Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled Apr. 27, 2022

Fraser v. Mint Mobile, LLC

Judge
William Alsup
Docket
3:22-cv-00138
Court
U.S. District Court · Northern District of California
Pages
16
Civil ProcedureMotion to DismissContractTort
In one sentence

In Fraser v. Mint Mobile, Judge Alsup partly granted and partly denied Mint’s dismissal motion, dismissing some claims and remedies while allowing others to proceed.

Who this affects

Daniel Fraser and Mint Mobile, LLC. The order determines which of Fraser’s claims and requested remedies may continue at the pleading stage concerning the alleged cryptocurrency theft.

What happened

Fraser v. Mint Mobile, LLC concerns an alleged data breach, a fraudulent transfer of Daniel Fraser’s cellphone service, and the theft of about $466,000 in cryptocurrency from an account held by a separate exchange. Fraser claimed Mint’s conduct helped criminals access and drain that account.

Mint asked the court to dismiss the complaint for failing to state legally sufficient claims. Mint challenged whether its conduct was closely enough connected to the cryptocurrency theft and challenged Fraser’s claims under the federal computer-crime law, California’s unfair-competition law, negligence law, and contract law. Mint withdrew its requests to dismiss the Federal Communications Act injunction request and to compel arbitration.

Judge Alsup granted the motion in part and denied it in part. The court dismissed Fraser’s federal computer-crime and unfair-competition claims, dismissed his separate implied-covenant claim with prejudice, and dismissed specified punitive-damages requests. The negligence and implied-in-fact contract claims could proceed, and the court otherwise denied Mint’s motion.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Fraser v. Mint Mobile, LLC · No. 3:22-cv-00138
Judge
William Alsup
Date
Apr. 27, 2022

Background

Daniel Fraser was a Mint Mobile customer. The opinion says Mint suffered a data breach between June 8 and June 10, 2021, exposing customer information that included names, addresses, email addresses, phone numbers, account numbers, and passwords. Fraser alleges that a criminal used the exposed information to transfer, or “port,” his cellphone service to Metro by T-Mobile on June 11. He also alleges that Mint bypassed a personal identification number security feature he had added to his account three days earlier.

Fraser had a cryptocurrency account with Ledger, a separate company. He alleges that the data breach and fraudulent cellphone-service transfer gave criminals the information and access needed to enter and drain that account. The opinion states that the theft began at 9:19 a.m. on June 11 and ultimately amounted to the equivalent of $466,000 in cryptocurrency.

Fraser asserted claims under the Federal Communications Act, California Business and Professions Code Section 17200, the federal Computer Fraud and Abuse Act, negligence, breach of contract, breach of an implied-in-fact contract, and breach of the implied covenant of good faith and fair dealing. He also sought various remedies, including punitive damages. Mint moved to dismiss for failure to state a claim. At the hearing, Mint withdrew its requests to dismiss the Federal Communications Act claim for injunctive relief and to compel arbitration.

Proximate cause

Mint argued that the complaint did not adequately connect Mint’s data breach and the cellphone-service transfer to the later theft from Fraser’s Ledger account. The court rejected that argument at the motion-to-dismiss stage. It found the alleged sequence sufficiently direct: the breach exposed information allegedly needed to port Fraser’s service; the port gave the criminal control of the cellphone service; and the Ledger account began being drained about one hour and eleven minutes later.

Mint also argued that the criminals’ independent illegal acts were “superseding causes”—intervening events that would ordinarily relieve an earlier defendant of responsibility. Applying California law, the court held that the complaint plausibly alleged that SIM hijacking and the resulting account theft were foreseeable risks of the alleged conduct. The court therefore found the proximate-cause allegations adequate for all counts at this stage.

California unfair-competition claims

The court dismissed Fraser’s Section 17200 claims. It explained that California’s unfair-competition law permits restitution and injunctive relief, but not broader monetary damages. The court dismissed with prejudice the requests in Counts IV through VI for relief beyond restitution and injunctive relief.

The court separately held that Fraser had not adequately pleaded a right to restitution. Restitution generally requires that the defendant have acquired the money or property that the plaintiff lost. Fraser alleged that a third-party criminal took his cryptocurrency, not Mint. Because Fraser did not seek injunctive relief and did not adequately allege restitution from Mint, the court dismissed Counts IV, V, and XI.

Computer Fraud and Abuse Act claim

The court dismissed Fraser’s claim under the Computer Fraud and Abuse Act, a federal law that provides a civil claim for certain unauthorized computer access. Fraser alleged that Mint violated provisions concerning unauthorized access to protected computers and that his losses exceeded $5,000.

The court did not resolve whether Fraser’s aiding-and-abetting theory was available under the Act. Instead, it held that the complaint failed for a more fundamental reason: the alleged loss was the stolen cryptocurrency, and the complaint did not identify a qualifying technological injury to a computer, computer system, or data. The court explained that the Act covers computer-related damage and loss, not losses resulting from criminals’ later use of unlawfully obtained information. The Computer Fraud and Abuse Act claim was dismissed.

Contract claims

The court dismissed with prejudice Fraser’s separate claim for breach of the implied covenant of good faith and fair dealing because it duplicated his breach-of-contract claim and sought the same relief. The allegations supporting that theory were to be treated as part of the breach-of-contract claim.

The court allowed Fraser’s implied-in-fact contract theory to proceed for now. An implied-in-fact contract is an agreement shown by the parties’ conduct rather than by express words. The court found that Fraser adequately alleged his subscription to Mint’s service and Mint’s alleged commitment, reflected in its privacy policy and terms, to maintain confidentiality and security. The court described the allegations as limited but sufficient at this stage.

Negligence claims

The court allowed Fraser’s negligence claims to proceed. Because Fraser sought recovery for economic losses, the court applied California’s six-factor test for whether a “special relationship” created a duty of care. The court found that the complaint plausibly alleged foreseeability, a close connection between Mint’s conduct and the injury, and moral blame, among other relevant considerations. The court concluded that the allegations plausibly supported a special relationship and adequately stated negligence claims.

Punitive damages and disposition

The court dismissed with prejudice the specific requests for punitive damages tied to Fraser’s Section 17200 claims, contract claims, Computer Fraud and Abuse Act claim, and Federal Communications Act claim. It dismissed Fraser’s punitive-damages requests for the negligence claims, without using the same “with prejudice” wording for those requests.

The court concluded that Mint’s motion to dismiss was GRANTED IN PART and DENIED IN PART. Fraser’s specific requests for punitive damages under the Section 17200, contract, Computer Fraud and Abuse Act, and Federal Communications Act claims were dismissed with prejudice. His requests for remedies beyond restitution and injunctive relief under Section 17200 were also dismissed with prejudice. His negligence punitive-damages request, separate implied-covenant claim, Computer Fraud and Abuse Act claim, and Section 17200 claims were dismissed, while the motion was otherwise denied. The court stated that Fraser could move for leave to amend claims dismissed without prejudice, with any such motion due by May 11 at noon.

The authoritative version

Read the full 16-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.