Fourth Circuit Narrows CFAA in Employee Data Breach Cases

How a major appellate ruling limited CFAA claims against employees who misused data they were allowed to access.

By Sneha Tete, Integrated MA, Certified Relationship Coach
Created on

When Employee Misuse Is Not Computer Fraud

The Computer Fraud and Abuse Act, or CFAA, is often described as the federal law that targets hacking. In practice, however, employers have sometimes tried to use it against departing employees who copied, moved, or misused company information. The Fourth Circuit rejected that broader approach, holding that the statute does not reach every form of workplace data misuse simply because a computer was involved.

That distinction matters. If a worker was allowed to see the information in the first place, the CFAA is usually not the right tool for the employer, even if the employee later acts disloyally or violates internal policies. The decision helped define a boundary between unauthorized access and unauthorized use, and that boundary continues to shape employee-dispute litigation.

The legal question behind the dispute

The core issue was whether an employee who had permission to access business information could violate the CFAA by later taking that information for an improper purpose. The Fourth Circuit answered no, concluding that the statute’s phrases “without authorization” and “exceeds authorized access” do not cover mere misuse of information that an employee was entitled to obtain at work.

In other words, the law focuses on access, not motive. If access was granted, the employee’s bad intent or breach of company policy does not automatically transform the conduct into a CFAA violation. That reading placed the Fourth Circuit in line with the Ninth Circuit’s narrower view of the statute.

How the court read the CFAA

The CFAA is aimed at people who access a protected computer without permission or go beyond the information they are allowed to obtain. The Fourth Circuit explained that “exceeds authorized access” refers to obtaining or altering information that a person is not entitled to reach, not to using properly accessed information for an improper reason.

This interpretation matters because many workplace disputes involve employees who were authorized to use company systems during their employment. If the employee could lawfully open the files, view the database, or download the material as part of the job, the later misuse of that information is usually a matter for trade secret law, contract law, or state unfair-competition claims rather than the CFAA.

Why the ruling was important for employers

For employers, the decision narrowed one possible litigation pathway. A company that discovers a departing employee has copied customer lists, pricing data, or internal strategy documents may want a federal computer-fraud claim. But under the Fourth Circuit’s approach, that claim is unlikely to succeed if the employee had permission to access the information before leaving.

The ruling does not leave employers without remedies. It simply means the CFAA is not a catch-all misappropriation statute. Employers may still pursue claims under trade secret laws, breach of confidentiality agreements, conversion theories where available, or other state-law causes of action depending on the facts.

How the Fourth Circuit fit into a larger national debate

The Fourth Circuit’s decision did not arise in isolation. Other courts had already begun rejecting an expansive reading of the CFAA, warning that turning the statute into a broad employee-misconduct law would stretch it beyond its anti-hacking purpose. The Ninth Circuit had taken a similar position, and later the Supreme Court would also embrace a limited reading in a different CFAA context.

This broader judicial trend reflects a concern about overcriminalizing ordinary workplace misconduct. If every violation of a computer-use policy became federal computer fraud, the line between poor judgment and federal liability would become uncomfortably thin. The Fourth Circuit’s approach preserved a more traditional distinction: hacking cases belong under the CFAA, while misuse of lawfully accessed information is usually addressed elsewhere.

Practical effects of the ruling

Issue Effect of the Fourth Circuit’s approach
Employee had permission to access the data CFAA claim is usually weak or unavailable.
Employee used data in violation of company policy Policy violation alone does not create CFAA liability.
Employee accessed areas of a system off-limits to them CFAA may still apply if access truly exceeded permission.
Employer wants to protect trade secrets Other legal remedies may be stronger than the CFAA.

This framework encourages employers to think carefully about how systems are structured and who can reach sensitive files. The more clearly access permissions are limited, the easier it becomes to identify conduct that truly goes beyond authorized access.

What employers can do instead

Companies concerned about insider misuse should focus on prevention and documentation. Clear access controls, password management, role-based permissions, and exit procedures can reduce the chance that an employee will leave with sensitive information.

  • Restrict sensitive files to employees who genuinely need them.
  • Use written confidentiality and data-use policies.
  • Track downloads, transfers, and external sharing activity.
  • Separate access rights from broad company-wide permissions.
  • Preserve audit logs before and after a resignation or termination.

These measures matter because they help establish whether an employee merely misused information or actually crossed an access boundary. The latter is far more likely to support a CFAA claim.

Why the distinction between access and use matters

The difference between access and use is central to the decision. Access concerns whether someone was entitled to open the file or enter the database. Use concerns what the person did with the information afterward.

That separation may sound technical, but it has major practical consequences. A sales employee who lawfully views a customer list but later emails it to a competitor may have engaged in wrongdoing, yet the CFAA may not apply if the employee was allowed to see the list in the first place. The court’s reasoning keeps the statute focused on unauthorized entry rather than every later abuse of legitimate access.

How later Supreme Court guidance reinforced the trend

Years after the Fourth Circuit’s ruling, the Supreme Court also took a narrower view of the CFAA in a case involving authorized access to a database. The Court explained that the statute targets access to parts of a computer system that are off-limits, not misuse of information that the person was otherwise allowed to obtain.

That later guidance is important because it shows the Fourth Circuit’s approach was not an outlier. Instead, it was part of a growing judicial consensus that the CFAA should not be converted into a general-purpose remedy for employee dishonesty. Employers still have legal options, but the federal anti-hacking statute is not designed to police every bad act in the workplace.

Frequently asked questions

Does the CFAA apply any time an employee steals data?

No. Under the Fourth Circuit’s approach, the CFAA usually does not apply if the employee was authorized to access the information, even if the employee later misused it.

Can a company still sue a departing worker who copied files?

Yes. A company may still have claims under trade secret laws, confidentiality agreements, or other state-law theories depending on the facts.

What if the employee accessed files they were never allowed to see?

That is different. The CFAA may apply when a person reaches information or system areas that are outside their permission set.

Is breaking a company policy the same as violating the CFAA?

No. The court’s reasoning separates policy violations from unauthorized access. A policy breach alone is not enough to establish CFAA liability if access itself was permitted.

Why do courts hesitate to read the CFAA broadly?

Courts have worried that a broad reading would turn the CFAA into a sweeping misappropriation statute and expose ordinary workplace conduct to federal liability.

What the ruling means for compliance teams

Compliance professionals should treat the decision as a reminder to build systems that define access with precision. If every employee can reach every file, it becomes harder to argue that later misuse involved unauthorized access. If access is segmented and monitored, the organization is in a stronger position to respond when someone truly goes beyond their role.

The practical lesson is straightforward: use the right legal tool for the right problem. The CFAA is best suited to genuine intrusion, credential misuse, or access to protected areas of a system. It is less effective when the issue is an insider who lawfully viewed information and later used it for the wrong reason.

References

  1. Fourth Circuit Holds CFAA Does Not Bar Employee’s Misappropriation of Business Information When Employee Was Authorized to Access Information Initially — Infolaw Group. 2012-08-01. https://www.infolawgroup.com/insights/2012/08/articles/computer-fraud-and-abuse-act-c/fourth-circuit-holds-cfaa-does-not-bar-employees-misappropriation-of-business-information-when-employee-was-authorized-to-access-information-initially
  2. Fourth Circuit Adopts “Narrow Reading” of Authorization under the Computer Fraud and Abuse Act — Trade Secrets and Employee Mobility. 2012-08-01. https://www.tradesecretsandemployeemobility.com/fourth-circuit-adopts-narrow-reading-of-authorization-under-the-computer-fraud-and-abuse-act
  3. Fourth Circuit Limits Scope of Employers’ Claims Under Computer Fraud and Abuse Act — Smith Anderson. 2012-08-01. https://www.smithlaw.com/newsroom/publications/Fourth-Circuit-Limits-Scope-of-Employers-Claims-Under-Computer-Fraud-and-Abuse-Act
  4. Noncompete News: Ninth Circuit Holds Employee Data Theft is Not Punishable Under the CFAA After All — FordHarrison. 2012-08-01. https://www.fordharrison.com/noncompete-news-ninth-circuit-holds-employee-data-theft-is-not-punishable-under-the-cfaa-after-all-1
  5. SCOTUS Resolves Circuit Split, Limits the Scope of the Computer Fraud and Abuse Act — K&L Gates. 2021-06-07. https://www.klgates.com/SCOTUS-Resolves-Circuit-Split-Limits-the-Scope-of-the-Computer-Fraud-and-Abuse-Act-6-7-2021
  6. U.S. Supreme Court Will Finally Weigh In on Scope of Computer Fraud and Abuse Act — Jackson Lewis. 2017-03-03. https://www.jacksonlewis.com/insights/us-supreme-court-will-finally-weigh-scope-computer-fraud-and-abuse-act
Sneha Tete
Sneha TeteBeauty & Lifestyle Writer
Sneha is a relationships and lifestyle writer with a strong foundation in applied linguistics and certified training in relationship coaching. She brings over five years of writing experience to waytolegal,  crafting thoughtful, research-driven content that empowers readers to build healthier relationships, boost emotional well-being, and embrace holistic living.

Read full bio of Sneha Tete