United States v. David Nosal, 828 F.3d 865 (9th Cir. 2016), amended and superseded on denial of rehearing en banc, 844 F.3d 1024 (9th Cir. 2016) was decided by the United States Court of Appeals for the Ninth Circuit on July 5, 2016 (No. 14-10037, 14-10275). The Ninth Circuit affirmed Nosal's conspiracy and § 1030(a)(4) convictions along with the Economic Espionage Act convictions, and vacated and remanded part of the restitution order for reconsideration of the attorneys' fees award. 'Without authorization' is unambiguous and means accessing a protected computer without permission. A revocation of access closes the back door as well as the front, so borrowed credentials from a cooperative insider do not restore authorisation.
The question before the court
Does a person act 'without authorization' under 18 U.S.C. § 1030(a)(4) when, after the computer owner has revoked his credentials, he re-enters the system using the login credentials of a current employee who lends them to him?
The governing rule
18 U.S.C. § 1030(a)(4) punishes whoever 'knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value.' Only the 'without authorization' prong was at issue. The court applied LVRC Holdings LLC v. Brekka, 581 F.3d 1127 (9th Cir. 2009), which construed 'authorization' under §§ 1030(a)(2) and (a)(4) as 'permission or power granted by an authority' turning on actions taken by the computer's owner. Nosal I, 676 F.3d 854 (9th Cir. 2012) (en banc), had separately held that the 'exceeds authorized access' prong does not reach violations of an employer's use restrictions. Trade secret counts arose under the Economic Espionage Act, 18 U.S.C. § 1831 et seq.
How the court applied it
The court separated the two prongs of § 1030(a)(4). The counts dismissed in Nosal I concerned employees who still held their own credentials and merely broke company use policy; those counts were gone and the government did not revive them. What remained were three occasions after Korn/Ferry had revoked the credentials of Nosal, Christian and Jacobson, when Christian and Jacobson logged in using credentials borrowed from FH, an assistant who stayed on at Nosal's request. Because the CFAA does not define authorization, the court took the ordinary meaning drawn in Brekka and corroborated by Black's Law Dictionary, the Oxford English Dictionary, and the more than 400 undefined uses of 'authorize' and its cognates in Title 18. Implicit in that meaning is that some identified entity grants and revokes permission. Korn/Ferry owned and controlled the Searcher database and kept exclusive discretion over access to it; FH held no delegated power to restore access the company had cancelled. Once revoked, Nosal and his co-conspirators were outsiders rather than insiders exceeding limits. The court also rejected the dissent's focus on FH's own authority, reasoning that collapsing her authorisation into theirs would exempt any intrusion conspiracy that recruits a cooperative person inside the target.
What the court concluded
The Ninth Circuit affirmed Nosal's conspiracy and § 1030(a)(4) convictions along with the Economic Espionage Act convictions, and vacated and remanded part of the restitution order for reconsideration of the attorneys' fees award. 'Without authorization' is unambiguous and means accessing a protected computer without permission. A revocation of access closes the back door as well as the front, so borrowed credentials from a cooperative insider do not restore authorisation.
From the opinion
- “once authorization to access a computer has been affirmatively revoked, the user cannot sidestep the statute by going through the back door” — Opening summary of the holding, immediately after the court defines 'without authorization' as accessing a protected computer without permission.
- “FH had no mantle or authority to give permission to former employees whose access had been categorically revoked by the company” — Analysis section, explaining that the entity controlling the system, not a current employee, holds the power to grant or revoke access.
- “it would remove from the scope of the CFAA any hacking conspiracy with an inside person” — Response to Judge Reinhardt's dissent, on the consequence of treating the insider's authorisation as the outsiders' own.
Why it matters for cyber conflict
Intrusions run through a recruited or compromised insider are the standard pattern in espionage and state-linked operations, and this decision holds that credentials passed on by someone still inside do not launder an outsider's revoked access. It also fixes the ordinary-meaning reading of 'without authorization' that the Ninth Circuit later carried into disputes over scraping and platform access.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: United States v. David Nosal on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on Private Sector · All case notes · Peer-reviewed scholarship