In re Salesforce Customers Security Incident Litigation
- Jacquelyn Corley
- 3:25-cv-07232
- U.S. District Court · Northern District of California
- 29
Counsel of record per CourtListener. Firm names are approximate and have been consolidated across spelling variants.
In re Salesforce Customers Security Incident Litigation: Judge Corley granted in part and denied in part Salesforce’s motion to dismiss data-breach claims.
The named plaintiffs and proposed classes may continue the data-breach claims that survived the motion, while the fraud-based Illinois claims and Washington claims based on invasion of privacy were dismissed at this stage. Salesforce, Inc. prevailed on those specified portions of its motion but otherwise remains subject to the claims the court allowed to proceed.
What happened
In In re Salesforce Customers Security Incident Litigation, customers and employees of Allianz, Farmers, and TransUnion sued Salesforce, Inc. over an alleged data breach that exposed personal information. They alleged that hackers exploited weaknesses in Salesforce’s access-token system and that plaintiffs faced identity-theft risks and spent time and resources monitoring and protecting their accounts.
Salesforce argued that the plaintiffs lacked the required connection to sue in federal court and had not adequately pleaded negligence or violations of California, Illinois, and Washington laws. The court found the alleged risks, monitoring efforts, and causal connection to Salesforce’s security practices sufficient at this stage. It also found the negligence, California Consumer Privacy Act, non-fraud Illinois Consumer Fraud Act, and most Washington Consumer Protection Act allegations adequately pleaded.
Judge Jacquelyn Scott Corley granted in part and denied in part Salesforce’s motion to dismiss. She granted it as to fraud-based Illinois claims and Washington claims based on invasion of privacy, but otherwise denied the motion, including as to standing, negligence, the California privacy claim, the remaining Illinois claims, and the remaining Washington claims.
The detailed version
- In re Salesforce Customers Security Incident Litigation · No. 3:25-cv-07232
- Jacquelyn Corley
- Sept. 14, 2026
Background
Plaintiffs sued Salesforce, Inc. on behalf of themselves and proposed classes after an alleged data breach involving information stored on Salesforce’s customer-relationship-management platform. The named plaintiffs were customers or employees of Allianz Life Insurance Company of North America, Farmers Group, Inc., and TransUnion, LLC. They alleged that a hacking group called SLH exploited weaknesses in Salesforce’s OAuth-token system, which allowed connected third-party applications to access data. Plaintiffs alleged that the breach exposed personal information such as names, addresses, dates of birth, Social Security numbers, and driver’s-license numbers.
Plaintiffs alleged that they received breach notices, faced an ongoing risk of fraud and identity theft, and spent time and resources monitoring accounts, reviewing credit reports, freezing credit, changing passwords, and taking other protective measures. Some also alleged unauthorized charges, attempted fraud, or other suspicious activity.
Salesforce’s Motion
Salesforce moved under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). It argued that plaintiffs had not plausibly alleged Article III standing, which requires an injury, a connection between that injury and the defendant’s conduct, and a likelihood that a court decision would remedy the injury. Salesforce also argued that plaintiffs failed to state claims for California negligence, violations of the California Consumer Privacy Act, violations of the Illinois Consumer Fraud and Deceptive Business Practices Act, and violations of the Washington Consumer Protection Act.
Article III Standing
The court denied the motion to dismiss for lack of standing. It held that the plaintiffs plausibly alleged a substantial and credible risk of identity theft and fraud. The breach notices, allegations that sensitive information was taken or exposed, reports that stolen data was posted online, and allegations of actual or attempted misuse supported that conclusion. The court also held that the time and resources plaintiffs spent monitoring and protecting their information were concrete injuries connected to the alleged risk.
The court rejected Salesforce’s argument that the involvement of hackers, Salesforce customers, and customers’ employees made the causal connection too speculative. Accepting the complaint’s allegations and drawing reasonable inferences for plaintiffs, the court found a plausible causal chain: Salesforce allegedly failed to secure OAuth tokens, hackers exploited that weakness, and plaintiffs’ information was exposed. The court held that this reasoning also applied to seven identified plaintiffs who did not allege specific misuse of their information.
California Negligence Claim
The court denied the motion as to the California negligence claim. Under California law, negligence requires a duty of care, a breach, causation, and injury.
For duty, the court held plaintiffs were not required to allege a special relationship with Salesforce because they alleged that Salesforce’s own affirmative conduct in designing and operating its platform created a foreseeable and unreasonable risk of harm. For breach, the court found the allegations sufficiently specific. Plaintiffs identified OAuth tokens as the vulnerability and alleged that Salesforce could have vetted and audited third-party applications and used measures such as automatic token expiration, automatic token rotation, or device-specific tokens.
For causation, the court held plaintiffs plausibly alleged that Salesforce’s conduct was a substantial factor in causing the breach, even though hackers also used social-engineering tactics. For damages, the court held Salesforce had not shown that the seven plaintiffs who alleged monitoring and mitigation efforts—but no specific misuse—could not state a negligence claim as a matter of law. The court deferred the choice-of-law issue concerning whether California negligence law governs non-California plaintiffs’ claims.
California Consumer Privacy Act Claim
The court denied the motion as to the California Consumer Privacy Act claim. Salesforce argued it was not a covered “business” because it did not directly collect the plaintiffs’ information and did not determine the purposes and means of processing it.
The court held plaintiffs plausibly alleged that Salesforce collected personal information because Salesforce required clients to provide sensitive data and managed the servers holding that data. The court also held plaintiffs plausibly alleged that Salesforce determined the purposes and means of processing personal information because it managed and stored data, operated the platform infrastructure, used artificial-intelligence tools, and maintained safeguards under a shared-responsibility model.
Illinois Consumer Fraud Act Claims
The court granted Salesforce’s motion as to fraud-based claims under the Illinois Consumer Fraud and Deceptive Business Practices Act. Although the complaint referred to misrepresentations and omissions, plaintiffs’ opposition stated that the substance of their allegations was Salesforce’s alleged failure to secure personal information, not deceptive practices or fraud.
The court otherwise denied the motion as to the Illinois claims. It held that, drawing inferences for plaintiffs, the allegations supported a sufficient connection to Illinois. Four named plaintiffs alleged they were Illinois citizens, and plaintiffs alleged that TransUnion’s principal place of business was in Chicago, Illinois.
Washington Consumer Protection Act Claims
The court granted Salesforce’s motion as to Washington Consumer Protection Act claims based on an “invasion of privacy” injury. It held that invasion of privacy is a personal injury rather than an injury to business or property, which the statute requires.
The court denied the motion as to claims based on lost time and lost opportunity costs spent mitigating the data-breach risks. It held those allegations could constitute pecuniary or otherwise unquantifiable injuries rather than merely personal feelings such as annoyance or aggravation. The court also found plaintiffs plausibly alleged that Salesforce’s conduct caused those mitigation-related injuries.
Disposition
Judge Jacquelyn Scott Corley granted in part and denied in part Salesforce’s motion to dismiss. The motion was granted to the extent the Illinois claims were based on fraud and the Washington claims were based on invasion of privacy. The motion was otherwise denied. The order disposed of Docket No. 86.
Read the full 29-page opinion on CourtListener, the free public archive maintained by the Free Law Project.