Jimenez Jr. v. OE Federal Credit Union
- Jon Tigar
- 4:24-cv-02746
- U.S. District Court · Northern District of California
- 16
In Jimenez Jr. v. OE Federal Credit Union, Judge Tigar partly granted and partly denied OEFCU’s motion to dismiss claims arising from a data breach.
Daniel Jimenez Jr., Mark Hendren, Erica Jaramillo, and the proposed class of individuals identified as affected by OEFCU’s data breach. Most claims survived the motion, while Erica Jaramillo’s implied-contract and Customer Records Act claims, the plaintiffs’ Unfair Competition Law claims, and the declaratory-relief claim were dismissed under the terms stated in the order.
What happened
Jimenez Jr. v. OE Federal Credit Union concerns a ransomware attack and data breach that allegedly exposed plaintiffs’ personal and health information. The plaintiffs sued on behalf of themselves and a proposed class, alleging negligence, contract, privacy, unjust enrichment, California statutory, and declaratory-relief claims.
The court allowed most claims to continue, including negligence, invasion of privacy, unjust enrichment, the California Consumer Privacy Act claim, and some California Customer Records Act claims. It dismissed Erica Jaramillo’s implied-contract and Customer Records Act claims, the plaintiffs’ California Unfair Competition Law claims, and the declaratory-relief claim.
Judge Jon S. Tigar granted OEFCU’s motion to dismiss in part and denied it in part. The dismissed claims generally may be amended, but the declaratory-relief claim was dismissed with prejudice; the plaintiffs had 28 days to amend the claims identified in the order.
The detailed version
- Jimenez Jr. v. OE Federal Credit Union · No. 4:24-cv-02746
- Jon Tigar
- Aug. 19, 2025
Background
The case concerns an alleged ransomware attack and data breach of OE Federal Credit Union’s network between approximately August 19, 2023, and October 29, 2023. The plaintiffs alleged that the breach allowed unauthorized access to personally identifiable information and protected health information, including names, Social Security numbers, financial-account information, driver’s-license numbers, medical information, and health-insurance information. OEFCU notified affected individuals on April 30, 2024, and offered a complimentary 12-month membership with a fraud and identity-monitoring service.
The plaintiffs alleged that OEFCU failed to follow identified cybersecurity frameworks and failed to take other security measures. They alleged that the breach caused time spent monitoring accounts, contacting credit bureaus, and changing or canceling account credentials; increased risks of fraud and identity theft; anxiety and emotional distress; and, for Mark Hendren and Erica Jaramillo, increased spam and scam calls, texts, and emails. The plaintiffs asserted negligence, breach of implied contract, invasion of privacy, unjust enrichment, violations of California’s Unfair Competition Law, California Consumer Privacy Act, and California Customer Records Act, and a request for declaratory relief.
Legal standard
The defendant moved to dismiss under Federal Rule of Civil Procedure 12(b)(6), which tests whether the complaint alleges a legally recognized claim supported by enough facts to make liability plausible. For purposes of the motion, the court accepted the complaint’s factual allegations as true and viewed the pleadings in the light most favorable to the plaintiffs.
Court’s analysis
Negligence
The court held that the plaintiffs adequately pleaded negligence. It concluded that OEFCU had a duty to store the plaintiffs’ personally identifiable and protected health information with care. The plaintiffs also alleged specific security failures, including failure to meet identified cybersecurity standards, monitor systems for intrusions, and ensure that vendors used reasonable security procedures. The court further held that the alleged time spent monitoring accounts and contacting credit bureaus, emotional distress, and increased spam and scam contacts were plausible damages at the pleading stage.
Breach of implied contract
The court allowed Daniel Jimenez Jr.’s and Mark Hendren’s implied-contract claims to proceed. Their allegations that they were required to provide their information as a condition of becoming OEFCU customers or obtaining its services were sufficient, at this stage, to allege consideration for an implied agreement that OEFCU would reasonably safeguard the information. Erica Jaramillo did not allege that she was an OEFCU customer, so the court dismissed her implied-contract claim with leave to amend.
Invasion of privacy
The court declined to dismiss the invasion-of-privacy claim. It reasoned that the alleged disclosure of protected health information, along with other personal information, could potentially constitute a sufficiently serious and highly offensive invasion of privacy. The court stated that this fact-intensive question generally should not be resolved at the pleading stage.
Unjust enrichment
The court declined to dismiss the unjust-enrichment claim. It rejected OEFCU’s argument that the claim was barred merely because the plaintiffs also alleged breach of implied contract. The court noted that the plaintiffs alleged an implied, rather than express, contract and that OEFCU identified no authority barring both claims in that circumstance.
California Unfair Competition Law
The court dismissed the plaintiffs’ California Unfair Competition Law claims with leave to amend for lack of statutory standing. The court held that the plaintiffs did not sufficiently allege an actual monetary loss. Time spent responding to the breach, possible future expenses, and a general allegation that the information had lost value were insufficient. The complaint also alleged that the credit-monitoring and identity-protection services offered by OEFCU were complimentary and did not allege that the plaintiffs paid OEFCU for services.
California Consumer Privacy Act
The court declined to dismiss the California Consumer Privacy Act claim. The plaintiffs plausibly alleged that OEFCU was a covered business because it collected their information to provide financial services and determined how to process it, including by storing it on OEFCU’s network. The court did not accept OEFCU’s argument that the complaint showed it was a service provider rather than a business covered by the claim.
California Customer Records Act
The court declined to dismiss Daniel Jimenez Jr.’s and Mark Hendren’s Customer Records Act claims. The plaintiffs plausibly alleged that OEFCU unreasonably delayed notifying them of the breach and that earlier notice could have allowed them to take protective measures sooner, potentially reducing later harm. Their allegations that they provided personal information as a condition of receiving OEFCU’s services also sufficiently alleged that they were customers under the statute. Erica Jaramillo’s Customer Records Act claim was dismissed with leave to amend because she did not allege that she was an OEFCU customer.
Declaratory relief
The court dismissed the declaratory-relief claim with prejudice. The requested declarations—that OEFCU owed and breached continuing data-security duties—would duplicate the negligence claim and would not provide a useful additional resolution. The court also stated that declaratory relief is a remedy rather than a standalone cause of action and concluded that amendment would be futile.
Disposition
The court granted OEFCU’s motion to dismiss in part and denied it in part. The implied-contract and Customer Records Act claims brought by Erica Jaramillo were dismissed with leave to amend. The plaintiffs’ Unfair Competition Law claims were dismissed with leave to amend. The declaratory-relief claim was dismissed with prejudice. The court denied the remainder of OEFCU’s motion. The plaintiffs could file an amended complaint within 28 days, limited to addressing the deficiencies identified in the order; failure to do so would result in dismissal of the relevant claims with prejudice.
Read the full 16-page opinion on CourtListener, the free public archive maintained by the Free Law Project.