Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058 (9th Cir. 2016), amending and superseding 828 F.3d 1068 (9th Cir. 2016) was decided by the United States Court of Appeals for the Ninth Circuit on July 12, 2016 (No. 13-17102, 13-17154). The Ninth Circuit held that after receiving the 1 December 2008 written notice, Power accessed Facebook's computers 'without authorization' and was liable under the CFAA. It also held that the messages were not materially misleading, so there was no CAN-SPAM violation, and it affirmed in part, reversed in part and remanded. Facebook satisfied the loss threshold through staff time spent analysing and responding to the campaign.
The question before the court
Does a platform's cease-and-desist letter and IP block revoke authorisation under the CFAA, so that continued automated access is 'without authorization' even though the platform's own users consented to the defendant acting on their accounts?
The governing rule
18 U.S.C. § 1030(a)(2)(C) creates criminal and civil liability for one who 'intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer.' A civil claim runs under § 1030(g) to any person suffering damage or loss, subject to a $5,000 loss threshold over one year — codified at § 1030(c)(4)(A)(i)(I), which § 1030(g) incorporates. 'Loss' is defined at § 1030(e)(11) to include the reasonable cost of responding to an offence and conducting a damage assessment. The court drew its authorisation rules from LVRC Holdings LLC v. Brekka, 581 F.3d 1127 (9th Cir. 2009), and United States v. Nosal, 676 F.3d 854 (9th Cir. 2012) (en banc). Parallel claims arose under the CAN-SPAM Act, 15 U.S.C. §§ 7704(a)(1), 7706(g)(1), and California Penal Code § 502.
How the court applied it
The court distilled two rules from its earlier cases. A defendant may violate the CFAA where he never had permission or where permission has been explicitly revoked, and once revoked, neither technical evasion nor the recruitment of a third party excuses the continued access. But breach of a website's terms of use, standing alone, cannot create liability. Applying those rules, the panel found Power's initial access at least arguably authorised: users who clicked 'Yes, I do!' had done something like lending a friend a login, and Power could reasonably have read that as permission. Everything changed on 1 December 2008, when Facebook sent a written cease-and-desist demanding that Power stop soliciting user information and interacting with Facebook through automated scripts, then imposed IP blocks. Power switched IP addresses and carried on. The court relied on Power's own litigation admission that it took and used Facebook data without permission after that notice, and on contemporaneous internal emails discussing the blocks and how to evade them. The court explained the result through an analogy: a person lent a key to a friend's safe deposit box still needs the bank's permission to walk its premises, and being banned ends that permission whatever the friend says.
What the court concluded
The Ninth Circuit held that after receiving the 1 December 2008 written notice, Power accessed Facebook's computers 'without authorization' and was liable under the CFAA. It also held that the messages were not materially misleading, so there was no CAN-SPAM violation, and it affirmed in part, reversed in part and remanded. Facebook satisfied the loss threshold through staff time spent analysing and responding to the campaign.
From the opinion
- “Once permission has been revoked, technological gamesmanship or the enlisting of a third party to aid in access will not excuse liability.” — First of the two general rules the panel distilled from Brekka and Nosal I before applying them to Power.
- “a violation of the terms of use of a website—without more—cannot establish liability under the CFAA” — Second of the two general rules, drawn from the en banc decision in Nosal I.
- “Permission from the users alone was not sufficient to constitute authorization after Facebook issued the cease and desist letter.” — Conclusion of the safe deposit box analogy, explaining that access required permission from both the user and the platform.
Why it matters for cyber conflict
The case sets the point at which a platform can unilaterally turn a tolerated automated collector into an unauthorised intruder, and holds that switching addresses to defeat a block is evidence of knowledge rather than a defence. That matters directly to platform countermeasures against influence operations and bulk collection, where the operator's cooperating users are the very channel being used.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: Facebook, Inc. v. Power Ventures, Inc. on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on Private Sector · All case notes · Peer-reviewed scholarship