676 F.3d 854 (9th Cir. 2012)
David Nosal used to work for Korn/Ferry, an executive search firm.1 Shortly after he left the company, he convinced some of his former colleagues who were still working for Korn/Ferry to help him start a competing business.2 The employees used their log-in credentials to download source lists, names and contact information from a confidential database on the company’s computer, and then transferred that information to Nosal.3
The employees were authorized to access the database, but Korn/Ferry had a policy that forbade disclosing confidential information.4 The opening screen of the database also included the warning that the product is intended to be used by Korn/Ferry employees for work on Korn/Ferry business only.5
The government indicted Nosal on twenty counts, including trade secret theft, mail fraud, conspiracy and violations of the CFAA.6 The CFAA counts charged Nosal with violations of 18 U.S.C. § 1030(a)(4), for aiding and abetting the Korn/Ferry employees in exceeding their authorized access with intent to defraud.7
Nosal filed a motion to dismiss the CFAA counts.8 The district court initially rejected Nosal’s argument.9 Shortly afterwards, however, the Ninth Circuit decided LVRC Holdings LLC v. Brekka.10 Nosal filed a motion for reconsideration and a second motion to dismiss.11 The district court reversed field and dismissed counts 2 and 4-7 for failure to state an offense.12 The government appeals.13
Whether the phrase exceeds authorized access in the CFAA applies to violations of computer use restrictions rather than only to accessing unauthorized information?14
The CFAA defines exceeds authorized access as accessing a computer with authorization and using that access to obtain or alter information the accesser is not entitled to obtain or alter.15 This refers to accessing unauthorized data or files, not to misusing information obtained through authorized access in violation of use restrictions or employer policies.16
No. The Korn/Ferry employees were authorized to access the confidential database using their log-in credentials. They did not access any information beyond what their authorization permitted, even though their subsequent transfer of the data to Nosal violated the company's policy against disclosing confidential information. The CFAA requires that the accesser obtain or alter information that he is not entitled so to obtain or alter.17 Here, the employees had full permission to view and retrieve the source lists and contact information as part of their employment duties.18
The CFAA prohibition on exceeding authorized access does not apply to the employees' conduct in this case.19
Related opinions on this issue
Joined by Circuit Judge Tallman
Circuit Judge Silverman dissented.20 He argued that the indictment properly charged a violation. The employees exceeded authorized access by using the database access to steal proprietary information for a competing business in violation of their employment agreements and with intent to defraud.21 Silverman contended that the statute plainly covers exceeding authorized access when done knowingly and with intent to defraud.22
He noted that the majority's concerns about innocuous policy violations do not apply to this subsection which requires specific intent to defraud.23 Silverman emphasized that other circuits have adopted the broader interpretation and that the facts alleged here clearly state a crime under a commonsense reading of the provision.24