74 F.4th 31
2d Cir.2023Background:
- In 2019 Medghyne Calonge was the Florida-based HR manager for 1-800-Accountant with "super administrator" access to the JazzHR applicant-tracking database; her supervisor Amy Gaspari worked at company headquarters in Manhattan.
- After Calonge was fired June 28, 2019, most credentials were revoked but JazzHR access was mistakenly left active.
- Between Friday evening and Sunday morning an account associated with Calonge deleted nearly all JazzHR data (employee accounts, ~17,000 applications, resumes, postings); JazzHR logs tied the deletions to her account.
- Gaspari, when logging in from her Manhattan desktop, could not access the deleted data; JazzHR’s servers were hosted on Amazon in Virginia and California; the company spent $140,000+ and weeks attempting to reconstruct the database.
- Calonge was charged under CFAA §§1030(a)(5)(A)–(B) for transmission/access and causing damage to a protected computer; she moved for acquittal arguing venue in the Southern District of New York was improper because the data resided on out-of-district servers.
- The district court instructed the jury that venue is proper where damage to a protected computer occurred; the jury convicted Calonge and this appeal followed.
Issues:
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Whether venue was proper in the Southern District of New York for CFAA §1030(a)(5) convictions | Venue is proper where a protected computer was damaged; Gaspari’s inability to access data from her NY computer shows damage in SDNY | Venue is improper because the deleted data physically resided on JazzHR servers in Virginia and California, so no protected computer in SDNY was damaged | Court held government met preponderance: Gaspari’s testimony that her NY computer lost access established damage in SDNY, so venue was proper |
| Whether United States v. Auernheimer compels reversal | Auernheimer is distinguishable because it involved a different CFAA subsection and different essential conduct elements | Auernheimer supports reversal because servers and access occurred outside the forum | Court distinguished Auernheimer and affirmed that under §§1030(a)(5)(A)–(B) venue may lie where damage to a protected computer occurs |
Key Cases Cited
- United States v. Rodriguez-Moreno, 526 U.S. 275 (1999) (identify conduct and location; separate essential conduct vs. circumstance elements for venue)
- United States v. Auernheimer, 748 F.3d 525 (3d Cir. 2014) (analyzed CFAA venue under a different subsection; distinguished by this court)
- United States v. Tang Yuk, 885 F.3d 57 (2d Cir. 2018) (venue may lie in more than one district when conduct implicates multiple locations)
- United States v. Davis, 689 F.3d 179 (2d Cir. 2012) (venue need only be proven by a preponderance of the evidence)
- United States v. Valle, 807 F.3d 508 (2d Cir. 2015) (definition of "protected computer" covers internet-connected computers)
- United States v. Rowe, 414 F.3d 271 (2d Cir. 2005) (purpose of venue protections against bias and inconvenience)
- United States v. Lange, 834 F.3d 58 (2d Cir. 2016) (venue analysis for offenses committed in multiple places)
