Shurgard Storage Centers, Inc. v. Safeguard Self Storage, Inc.Shurgard Storage Centers, Inc. v. Safeguard Self Storage, Inc.
ORDER
INTRODUCTION
Shurgard Storage Centers, Inc. (plaintiff) and Safeguard Self Storage, Inc. (defendant) are competitors in the self-storage business. The plaintiff alleges that the defendant embarked on a systematic scheme to hire away key employees from the plaintiff for the purpose of obtaining the plaintiffs trade secrets. The plaintiff also alleges that some of these employees, while still working for the plaintiff, used the plaintiffs computers to send trade secrets to the defendant via e-mail. The plaintiffs complaint alleges misappropriation of trade secrets, conversion, unfair competition, violations of the Computer Fraud and Abuse Act (CFAA), tortious interference with a business expectancy, and seeks injunctive relief and damages. The defendant has moved to dismiss the CFAA claim pursuant to
MOTION TO DISMISS STANDARD
When considering a motion to dismiss under 12(b)(6), a court must accept all allegations in the complaint as true and make all reasonable inferences in favor of the plaintiff.
See Scheuer v. Rhodes,
FACTS
The plaintiff alleges the following facts which the Court accepts as true for the purposes of this motion. The plaintiff is the industry leader in full and self-service storage facilities in both the United States and Europe. The plaintiffs growth in the last 25 years is primarily due to the development and construction of top-quality storage centers in “high barrier to entry”
The defendant began self-storage operations in 1997. The defendant is a direct competitor of the plaintiff and develops self-storage facilities in the United States and abroad.
In late 1999, the defendant approached Eric Leland, a Regional Development Manager for the plaintiff, and offered him employment with the defendant. Because of his position with the plaintiff, Mr. Leland had full access to the plaintiffs confidential business plans, expansion plans, and other trade secrets. While still employed by the plaintiff, but acting as an agent for the defendant, Mr. Leland sent e-mails to the defendant containing various trade secrets and proprietary information belonging to the plaintiff. Mr. Leland did this without the plaintiffs knowledge or approval. Mr. Leland was later hired by the defendant in October 1999, and he has continued to give the defendant proprietary information belonging to the plaintiff. The defendant has hired away other employees of the plaintiff who have intimate knowledge of the plaintiffs business models and practices, and the defendant continues to recruit employees of the plaintiff.
DISCUSSION
The motion to dismiss raises challenging issues regarding the scope of a civil claim under a criminal statute, the Computer Fraud and Abuse Act,
A. Statutory Interpretation
As a preliminary matter, the Court must determine the appropriate method by which to interpret the statute. The defendant, citing
United States v. Flores-Garda,
B. Does the plaintiff state a claim under
Under
The defendant contends the plaintiffs complaint does not state a claim for relief under
i. Did Plaintiff allege that its former employees were without authorization or that they exceeded authorized access?
The defendant’s first ground for challenging the plaintiffs claim under
The plaintiff responds by arguing that the authorization for its former employees ended when the employees began acting as agents for the defendant. The plaintiff cites to the Restatement (Second) of Agency § 112 (1958) and argues that when Mr. Leland or other former employees used the plaintiffs computers and information on those computers in an improper way they were “without authorization.”
In
United States v. Galindo,
Under the Restatement (Second) of Agency, relied upon by the Galindo court:
Unless otherwise agreed, the authority of an agent terminates if, without knowledge of the principal, he acquires adverse .interests or if he is otherwise guilty of a serious breach of loyalty to the principal.
Restatement (Second) of Agency § 112 (1958). Under this rule, the authority of the plaintiffs former employees ended when they allegedly became agents of the defendant. Therefore, for the purposes of this 12(b)(6) motion, they lost their authorization and were “without authorization” when they allegedly obtained and sent the proprietary information to the defendant via e-mail. The plaintiff has stated a claim under
ii. Did the plaintiff have to allege that the violation of18 U.S.C. § 1030(a)(2)(C) affected the national economy?
The defendant’s second argument challenging the plaintiffs claim under
Nowhere in language of
C. Does the plaintiff state a claim under
A person violates
knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value, unless the object of the fraud and the thing obtained consists only of the use of the computer and the value of such use is not more than $5, 000 in any 1-year period.
D. Does the plaintiff state a claim under
Under
The defendant raises two objections to this claim. First, the defendant asserts that the legislative history of this section of the CFAA shows that it is only intended to apply to “outsiders,” and thus would not apply to employees. However, there is no ambiguity in the statute as to when a party is liable,
(“Whoever
... intentionally accesses....”) so this argument lacks merit.
See
Second, the defendant argues that the plaintiff has not pled that it incurred “damage” as defined in the statute. Specifically, the defendant argues that the alleged loss of information by the plaintiff is not “damage” under the statute. The statute says damage is
“any impairment
to the integrity ... of data ... or information.”
The term “damage” was addressed in the Senate Report regarding the 1996 amendments to the CFAA:
The 1994 amendment required both “damage” and “loss,” but it is not always clear what constitutes “damage.” For example, intruders often alter existing log-on programs so that user passwords are copied to a file which the hackers can retrieve later. After retrieving the newly created password file, the intruder restores the altered log-on file to its original condition. Arguably, in such a situation, neither the computer nor its information is damaged. Nonetheless, this conduct allows the intruder to accumulate valid user passwords to the system, requires all system users to change their passwords, and requires the system administrator to devote resources to resecuring the system. Thus, although there is arguably no “damage,” the victim" does suffer “loss.” If the loss to the victim meets the required monetary threshold, the conduct should be criminal, and the victim should be entitled to relief.
The bill therefore defines “damage” in new subsection 1030(e)(8), with a focus on the harm that the law seeks to prevent.
S.Rep. No. 104-357, at 11 (1996). This example given in the report is analogous to
E. The Legislative History of the CFAA Supports the Plaintiffs Claim in This Case.
Although the Court concludes that the plaintiff has stated a claim under the CFAA, this Court is mindful of its obligation to construe statutes so as to avoid “absurd” results.
See Burton,
The core of the defendant’s arguments concerning legislative intent is that the CFAA was not meant to apply to the kind of factual situation presented in this case. Instead, the defendant maintains the CFAA is limited to those industries whose computers contain vast amounts of information, which if released, could significantly affect privacy interests in the public at large. The defendant also maintains the CFAA is limited to “outsiders” or “hackers,” and not “insiders” (employees). Though the original scope of the CFAA was limited to the concerns addressed by the defendant, its subsequent amendments have broadened the scope sufficiently to cover the behavior alleged in this case.
The first version of the CFAA was passed in 1984. See S.Rep. No. 99-432, at 3 (1986). This first bill was directed at protecting classified information on government computers as well as protecting financial records and credit information on government and financial institution computers. See id. In 1986, the CFAA was amended to “provide additional penalties for fraud and related-activities in connection with access devices and computers.” Id. at 1. Specifically, the 1986 amendments added protection for “federal interest computers:”
Throughout its consideration of computer crime, the Committee has been especially concerned about the appropriate scope of Federal jurisdiction in this area. It has been suggested that, because some States lack comprehensive computer crime statutes of their own, the Congress should enact as sweeping a Federal statute as possible so that no computer crime is left uncovered. The Committee rejects this approach and prefers instead to limit Federal jurisdiction over computer crime to those cases in which there is a compelling Federal interest, i.e., where computers of the Federal Government or certain financial institutions are involved, or where the crime itself is interstate in nature.
Id. at 4. Thus, the original version of the CFAA did not intend to enact sweeping federal jurisdiction. However, the CFAA was intended to control interstate computer crime, and since the advent of the Internet, almost all computer use has become interstate in nature.
As for the scope of the CFAA after the 1986 amendments, there is language in the Senate Report that favors both the plaintiffs and the defendant’s contentions. Examples of language helpful to the plaintiff are: “The Judiciary Committee’s concern
Any enforcement action in response to criminal conduct indirectly or directly related to computers must rely upon a statutory restriction dealing with some other offense. This requires the law enforcement officer, initially the agent, and then the prosecutor, to attempt to create a “theory of prosecution” that somehow fits what may be the square peg of computer fraud into the round hole of theft, embezzlement or even the illegal conversion of trade secrets.
Id. at 14 (citation omitted and emphasis added).
However, other language tends to support the defendant’s contention that the CFAA. has a narrow scope: “[programs should be implemented that] deflate the myth that computer crimes are glamou-rous, harmless pranks.” Id. at 3; “The premise of 18 U.S.C. 1030(a)(2) will remain the protection, for privacy reasons, of computerized credit records and computerized information relating to customers’ relationships with financial institutions.” Id. at 6; “The Committee wishes to avoid the danger that every time an employee exceeds his authorized access to his department’s computers ... he could be prosecuted under [1030(a)(5) ] ... By precluding liability in purely ‘insider’ cases such as these.... ” Id. at 7-8.
The CFAA was amended in 1996, and the phrase “protected computer” was added in place of “federal interest computer.” The Senate Report on these amendments demonstrates the broad scope of this phrase. See S.Rep. No. 104-357, at 3 (1996) (“[The CFAA is strengthened] by closing gaps in the law to protect better the confidentiality, integrity, and security of computer data and networks.”); Id. at 4; (“The privacy protection coverage of the statute has two significant gaps. First, omitted from the statute’s coverage is information on any civilian or State and local government computers, since the prohibition on unauthorized computer access to obtain non classified information extends only to the Federal Government when the perpetrator is an outsider.”) (emphasis added); Id. at 5; (“[The CFAA] facilitates addressing in a single statute the problem of computer crime, rather than identifying and amending every potentially applicable statute affected by advances in computer technology. As computers continue to proliferate in businesses and homes, and new forms of computer crimes emerge, Congress must remain vigilant to ensure that the [CFAA] is up-to-date and provides law enforcement with the necessary legal framework to fight computer crime.”) Id.
Finally, in what is dispositive of the scope of the CFAA, the report states:
The proposed subsection 1030(a)(2)(C) is intended to protect against the interstate or foreign theft of information by computer.... This subsection would ensure that the theft of intangible information by the unauthorized use of a computer is prohibited in the same way theft of physical items are protected. In instances where the information stolen is also copyrighted, the theft may implicate certain rights under the copyright laws. The crux of the offense under subsection-1030(a)(2)(C), however, is the abuse of a computer to obtain the information.
... Those who improperly use computers to obtain other types of information — such as financial records, non-classified Government information, and information of nominal value from private individuals or companies —-face only misdemeanor penalties, unless the information is used for commercial advantage, private financial gain or to commit any criminal or tortious act.
For example, individuals who intentionally break into, or abuse their authority to use, a computer and thereby obtain information of minimal value of $5,000 or less, would be subject to a misdemeanor penalty. The crime becomes a felony if the offense was committed for purposes of commercial advantage or private financial gain, for the purposes of committing any criminal or tortious act in violation ... of the laws of the United States or of any State, or if the value of the information obtained exceeds $5,000.
Id.
at 7-8 (emphasis added). This legislative history, although in reference
CONCLUSION
For the reasons stated above, the defendant’s motion to dismiss the Computer Fraud and Abuse Act claim is DENIED.
IT IS SO ORDERED.
Notes
. In a previous Minute Order, docket no. 16, the Court dismissed the unfair competition claim and denied the motion to dismiss the tortious interference claim.
. Though other cases have dealt with the CFAA, none have dealt with the precise issues presented by this case.
See, e.g., United States v. Czubinski,
. The 1994 amendments to the CFAA added this private cause of action. See H.R.Conf. Rep. No. 103-711, at Section 290001 (1994).
. Since the plaintiff has sufficiently alleged that the former employees were without authorization, the Court need not examine whether the employees exceeded their authorized access.