Sewell v. Bernardin
- Court
- Court of Appeals for the Second Circuit (Federal circuit court)
- Decided
- 2015
- Citation
- 795 F.3d 337 (2d Cir. 2015)
- Standard applied
- CFAA § 1030(g) and SCA § 2707(f) limitations periods
What the court held
Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of the particular violation, and that unauthorised access to separate accounts gives rise to separately accruing claims. Claims about the plaintiff's e-mail account, whose compromise she discovered more than two years before suit, were time-barred, while claims about her social-media account, discovered later, were timely.
Why
The CFAA's civil provision requires suit within two years of the act complained of or the discovery of the damage, and the SCA within two years of when the claimant first discovered or had a reasonable opportunity to discover the violation. Because the plaintiff discovered the two account compromises about six months apart, the clock on each began when she found she could not log in to that account.
Our reading — not the court’s words
Why this matters in practice
This is the case that decides whether a computer-intrusion claim is alive, and it turns on a date an examiner is often best placed to establish: when the victim first could not log in, or first had reason to know. Practically it means that in a multi-account intrusion the accounts have to be analysed separately rather than treated as one episode. Preserving the evidence of discovery — password-reset notices, provider security alerts, support tickets — matters as much as the intrusion artefacts themselves.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · Stored Communications Act · limitations · account compromise
Cited 91times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on privacy & surveillance and computer-crime statutes
- United States v. JonesSupreme Court of the United States · 2012Attaching a GPS tracking device to a vehicle and using it to monitor the vehicle's movements constitutes a search within the meaning of the Fourth Amendment. Th…
- Riley v. CaliforniaSupreme Court of the United States · 2014Police generally may not search the digital contents of a cell phone seized incident to an arrest without a warrant. The search-incident-to-arrest exception, wh…
- Carpenter v. United StatesSupreme Court of the United States · 2018The government's acquisition of historical cell-site location information from a wireless carrier is a Fourth Amendment search, and generally requires a warrant…
- Snow v. DirecTV, Inc.Court of Appeals for the Eleventh Circuit · 2006A complaint alleging that a company and its lawyers accessed the plaintiff's electronic bulletin board without authorisation failed to state a claim under the S…
- United States v. WarshakCourt of Appeals for the Sixth Circuit · 2010A subscriber has a reasonable expectation of privacy in the contents of e-mails stored with, or sent or received through, a commercial internet service provider…
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.