Socialedge, Inc. v. Traackr, Inc.
- Paul Engelmayer
- 1:23-cv-06860
- U.S. District Court · Southern District of New York
- 13
Socialedge v. Traackr: Judge Engelmayer dismissed the Computer Fraud and Abuse Act claim because the alleged losses did not involve damage to the computer system; the remaining motion was withdrawn.
Socialedge, doing business as CreatorIQ, lost its Computer Fraud and Abuse Act claim at the pleading stage. Traackr, Inc. and Ben Staveley obtained dismissal of that claim. The other portions of defendants’ motion were treated as withdrawn rather than decided.
What happened
In Socialedge, Inc. v. Traackr, Inc., Socialedge, doing business as CreatorIQ, alleged that former employee Ben Staveley accessed its HubSpot account and shared confidential information with Traackr. Defendants moved to dismiss several claims, including CreatorIQ’s claim under the Computer Fraud and Abuse Act.
The court accepted the parties’ agreement to treat the common-law claims as arising under New York law. It therefore treated defendants’ arguments that California law preempted those claims as withdrawn. For the remaining claim, the court held that the complaint did not allege the type of computer-system damage or related loss required by the federal statute.
The court granted defendants’ motion to dismiss the Computer Fraud and Abuse Act claim and treated the balance of the motion as withdrawn. Judge Paul A. Engelmayer said the alleged investigation costs concerned identifying unauthorized access and assessing competitive harm, not repairing damage to the computer system itself.
The detailed version
- Socialedge, Inc. v. Traackr, Inc. · No. 1:23-cv-06860
- Paul Engelmayer
- Apr. 9, 2024
Background
Socialedge, doing business as CreatorIQ, alleged that its former employee, Ben Staveley, used access to confidential and proprietary information to provide trade secrets to Traackr, a competitor. The complaint alleged that Staveley had administrator credentials for CreatorIQ’s HubSpot account, exported more than 200,000 contact and company records before leaving his employment, and later used a separate account to access the HubSpot account without authorization on 12 occasions. It also alleged that Staveley shared CreatorIQ information with Traackr employees.
The amended complaint asserted 11 claims, including claims under the federal Defend Trade Secrets Act, the California Uniform Trade Secrets Act, state-law theories, breach of contract, and the Computer Fraud and Abuse Act (CFAA). Defendants moved under Rule 12(b)(6), which allows dismissal when a complaint does not adequately state a legal claim, against several state-law claims and the CFAA claim. The motion did not challenge the Defend Trade Secrets Act claim, the California trade-secrets claim, or the breach-of-contract claim.
The parties’ stipulation
In its opposition, CreatorIQ offered to withdraw its California-law common-law claims if defendants agreed that New York law applied to the common-law claims. Defendants agreed to the application of New York law for purposes of moving the case forward, while stating that they did not concede that the facts otherwise required applying New York law. Defendants then limited their reply to the CFAA claim.
The court accepted this as a stipulation. It treated all of the amended complaint’s common-law claims as arising under New York law and treated defendants’ motion to dismiss those claims based on preemption by the California Uniform Trade Secrets Act as withdrawn. The court did not decide the merits of those withdrawn portions of the motion.
CFAA claim
The CFAA permits a private civil claim in limited circumstances when a person intentionally accesses a protected computer without authorization or exceeds authorized access and causes a qualifying loss. For the claim at issue, CreatorIQ needed to allege more than $5,000 in qualifying loss.
The court explained that the CFAA defines loss to include reasonable costs of responding to an offense, conducting a damage assessment, restoring data or a system, and certain losses caused by an interruption of service. But those costs must relate to damage to the computer system itself. The court distinguished technological harm—such as impairment of a system, its data, or service—from business or competitive harm caused by obtaining or copying information.
The complaint alleged unauthorized access to CreatorIQ’s HubSpot account and export of confidential information. It did not allege that Staveley impaired HubSpot, CreatorIQ’s computer systems, or third-party cloud storage. The alleged harms were competitive injuries, not technological damage covered by the CFAA.
CreatorIQ argued that the cost of its forensic investigation supplied the required loss. The court rejected that argument because the complaint described an investigation into who accessed the account, what information was viewed or taken, and how the access occurred. It did not allege that the investigation concerned or uncovered damage to the computer system itself. The court therefore held that the CFAA claim was not adequately pleaded.
Disposition
The court granted defendants’ motion to dismiss the amended complaint’s CFAA claim and treated the balance of the motion to dismiss as withdrawn. It directed the court clerk to terminate all pending motions and stated that a separate order would schedule an initial pretrial conference.
Read the full 13-page opinion on CourtListener, the free public archive maintained by the Free Law Project.