Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled Feb. 22, 2024

Liau v. WEEE! Inc.

Judge
Paul Engelmayer
Docket
1:23-cv-01177
Court
U.S. District Court · Southern District of New York
Pages
15
Civil ProcedureMotion to Dismiss
In one sentence

In Liau v. WEEE!, Judge Engelmayer dismissed the data-breach case for lack of standing and denied leave to amend.

Who this affects

Tyson Liau and Richard Teng’s proposed class action was dismissed for lack of Article III standing; the court denied their request to amend again, while stating that the jurisdictional dismissal did not prevent a separate lawsuit.

What happened

In Liau v. WEEE! Inc., former customers Tyson Liau and Richard Teng sued over a data breach that disclosed customer names, addresses, and phone numbers, but not payment information or passwords. They claimed the breach violated consumer-protection laws and an implied agreement to protect customer data.

The court ruled that the plaintiffs had not shown a concrete injury required to bring a case in federal court. Their monitoring expenses were not enough because the disclosed information was not sensitive enough to create a substantial risk of identity theft. Teng’s spam calls and texts also did not establish an injury, and he did not plausibly connect them to the breach.

Judge Engelmayer granted WEEE! Inc.’s motion to dismiss for lack of federal subject-matter jurisdiction and denied the plaintiffs’ request to amend again. Because the dismissal was for lack of jurisdiction, the court stated that it did not prevent the plaintiffs from bringing the same claims in a separate lawsuit.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Liau v. WEEE! Inc. · No. 1:23-cv-01177
Judge
Paul Engelmayer
Date
Feb. 22, 2024

Background

Tyson Liau and Richard Teng, former Weee! customers, brought a proposed class action after Weee! disclosed that customer information had been leaked in a data breach. The disclosed information included names, addresses, and phone numbers, but not payment data or account passwords. The plaintiffs alleged claims under New York General Business Law § 349 and similar consumer-protection laws in other states, as well as a claim that Weee! breached an implied agreement to take reasonable measures to safeguard customer data.

The plaintiffs alleged two injuries. First, they claimed they spent time monitoring their financial and bank accounts after the breach. Teng also alleged that he paid $24.99 per month for a credit-monitoring service. Second, Teng alleged that he received numerous spam telephone calls and text messages because his phone number had been exposed.

Motion and Legal Issue

Weee! moved to dismiss under Federal Rule of Civil Procedure 12(b)(1) for lack of subject-matter jurisdiction and, alternatively, under Rule 12(b)(6) for failure to state a claim. The court addressed the jurisdictional argument first. Article III standing requires a plaintiff to show a concrete injury, a connection between that injury and the defendant’s conduct, and a likelihood that a court decision would remedy the injury.

Court’s Analysis

The court held that the alleged monitoring costs did not establish a concrete injury. Under controlling precedent, preventive expenses after a data breach may qualify as an injury when they are reasonably incurred to address a substantial and imminent risk of identity theft or fraud. The court considered the fact that a known threat actor had stolen and posted the information, but found that factor insufficient by itself.

The court emphasized that the information disclosed here—names, addresses, and phone numbers—was low-risk information that was often publicly available. The complaint did not plausibly explain how this information would cause identity theft. Because the plaintiffs did not show a substantial risk of identity theft or fraud, their time spent monitoring accounts and Teng’s credit-monitoring subscription did not establish standing.

The court separately rejected Teng’s spam-call and text-message theory. It stated that courts generally do not treat ordinary spam calls or texts as a concrete injury. The complaint did not allege that Teng received unusually large or severe amounts of spam, that the calls and texts increased after the breach, or that they used information that could realistically have come only from Weee!’s records. The court therefore found both that the alleged annoyance was insufficient and that the complaint did not fairly connect the communications to the breach.

Because the plaintiffs lacked Article III standing, the court dismissed the Second Amended Complaint under Rule 12(b)(1) and did not reach Weee!’s Rule 12(b)(6) arguments.

Leave to Amend and Disposition

The plaintiffs asked for permission to amend again if the complaint were dismissed. The court denied that request. It noted that the plaintiffs had already had two opportunities to amend, made only a general request for another amendment, and did not identify specific additional facts or changes that could cure the jurisdictional defects.

Judge Engelmayer granted Weee! Inc.’s motion to dismiss under Rule 12(b)(1), denied the plaintiffs’ request for leave to amend, directed the Clerk of Court to enter judgment and close the case, and terminated the pending motions. The court expressly stated that, because the dismissal was for lack of subject-matter jurisdiction, it was without prejudice to the plaintiffs’ right to pursue claims arising from these events in a separate lawsuit.

The authoritative version

Read the full 15-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.