Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Sept. 14, 2026

In re Salesforce Customers Security Incident Litigation

Judge
Jacquelyn Corley
Docket
3:25-cv-07232
Court
U.S. District Court · Northern District of California
Pages
29

Counsel50 of record
PLAINTIFF
Girard Sharp LLPLLP3 attorneys
Kyle Paul Quackenbush, Samhita Collur, Adam E. Polk
Aylstock Witkin Kreis & Overholtz PLC2 attorneys
Amber Love Schubert, Sonum Dixit
Ahdoot & Wolfson, PCPC2 attorneys
Robert Ahdoot, Tina Wolfson
Tycko & Zavareei LLPLLP
Sabita J. Soneji
Lieff Cabraser Heimann & Bernstein, LLPLLP
Jason Louis Lichtman
Clarkson Law Firm, P.C.PC
Bryan Paul Thompson
Schubert Jonckheer & Kolbe LLPLLP
Robert C. Schubert
Milberg, PLLCPLLC
John J. Nelson
INTERESTED PARTY
Dena C. Sharp Girard Sharp LLP
Adam E. Polk Girard Sharp LLP
CONSOL PLAINTIFF
Girard Sharp LLPLLP5 attorneys
Adam E. Polk, Dena C. Sharp, Scott M. Grzenczyk
Lieff Cabraser Heimann & Bernstein, LLPLLP3 attorneys
Margaret Mattes Becko, Michael J. Miarmi, Jason Louis Lichtman
Berger Montague PCPC3 attorneys
Colleen Fewer, E. Michelle Drake, Mark B. DeSanto
Hausfeld LLPLLP2 attorneys
James J. Pizzirusso, Nicholas Murphy
Ahdoot & Wolfson, PCPC2 attorneys
Robert Ahdoot, Tina Wolfson
Aylstock Witkin Kreis & Overholtz PLC2 attorneys
Sonum Dixit, Amber Love Schubert
Barrack, Rodos & Bacine2 attorneys
Stephen R. Basser, Samuel M. Ward
Morgan & Morgan Mass Tort Dept.2 attorneys
Michael Francis Ram, Ronald Podolny
Lieff Cabraser Heimann and Bernstein, LLPLLP
Jason L. Lichtman
Tycko & Zavareei LLPLLP
Sabita J. Soneji
Schubert Jonckheer & Kolbe LLPLLP
Robert C. Schubert
Morgan & Morgan Complex Litigation Group
John A. Yanchunis
Morgan and Morgan Complex Litigation Group
Ryan McGee
Strauss Borrelli PLLCPLLC
Andrew Gerald Gunem
Wynne Law Firm
Edward Joseph Wynne
Clapp Legal APC
James F. Clapp
Thomas Eric Loeser
DEFENDANT
Morrison & Foerster LLPLLP5 attorneys
Adam James Hunt, Katie Viggiani, Michelle Sosa-Acosta
Orrick Herrington and Sutcliff
Melissa Levin

Counsel of record per CourtListener. Firm names are approximate and have been consolidated across spelling variants.

Civil ProcedureMotion to DismissTort
In one sentence

In re Salesforce Customers Security Incident Litigation: Judge Corley granted in part and denied in part Salesforce’s motion to dismiss data-breach claims.

Who this affects

The named plaintiffs and proposed classes may continue the data-breach claims that survived the motion, while the fraud-based Illinois claims and Washington claims based on invasion of privacy were dismissed at this stage. Salesforce, Inc. prevailed on those specified portions of its motion but otherwise remains subject to the claims the court allowed to proceed.

What happened

In In re Salesforce Customers Security Incident Litigation, customers and employees of Allianz, Farmers, and TransUnion sued Salesforce, Inc. over an alleged data breach that exposed personal information. They alleged that hackers exploited weaknesses in Salesforce’s access-token system and that plaintiffs faced identity-theft risks and spent time and resources monitoring and protecting their accounts.

Salesforce argued that the plaintiffs lacked the required connection to sue in federal court and had not adequately pleaded negligence or violations of California, Illinois, and Washington laws. The court found the alleged risks, monitoring efforts, and causal connection to Salesforce’s security practices sufficient at this stage. It also found the negligence, California Consumer Privacy Act, non-fraud Illinois Consumer Fraud Act, and most Washington Consumer Protection Act allegations adequately pleaded.

Judge Jacquelyn Scott Corley granted in part and denied in part Salesforce’s motion to dismiss. She granted it as to fraud-based Illinois claims and Washington claims based on invasion of privacy, but otherwise denied the motion, including as to standing, negligence, the California privacy claim, the remaining Illinois claims, and the remaining Washington claims.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
In re Salesforce Customers Security Incident Litigation · No. 3:25-cv-07232
Judge
Jacquelyn Corley
Date
Sept. 14, 2026

Background

Plaintiffs sued Salesforce, Inc. on behalf of themselves and proposed classes after an alleged data breach involving information stored on Salesforce’s customer-relationship-management platform. The named plaintiffs were customers or employees of Allianz Life Insurance Company of North America, Farmers Group, Inc., and TransUnion, LLC. They alleged that a hacking group called SLH exploited weaknesses in Salesforce’s OAuth-token system, which allowed connected third-party applications to access data. Plaintiffs alleged that the breach exposed personal information such as names, addresses, dates of birth, Social Security numbers, and driver’s-license numbers.

Plaintiffs alleged that they received breach notices, faced an ongoing risk of fraud and identity theft, and spent time and resources monitoring accounts, reviewing credit reports, freezing credit, changing passwords, and taking other protective measures. Some also alleged unauthorized charges, attempted fraud, or other suspicious activity.

Salesforce’s Motion

Salesforce moved under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). It argued that plaintiffs had not plausibly alleged Article III standing, which requires an injury, a connection between that injury and the defendant’s conduct, and a likelihood that a court decision would remedy the injury. Salesforce also argued that plaintiffs failed to state claims for California negligence, violations of the California Consumer Privacy Act, violations of the Illinois Consumer Fraud and Deceptive Business Practices Act, and violations of the Washington Consumer Protection Act.

Article III Standing

The court denied the motion to dismiss for lack of standing. It held that the plaintiffs plausibly alleged a substantial and credible risk of identity theft and fraud. The breach notices, allegations that sensitive information was taken or exposed, reports that stolen data was posted online, and allegations of actual or attempted misuse supported that conclusion. The court also held that the time and resources plaintiffs spent monitoring and protecting their information were concrete injuries connected to the alleged risk.

The court rejected Salesforce’s argument that the involvement of hackers, Salesforce customers, and customers’ employees made the causal connection too speculative. Accepting the complaint’s allegations and drawing reasonable inferences for plaintiffs, the court found a plausible causal chain: Salesforce allegedly failed to secure OAuth tokens, hackers exploited that weakness, and plaintiffs’ information was exposed. The court held that this reasoning also applied to seven identified plaintiffs who did not allege specific misuse of their information.

California Negligence Claim

The court denied the motion as to the California negligence claim. Under California law, negligence requires a duty of care, a breach, causation, and injury.

For duty, the court held plaintiffs were not required to allege a special relationship with Salesforce because they alleged that Salesforce’s own affirmative conduct in designing and operating its platform created a foreseeable and unreasonable risk of harm. For breach, the court found the allegations sufficiently specific. Plaintiffs identified OAuth tokens as the vulnerability and alleged that Salesforce could have vetted and audited third-party applications and used measures such as automatic token expiration, automatic token rotation, or device-specific tokens.

For causation, the court held plaintiffs plausibly alleged that Salesforce’s conduct was a substantial factor in causing the breach, even though hackers also used social-engineering tactics. For damages, the court held Salesforce had not shown that the seven plaintiffs who alleged monitoring and mitigation efforts—but no specific misuse—could not state a negligence claim as a matter of law. The court deferred the choice-of-law issue concerning whether California negligence law governs non-California plaintiffs’ claims.

California Consumer Privacy Act Claim

The court denied the motion as to the California Consumer Privacy Act claim. Salesforce argued it was not a covered “business” because it did not directly collect the plaintiffs’ information and did not determine the purposes and means of processing it.

The court held plaintiffs plausibly alleged that Salesforce collected personal information because Salesforce required clients to provide sensitive data and managed the servers holding that data. The court also held plaintiffs plausibly alleged that Salesforce determined the purposes and means of processing personal information because it managed and stored data, operated the platform infrastructure, used artificial-intelligence tools, and maintained safeguards under a shared-responsibility model.

Illinois Consumer Fraud Act Claims

The court granted Salesforce’s motion as to fraud-based claims under the Illinois Consumer Fraud and Deceptive Business Practices Act. Although the complaint referred to misrepresentations and omissions, plaintiffs’ opposition stated that the substance of their allegations was Salesforce’s alleged failure to secure personal information, not deceptive practices or fraud.

The court otherwise denied the motion as to the Illinois claims. It held that, drawing inferences for plaintiffs, the allegations supported a sufficient connection to Illinois. Four named plaintiffs alleged they were Illinois citizens, and plaintiffs alleged that TransUnion’s principal place of business was in Chicago, Illinois.

Washington Consumer Protection Act Claims

The court granted Salesforce’s motion as to Washington Consumer Protection Act claims based on an “invasion of privacy” injury. It held that invasion of privacy is a personal injury rather than an injury to business or property, which the statute requires.

The court denied the motion as to claims based on lost time and lost opportunity costs spent mitigating the data-breach risks. It held those allegations could constitute pecuniary or otherwise unquantifiable injuries rather than merely personal feelings such as annoyance or aggravation. The court also found plaintiffs plausibly alleged that Salesforce’s conduct caused those mitigation-related injuries.

Disposition

Judge Jacquelyn Scott Corley granted in part and denied in part Salesforce’s motion to dismiss. The motion was granted to the extent the Illinois claims were based on fraud and the Washington claims were based on invasion of privacy. The motion was otherwise denied. The order disposed of Docket No. 86.

The authoritative version

Read the full 29-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.