Andrew Auernheimer revealed a security flaw in AT&T's iPad user database, allowing him to scrape data from 114,000 iPad users. Auernheimer immediately went to the press with this information, and emailed some of the people whose email addresses were obtained. Auernheimer did nothing else with the information. At trial there was no evidence of any harm to anyone except for the allegation that AT&T was embarrassed by its failure to protect what it claimed was confidential information.
Auernheimer was convicted on conspiracy to access a computer without authorization (18 U.S.C. § 1030(a)(2)(C), part of the Computer Fraud and Abuse Act of 1986) and fraud in connection with personal information (18 U.S.C. § 1028(a)(7)) and sentenced to 41 months in prison, plus 3 years supervised probation.



