As hacking hits the headlines, steps can be taken to prosecute over stolen emails
"The passwords to the claimant's email accounts had been obtained in July 2008 through the services of a group based in China called (remarkably) 'The Invisible Hacking Group'..." - Skadden on what English law can offer hacking victims
December 07, 2011 at 07:03 PM
6 minute read
Skadden litigation and international arbitration duo on the support that English law can offer hacking victims
There is no doubt that email hacking poses a very real threat both to individuals and to corporations. The recent case of Bassam Alghanim v Steven McIntyre & Ors [2011] is a useful reminder of the ease with which email hacking can occur, but also the steps that a hacking victim can take to uncover the unlawful activity and secure relief.
In August 2009, a routine Google search by one of the claimant's employees identified a file transfer protocol (FTP) website that contained a large number of private and confidential emails (arranged in PDF batches), which had been stolen from two of the claimant's private AOL email accounts. The specific emails that had been targeted were those that included legal advice from the claimant's lawyers regarding ongoing disputes (among other things), confidential information relating to the claimant's personal finances and confidential medical information.
The process of uncovering precisely what had happened required close co-operation between the claimant's lawyers and an IT forensics firm. On the basis of the stolen email batches discovered on the FTP site (and additional batches found in the Google cache for the site), we obtained a third-party disclosure order for disclosure of the site's data logs against the English Internet Service Provider (ISP) responsible for hosting the FTP site. In addition, with the claimant's consent, AOL provided the access logs for both email accounts. A forensic review of this material identified a number of IP addresses in the UK, which, in turn, led to further third-party disclosure orders against additional English ISPs to reveal who was behind those IP addresses.
Within a matter of weeks the IT firm had tracked the timeline for each batch of stolen emails, starting from the time the emails were unlawfully accessed up until the time that they were downloaded from the FTP site and viewed. As a result, it was possible to pinpoint which IP addresses were involved and responsible for each step of the hacking scheme.
Responsibility for the hacking and uploading was ultimately traced back to certain individuals and companies in England, and the forensic evidence was sufficiently clear (as was the risk that relevant evidence might be destroyed) that the court agreed to grant search and seizure orders in relation to three separate properties (two commercial and one domestic).
As the details of the story were gradually pieced together, the full scale of the hacking operation became clear. The passwords to the claimant's email accounts had been obtained in July 2008 through the services of a group based in China called (remarkably) 'The Invisible Hacking Group' (a fee of £265 had been paid for each password). Between July 2008 and August 2009, approximately 20 pages of stolen emails had been posted to the FTP site every two to three days. The site had been deliberately set up so as to ensure that it would not appear on any Google searches; in fact, the only reason why the site was discovered in August 2009 was because the defendants had accidentally activated the Google Analytics function in the site's control panel.
The evidence also indicated that the hacking scheme had been done on the instructions of the claimant's nephew acting on behalf of the claimant's brother, Kutayba Alghanim (with whom the claimant was involved in a dispute). Indeed, as Mr Justice Smith concluded, "the evidence shows that the whole operation was done at the behest of the Kutayba camp… who orchestrated the campaign and I do not accept that there is any realistic possibility of them establishing, on the material before me, that they were innocent as to the modus operandi of the people who got the emails on their behalf. One cannot see this material, read it and use it and have any credible belief that it is being obtained honestly".
The claim itself comprised three causes of action: breach of confidence, unlawful means conspiracy and infringement of copyright (in respect of the emails authored by the claimant and those authored on his behalf). On the facts, there was little doubt that the claim for breach of confidence fell squarely within the approach taken by the Court of Appeal in Imerman v Tchenguiz [2010]. Namely, that it is a breach of confidence for a person intentionally to obtain another person's information secretly and without authorisation, knowing that he reasonably expected it to be private, and, without that other person's authority, to examine or copy a document the contents of which were or ought to have been appreciated by the person who obtained it to be confidential to that other person.
The significance of the additional claim for copyright infringement was twofold: (i) the privilege against self-incrimination does not apply to proceedings for "infringement of rights pertaining to any intellectual property" (section 72 of the Senior Courts Act 1981); and (ii) the Courts have discretion to award additional damages for flagrancy (section 97(2) of the Copyright, Designs and Patents Act 1988).
In conclusion, if suspicious email activity is discovered, there are effective steps and remedies that are available under English law and the courts will fully support the victim with mechanisms and processes to detect who is responsible, preserve evidence and secure relief. In terms of relief, the Alghanim case is also an important reminder that in these types of claims it may be possible to quantify damages not on the usual compensatory measure, but on the basis of the defendant's gain; the claimant may ultimately elect for an account of the defendant's profits in lieu of compensatory damages.
Bruce Macaulay (pictured) is a partner and Ben Lasserson an associate at Skadden Arps Slate Meagher & Flom.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrump and Latin America: Lawyers Brace for Hard-Line Approach to Region
BCLP Mulls Merger Prospects as Profitability Lags, Partnership Shrinks
Trending Stories
- 1King & Spalding E-Discovery Director Jumps to Nebraska Women-Owned Firm
- 2Nation's Largest Utility Parts Ways With CLO Who Helped It Navigate Bribery Scandal
- 3Advocates Renew Campaign for Immigrant Right to Counsel in New York
- 4From ‘Unregulated’ to ‘A Matter of Great Concern’: PFAS Regulation under Biden
- 5Public Interest Lawyers in NY Fear Rollback of Federal Loan Assistance in '25, Ask Gov. to Add $4M to State Program
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250