plaintiffs' technology and resources [and] ... misappropriating Plaintiffs' proprietary technology." The complaint alleges: violations of the CFAA and New York Trade Secret Act, civil conspiracy, conversion, tortious interference with contract, tortious interference with prospective economic damage, and breach of fiduciary duty. The defendants filed a motion to dismiss on multiple Rule 12 grounds, including failure to state a claim.

The actions related to the CFAA claim, as described by the court, are:
Plaintiffs argue Defendants violated the CFAA when: (1) Todaro, Chalder, and Tarby continued to access AAT's computers to obtain information for Flowcastings after they secretly resigned through Todaro's letter to his co-conspirator, Byrd, on March 8, 2011; (2) Byrd directed moles still at AAT after his departure to pilfer AAT's data; (3) Todaro wrongfully deleted emails from his account and the AAT email server; and (4) Leonhardt used an erasure program to wipe the contents of his AAT laptop.
I highlighted the above portion because it is the most important fact: the alleged actions occurred after the defendants had "secretly resigned," but more importantly they "continued to access" AAT resources after such resignation; implicit within the statement is that at some point in time, defendants had been granted access to the systems by AAT (for work use).

The court focuses on "unauthorized access" because there was no evidence that the defendants were given limited access to files; stated another way, the defendants had the highest level of access available, so it is not possible to "exceed" full access.

Addressing the unauthorized access analysis, the court stated that:
Nowhere in the Complaint ... do Plaintiffs claim AAT expressly revoked Defendants' permission to use its computers, files, and systems. Rather, Plaintiffs invite the Court to find Defendants' use of AAT's computers after their secret resignations constituted unauthorized access because, in reality, they were no longer employees, even though AAT did not know about the resignations and had not terminated their access to its systems. Plaintiffs also argue that through Konrad's misappropriation of AAT's confidential information, he accessed AAT files without authorization because AAT clearly would not have allowed him to retrieve its confidential information for the purposes for which he ultimately used it.
It is clear, at this juncture, the flaw in the case (and often the application of the CFAA in similar factual scenarios) - AAT is attempting to use the CFAA to bail out their own mistake of not cutting off access. There isn't any other way to convincingly argue otherwise. The question then becomes, was the CFAA intended to criminalize violations of company policy?

The court attempts to answer the question just posed by surveying how courts have handled similar scenarios (quoting Major, Lindsey & Africa, LLC v. Mahn, No. 10 Civ. 4239 (CM), 2010 U.S. Dist. LEXIS 94033, 2010 WL 3959609, at *5 (S.D.N.Y. Sept. 7, 2010)):
The First and Seventh Circuits . . . have concluded that the CFAA applies . . . because an employee's "authorization" to access her employer's protected computer and the information contained therein is effectively terminated once the employee acquires interests adverse to her employer or is "otherwise guilty of a serious breach of loyalty to the principal." Int'l Airport Ctrs. v. Citrin, 440 F.3d 418, 421 (7th Cir.2006) . . . Put simply, these courts take the position that a faithless employee — someone who accesses a computer for the purpose of stealing information with the intention of using it for her own purposes rather than the employer's — accessed the computer without authorization or exceeded authorized access.
The flip-side, according to the court: "There are several cases from our district and the Eastern District of New York, however, rejecting this broad interpretation of the CFAA. See United States v. Aleynikov, 737 F. Supp. 2d 173, 192 (S.D.N.Y. 2010) (finding there was no violation of the CFAA when the Defendant, who had authorization to access the system, misappropriated the information)."

The court finds Aleynikov persuasive, and focusing on the language from United States v. Morris, quoted in Aleynikov, that "the ordinary meaning of "authorization" to find "a person who 'accesses a computer without authorization' does so without any permission . . . ." Aleynikov, 737 F. Supp. 2d at 191."

In summary, the court stated:
This Court declines the opportunity to expand the CFAA to include situations where an employee takes confidential information, using authorization given to him and controlled by his employer, for the reasons set forth in Aleynikov and the cases following a narrow interpretation of the statute. See id. ("Put simply, this other line of cases [interpreting the CFAA broadly] identifies no statutory language that supports interpreting the CFAA to reach mere misuse or misappropriation of information, let alone language strong enough to justify that interpretation where the rule of lenity counsels a narrow reading."). In this case, because there is no allegation that AAT revoked Defendants' unlimited access to its system, Plaintiffs cannot state a cognizable claim under the CFAA.
(emphasis added). The court also dismissed the argument that the deletion of emails from an account and the use of an erasure program were violations of the CFAA, relying on the same logic from above. Namely, "there are no allegations that Todaro and Leonhardt deleted data or emails from their computers after AAT terminated their authorization to use its systems and equipment." Thus, even if the actions taken by the employee were to erase files, emails, etc., it still does not rise to "unauthorized access" because the employee was given such access to begin with (and it was not revoked).

I reiterate my point above that AAT is attempting to use the CFAA to bail out their failure to secure their own systems. I think the court gets it right. The CFAA was created to address hacking, and more specifically, breaking into systems that you had no access (or right to access), or breaking out of some sort of limited access for nefarious purposes. Neither of the situations just mentioned occurred here.