Black & Decker (US), Inc. v. SmithBlack & Decker (US), Inc. v. Smith
ORDER GRANTING IN PART AND DENYING IN PART THE DEFENDANT’S MOTION TO DISMISS
On November 15, 2007, the Plaintiff, Black & Decker, Inc., (“B & D”) filed the instant action against the Defendant, Timothy Smith, alleging that Smith shared certain confidential data with one of the Plaintiffs competitors in violation of the Computer Fraud and Abuse Act, 18 U.S.C. §§ 1030 et seq., the Tennessee Uniform Trade Secrets Act, Tenn.Code Ann. § 47-25-1701, and the Tennessee Personal and Commercial Computer Act of 2003, Tenn. Code Ann. § 39-14-602. B & D also includes claims of breach of contract, breach of duty of loyalty and/or fiduciary duty, misappropriation of confidential and proprietary information, and unfair competition and unfair trade practices against Smith. Before the Court is the Defendant’s motion to dismiss two of these claims pursuant to Rule 12(b)(6) of the Federal Rules of Civil Procedure. The Plaintiff has responded and this motion is now ripe for disposition.
BACKGROUND
The Complaint alleges that the Defendant was hired by B & D in June 2004. (Docket Entry (“D.E.”) No. 1, Compl. ¶ 6.) He began working for Michael Wilson, the Director of Engineering for the Pressure Washer Design Group at B & D, as a project engineer in June 2006.(M) In July or August of 2007, B & D was informed by one of its customers that its contract to supply pressure washers would not be renewed for the year 2008. (Id. ¶ 7.) Instead, the contract was awarded to a competitor of B & D’s, Techtronic Industries Co. (“TTI”). (Id.) According to the Plaintiff, TTI had not previously been engaged in large scale manufacturing of pressure washers in the United States. (Id.)
Shortly after B & D lost the contract, a recruiter began calling Wilson and many of the engineers who worked for him to ask them to interview at TTI.
(Id.
¶ 8.) The Defendant was one of those contacted by the recruiter.
(Id.)
On October 8, 2007, Smith took a day off from work and interviewed with TTI in South Carolina.
(Id.)
He accepted a position with that company approximately four days later.
(Id.)
Wilson confronted the Defendant on October 15, 2007, about whether he intended to go work for TTI and Smith admitted that he
B & D contends that Smith was asked to return all of its property and sign a termination agreement, in conformance with its regular practice. (Id.) In the termination agreement, the Defendant confirmed that he did not possess any confidential information or property of the Plaintiffs and that he would not disclose any trade secrets, confidential information, or proprietary data to any third party. (Id.) Smith had previously also signed a confidentiality agreement while he was working at a “related corporate entity to B & D,” which encompassed both that company and its “ ‘parents, subsidiaries, successors and assignees,’ i.e. B & D.” (Id. ¶ 11 (quoting the confidentiality agreement).) This agreement required him to hold his work product in confidence and return any physical copies of such work to the company upon his termination. (See id.)
After Smith left his employment with B & D, Wilson became concerned that the Defendant might have taken confidential documents. (Id. ¶ 14.) With the assistance of an Information Technology Site Support Manager and a computer consultant, Wilson launched an investigation which revealed that on September 27, 2007, shortly after being contacted by the recruiter about TTI, the Defendant copied a large volume of confidential documents from B & D’s secure servers into a file Smith had created under his own name on the company’s H drive. (Id. ¶¶ 14-15.) The Plaintiff alleges that the documents Smith copied included confidential and proprietary information about B & D pressure washers and other B & D products in various stages of pre-market development. (Id. ¶ 15.) The investigation also revealed that the Defendant had again accessed certain confidential information on October 14, 2007, including material relating to pump strategies on B & D pressure washers, crankshaft issues, and the Plaintiff’s Chinese engine supplier. (Id. ¶ 16.) He also accessed drawings and specifications relating to two confidential projects he was working on, as well as a suite of photographs of B & D prototypes, panel charts showing milestones and market research, test results on products, photographs of products in developments, copies of prototypes for new businesses, and pictures and files on new products. (Id.)
That same day, Smith attached a large external storage device to his B & D office desktop computer and saved many of these documents onto that device. (Id. ¶¶ 17, 20.) He also sent documents from his work email address to his personal Yahoo account, including an email he had received from a B & D co-worker that related to a B & D product. (Id. ¶ 18.) The Complaint contends that these actions violated the Computer Fraud and Abuse Act, 18 U.S.C. §§ 1030 et seq. and the Tennessee Personal and Commercial Computer Act of 2003, Tenn.Code Ann. § 39-14-602. (Id. ¶¶ 26-32, 40-43.) In his motion to dismiss, the Defendant argues that these counts should be dismissed because the allegations in the Complaint cannot support a finding that he violated these statutes.
STANDARD OF REVIEW
Rule 12(b)(6) permits dismissal of a lawsuit for failure to state a claim upon which relief could be granted.
See
Fed.R.Civ.P. 12(b)(6). The Rule requires the Court to “construe the complaint in the light most favorable to the plaintiff, accept all of the complaint’s factual allegations as true, and determine whether the plaintiff undoubtedly can prove no set of facts in support of the claims that would entitle relief.”
Grindstaff v. Green,
ANALYSIS
I. The Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA) prohibits certain conduct involving unauthorized access to computers. See 18 U.S.C. § 1030(a)(l)-(a)(7). While primarily a criminal statute, it permits “[a]ny person who suffers damage or loss by reason of a violation of this section [to] maintain a civil action against the violator to obtain compensatory damages and in-junctive relief or other equitable relief.” Id. § 1030(g). The Complaint charges that the Defendant violated subsection (a)(2)(C) of 18 U.S.C. § 1030, which prohibits “intentionally accessing] a computer without authorization or exceeding] authorized access, and thereby obtaining] ... information from any protected computer if the conduct involved an interstate or foreign communication.” Smith is also alleged to have violated § 1030(a)(4), which forbids “knowingly and with intent to defraud, accessing] a protected computer without authorization, or exceeding] authorized access, and by means of such conduct further[ing] the intended fraud and obtaining] anything of value.... ” Last, he is charged with a violation of § 1030(a)(5)(A), which provides that whoever
(i) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;
(ii) intentionally accesses a protected computer without authorization, and as a result of such conduct, recklessly causes damage; or
(iii) intentionally accesses a protected computer without authorization, and as a result of such conduct, causes damage;
and, pursuant to § 1030(a)(5)(B), by such conduct caused or, in the case of an attempted offense, would have caused
(i) loss to 1 or more persons during any 1-year period (and, for purposes of an investigation, prosecution, or other proceeding brought by the United States only, loss resulting from a related course of conduct affecting 1 or more other protected computers) aggregating at least $ 5,000 in value;
(ii) the modification or impairment, or potential modification or impairment, of the medical examination, diagnosis, treatment, or care of 1 or more individuals;
(iii) physical injury to any person;
(iv) a threat to public health or safety; or
(v) damage affecting a computer system used by or for a government entity in furtherance of the administration of justice, national defense, or national security;
is guilty of an offense punishable under § 1030(c). 1
The Defendant argues that these charges must be dismissed because the CFAA only prohibits conduct that involves access without authorization or access that exceeds authorization. Smith, however, was granted access to B & D’s network and systems, including electronic mail (“email”) and internet access, by the Plaintiff per a July 18, 2007 Employee Access Agreement, which is attached to the Complaint. (D.E. No. 44, Mem. in Supp., at 1-2.) That agreement does not limit his access, but does provide that the Defendant “will maintain the confidentiality of all information of a confidential, proprietary or other legally sensitive nature ...” and “will not send, share, or publish any such information on the internet without prior approval ...” “in consideration for [his] request for access to [B & D]’s network. ...” (D.E. No. 1, Ex. C to Aff. of Michael Wilson.)
Both sides acknowledge that there is a split in legal authority as to whether the CFAA applies in a situation where an employee who has been granted access to his employer’s computers uses that access for an improper purpose. Some courts have concluded that an employee may exceed his authorization or act without authorization when he retrieves confidential or proprietary information from his employer’s computers that he has permission to access, but then uses that information in a manner that is inconsistent with the employer’s interests or in a manner that violates a contractual obligation.
See e.g., Int’l Airport Ctrs., L.L.C. v. Citrin,
In coming to this conclusion, some of these courts have relied on the rules of agency, finding that the authority of an agent terminates when he acquires adverse interests or is otherwise guilty of a serious breach of loyalty to the principal.
Citrin,
Other courts have criticized this rationale, holding that the CFAA targets the unauthorized procurement or alteration of information, not its misuse.
See e.g., Shamrock Foods Co. v. Gast,
After reviewing the language of the statute and its legislative history, the Court concludes that the latter line of cases is the more correct interpretation and that Congress did not intend to criminalize the Defendant’s conduct. “As with any question of statutory interpretation, [the Court] must first look to the language of the statute itself.”
Brilliance Audio, Inc. v. Haights Cross Commc’ns, Inc.,
As stated above, the statute defines the term “exceeds authorized access” as “ae-cessfing] a computer with authorization and [using] such access to obtain or alter information in the computer that the ac-cesser is not entitled so to obtain or alter.” § 1030(e)(6). The Court agrees with
Lockheed MaRin
that the plain meaning of “exceeds authorized access” is “to go beyond the access permitted.”
Furthermore, the legislative history supports the conclusion that Congress intended the CFAA to do “for computers what trespass and burglary laws did for real property.” Orin S. Kerr, Cybercrimes’ Scope: Interpreting “Access” and Au thorization” in Computer Misuse Statutes, 78 N.Y.U. L. Rev. 1596,1617 (2003). Prior to the passage of the CFAA, Congress relied on wire and mail fraud statutes to prosecute computer crimes, but these laws were only applicable when defendants used a means of interstate commerce to execute the crime, such as making telephone calls across state lines. H.R.Rep. No. 98-894, at 6 (1984), U.S.Code Cong. & Admin.News 1984, pp. 3689, 3691. A 1984 House Report states that the proposed legislation was necessary because “[i]t is obvious that traditional theft/larceny statutes are not the proper vehicles to control the spate of computer abuse and computer-assisted crimes,” given that they generally do not define property to include electronically processed or stored data, a problem compounded by the threat posed by “hackers who have been able to access (trespass into) both private and public computer systems.” Id. at 9-10, U.S.Code Cong. & Admin.News 1984, pp. 3689, 3695. Congress noted that modern computer networking capabilities “enabled the recent flurry of electronic trespassing incidents.” Id. at 10, U.S.Code Cong. & Admin.News 1984, pp. 3689, 3696. 2
Because Smith had permission to access the information in question and doing so was within the scope of his duties, it cannot be successfully argued that his access constituted a trespass. Clearly, the Plaintiff objects not to Smith’s accessing of the information, but to his later misuse thereof. Thus, while the Complaint includes claims that the Defendant breached both the Employee Access Agreement and the confidentiality agreements by allegedly disclosing B & D’s trade secrets and proprietary information, the Court finds that no facts alleged indicate that Smith exceeded the access he was granted by the Plaintiff or that he accessed the data without authorization. Accordingly, the Defendant’s contentions brought pursuant to subsections (a)(2), (a)(4), and (a)(5)(A)(ii)(iii) of 18 U.S.C. § 1030 are dismissed. 4
At least one court has held that the unauthorized copying and emailing of confidential or proprietary information does not constitute damage under the CFAA, because it does not impair any data, system or information.
See Garelli Wong &
Assocs.
v. Nichols,
The legislative history of the Act supports the conclusion that intentionally rendering a computer system less secure should be considered “damage” under § 1030(a)(5)(A), even when no data, program, or system, is damaged or destroyed.
See
S.Rep. No. 104-357, at 11 (1996) (discussing as an example of damage a situation where hackers alter existing log-on programs to gather user passwords and then restore the programs to their original condition; while neither the computer nor its data is technically damaged, such action “allows the intruder to accumulate valid user passwords to the system, requires all system users to change their passwords, and requires the system administrator to devote resources to resecuring the system. Thus, although there is arguably no ‘damage,’ the victim does suffer ‘loss.’ If the loss to the victim meets the required monetary threshold, the conduct should be criminal, and the victim should be entitled to relief.... ”).
5
Because the allegations in
II. The Tennessee Personal and Commercial Computer Act of2003
The Complaint also charges the Defendant with violating subsections (a)(1) and (b)(5) of section 89-14-602 of the Tennessee Annotated Code. (D.E. No. 1 Compl. ¶¶ 41-42.) Like the CFAA, the Tennessee Personal and Commercial Computer Act of 2003 is a criminal statute with a civil remedy. Tenn.Code Ann. § 39-14-604. Section 39-14-602(a)(l) provides that
[wjhoever knowingly, directly or indirectly, accesses, causes to be accessed, or attempts to access any telephone system, telecommunications facility, computer software, computer program, data, computer, computer system, computer network, or any part thereof, for the ■ purpose of ... [obtaining money, property, or services for oneself or another by means of false or fraudulent pretenses, representations, or promises violates this subsection (a)....
Id. § 39-14-604(a)(l). Smith argues that this claim must be dismissed because no facts alleged in the Complaint support the conclusion that he acted “by means of false or fraudulent pretenses, representations, or promises.” (D.E. No. 44, Mem. in Supp., at 11.) The Plaintiff insists, however, that the Defendant violated the statute because he did not tell B & D that he had considered and later accepted an offer of employment from TTI. (D.E. No. 52, Resp., at 16.)
There is no definition of the phrase “false or fraudulent pretenses” in the statute and no case interpreting it. However, the state of Tennessee has long criminalized the obtaining of property, money, or services by means of false pretenses.
See
Tenn.Code Ann. § 39-3-901 (repealed in 1989 and replaced by §§ 39-14-101
et seq.,
which consolidated various theft offenses such as embezzlement, false pretense, fraudulent conversion, and larceny, into a single statute);
Rafferty v. Tennessee,
all cases of pretended buying, borrowing and hireing [sic], and all other cases of bailment where the buyer or bailee intended at the time he received the goods, feloniously to steal the same. These words also include all cases where a person feloniously gets the money or goods or choses in action of another into possession by any false token or counterfeit letter, or by falsely personating [sic] another, or by falsely pretending to be the owner of such goods or choses in action, or by any other false and fraudulent pretense, where the party obtaining or getting the goods or choses in action into possession, intended at the time feloniously to steal the same....
Sloan v. Tennessee,
The question before the Court is, thus, whether the Defendant’s alleged silence about his plan to resign and go to work for B & D’s competitor qualifies as a false statement that allowed him access to the Plaintiffs property. The Court finds that it was not. Although Smith’s failure to tell his employer that he was planning to resign was perhaps not forthright, he did not misrepresent that he was employed by B & D as a pressure washer engineer, and as such, he had the right to view and access the Defendant’s data. Moreover, his right to access that information pre-dated any contact he had with TTI and was not obtained by virtue of his omission. The Court therefore finds that the Plaintiff can prove no set of facts that would establish a violation of section 39 — 14—602(a)(1).
Section 39-14-602(b)(5) prohibits “intentionally and without authorization, directly or indirectly .... [making or causing] to be made an unauthorized copy ... of computer data, computer programs, or computer software residing in, communicated by, or produced by a computer or computer network commits an offense .... ” The statute defines “authorization” as “any and all forms of consent, including both implicit and explicit consent.” § 39-14-601(2). There are no cases applying this statute. As stated above, the Complaint alleges that the Defendant attached several documents to an email he sent to his personal Yahoo account and copied others to an external storage device. (D.E. No. 1, Compl. ¶¶ 17-18.) Smith argues that as an employee of B & D, he had implicit consent to copy its files. (D.E. No. 44, Mem. in Supp., at 12.) However, while the Court acknowledges that the Tennessee legislature intended for the concept of authorization to be interpreted broadly, it finds that the Complaint does state a claim upon which relief can be granted. The Plaintiff has alleged that the Defendant made a copy of confidential information for non-work related purposes without its permission. The issue of whether he had implied consent to do so is a factual question, which should not be resolved on a motion to dismiss. Thus, the Court denies the Defendant’s motion as to section 39 — 14—602(b)(5).
CONCLUSION
For the reasons discussed above, the Court hereby GRANTS in part and DENIES in part the Defendant’s motion to dismiss. Specifically, the Court dismisses all of the Plaintiffs CFAA claims, except that brought pursuant to 18 U.S.C. § 1030(a)(5)(A)(i). The Court also dismisses B & D’s claim under section 39-14-602(a)(1) of the Tennessee Code Annotated, but denies Smith’s motion to dismiss that brought under section 39-14-602(b)(5).
Notes
. In order for a civil action to be maintained pursuant to the CFAA, one of the five factors in subsection (a)(5)(B) must be involved in the alleged misconduct. 18 U.S.C. § 1030(g). The only applicable subsection to the facts of this case is (a)(5)(B)(i), which requires a loss of $5000. "Loss” is defined as "any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service.”
. The scope of the statute has been broadened several times. Deborah F. Buckman,
Validity, Construction, and Application of Computer
. The court in
Shurgard Storage
relied heavily on legislative history in coming to the opposite conclusion.
. The Plaintiff argues that dismissing the Complaint would be premature because it has discovered evidence that the Defendant ac
. The example provided in the Senate Report is less than clear about what constitutes “damage,” given that its author seems to indicate that the victim in that situation has suffered loss, not damage. See id. However, read in context, it is clear that Congress intended for the conduct described in the example to be considered a violation of the offense described in § 1030(a)(5)(A)(i), which then, as now, required that the defendant cause damage. The term "damage” was defined, in relevant part by the 1996 amendments, as “any impairment to the integrity or availability of data, information, program or system which (A) causes loss of more than $5,000 during any 1-year period ...” Id. at 13. That definition has been shortened to not require anything more than “impairment to the integrity or availability of data, a program, a system, or information.” § 1030(e)(8).