The Unspoken Reality of Megan Taylor Meier: the Deception That Forever Altered Digital Safety
When local law enforcement unmasked the adults behind the fictitious Josh Evans account, public fury swept through St. Charles County. Yet local prosecutors quickly hit a wall. In 2006, Missouri's stalking and harassment statutes were rooted strictly in physical-world encounters, telephone calls, or direct postal threats. Investigators found that Drew had broken no local laws on the books. No existing statute prohibited an adult from lying about their identity on an open website to berate an adolescent.
Faced with state inaction, the U.S. Attorney's Office in Los Angeles, where MySpace servers were based, stepped in with a radical legal strategy. Federal prosecutors indicted Lori Drew under the Computer Fraud and Abuse Act (CFAA), a 1986 anti-hacking statute designed to combat digital espionage and unauthorized network access. The government argued that by creating a fictitious account, Drew had violated MySpace's terms of service, thereby accessing the servers without authorization.
In November 2008, a federal jury deadlocked on conspiracy charges but convicted Drew of three misdemeanor counts of unauthorized computer access. The verdict sent shockwaves through the tech and civil liberties sectors. Legal scholars warned that criminalizing violations of website terms of service would turn tens of millions of everyday internet users into federal criminals overnight.
In July 2009, U.S. District Judge Terry Hatter Jr. overturned the conviction entirely. In his ruling, Hatter determined that using a terms-of-service violation as the predicate for a federal criminal conviction was unconstitutionally vague under the void-for-vagueness doctrine. The decision left the public frustrated and legally empty-handed. Drew faced zero prison time, but the case highlighted the urgent need for tailored cyberstalking laws.