top of page

The Computer Fraud and Abuse Act Turns Out Not to be an Effective Tool

  • paulnicolai5
  • May 26
  • 1 min read

The Computer Fraud and Abuse Act of 1986 (“CFAA”) targets computer-related fraud and activities, including unauthorized access to “protected computers” and data theft. It can impose civil and criminal liability for unauthorized or excessive access. Employers have attempted to use the CFAA against ex-employees for workplace policy violations, but success has been limited.

 

The Third Circuit Court recently ruled that an employer failed to prove a CFAA or Defend Trade Secrets Act (“DTSA”) violation. The lower court had ruled against the employees on all claims.

 

The Court clarified that employees, as authorized users, are not hacking if they access employer systems with approval. Without evidence of code-based hacking, the CFAA does not support claims of policy breaches by current employees.

 

Regarding the DTSA, the Court examined if a password spreadsheet had independent economic value as a trade secret. Since the passwords lacked any value, the Court concluded they were not trade secrets.

 

This decision greatly restricts the scope of the CFAA, especially if it spreads to other circuits.

Recent Posts

See All

Comments


bottom of page