In re Christie's Data Breach Litigation
- Jesse Furman
- 1:24-cv-04221
- U.S. District Court · Southern District of New York
- 2
In re Christie’s Data Breach Litigation: Judge Furman required more information about fraud risk before considering preliminary approval of the proposed class settlement.
The consumers who brought the class action and Christie’s Inc.; the court’s order requires additional information before it considers preliminary approval of the proposed settlement.
What happened
In In re Christie’s Data Breach Litigation, consumers brought a class action alleging that personal information, including drivers’ license and passport numbers, was disclosed in a 2024 hacking incident involving Christie’s computer systems. The parties asked the court to preliminarily approve a proposed class-action settlement.
The court questioned whether the consumers had standing, meaning a sufficient legal interest to bring the case in federal court. The court focused on whether exposing the types of information at issue created a high risk of identity theft or fraud, including whether the record showed actual or potential fraud involving the combined information.
Judge Furman ordered the consumers to file either a declaration addressing the potential for fraud or identity theft or a short supplemental brief explaining why a declaration should not be required. Christie’s may respond with its own short brief. The opinion did not decide standing or rule on preliminary approval of the settlement.
The detailed version
- In re Christie's Data Breach Litigation · No. 1:24-cv-04221
- Jesse Furman
- Jan. 28, 2025
Background
A group of consumers filed a class action alleging that personal information—including drivers’ license numbers and passport numbers—was disclosed in a 2024 hacking incident targeting Christie’s Inc.’s computer systems. The parties later filed a motion seeking preliminary approval of a class-action settlement. Preliminary approval is an initial court review before a proposed class settlement can move forward through notice and a later approval process.
The court had previously ordered supplemental briefing on whether the plaintiffs had standing. Standing is the requirement that a plaintiff show a sufficient connection to the alleged injury to invoke the federal court’s authority. The court stated that standing might depend on whether the exposed information was sensitive enough to create a high risk of identity theft or fraud. It noted that courts had reached different conclusions about whether exposure of drivers’ license numbers meets that standard.
Court’s Analysis
The court observed that the answer may depend on whether the record contains allegations that fraudulent activity had already resulted from the exposure of drivers’ license numbers, or that fraud could result from the combined exposure of those numbers with other information. The court also stated that it could consider materials outside the pleadings when evaluating standing.
The opinion did not resolve whether the plaintiffs had standing. It also did not grant or deny the motion for preliminary approval of the settlement.
Order
Judge Jesse M. Furman ordered the plaintiffs, by February 4, 2025, to file either: (1) a declaration addressing the potential for fraud or identity theft resulting from the information exposed in the data breach, including drivers’ license and passport numbers; or (2) a supplemental brief of no more than five pages explaining why such a declaration should not be required. Christie’s may file a response, in the form of a supplemental brief of no more than five pages, by February 7, 2025.
Read the full 2-page opinion on CourtListener, the free public archive maintained by the Free Law Project.