In re Christie's Data Breach Litigation
- Jesse Furman
- 1:24-cv-04221
- U.S. District Court · Southern District of New York
- 9
In re Christie's Data Breach Litigation: Judge Furman found customers had standing and granted preliminary settlement approval, with one change.
The plaintiffs and proposed settlement class members whose personal information was stolen in the Christie’s data breach, as well as Christie’s Inc. The ruling preliminarily approved the proposed class settlement but did not announce final approval or decide liability.
What happened
In In re Christie's Data Breach Litigation, customers sued Christie’s after cybercriminals stole personal information, including names, birthdates, addresses, passport numbers, and driver’s-license numbers. The parties reached a proposed class settlement before Christie’s request to dismiss was decided.
The court considered whether the customers had Article III standing, meaning a sufficient injury to bring a case in federal court. It concluded that disclosure of their private information and their efforts and expenses to reduce the resulting risks were enough. The court then reviewed the proposed class settlement for preliminary approval.
Judge Jesse M. Furman granted the unopposed motion for preliminary approval of the settlement, but removed a proposed provision that would have stayed related actions in other courts. The clerk was directed to terminate the motion docket entry.
The detailed version
- In re Christie's Data Breach Litigation · No. 1:24-cv-04221
- Jesse Furman
- Feb. 19, 2025
Background
On May 8, 2024, cybercriminals hacked Christie’s Inc.’s systems and stole customer personal identifying information. The information included full names, birthdates, addresses, passport numbers, driver’s-license numbers, and other state and government-issued identification information. Some affected people filed a proposed class action alleging that Christie’s failed to adequately protect their data.
Christie’s moved to dismiss, arguing in part that the plaintiffs lacked standing under Article III of the Constitution. Before that motion was resolved, the parties reached a proposed class-wide settlement. They jointly asked the court to stay deadlines while the plaintiffs sought preliminary approval under Rule 23(e) of the Federal Rules of Civil Procedure. Because the court had to confirm its jurisdiction before reviewing the settlement, it ordered supplemental briefing on standing.
Standing
The court held that the plaintiffs had Article III standing. Standing requires a plaintiff to show a concrete and particularized injury that is actual or imminent.
The court identified two alleged injuries. First, the plaintiffs alleged that their private information had already been disclosed to unauthorized cybercriminals. Relying on Second Circuit precedent, the court concluded that this disclosure itself was a concrete and actual injury. Because the disclosure had already occurred, the court said it did not need to apply the factors used to assess a risk of future identity theft or fraud.
Second, the plaintiffs alleged that they had spent significant time, effort, and money to reduce the risks created by the breach. The court analyzed this injury under the factors from McMorris v. Carlos Lopez & Associates, LLC: whether the data was taken in a targeted attack, whether some of the data had been misused, and whether the type of data created a continuing risk of identity theft or fraud. The court found that the targeted cyberattack supported standing. Although the allegations about attempted cellphone and PayPal account hacking were unclear or potentially unrelated to the breach, the court found that the stolen driver’s-license, passport, and identification information was sufficiently capable of facilitating fraud to satisfy the remaining factor.
Settlement ruling
After finding that it had subject-matter jurisdiction, the court reviewed the proposed class settlement. It found that the settlement warranted preliminary approval, substantially for the reasons given in the plaintiffs’ submissions.
The court rejected one requested provision. The parties had proposed staying actions brought by settlement-class members concerning released claims until final approval of the settlement. The court found that no such actions were known, making the stay unnecessary. It also stated that it would not interfere with other courts’ control over their proceedings or with other litigants’ rights without notice and an opportunity to be heard. The court therefore struck that language from the proposed order.
Disposition
The court granted the plaintiffs’ unopposed motion for preliminary approval of the proposed class action settlement, with the amendment described above. It stated that it would enter a separate order preliminarily approving the settlement and directed the clerk to terminate ECF No. 49. The opinion did not announce final approval of the settlement or decide Christie’s liability on the data-protection claims.
Read the full 9-page opinion on CourtListener, the free public archive maintained by the Free Law Project.