A MySpace Rule Became a Federal Charge. The Conviction Failed.
The failed prosecution of Lori Drew shows the route from a platform checkbox to a criminal courtroom, and the limit courts placed on turning private rules into public law.
August 22, 2026 · 8 min read

The object at the center of United States v. Drew was mundane even by internet standards: a checkbox beneath MySpace’s terms of service. In 2006, Lori Drew and others created a fictional profile for “Josh Evans,” presented as a teenage boy, to communicate with 13-year-old Megan Meier. The account used false registration information and became part of a cruel deception preceding Meier’s death by suicide.
The conduct caused real harm. The legal problem was different. Federal prosecutors in California needed a federal offense, and no statute made creating a fake social profile the crime they wanted to charge. Their answer was the Computer Fraud and Abuse Act, or CFAA, the federal anti-hacking law that punishes certain access to computers without authorization or beyond authorized access.
MySpace prohibited false registration information and harmful use of material obtained through the site. Prosecutors argued that violating those terms withdrew MySpace’s authorization, which turned ordinary website access into unauthorized access under the CFAA. A private rule, accepted through that checkbox, supplied a boundary for a criminal statute.
That theory won misdemeanor verdicts from a jury. It did not survive the trial judge, who entered judgments of acquittal in 2009. If a website could define criminal authorization through sprawling terms that it wrote and changed itself, the court reasoned, millions of users could become federal offenders without fair notice of where the criminal line sat.
The checkbox mattered. It just could not do all the work prosecutors assigned to it.
Private rules are cheap law
A platform’s terms govern the relationship between the company and the account holder. Depending on how users accepted them and what state law allows, those terms may operate as a contract. The company can suspend an account, remove material, cut off access or pursue a civil claim. None of those actions requires a criminal conviction.
Criminal law comes from legislatures, carries defined elements and must satisfy constitutional demands such as due process. A platform cannot add a new offense to the criminal code by editing its community guidelines on Tuesday afternoon. That is the binding distinction.
Evidence follows another route. A terms violation can enter a criminal case without becoming the charged crime. It may help establish that a defendant controlled an account, understood a restriction, concealed an identity or continued accessing a system after permission had been revoked. Messages can show intent.
Login records can place activity in a sequence. A moderation notice can prove that the person received a warning before acting again.
Prosecutors still need a statute. Fraud requires its own elements. Threat and stalking laws require theirs. The CFAA requires proof about access, not a general showing that someone behaved badly online.
The platform record bridges facts to those elements, but the bridge is not the destination.
Drew exposed what happens when prosecutors reverse that order. The government began with a disturbing episode, found the MySpace rule that described part of it, then treated the breach of that rule as the authorization element of a hacking charge. The terms stopped being supporting material and became the engine of criminal liability.
That was too much delegated power for one checkbox.
How a moderation file reaches court
Platforms produce records for their own purposes long before police arrive. They log account creation, device and network information, reports from other users, deleted posts, internal enforcement decisions and notices sent to the account holder. A ban can leave a particularly useful trail because it establishes a before and after: the company withdrew access, told the user, and recorded any attempt to return.
Investigators may obtain basic subscriber records through legal demands and seek message content with a warrant. A preservation request tells the company to retain existing data while investigators pursue the required court order. Platforms also make some reports voluntarily, especially where federal law imposes reporting duties for apparent child sexual abuse material.
The platform’s compliance operation performs part of the early sorting. It stores the data, labels the account and packages responsive records. Law enforcement benefits from infrastructure funded and designed by a private company, while the person whose account generated the file generally cannot inspect the platform’s internal reasoning until litigation, if disclosure happens at all.
A prosecutor then has to authenticate the records, meaning show that they are what the government claims. Business records from the platform may establish how the system captured a login or sent a notice. A user’s own messages can often be offered against that user, although account ownership still needs proof. An IP address alone does not identify the hands on a keyboard.
A profile name alone is worse.
Admissibility does not make the platform’s conclusion true. “Violative” is a moderation category, produced under private standards with no criminal burden of proof. Automated detection can be wrong. Reports can be malicious.
A ban may combine several suspected violations without identifying which one triggered enforcement. The prosecution can introduce the surrounding records, but a criminal court does not owe deference to the trust and safety label.
Revocation carries more weight than fine print
Later computer-access cases drew a harder line between breaking a use policy and entering somewhere permission no longer reaches.
In United States v. Nosal, a former employee of the executive search firm Korn Ferry was prosecuted after people working with him obtained information from the company’s database. The litigation produced several appellate decisions, but the durable distinction was practical: violating an employer’s limits on how information may be used is different from accessing its system after credentials and permission have been revoked.
The same distinction appeared in United States v. Valle, the prosecution of a New York police officer who used a restricted law-enforcement database for personal reasons. The Second Circuit reversed his CFAA conviction in 2015 because he had permission to access the database, even though his purpose violated department rules. Misuse was evidence of misconduct.
It did not convert permitted entry into hacking under that court’s reading of the statute.
The Supreme Court made the boundary nationally important in Van Buren v. United States in 2021. A police officer had accessed license-plate information for an improper purpose, violating department policy, but he was entitled to retrieve that category of information through his account. The Court rejected a CFAA interpretation that would make criminal liability turn on purpose restrictions covering everyday computer use.
That ruling is binding on federal courts interpreting the relevant CFAA language. It does not erase terms of service from criminal cases. It limits one prosecutorial move: treating misuse of information that a person was allowed to access as exceeding authorized access merely because a policy forbade the reason.
A clear ban notice can still matter more than page 47 of standard terms. It can show that access was withdrawn, which supports an unauthorized-access theory if the person returns through another credential or technical route. It can also help prove knowledge. The notice is evidence of a closed gate, not legislation written by a moderation team.
Platforms can become the first search layer
United States v. Ackerman shows a related route. AOL’s automated system detected a known child sexual abuse image attached to an email, terminated the account and sent a report containing the email and attachments to the National Center for Missing and Exploited Children. NCMEC then examined the material and referred it to law enforcement.
The Tenth Circuit ruled in 2016 that NCMEC counted as a governmental entity for Fourth Amendment purposes and that expanding the inspection beyond what AOL’s system had examined raised a constitutional search problem. The case did not make AOL’s policy the criminal law. It showed how private enforcement can generate the first investigative package, with constitutional limits attaching as government actors take over.
This is the mechanism that disappears when a charging document describes platform records as if they arrived from nowhere. The company detects and classifies. Its enforcement action preserves a chronology. Police obtain or receive the file.
Prosecutors select parts that map onto a statute. Defense lawyers challenge the search, the account attribution or the leap from a policy label to criminal intent.
Each institution applies a different standard, but the records move easily between them. That asymmetry works for prosecutors. Platforms can remove an account under broad rules and limited process; the government can later present the resulting trail while insisting that the criminal charge rests on an independent law. Sometimes it does.
Drew is the warning about the moment it does not.
The fictional “Josh Evans” profile remains useful because the harm, the policy breach and the federal offense were never interchangeable. MySpace could prohibit the account. A jury could consider records showing who created and used it. The government still could not let MySpace’s checkbox decide what counted as a federal computer crime.
Questions people ask
Is violating terms of service a crime?
Usually, no. Terms of service are private rules that may support account enforcement or a civil dispute. Criminal liability requires a statute whose elements fit the conduct. A policy violation can supply evidence relevant to those elements, but it does not create an offense merely because the user clicked “agree.”
Can prosecutors use an account ban as evidence?
Yes, if the record is obtained lawfully, authenticated and relevant. A ban notice may show that access was revoked or that a person knew about a restriction before returning. The platform’s decision does not prove guilt, and courts can still exclude unreliable or unfairly prejudicial material.
Does a fake profile count as hacking?
A fake profile may violate platform rules and may support charges under other laws when the conduct satisfies their elements. After Drew and the Supreme Court’s narrower CFAA interpretation in Van Buren, false information or improper purpose alone does not automatically turn permitted website access into federal hacking.
What is the difference between platform evidence and platform judgment?
Platform evidence includes messages, login records, notices and moderation history that can help establish events. Platform judgment is the company’s conclusion that an account violated its rules. A criminal court may consider the underlying records, but it must apply public law and the criminal burden of proof rather than adopting the company’s label.
One update a day
Today's story, in your inbox
One story each morning — no hype, no filler, no algorithm deciding for you.



