Showing posts with label unauthorized access. Show all posts
Showing posts with label unauthorized access. Show all posts

Wednesday, October 16, 2013

CFAA claim dismissed in Givaudan Fragrances Corp. v. Krivda

On September 26, 2013, the court in Givaudan Fragrances Corp. v. Krivda issued an order dismissing Givaudan's claim that one of its former employees, James Krivda, violated the Computer Fraud and Abuse Act (18 U.S.C. § 1030). This dismissal, granted by Judge Peter Sheridan of the District Court of New Jersey, provides yet another example of a court distinguishing between “unauthorized use of information” and the “unauthorized access to information” when interpreting the CFAA.

According to the court order (and this 2009 opinion, which provides a much more detailed factual summary), Krivda was a perfumer at Givaudan Fragrances, “a manufacturer of fragrances for consumer products and the fine fragrance industry.” In April of 2008, Krivda resigned from Givaudan to take a position with a Givaudan competitor, MANE International. Givaudan alleged that, prior to his departure, Krivda printed over 500 confidential fragrance formulas from Givaudan’s management database. Displeased with Krivda’s explanation as to why he printed the formulas just days prior to his departure from the company, Givaudan filed a complaint against Krivda.

Specifically, Givaudan’s complaint alleged, amoung other claims, that Krivda violated § 1030(a)(4) of the CFAA, which holds liable a person who
knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer and the value of such use is not more than $5,000 in any 1-year period
Krivda moved for partial summary judgment to dismiss the CFAA claim. Krivda argued that, as a perfumer for Givaudan, he was provided access to the formula management database and therefore did not "access a protected computer without authorization" or "exceed authorized access." Givaudan argued that, while Krivda had access to the database, he was not authorized to "review and print" formulas maintained on their database.

In granted Krivda’s motion, the court stated that “the Computer Fraud and Abuse Act § 1030(a)(4), prohibits the unauthorized access to information rather than unauthorized use of such information."  “The inquiry” the court stated, “depends not on the employee's motivation for accessing the information, but rather whether the access to that information was authorized.” The court concluded that Krivda’s authorization to access the database ended its CFAA inquiry.
Here, Krivda was authorized to access that information, namely, Givaudan's computerized formula management database system, a fact Givaudan does not dispute. . . . [T]he term "exceeds authorized access," refers to one who had access to part of a system and then accessed other parts of the computer system to which he had no permissible access. Here Krivda had permissible access to the formula management database system. Givaudan's proposition that Krivda could not "review and print" does not fall within the definition of exceeds authorized access. In applying the summary judgment standard and utilizing Givaudan's version of the facts, it is clear that Krivda had access to the computerized formula management system, and Krivda entered areas to which he had access. Summary judgment is granted . . . .
The “use” vs “access” distinction has been a common discussion among courts faced with interpreting the CFAA, particularly in the employee context. A few months back, I wrote a post discussing a Southern District of New York case, JBCHoldings v. Pakter, in which the court determined that the plain meaning of “without authorization” and “exceeds authorized access” “plainly speaks to permitted access, not permitted use.” However, I also discussed how some circuits have adopted a broader interpretation of the CFAA, in which the misuse of information by an employee would satisfy the statute's terminology. In the criminal context, I touched on this issue a bit when discussing Untied States v. Vargas, where a NYPD officer was charged under the CFAA for, among other claims, conducting improper searches on the precincts’ NCIC system to gain information on fellow NYPD officers.

For a more detailed look on the issue, I would suggest this recent Comment by JD candidate Alden Anderson, The Computer Fraud and Abuse Act: Hacking Into The Authorization Debate, published in this summer's issue of Jurimetrics: The Journal of Law, Science, and Technology.

Friday, April 19, 2013

District court holds that lost profits--due to fraudulent bids, not service interruption or degradation--constitute “loss” under the CFAA

The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, continues to receive some uneven treatment by the courts. In Yoder & Frey Auctioneers, Inc. v. Equipmentfacts, LLC, No. 3:10 CV 1590, slip op. (N.D. Ohio Apr. 8, 2013), the United States District Court for the Northern District of Ohio ruled that a private claim under the CFAA could proceed even though the harm it alleged did not seem to flow directly from unauthorized access.

Background

The plaintiffs, Yoder & Frey, an equipment auctioneer, and RealTimeBid.Com (RTB), an online auction service provider, are business partners. They alleged that Equipmentfacts, defendant and one-time auction service provider to Yoder & Frey, accessed the company’s new RTB-provided auction portal, first with an old administrative account and then with the “stolen” account of a long-time Yoder & Frey customer. According to the complaint, Equipmentfacts used both of these accounts to post defamatory, negative statements on the auction portal’s built-in message board, and then used the latter to post “false bids” for items up for auction--eventually winning eighteen items for a total of $1,171,074, which it has not paid.

Equipmentfacts disputed the underlying facts, but also moved for summary judgment on the CFAA claim, arguing that the CFAA does not encompass the type of damage alleged, because the harm was not due to the unauthorized access, and on the alleged facts did not even occur until the winning bidder refused to pay. Its argument focused on the disconnect between the alleged unauthorized access and the accrual of harm, arguing that “damages not flowing from an interruption of service are not recoverable under the CFAA.” The court, however, was unimpressed, and focused on the type of harm alleged rather than its nexus to the alleged unauthorized activity. It found that “interruption of service” could be found even when the website and bidding software performed as designed.

Finding "loss" under the CFAA

Civil plaintiffs under the CFAA must plead “loss” of at least $5,000 (or one of a few other narrow requirements, inapplicable here). 18 U.S.C. § 1030(g); 18 U.S.C. § 1030(c)(4)(A)(i)(I). “Loss” is statutorily defined as “any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service.” 18 U.S.C. § 1030(e)(11). The court analyzed the language and the legislative history of this provision to conclude that the CFAA claim could withstand summary judgment:
“Whether the alleged action left the system inoperable is too narrow a reading of the statute. An auction's high bidder, by definition, denies the other bidders the right to purchase that item at their bid price. . . . Fake bids deny the entire sale to both the auctioneer and the other bidders; particularly so when the auctioneer cannot discover the falsity of the high bid until the sale is long over. Depriving a business of potential sales is a loss contemplated by the CFAA. E.g., United States v. Schuster, 467 F.3d 614, 617 (7th Cir. 2006) (Affirming a restitution finding that the defendant was liable for the victim's loss of business productivity because he caused a computer attack that rendered the victim's system less available to customers)” (emphasis added).
While few would quarrel with the argument that some lost sales revenue is contemplated by the CFAA (e.g., sales lost during an outage caused by unauthorized access), the court’s analysis broadly implies that any sales revenue lost by an online portal is sufficient to show “loss” under the CFAA. Moreover, it seems to stray from its own citation. In Schuster (a criminal CFAA case that included restitution), the defendant conceded that his actions had impaired the availability of a system to other customers’ and the owner’s detriment, but here Equipmentfacts’ alleged unauthorized access to the bidding portal did not directly cause any harm. As its brief in support of its motion for summary judgment points out, the system remained functional throughout the alleged episode: RTB, in fact, conceded in deposition that there was no interruption in the availability or the integrity of the auction portal’s technical services whatsoever:
Q: So bidders could still place bids at the auction on your technology platform?
A: Yes.
Q: Even though there was someone allegedly placing false bids?
A: Correct.
. . .
Q: And the only thing that went wrong was that someone submitted a bid for which they had no intention of paying, right?
A: Yeah.
Now, this line of questioning by the defense attorney is slightly misleading, because the plaintiffs did not “only” allege that a bid was submitted by someone who never intended to pay; they also alleged that the false bid was submitted using the “stolen identity” of a long-time Yoder & Frey customer, and that Yoder & Frey approved each bidder before allowing them to participate in the auction. These facts might tie the alleged unauthorized access sufficiently closely to the “loss” required by the CFAA, but the court’s analysis does not follow this line of reasoning. Instead, it glosses over the distinction between placing a false bid in an online auction and using a stolen identity to participate in an online auction. The argument that a CFAA claim may be made on allegations of bidding online without intending to pay seems much more tenuous than the argument that a CFAA claim may be made on allegations of using a false identity to participate in an online auction, whether that bidder intended to pay for the items or not. The former claim, based on “false bids,” seems to be nothing more than a fraudulent, electronically concluded contract, which almost certainly falls outside the CFAA. Making such a claim based on falsely assuming the identity of a trusted customer seems much more like the type of conduct to which the CFAA was intended to apply. In a very confusing opinion, however, the court fails to distinguish these two very different issues.

Instead, its analysis seems to rely on its previous finding that the “[d]efendant’s alleged intentional disruption of even a portion of the online auction through surreptitiously submitted false bids interrupted the service of that site.” This portion of analysis considers false bids and bids submitted by means of a false identity (“surreptitiously submitted”) together, but the rest of that opinion seems to indicate that the court’s thinking hewed closer to the more tenuous false-bids analysis: “While the online auction was not totally thwarted, a number of individual online transactions were. As such, the auction website did not provide service to either Plaintiffs or the buyers and sellers in the auction while Defendants allegedly submitted false winning bids.” This line of inquiry requires the court to find that the bidding portal “did not provide service” even though it functioned exactly as designed, without any degradation or impairment of any of its functions.

This broad reading of the CFAA seems to extend “interruption of service” to include any thwarted commercial service--potentially, any electronically but fraudulently concluded contract. While it is possible that the authors of the CFAA contemplated such broad meaning, and, as the court points out, left “interruption of service” undefined, it is unclear why Congress would have intended to allow plaintiffs alleging fraudulent creation of contract to access CFAA remedies if the relevant contract was concluded electronically. And although construction of the CFAA has sometimes been controversial, this decision stands out for eschewing a narrow reading of CFAA liability (more here and here). If the court (and the plaintiff) had focused on illustrating the nexus between the alleged use of a stolen identity, which was trusted by the plaintiffs (and therefore approved as a bidder), and the lost commissions, it could have avoided muddying the waters with its analysis of “interruption of service.” As written, however, the opinion is unclear as to why this auctioneer’s harm had a sufficient nexus to any unauthorized access to warrant CFAA liability.

In addition to the CFAA claim, the complaint included claims based on common law fraud, common law trespass to chattels, and breach of contract. All of them survived the motion to dismiss. It will be interesting to see whether the parties settle, and if not, whether Yoder & Frey and its new service provider RTB can make the CFAA claim stick at trial.

--Brad Edmondson

Monday, March 4, 2013

CFAA read narrowly by another court; misuse by employee is not "unauthorized access"

In Advanced Aerofoil Techs., AG v. Todaro, No. 11 Civ 9505 (S.D.N.Y. Jan. 30, 2013), a federal district court held that employee misuse of access granted by an employer cannot sustain a cause of action under the Computer Fraud and Abuse Act (CFAA) for "unauthorized access." The court essentially withdrew terms of service violations from the ambit of the CFAA, as some other federal courts have done. The decision was based on a survey of recent holdings, as well as an appeal to the legislative intent of the CFAA.

(The Complaint and Memo/Order are embedded, below, for reference.)

The case is a typical theft of IP/trade secrets/etc. case, where former employees are sued for misappropriating such information after switching to a competitor (or startup). Advanced Aerofoil Techs (AAT) alleged that the defendants "developed and began to execute a scheme whereby they would form a venture to compete with Plaintiffs, [by] using Plaintiffs' technology and resources [and] ... misappropriating Plaintiffs' proprietary technology." The complaint alleges: violations of the CFAA and New York Trade Secret Act, civil conspiracy, conversion, tortious interference with contract, tortious interference with prospective economic damage, and breach of fiduciary duty. The defendants filed a motion to dismiss on multiple Rule 12 grounds, including failure to state a claim.

The actions related to the CFAA claim, as described by the court, are:
Plaintiffs argue Defendants violated the CFAA when: (1) Todaro, Chalder, and Tarby continued to access AAT's computers to obtain information for Flowcastings after they secretly resigned through Todaro's letter to his co-conspirator, Byrd, on March 8, 2011; (2) Byrd directed moles still at AAT after his departure to pilfer AAT's data; (3) Todaro wrongfully deleted emails from his account and the AAT email server; and (4) Leonhardt used an erasure program to wipe the contents of his AAT laptop.
I highlighted the above portion because it is the most important fact: the alleged actions occurred after the defendants had "secretly resigned," but more importantly they "continued to access" AAT resources after such resignation; implicit within the statement is that at some point in time, defendants had been granted access to the systems by AAT (for work use).

The court focuses on "unauthorized access" because there was no evidence that the defendants were given limited access to files; stated another way, the defendants had the highest level of access available, so it is not possible to "exceed" full access.

Addressing the unauthorized access analysis, the court stated that:
Nowhere in the Complaint ... do Plaintiffs claim AAT expressly revoked Defendants' permission to use its computers, files, and systems. Rather, Plaintiffs invite the Court to find Defendants' use of AAT's computers after their secret resignations constituted unauthorized access because, in reality, they were no longer employees, even though AAT did not know about the resignations and had not terminated their access to its systems. Plaintiffs also argue that through Konrad's misappropriation of AAT's confidential information, he accessed AAT files without authorization because AAT clearly would not have allowed him to retrieve its confidential information for the purposes for which he ultimately used it.
It is clear, at this juncture, the flaw in the case (and often the application of the CFAA in similar factual scenarios) - AAT is attempting to use the CFAA to bail out their own mistake of not cutting off access. There isn't any other way to convincingly argue otherwise. The question then becomes, was the CFAA intended to criminalize violations of company policy?

The court attempts to answer the question just posed by surveying how courts have handled similar scenarios (quoting Major, Lindsey & Africa, LLC v. Mahn, No. 10 Civ. 4239 (CM), 2010 U.S. Dist. LEXIS 94033, 2010 WL 3959609, at *5 (S.D.N.Y. Sept. 7, 2010)):
The First and Seventh Circuits . . . have concluded that the CFAA applies . . . because an employee's "authorization" to access her employer's protected computer and the information contained therein is effectively terminated once the employee acquires interests adverse to her employer or is "otherwise guilty of a serious breach of loyalty to the principal." Int'l Airport Ctrs. v. Citrin, 440 F.3d 418, 421 (7th Cir.2006) . . . Put simply, these courts take the position that a faithless employee — someone who accesses a computer for the purpose of stealing information with the intention of using it for her own purposes rather than the employer's — accessed the computer without authorization or exceeded authorized access.
The flip-side, according to the court: "There are several cases from our district and the Eastern District of New York, however, rejecting this broad interpretation of the CFAA. See United States v. Aleynikov, 737 F. Supp. 2d 173, 192 (S.D.N.Y. 2010) (finding there was no violation of the CFAA when the Defendant, who had authorization to access the system, misappropriated the information)."

The court finds Aleynikov persuasive, and focusing on the language from United States v. Morris, quoted in Aleynikov, that "the ordinary meaning of "authorization" to find "a person who 'accesses a computer without authorization' does so without any permission . . . ." Aleynikov, 737 F. Supp. 2d at 191."

In summary, the court stated:
This Court declines the opportunity to expand the CFAA to include situations where an employee takes confidential information, using authorization given to him and controlled by his employer, for the reasons set forth in Aleynikov and the cases following a narrow interpretation of the statute. See id. ("Put simply, this other line of cases [interpreting the CFAA broadly] identifies no statutory language that supports interpreting the CFAA to reach mere misuse or misappropriation of information, let alone language strong enough to justify that interpretation where the rule of lenity counsels a narrow reading."). In this case, because there is no allegation that AAT revoked Defendants' unlimited access to its system, Plaintiffs cannot state a cognizable claim under the CFAA.
(emphasis added). The court also dismissed the argument that the deletion of emails from an account and the use of an erasure program were violations of the CFAA, relying on the same logic from above. Namely, "there are no allegations that Todaro and Leonhardt deleted data or emails from their computers after AAT terminated their authorization to use its systems and equipment." Thus, even if the actions taken by the employee were to erase files, emails, etc., it still does not rise to "unauthorized access" because the employee was given such access to begin with (and it was not revoked).

I reiterate my point above that AAT is attempting to use the CFAA to bail out their failure to secure their own systems. I think the court gets it right. The CFAA was created to address hacking, and more specifically, breaking into systems that you had no access (or right to access), or breaking out of some sort of limited access for nefarious purposes. Neither of the situations just mentioned occurred here.