Schmitt v. SN Servicing Corporation, an Alaska Corporation
- William Orrick
- 3:21-cv-03355
- U.S. District Court · Northern District of California
- 19
In Schmitt v. SN Servicing, Judge Orrick denied in part and granted in part the company’s dismissal motion, allowing amendment.
Desiree Schmitt and James Furth, and the proposed nationwide class of borrowers affected by SNSC’s data breach; SNSC was also affected by the partial dismissal ruling.
What happened
In Schmitt v. SN Servicing Corporation, Desiree Schmitt and James Furth sued over a 2020 ransomware attack that exposed borrowers’ personal and financial information. They brought negligence, privacy, and California unfair-competition claims for themselves and a proposed nationwide class.
The court ruled that the Ohio plaintiffs could pursue California-law claims because the company’s principal place of business and important decisions were in California. But the complaint did not adequately allege that the company had a duty to protect the disclosed information, that the breach seriously invaded privacy, or that the unfair-competition allegations were specific enough. The court did find that the plaintiffs alleged enough financial loss to have standing for their unfair-competition claim.
Judge William H. Orrick denied in part and granted in part SN Servicing Corporation’s motion to dismiss, giving the plaintiffs 20 days to amend. The court denied dismissal based on the use of California law and denied dismissal for lack of unfair-competition standing, but granted dismissal of the negligence, privacy, unlawful-prong, and unfair-prong claims with leave to amend.
The detailed version
- Schmitt v. SN Servicing Corporation, an Alaska Corporation · No. 3:21-cv-03355
- William Orrick
- Aug. 9, 2021
Background
Desiree Schmitt and James Furth sued SN Servicing Corporation (SNSC) over a ransomware attack that occurred on SNSC’s computer system in October 2020. The plaintiffs alleged that an unauthorized group acquired files containing information about approximately 20,155 borrowers, including names, addresses, loan numbers, balances, and billing information. SNSC learned of the breach around October 15, 2020, but did not send the plaintiffs and class members a breach-notification letter until January 14, 2021. The letter stated that the investigation was continuing to determine whether additional information had been taken.
The plaintiffs alleged that they faced an increased risk of fraud and identity theft and spent time and money monitoring and protecting their identities and credit. Schmitt alleged that she purchased credit monitoring, a password manager, and password-protection hardware and spent at least 10 hours changing passwords. Furth alleged that he purchased identity protection. Both plaintiffs alleged anxiety, emotional distress, and loss of privacy.
The plaintiffs brought claims for negligence, invasion of privacy, and relief under the “unlawful” and “unfair” prongs of California’s Unfair Competition Law (UCL). SNSC removed the case from state court and moved to dismiss under Federal Rule of Civil Procedure 12(b)(6), which allows dismissal when a complaint does not plausibly state a claim for relief.
California Law and Out-of-State Plaintiffs
The court denied SNSC’s motion to dismiss on the ground that the plaintiffs lived outside California. Although California generally limits the out-of-state application of its laws, the court held that plaintiffs outside California may invoke California law when they are harmed by wrongful conduct occurring in California. The complaint alleged that SNSC’s principal place of business was in Eureka, California; that its high-level activities, including data-security functions and policy decisions, were directed from California; and that its investigation and notification responses came from California. The court found those allegations sufficient at the pleading stage to connect the alleged conduct to California.
Negligence
The court granted SNSC’s motion to dismiss the negligence claim with leave to amend. The complaint alleged that the breach exposed names, addresses, loan numbers, balance information, and billing information. The court explained that California law identifies certain categories of sensitive personal identifying information for which a legal duty to provide reasonable security applies, including a name combined with a Social Security number, government identification number, qualifying financial-account information, biometric information, medical information, or an email or username combined with a password that permits account access.
The court held that the complaint did not plausibly allege that the information disclosed was within the category of information SNSC had a legal duty to protect. The plaintiffs mentioned Social Security numbers in their opposition, but that allegation was not in the complaint. The court allowed amendment and suggested that the plaintiffs could provide facts about the information they and similar customers gave SNSC, together with the information known to have been released, to support an inference that more sensitive information was also compromised.
The court did not reject the plaintiffs’ alleged monitoring costs and lost time as damages. It stated that money and time spent on credit monitoring can be recognizable harm and that an actual identity theft or fraud incident is not necessarily required. But because the complaint did not plausibly allege that protected personal identifying information was disclosed, it also did not plausibly allege that the plaintiffs’ monitoring expenses were reasonable and necessary. The court stated that this problem could be addressed if the plaintiffs plausibly alleged that such information was compromised.
Invasion of Privacy
The court granted SNSC’s motion to dismiss the invasion-of-privacy claim with leave to amend. Under California law, the claim requires a legally protected privacy interest, a reasonable expectation of privacy, and a serious invasion of that interest.
The court held that the plaintiffs did not adequately allege a sufficiently serious invasion. It explained that the claim has a high pleading bar and that negligent conduct leading to the theft of personal information, even including Social Security numbers, generally does not meet the required standard for an egregious breach of privacy norms. The court distinguished cases involving medical information posted online or intentional disclosures of privileged information.
Unfair Competition Law
The court denied SNSC’s motion to dismiss the UCL claim for lack of statutory standing. UCL standing requires a plaintiff to allege lost money or property. The court held that the plaintiffs’ allegations that they paid for enhanced credit monitoring and related services after the breach were sufficient at the pleading stage. The court also stated that whether those expenses were actually necessary could not be resolved on the motion to dismiss.
The court granted SNSC’s motion to dismiss the UCL claim under the unlawful prong with leave to amend. The unlawful prong allows a plaintiff to treat a business practice as unlawful by alleging that it violates another law. The plaintiffs identified five alleged statutory violations: the Federal Trade Commission Act, two provisions of California’s Customer Records Act, the California Financial Information Privacy Act, and an Ohio breach-notification statute. But the court found that the plaintiffs did not identify the specific statutory provisions and facts supporting each alleged violation with reasonable particularity. The court also held that the UCL claim could not be based on the Federal Trade Commission Act in the manner alleged because that federal statute does not create a private right of action. The court found the proposed bases involving the other statutes inadequately explained or questionable on the allegations presented.
The court also granted SNSC’s motion to dismiss the UCL claim under the unfair prong with leave to amend. The plaintiffs’ allegations were too vague and conclusory to show unfair conduct under the legal standards discussed by the court. The court noted that the complaint did not adequately allege a duty to provide timely breach notifications or that SNSC breached such a duty.
Disposition
Judge William H. Orrick ordered that SNSC’s motion to dismiss was denied in part and granted in part, with leave to amend within 20 days. Specifically, the court denied dismissal based on the application of California law and denied dismissal for lack of UCL statutory standing. It granted dismissal of the negligence claim, the invasion-of-privacy claim, and the UCL claims under both the unlawful and unfair prongs, each with leave to amend.
Read the full 19-page opinion on CourtListener, the free public archive maintained by the Free Law Project.