
A federal law known as the FACE Act outlaws forcibly interfering with someone walking into an abortion clinic. But what if that interference happens online?
A new lawsuit alleges that when a cyberattacker targeted a national abortion group in 2016, they violated not only computer fraud laws but also the Freedom of Access to Clinic Entrances (or FACE) Act.
The attack affected not only national abortion funds, but <a href=”https://www.thestranger.com/slog/2016/04/21/23986082/anti-choice-hackers-attacked-a-local-abortion-fund-heres-how-you-can-help
“>Washington and Oregonโs abortion fund too. The National Network of Abortion Funds (NNAF) and local abortion funds around the country help people pay for abortions.
In April 2016, as the NNAF was preparing for its annual bowl-a-thon fundraiser, it was hit with a cyberattack. The group’s supporters received racist and anti-choice emails and the NNAF donation site received a flood of fake donations. The attack forced the national group to shut down its fundraising site. Here in Washington, the CAIR Project, which covered Washington, Idaho, and Alaska, saw a significant hit to donations when the site went down. At the time, the bowl-a-thon made up 40 percent of the CAIR Projectโs annual budget. The CAIR Project has since merged with Oregonโs fund to form the Northwest Abortion Access Fund (NWAAF). The NWAAF is now plaintiff on the cyberattack lawsuit.
The complaint alleges that the cyberattack directly affected the services abortion funds provide. โBy ransacking the single-most important abortion fundraiser of the year, Defendant(s) took away the ability to access abortions from the persons most in need of help,โ the complaint says.
The complaint names 15 John Does, most of them not identified. John Doe #1, however, was โprimarily responsible.โ The complaint alleges Joe Doe #1 is Matthew James Davis, a โreligious anti-abortion activist with a background in technology and codingโ believed to live in Florida. Davis allegedly owned a since-deleted Twitter account, @matthewjames. Davis did not return a request for comment.
According to the complaint, Davis set up a sham donation form that appeared on the NNAFโs website and was able to use that form to steal the names and contact information of thousands of bowl-a-thon participants and donors as well as 435 credit card numbers. He also allegedly sent racist and anti-choice emails to people who had registered for the bowl-a-thon event.
The complaint outlines the way the chaos unfolded over several days.
According to the complaint, NNAF used a company called Blue Sky Collaborative, which provides online fundraising applications for charities. In early April, someone put โmalicious codeโ in that fundraising application.
Soon, suspicious comments began showing up on the NNAFโs registration page for the bowl-a-thon and someone registered fundraising accounts with names like โadolph hitlerโ, โAdolph,โ and โhitlerโ [sic].
โThe next day the Bowl-a-Thon website began to display the receipt of absurdly large offline donations from registered participant accounts,โ the complaint says. โFor instance, one of these donations, from user qwerty, was for $999,999,999.00.โ
Soon, the @matthewjames Twitter account sent tweets congratulating NNAF on โpassing the $830 trillion markโฆ youโre gunna [sic] make little boys and girls a complete thing of the past!โ according to the complaint.
The NNAF site then received $66 billion in fake donations, including some from โAdolph [sic] Hitler,โ over several hours. That caused the site to crash, according to the complaint.
Some people who had registered for the bowl-a-thon then received an email from โAdolph Hitler.โ
โI believe that the Aryan race is the Master Race; the purest human genetic strain currently available,โ the email said, according to the complaint. โConsequently, it tickles me to fund abortions for the lower races, such as the Negroes and the Jews. There is no longer any need to send these parasites to my concentration camps โ they willingly slaughter their own young if given enough money to afford the ope [sic] I am indebted to feminism and this new opportunity it has provided to cleanse our future generations. Keep it up, NNAF!โ
Some registrants also received an email with a picture of a fetus that said, โI hope I grow up big enough to go bowling someday.โ
The interruption to fundraising, offensive emails to the groupโs supporters, and security breach meant โefforts and resources were redirected from fundraising to crisis management,โ the complaint says. National and local abortion funds โscrambled to find alternate means of accepting donations, acted to protect their donorโs private information, took preventive measures, and triaged their own reputational fallout from being victimized by an attack of this nature.โ
Rebounding from the attack took months of work and โhad profound and harmful effectsโ on the relationship between the national fund that organizes the fundraising event and the local funds that depend on the event for big shares of their budgets. In total, the attack cost NNAF $252,000 in legal and security costs, according to the complaint. The complaint says the Northwest Abortion Access Fund saw lower fundraising than in past years due to the attack and seven NWAAF donors had their credit card information stolen.
All of this violates the Computer Fraud and Abuse Act and the FACE Act relating to access to reproductive health services, the complaint alleges.
Because the FACE Act defines reproductive health services to include counseling and referrals, the case argues the abortion funds are covered by that law.
The โhacking and phishingโ and โcreation and distribution of racist and violent imageryโ interfered with the fundsโ ability to provide services, the complaint says.
Carrie Goldberg, who is representing the abortion funds, told CNN the FACE Act has not been applied to a hacking case before.
The suit was filed in U.S. District Court in Massachusetts and seeks a jury trial.
