Riordan v. Western Digital Corporation
- Edward Davila
- 5:21-cv-06074
- U.S. District Court · Northern District of California
- 17
Riordan v. Western Digital, Judge Davila, dismissed most claims but allowed unjust-enrichment and nationwide-class allegations to proceed, with leave to amend.
The ruling affected the four named plaintiffs, the proposed national class and California subclass, and Western Digital Corporation. The plaintiffs’ unjust-enrichment claim and nationwide-class allegations remained in the case at this stage, while several other claims were dismissed with leave to amend.
What happened
In Riordan v. Western Digital Corporation, four people alleged that a cyber-attack wiped personal, business, and other stored data from Western Digital devices. They sued Western Digital in a proposed class action, asserting consumer-warranty, negligence, contract-related, unfair-competition, and unjust-enrichment claims.
The court rejected the challenge to the proposed nationwide class at this stage, but held that the plaintiffs had not adequately alleged a future risk that their data would be misused and therefore dismissed their requests for injunctions. It also dismissed the consumer-warranty, failure-to-warn, implied-covenant, and unfair-competition claims, while allowing the unjust-enrichment claim to continue as an alternative restitution claim.
Judge Davila granted in part and denied in part Western Digital’s motion to dismiss, with leave to amend. The plaintiffs could file an amended complaint by October 16, 2023, but could not add new claims or parties without permission or the parties’ agreement.
The detailed version
- Riordan v. Western Digital Corporation · No. 5:21-cv-06074
- Edward Davila
- Sept. 29, 2023
Background
Kevin Riordan, Ashley Laurent, Jeremy Bobo, and Nagui Sorial alleged that cyber criminals remotely executed malicious code on Western Digital’s My Book Live and My Book Duo devices on June 23, 2021. The attack reset the devices to factory settings, wiped stored data, and prevented users from logging in with their credentials. The alleged losses included family photographs and videos, business records, financial information, health information, immigration and naturalization documents, and other data.
The plaintiffs brought claims under California’s Song-Beverly Consumer Warranty Act, for negligent failure to warn, for breach of the implied covenant of good faith and fair dealing, under California’s Unfair Competition Law, and for unjust enrichment. They sought to represent a national class and a California subclass. Western Digital moved to dismiss under Federal Rules of Civil Procedure 12(b)(1), which addresses subject-matter jurisdiction, and 12(b)(6), which addresses whether a complaint states a legally sufficient claim.
Standing and Class Allegations
The court granted Western Digital’s motion to dismiss claims based on a possible future misuse of the plaintiffs’ data. The complaint alleged that the data might have reached cyber criminals, but did not allege facts showing that the data was actually stolen. The court found that this speculative possibility did not establish an injury sufficient for federal standing. Because the plaintiffs did not show a risk of future injury, the court also dismissed their claims for injunctive relief.
The court denied Western Digital’s motion to dismiss the nationwide-class allegations for lack of standing. It declined to conduct a choice-of-law analysis at the pleading stage, stating that the issue would be more appropriately addressed at class certification.
Claims Under the Complaint
The court granted the motion to dismiss the Song-Beverly Act claim with leave to amend. The complaint did not allege where or when the representative plaintiffs purchased their devices, facts relevant to whether California’s implied warranty applied and whether the claim was timely.
The court granted the motion to dismiss the negligent failure-to-warn claim with leave to amend. Although the plaintiffs alleged that the devices had vulnerabilities, they did not adequately identify the specific flaw, explain how it enabled the cyber-attack, or show how the alleged flaw fell below the applicable standard of care.
The court dismissed the breach-of-implied-covenant claim with leave to amend. The plaintiffs did not specify whether they bought the devices from Western Digital, so the complaint did not sufficiently allege a contract from which the implied covenant could arise.
The court dismissed the Unfair Competition Law claim with leave to amend to the extent the plaintiffs could allege that they lacked an adequate remedy at law. The complaint sought equitable relief, including restitution, but did not allege that legal remedies were inadequate.
The court denied the motion to dismiss the unjust-enrichment claim. It treated the claim as a quasi-contract claim seeking restitution rather than as an improper standalone cause of action. The court also held that the plaintiffs could plead restitution in the alternative at the pleading stage, even though such alternative relief might not be available if another claim ultimately provided recovery.
Disposition
The court granted in part and denied in part Western Digital’s motion to dismiss. Specifically, it granted dismissal of the future-data-misuse claims and injunctive-relief claims; denied dismissal of the nationwide-class allegations for lack of standing; granted dismissal of the Song-Beverly Act, failure-to-warn, Unfair Competition Law, and implied-covenant claims; and denied dismissal of the unjust-enrichment claim. The court granted leave to amend and set October 16, 2023, as the deadline for an amended complaint. It stated that failure to correct the identified deficiencies would result in dismissal of those claims, and that new claims or parties could not be added without court permission or the parties’ stipulation.
Read the full 17-page opinion on CourtListener, the free public archive maintained by the Free Law Project.