Third Circuit's Decision Limits Employers' Ability to Pursue Claims Under the Computer Fraud and Abuse Act
The United States Court of Appeals for the Third Circuit has issued a significant decision in NRA Group, LLC v. Durenleau et al., limiting employers' ability to pursue claims under the Computer Fraud and Abuse Act (CFAA) against current employees who violate company computer-use policies. The decision, handed down on August 26, 2025, holds that violating a company's computer-use policy does not, in and of itself, constitute a claim under the CFAA absent evidence of code-based hacking. The court also concluded that passwords disclosed by employees were not trade secrets under state and federal law because they lacked independent economic value.
Key Takeaways:
- The CFAA does not countenance claims premised on a breach of workplace computer-use policies by current employees absent evidence of code-based hacking.
- The court's definition of "authorized access" under the CFAA emphasizes that an employee is authorized to access a computer when their employer approves or sanctions their admission to that computer.
- The court rejected the notion that a company's computer-use policies are a substitute for CFAA claims, citing the statute's purpose to target hackers and curb malicious behavior.
- Employers may still pursue claims for violations of computer-use policies through alternative causes of action, such as breach of contract, business torts, fraud, and negligence.
- Passwords are not considered trade secrets under state and federal law if they lack independent economic value, which may be determined by factors such as their derivation from a formula or algorithm.
- Employers can still protect their confidential information and business interests through well-crafted confidentiality provisions and strong internal protocols.
Statistics:
- The CFAA is a federal law that prohibits individuals from accessing computers without authorization or exceeding their authorized access, carrying civil and criminal penalties.
- The court's decision affects employers in Delaware, New Jersey, Pennsylvania, and the U.S. Virgin Islands.
- The NRA Group LLC decision limits employers' ability to pursue claims under the CFAA against current employees who violate company computer-use policies.
Sources:
- NRA Group, LLC v. Durenleau et al., 3rd Cir., 2025.
- 18 U.S.C. § 1030 (Computer Fraud and Abuse Act).
- Van Buren v. United States, 593 U.S. 374, 396 (2021).
- 18 U.S.C. § 1839(3) (Defend Trade Secrets Act).
- 12 Pa. Cons. Stat. § 5302 (Pennsylvania Uniform Trade Secrets Act).
- Mondaq Ltd, 2025 - Tel. +44 (0)20 8544 8300 - http://www.mondaq.com.