United States v. PhillipsUnited States v. Phillips
Christоpher Andrew Phillips (“Phillips”) appeals his conviction for intentionally accessing a protected computer without authorization and recklessly causing damage in excess of $5,000, pursuant to the Computer Fraud and Abuse Act (“CFAA”),
I. BACKGROUND
Phillips entered the University of Texas at Austin (“UT”) in 2001 and was admitted to the Department of Computer Sciences in 2003. Like all incoming UT students, Phillips signed UT’s “acceptable use” computer policy, in which he agreed not to perform port scans using his university computer account. 1 Nonetheless, only a few weeks after matriculating, Phillips began using various programs designed to scan computer networks and steal encrypted data and passwords. He suсceeded in infiltrating hundreds of computers, including machines belonging to other UT students, private businesses, U.S. Government agencies, and the British Armed Services Webserver. In a matter of months, Phillips amassed a veritable informational goldmine by stealing and cata-loguing a wide variety of personal and proprietary data, such as credit card numbers, bank account information, student financial aid statements, birth records, passwords, and Social Security numbers.
The scans, however, were soon discovered by UT’s Information Security Office (“ISO”), which informed Phillips on three separate occasions that his computer had been detected portscanning hundreds of thousands of external computers for vulnerabilities. Despite several instructions
At around the time ISO issued its first warning in early 2002, Phillips designed a computer program expressly for the purpose of hacking into the UT system via a portal known as the “TXClass Learning Central: A Complete Training Resource for UT Faculty and Staff.” TXClass was a “secure” server operated by UT and used by faculty and staff as a resource for enrollment in professional education courses. Authorized users gained access to their TXClass accounts by typing their Social Security numbers in a field on the TXClass website’s log-on page. Phillips exploited the vulnerability inherent in this log-on protocol by transmitting a “brute-force attack” program, 2 which automatically transmitted to the website as many as six Social Security numbers per second, at least some of which would correspond to those of authorized TXClass users.
Initially, Phillips selected ranges of Social Security numbers for individuals born in Texas, but he refined the brute-force attack to include only numbers assigned to the ten most populous Texas counties. When the program hit a valid Social Security number and obtained access to TXClass, it automatically extracted personal information corresponding to that number from the TXClass database and, in effect, provided Phillips a “back door” into UT’s main server and unified database. Over a fourteen-month period, Phillips thus gained access to a mother lode of data about more than 45,000 current and prospective students, donors, and alumni.
Phillips’s actions hurt the UT computer system. The brute-force attack program proved so invasive — increasing the usual monthly number of unique requests received by TXClass from approximately 20,-000 to as many as 1,200,000 — that it caused the UT computer system to crash several times in early 2003. Hundreds of UT web applications became temporarily inaccessible, including the university’s online library, payroll, accounting, admissions, and medical records. UT spent over $122,000 to assess the damage and $60,000 to notify victims that their personal information and Social Security numbers had been illicitly obtained.
After discovering the incursions, UT contacted the Secret Service, and the investigаtion led to Phillips. Phillips admitted that he designed the brute-force attack program to obtain data about individuals from the UT system, but he disavowed that he intended to use or sell the information.
Phillips was indicted and convicted after a jury trial on one count of computer fraud pursuant to
II. DISCUSSION
A. Sufficiency of the Evidence
Phillips asserts that the Government failed to produce sufficient evidence that he “intentionally accessed] a protected computer without authorization” under
Although Phillips timely filed a motion for judgment of acquittal,
see
Phillips’s insufficiency argument takes two parts: that the Government failed to prove (1) he gained access to the TXClass website without authorization and (2) he did so intentionally.
With regard to his authorization, the CFAA does not define the term, but it does clearly differentiate between unauthorized users and those who “exceed[] authorized access.”
See
Courts have therefore typically analyzed the scope of a user’s authorization to access a protected computer on the basis of the expected norms of intended use or the nature of the relationship established between the computer owner and the user. Applying such an intended-use analysis, in
United States v. Morris,
Phillips’s brutе-force attack program was not an intended use of the UT network within the understanding of any reasonable computer user and constitutes a method of obtaining unauthorized access to computerized data that he was not permitted to view or use. During cross-examination, Phillips admitted that TXClass’s normal hourly hit volume did not exceed a few hundred requests, but that his brute-force attack created as many as 40,000. He also monitored the UT system during the multiple crashes his program caused, and backed up the numerical ranges of the Social Security numbers after the crashes so as not to omit any potential matches. Phillips intentionally and meticulously executed both his intrusion into TXClass and the extraction of a sizable quantity of confidential personal data. There was no lack of evidence to find him guilty of intentional unauthorized access.
Phillips makes a subsidiary argument that because the TXClass website was a public application, he, like any internet user, was a
de facto
authоrized user. In essence, Phillips contends that his theft of other people’s data from TXClass merely exceeded the preexisting generic authorization that he maintained as a user of the World Wide Web, and he cannot be considered an unauthorized user under
This argument misconstrues the nature of obtaining “access” to an internet application and the CFAA’s use of the term “authorization.” While it is true that any internet user can insert the appropriate URL into a web browser and thereby view the “TXClass Administrative Training System” log-in web page, a user cannot gain access to the TXClass application itself without a valid Social Security number password to which UT has affirmatively granted authorization.
4
Neither Phillips,
B. Constructive Amendment of the Indictment
For the first time on appeal, Phillips alleges as error that the district court constructively amended his indictment in its jury instructions. The district court charged the jury based on the Government’s proposed instruction and a modified version of the Eleventh Circuit’s Criminal Pattern Jury Instruction 42.3 that adopts language from
Phillips asserts that the deviation between the terms of the charged offense and the language of the jury instruction was plain and adversely affected his substantial rights in two ways. First, the jury instruction impermissibly reduced the Government’s burden of proof by not requiring the jury to find that he intentionally accessed TXClass without authorization, but instead only that he transmitted a program without authorization. Second, Phillips claims that while
Constructive amendment of an indictment occurs when the trial court “through its instruсtions and facts it permits in evidence, allows proof of an essential element of the crime on an alternative basis provided by the statute but not charged in the indictment.”
United States v. Slovacek,
With respect to Phillips’s first argument, the district court’s instruction plainly modified an essential element of the charged offense by supporting the act of accessing a protected computer under subsection (ii) on the basis of transmitting a program under subsection (i).
See, e.g., United States v. Reyes,
We nonetheless find no reversible plain error with respect to the transmission/access discrepancy. Phillips gained access to TXClass by the act of transmitting the brute-force attack program. The factual predicates for Phillips’s particular conviction under the jury charge and the indictment — knowingly transmitting a program and intentionally аccessing a protected computer — are identical. There is no conceivable basis upon which the jury could have concluded that Phillips transmitted the program and obtained information from UT’s database without having also accessed a protected computer. The instruction on this element of the charged offense, although incorrect, was immaterial.
Phillips’s second argument is that the indictment charged him with “intentionally access[ing] a protected computer without authorization,” while the jury instruction only required that he “knowingly” transmitted the program.
We agree that the plain language of the statute, tracked in the indictment, indicates that the actus reus was the
intentional
unauthorized access of a protected computer. In fact, the 1986 amendment to
The district court instructed the jury that to convict, it must find that Phillips “knowingly caused the transmission of a program” and that he “so acted without the authorization” of appropriate persons or entities. This instruction, as Phillips contends, does not fully convey that the jury must find that Phillips intentionally acted without authorization. However, as discussed above in the context of his sufficiency claim, the evidence leaves no doubt that Phillips knew he was unauthorized to transmit an invasive computer program designed to gain access to the TXClass system and to steal thousands of Social Security numbers. It beggars belief that, having transmitted such a program, Phillips did not intend to access a protected computer and that he access be unauthorized. 8 To the extent the jury instructions were wrong, the errors did not affect Phillips’s substantial rights. See Bieganowski, supra.
C. Lesser-ineluded Offense Instruction
Phillips next contends that the district court improperly failed to instruct the jury on a lesser-ineluded offense under
We construe this train of events as а waiver of the argument Phillips now urges. Waiver is an “affirmative choice by the defendant to forego any remedy available to him, presumably for real or perceived benefits.”
United States v. Dodson,
D. Restitution Award
Finally, Phillips contends that the district court erred in its award of restitution for costs incurred by UT in conducting a computer damage and systems evaluation and contacting individuals whose biographical information and Social Security numbers were stolen. Since Phillips raises this issue for the first time on appeal, we review the award for plain error.
United States v. Garza,
A defendant sentenced under provisions of the Mandatory Restitution to Victims Act (“MRVA”),
Relying on
United States v. Schinnell,
Schinnell’s reasoning is inapplicable to the instant case. First,
Schinnell
involved a separate restitutionary provision, while
Second,
Schinnell
involved a violation of § 1343, the federal wire fraud statute, not
[T]he term “loss” means any reasonable cost to any victim, including the cost of responding to an offense, conducting a damage assessment, and restoring the data, program, system, or information to its condition prior to the offense, and any revenue lost, cost incurred, or other consequential damages incurred because of interruption of service....
III. CONCLUSION
For the foregoing reasons, the conviction and sentence are AFFIRMED.
Notes
. Port scanning is a technique used by computer hackers by which an individual sends requests via a worm or other program to various networked computer ports in an effort to ascertain whether particular machines have vulnerabilities that would leave them susceptible tо external intrusion. Often used as an initial step in launching an attack on another computer or transmitting a virus, port scanning is a relatively unsophisticated, but highly effective, reconnaissance method, likened at trial by UT’s information technology chief as the electronic equivalent of "rattling doorknobs” to see if easy access can be gained to a room.
. "Brute-force attack" is term of art in computer science used to describe a program designed to decоde encrypted data by generating a large number of passwords.
. Section 1023(a)(6) was amended on April 30, 2003, by adding the phrase "knowingly possesses an authentication feature of the United States which is stolen." Because the last act Phillips committed that would qualify for punishment under this provision occurred on March 2, 2003, the district court correctly dismissed the conviction under this count as
. Phillips’s contention that an individual's ability to view TXClass’s log-in webpage amounts to a general grant of authorized aсcess to the public-at-large is unsupported by various judicial interpretations of what constitutes obtaining access to a protected computer.
See, e.g., State v. Allen,
.
See, e.g., Int’l Airport Ctrs. LLC v. Citrin,
. Discussion of the changes to the scienter elements of
.
Compare
. We note that, in any event, the district court rectified its error in misstating the scienter requirement as applied to Phillips's access. The court instructed the jury that "knowingly” means "that the act was done voluntarily and intentionally, not because of mistake or accident.”
.
The differing degrees of culpability envisioned by Congress for the two subsections are reflected in the punishments Congress allotted to their violation. According to
.