Feeds

US appeals court cans CAN-SPAM suit

A farewell to litigation factories

Top three mobile application threats

In a decision that could make it harder for internet users to take spammers to court, a federal appeals court has upheld the dismissal of a lawsuit against a company that sent a man more than 13,000 unsolicited emails.

A three-judge panel from the Ninth US Circuit Court of Appeals agreed with a lower-court judge that under a federal law that went into effect in 2004, plaintiff James S. Gordon Jr. lacked standing to sue online marketing business Virtumundo. The panel ruled that under the Controlling the Assault of Non-Solicited Pornography and Marketing, or CAN-SPAM, act, lawsuits can only be brought by select law-enforcement agencies and providers of an IAS, or "internet access service."

The judges went on to dismiss claims Gordon brought under a separate Washington-state law forbidding deceptive commercial emails, holding that that CAN-SPAM preempted the law. The state statute allowed private individuals to sue people who send them deceptive marketing emails that were unsolicited. The net effect, legal experts said, is that internet users will have fewer options for taking legal action against spammers.

"It is going to be harder for individuals to sue companies that send them spam because trying to shoehorn a claim under statutes prohibiting deception will be looked on by courts with skepticism," said Dave Kramer, an attorney at Wilson Sonsini Goodrich & Rosati who helped draft the Washington law.

Critics have long complained that CAN-SPAM was full of so many loopholes that it had little effect on the torrent of spam that lands in inboxes everyday. The Ninth Circuit's decision is only likely to strengthen those claims. It will set a higher bar for individuals who want to invoke it in lawsuits. Specifically, they will have to show they are an IAS and will then have to show they faced significant harm as a result of receiving spam.

When Gordon brought the suit in 2006, he was already a fixture in state in federal courts, which he peppered with lawsuits against spammers. He made it a habit to send spammers responses demanding they cease their junkmail campaign and demanding $500 for any repeat offenses. He also set up multiple email accounts on behalf of friends and family members and monitored them for unsolicited messages.

Gordon told the court he had collected more than 13,800 junk messages.

This has led to criticism that Gordon is a "professional plaintiff" who opportunistically milks anti-spam laws for his own personal gain. Those points weren't lost on US Appeals Court Judge Ronald M. Gould.

"For a person seeking to operate a litigation factory, the purported harm is illusory and more in the nature of manufactured circumstances in an attempt to enable a claim," he wrote in a concurring opinion. "In my view, manufactured claims should not be tolerated absent a clear endorsement from Congress."

A PDF of the decision is available here. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
Oracle working on at least 13 Heartbleed fixes
Big Red's cloud is safe and Oracle Linux 6 has been patched, but Java has some issues
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.