Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Sept. 18, 2019

Sgarlata v. PayPal Holdings, Inc.

Judge
Edward Chen
Docket
3:17-cv-06956
Court
U.S. District Court · Northern District of California
Pages
18
SecuritiesMotion to DismissCivil Procedure
In one sentence

In Sgarlata v. PayPal Holdings, Judge Chen dismissed with prejudice investors’ securities-fraud claims because they did not adequately plead defendants’ knowledge of the breach’s scope.

Who this affects

The order affected Michael Eckert and Edwin Bells, the proposed class of people who purchased PayPal securities during the stated class period, and the named defendants, including PayPal Holdings, Inc., TIO Networks ULC, TIO Networks USA, Inc., Daniel H. Schulman, John D. Rainey, Jr., and John Kunze.

What happened

Sgarlata v. PayPal Holdings, Inc. involved investors who said PayPal’s November 2017 announcement about security vulnerabilities at TIO Networks misleadingly understated an actual data breach. They sought to represent people who bought PayPal securities between November 10 and December 1, 2017.

The investors relied on statements from three former TIO employees and a cybersecurity expert to argue that defendants knew the breach had compromised information belonging to about 1.6 million customers. Defendants argued that the complaint did not adequately allege that the November announcement was false or that the defendants knowingly or recklessly misled investors.

The court found that the complaint adequately explained why the November announcement could have misled investors, but it did not adequately show that the speaker, John Kunze, knew the breach’s full scope. Judge Chen granted defendants’ motion to dismiss with prejudice, dismissed the related control-liability claim with prejudice, and ordered judgment and closure of the case.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Sgarlata v. PayPal Holdings, Inc. · No. 3:17-cv-06956
Judge
Edward Chen
Date
Sept. 18, 2019

Background

Plaintiffs Michael Eckert and Edwin Bells brought the action individually and on behalf of people who purchased PayPal securities during the November 10–December 1, 2017 class period. They alleged that defendants PayPal Holdings, Inc., TIO Networks ULC, TIO Networks USA, Inc., Daniel H. Schulman, John D. Rainey, Jr., and John Kunze violated Sections 10(b) and 20(a) of the Securities Exchange Act and Securities and Exchange Commission Rule 10b-5.

PayPal acquired TIO Networks in July 2017. On November 10, 2017, PayPal and TIO announced that TIO had suspended operations after PayPal discovered security vulnerabilities and problems with TIO’s data-security program. The announcement said that the PayPal platform was not affected and PayPal customers’ data remained secure. On December 1, 2017, the companies announced that a review had identified a potential compromise of personally identifiable information for approximately 1.6 million customers. PayPal’s share price fell $4.33, or 5.75%, on December 4, 2017.

Plaintiffs claimed that the November announcement misleadingly described the problem as a vulnerability rather than disclosing that an actual breach had occurred and that customer information may have been compromised. They relied mainly on statements attributed to three confidential former TIO employees, along with an opinion from cybersecurity expert Kenny Yeung.

Legal standard

Defendants moved to dismiss under Federal Rule of Civil Procedure 12(b)(6), which permits dismissal when a complaint does not state a legally sufficient claim. Plaintiffs also had to meet the heightened pleading requirements of Federal Rule of Civil Procedure 9(b) and the Private Securities Litigation Reform Act. Those requirements called for particularized allegations identifying the misleading statement, explaining why it was misleading, and showing a strong inference that defendants acted with scienter—the required state of mind, such as intent to deceive or deliberate recklessness.

For a Section 10(b) and Rule 10b-5 claim, plaintiffs had to plead a material misrepresentation or omission, a purchase or sale of a security, reliance, economic loss, and loss causation. The Section 20(a) claim required an adequately pleaded primary violation and control over the person who committed it.

Court’s analysis

Misleading statement. The court concluded that plaintiffs adequately pleaded falsity. The November announcement’s reference to a security “vulnerability,” followed by the December announcement’s disclosure of unauthorized access and a potential compromise affecting approximately 1.6 million customers, could plausibly have created the impression that only a potential or less serious problem had been discovered. The court therefore rejected defendants’ argument that the two announcements were necessarily consistent.

Scienter. The court held that plaintiffs did not adequately plead scienter. Because Kunze was the only alleged speaker of the November announcement, plaintiffs had to plead facts creating a strong inference that Kunze knew, or deliberately disregarded, that the breach had compromised information belonging to approximately 1.6 million customers.

The court found that the former employees’ statements did not meet that standard. Former Employee 1’s account did not identify who provided the information or show that Kunze knew the breach’s magnitude. The court also noted inconsistencies between that employee’s earlier and amended statements and found that much of the account relied on statements from unnamed people. Former Employee 2’s statement that Kunze announced a breach showed, at most, knowledge of some breach; the court found that the network being divided could reflect preventive measures during an investigation rather than knowledge of the breach’s full scope. Former Employee 3’s statement likewise did not show that Kunze had the required knowledge.

The court also rejected the cybersecurity expert’s opinion as insufficient to strengthen the inference of scienter. Although Yeung had substantial information-technology experience, the complaint did not allege that he knew the defendants’ specific network architecture. The court characterized his conclusion that all customer data was potentially compromised as an inference about what likely happened, rather than evidence based on personal knowledge of the defendants’ systems or contemporaneous information available to Kunze.

The court further observed that plaintiffs did not allege an obvious motive for delaying disclosure of the breach’s full scope. Considering the allegations together, the court found no strong inference that Kunze knowingly or recklessly misled the market.

Disposition

The court granted defendants’ motion to dismiss the securities-fraud claims with prejudice. It also granted defendants’ motion to dismiss the Section 20(a) control-liability claim with prejudice because that claim depended on an adequately pleaded Section 10(b) violation. The court dismissed the second amended complaint with prejudice, directed the Clerk to enter judgment and close the file, and stated that the order disposed of Docket No. 79. Judge Edward M. Chen signed the order on September 18, 2019.

The authoritative version

Read the full 18-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.