WEC Carolina Energy Solutions LLC v. Miller
- Court
- Court of Appeals for the Fourth Circuit (Federal circuit court)
- Decided
- 2012
- Citation
- 687 F.3d 199 (4th Cir. 2012)
- Standard applied
- CFAA § 1030 — “without authorization” and “exceeds authorized access”
What the court held
An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the bounds of his approved access. Because the former employee had authorised access to the material he downloaded, the employer failed to state a CFAA claim and dismissal was affirmed.
Why
Following Brekka, the court declined to read either CFAA phrase to cover misuse of information the employee was permitted to obtain, and refused to make a breach of a company computer-use policy a basis for federal liability. It acknowledged directly that its conclusion would disappoint employers hoping for a tool against rogue employees, but held that Congress had chosen to limit liability to access rather than use.
Our reading — not the court’s words
Why this matters in practice
WEC matters because of how candidly it states the trade-off: the narrow reading leaves genuine insider misappropriation to other causes of action. That is the conversation to have with a client early, because the forensic work that proves a CFAA claim and the work that proves trade-secret misappropriation are not the same work. Together with Brekka and Nosal I it formed the circuit majority that Van Buren ratified, which is why pre-2021 CFAA opinions from the other side of the split should be read with care.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · departing employee · computer-use policy
Cited 98times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.