Sewell v. BernardinSewell v. Bernardin
- Reporters:
- , ,
- Before:
- Spatt
On January 2, 2014, the Plaintiff Chan-tay Sewell (the “Plaintiff’) commenced this action against the Defendant Phil Bernar-din (the “Defendant”), who she alleges hacked her American Online (“AOL”) email account (the “AOL Account”) and her Facebook social media account (the “Face-book Account,” and collectively, with the AOL Account, the “Internet Accounts”). In this regard, pursuant to the Computer Fraud and Abuse Act of 2008,
The Plaintiff also brings a claim against the Defendant pursuant to the Stored Communications Act,
Presently before the Court is a motion by the Defendant to dismiss the Plaintiffs Complaint pursuant to Federal Rule of Civil Procedure (“Fed. R. Civ.P.”) 12(b)(6). The Court pauses here to note that the Defendant’s submissions use footnotes, which is contrary to this Court’s Individual Rule II.A. Notwithstanding this infraction, the Court will consider the Defendant’s papers in rendering its decision. However, the Court advises the Defendant’s counsel that any future filings that contain footnotes will not be considered by this Court.
For the reasons that follow, the Defendant’s motion is granted.
I. BACKGROUND
Unless otherwise stated, the following facts are drawn from the Plaintiffs Complaint and are construed in a light most favorable to the Plaintiff.
A. Factual Background
The Plaintiff is an individual residing in the State of New York, County of Queens. In her opposition to the Defendant’s motion to dismiss, the Plaintiff states that in or about 2002, she became involved in a romantic relationship with the Defendant. This relationship lasted about nine years and was terminated in or about 2011.
The Plaintiff maintained private electronic accounts with several internet service providers. Of relevance here, the Plaintiff had an e-mail account with AOL. In addition, she had a social media account with the website Facebook. She was the sole authorized user of these Internet Accounts and maintained private passwords for them. Through the Internet Accounts, the Plaintiff maintained information electronically, including her personal information, electronic messages, electronic posts, and contact lists.
According to the Plaintiff, she did not knowingly provide the Defendant or any other third parties with the means to access the Internet Accounts. In this regard, the Plaintiff never provided the Defendant with the passwords for the Internet Accounts, nor did she authorize him to obtain and/or utilize said passwords.
The Plaintiff alleges that on an unspecified date, the Defendant gained unauthorized access to the passwords for the Internet Accounts while he was at the Plaintiffs home. Then, without permission, the Defendant later used the passwords to access the Internet Accounts. In this regard, on August 1, 2011, the
In the Complaint, the Plaintiff alleges that records from Verizon (the “Verizon Records”) indicate that the Internet Accounts, as well as the computer servers on which the Internet Accounts were stored, had been accessed without authorization or permission. In this regard, based on exhibits the Plaintiff submitted with her opposition papers, it appears to the Court that the Plaintiff bases this allegation on the fact that the Verizon Records indicate that the Internet Accounts were accessed from an IP address associated with a computer located at the home address of the Defendant’s wife, Tara Bernardin (“Tara”). Thus, the Plaintiff theorizes that the Defendant used his wife’s computer to log onto the Internet Accounts and proceeded to their passwords so as to prevent the Plaintiff from accessing them.
The Plaintiff further alleges that without permission or authorization, the Defendant accessed the Plaintiffs Internet Accounts on additional dates beyond August 1, 2011 and February 24, 2012. These other dates include February 12, 2012, February 17, 2012, February 24, 2012, March 24, 2012, and March 26, 2012. According to the Plaintiff, through this unauthorized access of the Internet Accounts, the Defendant obtained access to the Plaintiffs electronic communications and electronic posts, which were in electronic storage. The Plaintiff also claims the Defendant obtained access to other personal and identifying information about her.
In addition, the Plaintiff alleges that Defendant used the Internet Accounts to publically post private information about the Plaintiff and to communicate with third parties while posing as the Plaintiff. For example, on an unspecified date in 2011, she alleges that the Defendant apparently sent an e-mail message from the AOL Account and a Facebook message from the Facebook Account to the Plaintiffs family and friends using the Plaintiffs contacts lists, which she maintained privately within the Internet Accounts. These messages contained malicious statements about the Plaintiff regarding certain sexually transmitted diseases and sexual activities.
Moreover, according to the Plaintiff, the Defendant engaged in a malicious campaign of unlawfully accessing and trespassing into the Internet Accounts and accessing her personal and confidential information, which were contained in the Internet Accounts. As a result of the Defendants conduct, the Plaintiff claims to have incurred monetary expenses in order to investigate the breaches to the Internet Accounts and to protect them from future unauthorized access.
B. Procedural History
On or about May 23, 2013, in a separate action, the Plaintiff filed suit against the Defendant’s wife, Tara, and John Does 1-5, in the- Supreme Court of the State of New York, Queens County. The Plaintiff accused Tara of computer fraud and brought the following claims: (1) fraud in connection with computers in violation of the CFAA; (2) unlawful access to stored communications in violation of the SC A; (3) trespass to chattels; and (4) civil conspiracy.
On June 18, 2013, Tara removed the ease, entitled Sewell v. Tara Bernardin
As a result, on October 3, 2013, Judge Seybert entered an order directing the Clerk of the Court to enter judgment in favor of the Plaintiff and mark the case closed. Thereafter, on January 2, 2014, the Plaintiff commenced the present action.
II. DISCUSSION
A. Legal Standard on a
It is well-established that a complaint should be dismissed under
However, “although ‘a court must accept as true all of the allegations contained in a complaint,’ that ‘tenet’ ‘is inapplicable to legal conclusions,’ and ‘[tjhreadbare recitals of the elements of a cause of action, supported by mere conclusory statements, do not suffice.’ ” Harris v. Mills,
B. Legal Standard Under the CFAA
“The CFAA is a criminal statute that provides, among other things, that ‘[whoever ... knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value ... shall be punished as provided in subsection (c) of this section.’ ” Schaeffer v. Kessler, 12 CIV. 8576 PKC,
The Court notes that it is “inappropriate to expand the CFAA in a manner not consistent with the statute’s plain meaning, and, in so doing, transform what has always been a common law civil tort (i.e., misappropriation of confidential information) into a federal criminal offense.” Jet One Group, Inc. v. Halcyon Jet Holdings, No. 08-CV-3980 (JS)(ETB),
Of relevance here, subsection “(c)(4)(A)(i)(I), applies to ‘loss to 1 or more persons during any 1-year period (and, for purposes of an investigation, prosecution, or other proceeding brought by the United States only, loss resulting from a related course of conduct affecting 1 or more other protected computers) aggregating at least $5,000 in value.’ ” Penrose Computer Marketgroup, Inc.,
The CFAA defines “damages” as “any impairment to the integrity or availability of data, a program, a system or information.”
Moreover, the CFAA defines “loss” as “any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service.”
According to the Plaintiffs Complaint, the Defendant “intentionally accessed a computer (i.e., the computers owned by Facebook, Inc. and AOL, Inc.) without authorization or exceeded authorized access, and thereby obtained information from a protected computer, namely Sewell’s personal information, electronic messages, electronic posts, contact lists, and other material stored in her Internet Accounts.” (Compl., ¶ 26.) As such, it appears to the Court that the Plaintiff is alleging that the Defendant violated
In relevant part, the CFAA defines “protected computer” as a computer “which is used in or affecting interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States.”
“A[ ] [civil] action under [the CFAA] must be brought within two years of ‘of the act complained of or the date of the discovery of the damage.’ ” FTA Mkt. Inc. v. Vevi Inc., 11 CV 4789 VB,
C. Legal Standard for a SCA Claim
Like the CFAA, the SCA is a criminal statute that “also creates a civil cause of action that allows any ‘subscriber, or other person aggrieved’ by a knowing or intentional violation of [the SCA] to recover damages from the violator.” Sood v. Rampersaud, 12 CV 5486 VB,
In this context, an “electronic communication service” means “any service which provides to users thereof the ability to send or receive wire or electronic communications.”
“The aim of the [SCA] was, in part, to protect individuals’ privacy interests in personal and proprietary information.” Kaufman v. Nest Seekers, LLC, No. 05 CV 6782(GBD),
The statute of limitations for a civil action brought pursuant to the SCA is two years.
D. As to Whether the Plaintiff’s CFAA and SCA Claims are Time-Barred
As a preliminary matter, the Court must first resolve whether the Plaintiffs CFAA and SCA claims are time-barred. See, e.g., Coleman v. B.G. Sulzle, Inc.,
As indicated above, “[t]he latest a CFAA cause of action may be commenced is two years from ‘the date of discovery of the damage.’ ” Smartix Int’l Corp. v. MasterCard Int’l LLC, 06 CV 5174(GBD),
Here, the Plaintiff commenced this action on January 2, 2014. However, in her Complaint, she alleges that on August 1, 2011, she first discovered she could no longer access the AOL Account as her password had been altered. As such, she clearly discovered the damage at issue—
Moreover, although the Plaintiff did not discover that she was unable to access the Facebook Account until February 24, 2012, she was already aware that the integrity of her computer had been compromised based on her August 1, 2011 discovery concerning her inability to access the AOL Account. See FTA Mkt. Inc.,
. For this reason, the Court dismisses the CFAA cause of action as untimely. As a consequence, the Court need not resolve whether the Plaintiff has stated a claim for relief under the CFAA. FTA Mkt. Inc.,
Similarly, as previously stated, an SCA claim is time-barred if it is not brought within “two years after the date upon which the claimant first discovered or had reasonable opportunity to discover the violation.”
In this regard, the Plaintiffs SCA claim consists of two alleged violations: (1) that the Defendant intentionally accessed without authorization a facility owned and operated by AOL, Inc., thereby preventing the Plaintiff from accessing electronic communication while they were stored in the AOL Account; and (2) that the Defendant intentionally accessed without authorization a facility owned and operated by Facebook, Inc., thereby preventing the Plaintiff from accessing electronic communications while they were stored in the Fa-cebook Account. Concerning the first purported violation, as discussed above, the Plaintiff discovered she was unable to access the AOL Account on August 1, 2011. As such, she was required to bring this claim within two years of that date, and her failure to do so renders her SCA cause of action premised on this violation untimely. See, e.g., Maddalena v. Toole, 2:13-CV-4873-ODW,
With respect to the second violation that makes up the Plaintiffs SCA claim, the Court finds that this part is also time-barred. While the Plaintiff learned that she could no’longer access the electronic communications stored in the Facebook Account on February 24, which is less than two years before her commencement of this action on January 2, 2014, she none
E. As to the Plaintiff’s Remaining Trespass to Chattel Claim
In addition to her federal claims, the Plaintiff brings a trespass to chattel claim pursuant to New York common law. In this regard, she alleges that (1) she had personal property rights to the information she stored on the Internet Accounts and (2) when the Defendant logged onto the Internet Accounts and accessed her information, he violated New York’s trespass to chattel law.
However, a court “may decline to exercise supplemental jurisdiction over a [pendent state law] claim” if the court “has dismissed all [federal] claims over which it has original jurisdiction.”
Having dismissed the Plaintiffs federal claims, and given the early stage of this litigation, the Court declines to exercise supplemental jurisdiction over Plaintiffs remaining state law claim. Therefore, the motion to dismiss the Plaintiffs trespass to chattel claim is granted without prejudice.
III. CONCLUSION
For the foregoing reasons, it is hereby
ORDERED that the motion to dismiss by the Defendant is granted, and the Clerk of the Court is directed to close this case.
SO ORDERED.