Shamrock Foods Co. v. Gast

535 F. Supp. 2d 962, 2008 U.S. Dist. LEXIS 15329, 2008 WL 450556
District Court, D. Arizona·Decided February 20, 2008·No. CV-08-0219-PHX-ROS·Published·Cited by 36 cases

Opinion

ORDER

ROSLYN O. SILVER, District Judge.

Pending is Defendants’ Motion to Dismiss. (Doc. 17.) This motion requires the Court to interpret the meaning of the terms “without authorization” and “ex *963 ceeds authorized access” in the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. § 1030. The Court concludes that a violation for accessing a protected computer “without authorization” occurs only when initial access is not permitted. And, an “exceeds authorized access” violation occurs only when initial access to a protected computer is permitted but the access of certain information is not permitted. Thus, Defendants’ Motion to Dismiss will be granted.

BACKGROUND

Plaintiff Shamrock Foods Company (“Shamrock”) alleges that Defendant Jeff Gast began working for Shamrock in September 2000. (Compl. ¶ 19.) As an employee of Shamrock, Gast signed a Confidentiality Agreement, agreeing not to use or disclose “any trade secrets, confidential information, knowledge or data relating or belonging to” Shamrock. (Id.) On December 20, 2007, Gast was promoted to Regional Sales Manager of Southern Arizona. (Id. ¶ 28.) Around this time, Gast began employment negotiations with Defendant Sysco Food Services of Arizona, Inc. (“Sysco”), a competitor of Shamrock. (Id. ¶ 31.) On January 4 and 7, 2008, Gast emailed numerous documents containing Shamrock’s confidential and proprietary information to his personal email account. (Id. ¶¶ 32, 36.) The next day, Gast informed his manager that he was considering leaving Shamrock. (Id. ¶ 40.) On January 14, 2008, Gast told his manager that he was going to work for Sysco, and, on January 15, 2008, submitted a written resignation. (Id. ¶¶ 42-45.) Gast began employment with Sysco on January 18, 2008. (Id. ¶ 55.)

After Gast left Shamrock on January 15, 2008, Shamrock performed a forensic analysis of Gast’s computer at a cost exceeding $5,000.00 and discovered the emails that Gast sent to himself. (Id. ¶ 49.) Shamrock alleges that Gast was acting as an agent of Sysco when he assessed and emailed the confidential information. (Id. ¶¶ 50-52.) Further, Shamrock alleges that Gast provided this confidential information to Sysco and that Sysco is using this information to Shamrock’s detriment. (Id. ¶¶ 52-53.)

On February 3, 2008, Shamrock filed a complaint and motion for temporary restraining order. The complaint asserts that this Court has federal-question jurisdiction under the CFAA. Specifically, Shamrock brings CFAA claims under § 1030(a)(2), (4), and (5)(A)(iii). In addition to the CFAA claims, Shamrock brings a host of state common law and statutory claims. Defendants moved to dismiss the CFAA claims for failure to state a claim and the remaining state law claims for lack of subject matter jurisdiction.

STANDARD

“A Rule 12(b)(6) motion tests the legal sufficiency of a claim.” Navarro v. Block, 250 F.3d 729, 732 (9th Cir.2001). When reviewing a motion to dismiss, the Court “must determine whether, assuming all facts and inferences in favor of the non-moving party, it appears beyond doubt that [Plaintiffs] can prove no set of facts to support [their] claims.” Marder v. Lopez, 450 F.3d 445, 448 (9th Cir.2006) (internal quotations omitted).

DISCUSSION

I. Computer Fraud and Abuse Act

The CFAA makes it a federal criminal offense to engage in any one of seven prohibited activities. 18 U.S.C. § 1030(a). While the CFAA is primarily a criminal statute, it also provides a civil cause of action under § 1030(g):

Any person who suffers damage or loss by reason of a violation of this section may maintain a civil action against the *964 violator to obtain compensatory damages and injunctive relief or other equitable relief. A civil action for a violation of this section may be brought only if the conduct involves 1 of the factors set forth in clause (i), (ii), (iii), (iv), or (v) of subsection (a)(5)(B).

The Ninth Circuit has clarified that subsection (g) enables a party to bring a private cause of action for any violation under the CFAA. Theofel v. Farey-Jones, 359 F.3d 1066, 1078 n. 5 (9th Cir.2004). While a civil cause of action “must involve one of the five factors in (a)(5)(B), it need not be one of the three offenses in (a)(5)(A).” Id. Here, the conduct alleged by Shamrock involves one of the five factors in (a)(5)(B) because it involves a loss aggregating at least $5,000 in value. See 18 U.S.C. § 1030(a)(5)(B)® and (e)(ll) (defining “loss” to include the cost of conducting a damage assessment). Thus, Shamrock may bring a civil cause of action under § 1030(a)(2), (4), and (5)(A)(iii).

It is a violation of § 1030(a)(2) when a person “intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer if the conduct involved an interstate or foreign communication.” Section 1030(a)(4) is violated when a person “knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value.... ” Section (a)(5)(A)(iii) is violated when a person “intentionally accesses a protected computer without authorization, and as a result of such conduct, causes damage.... ” Thus, to state a claim under (a)(2) and (a)(4), Shamrock must allege conduct showing that Gast accessed a protected computer without authorization or exceeded authorized access. Unlike (a)(2) and (a)(4), which also prohibit a person from exceeding authorized access, (a)(5)(A)(iii) only prohibits access without authorization. Thus, to state a claim under (a)(5)(A)(iii), Shamrock must allege conduct showing that Gast accessed a protected computer without authorization.

Defendants do not deny that Gast accessed a protected computer. Instead, they argue that Gast was authorized to access the computer and information at issue. Shamrock concedes that “Gast may very well be correct that he was entitled to access Shamrock’s confidential and proprietary information while he was an employee.” (Doc. 28 at 9.) Nevertheless, Shamrock argues that Gast was no longer authorized to access its confidential information once he acquired the improper purpose to use this information to benefit himself and Sysco.

Free access — add to your briefcase to read the full text and ask questions with AI

Shamrock Foods Co. v. Gast, 535 F. Supp. 2d 962, 2008 U.S. Dist. LEXIS 15329, 2008 WL 450556 (D. Ariz. 2008).

535 F. Supp. 2d 962 (Shamrock Foods Co. v. Gast) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

THOMAS v. KEOUGH
D. New Jersey, 2024
NW Monitoring LLC v. Hollander
W.D. Washington, 2021
Gupta v. Franklin
S.D. Alabama, 2017
Copart, Inc. v. Sparta Consulting, Inc.
277 F. Supp. 3d 1127 (E.D. California, 2017)
Infinity Headwear & Apparel, LLC v. Coughlin
2014 Ark. App. 609 (Court of Appeals of Arkansas, 2014)
United States v. Rossini
District of Columbia, 2014
Cranel Inc. v. Pro Image Consultants Group, LLC
57 F. Supp. 3d 838 (S.D. Ohio, 2014)
United States v. Valle
301 F.R.D. 53 (S.D. New York, 2014)
Dresser-Rand Co. v. Jones
957 F. Supp. 2d 610 (E.D. Pennsylvania, 2013)
Ajuba International, L.L.C. v. Saharia
871 F. Supp. 2d 671 (E.D. Michigan, 2012)
United States v. Nosal
676 F.3d 854 (Ninth Circuit, 2012)
Trademotion, LLC v. Marketcliq, Inc.
857 F. Supp. 2d 1285 (M.D. Florida, 2012)
Nucor Steel v. Mauer
2010 DNH 207 (D. New Hampshire, 2010)