Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled June 7, 2022

Riordan v. Western Digital Corporation

Judge
Edward Davila
Docket
5:21-cv-06074
Court
U.S. District Court · Northern District of California
Pages
7
Civil ProcedureMotion to Dismiss
In one sentence

In Riordan v. Western Digital, Judge Davila granted Western Digital’s motion to dismiss the data-breach lawsuit for lack of standing, with leave to amend.

Who this affects

The ruling affected Kevin Riordan, Ashley Laurent, Jeremy Bobo, and Nagui Sorial’s data-breach claims against Western Digital Corporation. The claims were dismissed with leave to amend, subject to the court’s stated deadline and limitations.

What happened

Kevin Riordan, Ashley Laurent, Jeremy Bobo, and Nagui Sorial sued Western Digital Corporation over a cyberattack that allegedly erased data from certain internet-connected hard drives. They sought money and court-ordered relief under warranty, negligence, unfair-business-practices, and other claims.

The court ruled that the plaintiffs had not shown a concrete injury from the alleged data loss or a sufficiently likely risk that criminals would misuse their information. Because the plaintiffs lacked the legal standing required to bring the case, the court did not consider Western Digital’s alternative argument that the complaint failed to state a valid claim.

Judge Edward J. Davila granted Western Digital’s motion to dismiss with leave to amend. The plaintiffs could file an amended complaint by June 27, 2022, alleging more specific facts about what data was taken and whether it had been misused.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Riordan v. Western Digital Corporation · No. 5:21-cv-06074
Judge
Edward Davila
Date
June 7, 2022

Background

The plaintiffs brought claims against Western Digital Corporation arising from a 2021 cyberattack on two legacy internet-connected hard drives: the My Book Live and My Book Live Duo. They alleged that vulnerabilities in the devices’ software allowed hackers to execute malicious code and remotely reset the devices, deleting stored data.

The plaintiffs alleged that they bought the devices based on Western Digital’s representations that the products were secure and that the company was committed to protecting their data. They claimed losses including personal, financial, commercial, and proprietary information. They also alleged that their information might have reached cybercriminals.

The complaint asserted six types of claims: violations of the Song-Beverly Consumer Warranty Act and the Magnuson-Moss Warranty Act; negligence and failure to warn; breach of the covenant of good faith and fair dealing; unfair business practices; and unjust enrichment. Western Digital moved to dismiss under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). The court also noted that Western Digital had offered affected users a free data-recovery service and the option to trade in affected devices for upgraded products, but the plaintiffs did not allege that they used those programs.

Standing Analysis

The court first addressed Article III standing, which is the requirement that a plaintiff show a concrete injury that is fairly traceable to the defendant’s conduct and likely to be remedied by a court decision. In a class action, at least one named plaintiff must have standing.

The plaintiffs relied on two theories of injury. First, they alleged that they lost data because of the factory reset. The court found those allegations insufficient because the complaint did not explain whether the data was permanently lost, whether copies existed elsewhere, what specific information was lost, why it had value, or how its loss caused personal or economic harm. The court concluded that the plaintiffs could not establish an injury merely by assuming that the hacking itself caused harm.

Second, the plaintiffs alleged a risk that their information had reached cybercriminals and might be misused. The court found that theory speculative because the plaintiffs did not allege facts showing that their specific personal information had been stolen or that any harm had resulted from the breach. The court contrasted those allegations with a case in which plaintiffs alleged account monitoring, credit-monitoring expenses, fraud alerts, anxiety, and an attempted fraudulent account opening after a laptop containing personal information was stolen.

Ruling

The court held that the plaintiffs had not alleged an injury in fact and therefore lacked Article III standing. Because it dismissed on that ground, the court did not reach Western Digital’s alternative argument under Rule 12(b)(6) that the complaint failed to state a claim.

The court granted Western Digital’s motion to dismiss with leave to amend. It stated that the plaintiffs might cure the standing problem by alleging more particular facts about what data was taken and whether the data had been misused. The court set June 27, 2022, as the deadline for an amended complaint and stated that failure to amend or cure the identified deficiencies would result in dismissal of the claims. Plaintiffs could not add new claims or parties without the court’s permission or the parties’ stipulation. Judge Edward J. Davila signed the order.

The authoritative version

Read the full 7-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.