Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled Sept. 3, 2025

In re Warner Music Group Data Breach

Judge
Paul Gardephe
Docket
1:20-cv-07473
Court
U.S. District Court · Southern District of New York
Pages
47
Civil ProcedureMotion to DismissTortContract
In one sentence

In re Warner Music Group Data Breach: Judge Gardephe denied dismissal of most claims but dismissed three types of data-breach claims.

Who this affects

The ruling affects the 14 named customers, the proposed nationwide and California classes, and Warner Music Group. The negligence, implied-contract, and California Consumer Privacy Act claims remain in the case, while the negligent-misrepresentation, unjust-enrichment, and New York General Business Law claims were dismissed subject to the stated amendment ruling.

What happened

In In re Warner Music Group Data Breach, customers sued Warner Music after hackers obtained payment-card and other personal information from its websites. They claimed Warner Music failed to protect their information and sought damages and court orders requiring better security.

Warner Music argued that the customers lacked a legally recognized injury and had not adequately stated their claims. The court found that all named plaintiffs had sufficiently alleged injury because their information was exposed, some experienced unauthorized charges, and others faced a substantial risk of future fraud.

Judge Gardephe denied the motion to dismiss the negligence, implied-contract, and California Consumer Privacy Act claims. He granted dismissal of the negligent-misrepresentation, unjust-enrichment, and New York deceptive-practices and false-advertising claims; plaintiffs may ask to amend the first and third groups, but not the unjust-enrichment claim.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
In re Warner Music Group Data Breach · No. 1:20-cv-07473
Judge
Paul Gardephe
Date
Sept. 3, 2025

Background

A 2020 cyberattack compromised several Warner Music Group websites between April 25 and August 5, 2020. According to the amended complaint, unauthorized third parties obtained approximately 130,000 customers’ names, contact information, billing and shipping addresses, payment-card numbers, security codes, and expiration dates. The plaintiffs alleged that the attack exploited weaknesses in Magento, an outside service provider used to host and support the websites.

The consolidated action was brought by 14 customers on behalf of proposed nationwide and California classes. The plaintiffs asserted negligence, negligent misrepresentation, breach of implied contract, unjust enrichment, deceptive-practices and false-advertising claims under New York law, and a California Consumer Privacy Act claim for the California subclass. They sought damages and injunctive relief requiring better protection of customer information.

Warner Music moved to dismiss under Federal Rule of Civil Procedure 12(b)(1), arguing that the plaintiffs lacked standing because they had not alleged a concrete injury. It also moved under Rule 12(b)(6), arguing that the complaint failed to state legally sufficient claims.

Standing

The court denied the Rule 12(b)(1) motion. It held that all named plaintiffs sufficiently alleged a concrete injury. The alleged exposure of private information was itself a concrete harm, and the plaintiffs also alleged time and money spent monitoring accounts and addressing the consequences of the breach.

The court also found that the alleged injuries were actual or imminent. The complaint described a targeted attack aimed at obtaining payment information, alleged that 11 named plaintiffs experienced unauthorized charges or other financial misuse, and identified information—such as payment-card numbers, security codes, expiration dates, and billing addresses—that presented a substantial risk of future fraud. The court held that the plaintiffs were not required to allege that Social Security numbers had been stolen.

Claim-by-claim rulings

Negligence. The court denied dismissal of the negligence claim. Applying New York law, it held that the complaint plausibly alleged that Warner Music owed customers a duty to use reasonable care in safeguarding information it required customers to provide for purchases. The complaint also identified alleged shortcomings, including failing to outsource payment processing, using code from outside domains, failing to install web-skimming protection, and using outdated software. The court rejected Warner Music’s argument that the economic-loss doctrine barred the claim, explaining that the doctrine did not apply to this data-breach negligence claim.

Negligent misrepresentation. The court granted dismissal of this claim under Rule 12(b)(6). The plaintiffs relied on alleged representations such as security-lock images and a privacy-policy statement that Warner Music used reasonable measures to protect personal information. But the complaint did not allege facts showing that the plaintiffs actually saw, read, or noticed those representations before providing their information. The court therefore found the allegations of reliance too conclusory.

Breach of implied contract. The court denied dismissal. It held that the complaint plausibly alleged an implied promise to protect the personal information that Warner Music required customers to provide as a condition of purchasing goods. The complaint also adequately alleged that Warner Music breached that promise by failing to take reasonable security measures.

Unjust enrichment. The court granted dismissal. It concluded that this claim was based on the same alleged failure to fund or implement security measures as the negligence claim and therefore duplicated that claim.

New York General Business Law Sections 349 and 350. The court granted dismissal of the deceptive-practices and false-advertising claims. The plaintiffs alleged that Warner Music’s privacy policy contained a misleading statement about its security practices, but they did not allege where, when, or how they saw or read that statement before making their purchases. The court held that this missing causal connection was fatal to both claims. It did not reach Warner Music’s additional argument that the privacy-policy statement was not materially misleading.

California Consumer Privacy Act. The court denied dismissal of the California subclass’s claim. It held that the alleged payment-card numbers combined with security codes qualified as covered personal information under the statute. The complaint also identified security practices that the plaintiffs said Warner Music should have used and alleged that Warner Music’s failure to use them allowed the unauthorized access and theft. Those allegations were sufficient at the pleading stage.

Leave to amend and disposition

Judge Paul G. Gardephe denied leave to amend the unjust-enrichment claim because it duplicated the negligence claim. He granted leave to move to amend the negligent-misrepresentation and New York General Business Law claims because the identified pleading defects might be curable.

The court’s final disposition was that Warner Music’s motion to dismiss the negligent-misrepresentation, unjust-enrichment, and New York General Business Law Sections 349 and 350 claims was granted. The motion was otherwise denied. Any motion for leave to amend was due by September 17, 2025.

The authoritative version

Read the full 47-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.