Sewell v. BernardinSewell v. Bernardin
The plaintiff, Chantay Sewell, appeals from an August 2, 2014, judgment of the United States District Court for the Eastern District of New York (Arthur D. Spatt, Judge) dismissing her claims under the Computer Fraud and Abuse Act,
We therefore AFFIRM in part, and VACATE and REMAND in part for further proceedings as indicated in this opinion.
HARVEY S. MARS, Law Office of Harvey S. Mars LLC, New York, NY, for Plaintiff–Appellant.
GARY T. CERTAIN, Law Office of Certain & Zilberg, PLLC, New York, NY, for Defendant–Appellee.
SACK, Circuit Judge:
In order to resolve this appeal, we address a matter of first impression in this Circuit: the operation of the statutes of limitations applicable under the civil enforcement provisions of the Computer Fraud and Abuse Act (ʺCFAAʺ),
BACKGROUND
We accept as true at this stage of the proceedings all facts alleged in Sewellʹs complaint. See Town of Babylon v. Fed. Hous. Fin. Agency, 699 F.3d 221, 227 (2d Cir. 2012). According to those allegations, Sewell and Bernardin were
On or about August 1, 2011, Sewell discovered that her AOL password had been altered, and she was therefore unable to log into her AOL e‐mail account. That same month, malicious statements about her sexual activities2 were e‐mailed to various family members and friends ʺvia Sewellʹs own contacts list maintained privately within her email account.ʺ Compl. ¶ 19 (J.A. 6).
On February 24, 2012, Sewell found herself unable to log into her Facebook account. Then, on March 1, 2012, someone other than she posted a public message from her Facebook account containing malicious statements, again concerning Sewellʹs sex life.
On May 15, 2013, Sewell filed a separate suit against Bernardinʹs wife, Tara Bernardin, and ʺJohn Does #1‐5,ʺ apparently believing that Tara Bernardin and others unknown to her had gained access to her Internet accounts. The complaint raised claims strikingly similar to those that she is pursuing in the instant action. Tara Bernardin settled her suit with Sewell on September 27, 2013, and the court accordingly entered judgment in Sewellʹs favor shortly thereafter.
Several months later, on January 2, 2014, Sewell filed the instant action against Phil Bernardin, alleging violations of the SCA and CFAA. On August 2, 2014, the United States District Court for the Eastern District of New York (Arthur D. Spatt, Judge) granted Bernardinʹs motion to dismiss, holding that Sewellʹs claims
DISCUSSION
We review the grant of a motion to dismiss under
I. The Applicable Statutes of Limitations
A. The Computer Fraud and Abuse Act
The statute also provides a civil cause of action to ʺ[a]ny person who suffers damage or loss by reason of a violation of this section.ʺ Id.
B. The Stored Communications Act
Under the SCA, it is a crime to:
- (1) intentionally access[] without authorization a facility through which an electronic communication service is providеd; or
- (2) intentionally exceed[] an authorization to access that facility;
As with the CFAA, the SCA establishes a civil cause of action. ʺ[A]ny . . . person aggrieved by any violation of this chapter in which the conduct constituting the violation is engaged in with a knowing or intentional state of mindʺ may file suit. Id.
II. Sewellʹs Discovery of Damage and Unauthorized Access to Her AOL and Facebook Accounts
The district court granted Bernardinʹs motion to dismiss Sewellʹs claims as untimely based on the courtʹs conclusion that Sewell was ʺaware that the integrity of her computer had been compromisedʺ as of August 1, 2011. Sewell v. Bernardin, 50 F. Supp. 3d 204, 212 (E.D.N.Y. 2014).
Sewell discovered the ʺdamageʺ to her AOL account for CFAA purposes on August 1, 2011, when she learned that she could not log into her AOL e‐mail account. That she may not have known exactly what happened or why she could not log in is of no moment. The CFAAʹs statute of limitations began to run when Sewell learned that the integrity of her account had been impaired.
The SCAʹs statute of limitations began to run when Sewell ʺfirst . . . had a reasonable opportunity to discover,ʺ
Sewellʹs CFAA and SCA claims with regard to her AOL account were first made оn January 2, 2014, and were premised on damage and unauthorized access to her AOL account which she had or should have discovered some two years and five months earlier. The two‐year statutes of limitations had therefore run.5
Sewellʹs Facebook‐related claims, by contrast, appear to have accrued on or about February 24, 2012. Her complaint alleges that she ʺwas the sole authorized user ofʺ her Facebook account. Compl. ¶ 10 (J.A. 4). On or about ʺFebruary 24, 2012, [she] discovered that she could no longer log into or access her account with www.facebook.com because her password [had been] altered.ʺ Compl. ¶ 12 (J.A. 5). Therе is nothing in the facts as alleged in the complaint from which to
The fact that Sewell had discovered ʺdamageʺ to her AOL account based on her inability to access AOLʹs computer servers at an earlier date does not lead to a different result. Contrary to the district courtʹs remark, Sewell did not allegedly discover ʺthat the integrity of her computer had been compromisedʺ as of August 1, 2011. Sewell, 50 F. Supp. 3d at 212 (emphasis added). She discovered only that the integrity of her AOL account had been compromised as of that time. Her CFAA claim accordingly is premised on impairment to the integrity of a computer owned and operated by AOL, not of her own physical computer.6 As a result, Sewell has two separate CFAA claims, one that accrued on August 1, 2011, when she found out that she could not access her AOL account, and one that accrued on February 24, 2012, when she found out that she could not access her Facebook account.
The district courtʹs conclusion may rest on the assumption that a plaintiff is on notice of the possibility that all of her passwords for all of the Internet accounts she holds have been compromised because one password for one Internet account was compromised. We do not think that that is a reasonable inference from the facts alleged in the complaint. We take judicial notice of the fact that it is not uncommon for one person to hold several or many Internet
We pause to acknоwledge that the statutes of limitations governing claims under the CFAA and SCA, as we understand them, may have troubling consequences in some situations. Even after a prospective plaintiff discovers that an account has been hacked, the investigation necessary to uncover the hackerʹs identity may be substantial. In many cases, we suspect that it might take more than two years. But it would appear that if a plaintiff cannot discover the hackerʹs identity within two years of the date she discovers the damage or violation, her claims under the CFAA and SCA will be untimely.
The plaintiff does have the option of initiating a lawsuit against a Jane or John Doe defendant, but she must still discover thе hackerʹs identity within two years of discovery or a reasonable opportunity to discover the violation to avoid
CONCLUSION
For the foregoing reasons, the judgment of the district court is AFFIRMED in part and VACATED and REMANDED in part for further proceedings.