Broidy v. Global Risk Advisors LLC
- Vyskocil
- 1:19-cv-11861
- U.S. District Court · Southern District of New York
- 32
In Broidy v. Global Risk Advisors, Judge Vyskocil granted in part and denied in part defendants’ motion to dismiss claims arising from alleged hacking.
The ruling limits the case by dismissing all claims against Courtney Chalker and the foreign corporate defendants and by dismissing the trade-secret and RICO claims. Claims under the Stored Communications Act, computer-access laws, California’s stolen-property law, intrusion upon seclusion, and civil conspiracy remain allowed against the defendants identified in the court’s disposition.
What happened
In Broidy v. Global Risk Advisors LLC, Elliott Broidy and Broidy Capital Management claimed that cybersecurity firm Global Risk Advisors and related defendants hacked their systems, accessed private information, and distributed it. The defendants asked the court to dismiss the case for lack of authority over some defendants and because the complaint did not state valid claims.
The court dismissed all claims against Courtney Chalker and the foreign corporate defendants because the complaint did not adequately show that they had sufficient connections to New York. It also dismissed the trade-secret and Racketeer Influenced and Corrupt Organizations Act claims. But it allowed claims involving the Stored Communications Act, computer access, stolen property, intrusion into private information, and civil conspiracy to proceed against specified defendants.
Judge Mary Kay Vyskocil granted in part and denied in part the motion to dismiss. The ruling did not dismiss all claims against every defendant, and the court did not add a statement that any dismissal was with or without prejudice.
The detailed version
- Broidy v. Global Risk Advisors LLC · No. 1:19-cv-11861
- Vyskocil
- Sept. 26, 2023
Background
Elliott Broidy and Broidy Capital Management, LLC alleged that Qatar hired Global Risk Advisors LLC (GRA) and others to hack Broidy’s personal systems and the company’s systems after Broidy publicly criticized Qatar. According to the Second Amended Complaint, the defendants used a spear-phishing campaign, accessed email accounts and company servers, obtained confidential communications and business information, and distributed hacked materials to media outlets. The complaint also alleged that some defendants destroyed electronic devices and other materials after Broidy began related litigation.
The Second Amended Complaint asserted ten claims, including claims under the Stored Communications Act, the Computer Fraud and Abuse Act, the Defend Trade Secrets Act, the Racketeer Influenced and Corrupt Organizations Act, California computer-access and trade-secret statutes, California’s stolen-property statute, intrusion upon seclusion, and civil conspiracy. The defendants moved to dismiss for lack of personal jurisdiction, failure to state a claim, and failure to provide adequate notice under Federal Rule of Civil Procedure 8(a).
Personal Jurisdiction
The court granted the motion with respect to all claims against Courtney Chalker. The complaint alleged that he helped destroy evidence but did not identify where that conduct occurred or allege that he transacted business in New York. The court also held that the complaint did not adequately allege personal jurisdiction over Global Risk Advisors EMEA Limited, GRA Maven LLC, GRA Quantum LLC, Qrypt, Inc., and GRA Research LLC. The complaint did not allege those entities’ principal places of business or states of incorporation, their business activity in New York, or acts they took in New York connected to the claims. The motion was therefore granted with respect to all claims against those foreign corporate defendants.
Rule 8 and the Anonymous Source
The court rejected the defendants’ argument that allegations based on an anonymous former GRA employee violated Rule 8(a). At the motion-to-dismiss stage, the court accepted the complaint’s factual allegations as true. The court also held that the complaint gave the individual defendants enough notice of the claims, even though it sometimes referred to defendants collectively. The complaint included allegations describing the roles of Denis Mandich, Antonio Garcia, and Kevin Chalker and alleged that the defendants acted together.
Claims Under Federal and State Computer Laws
The court denied the motion as to the Stored Communications Act claim against Kevin Chalker and GRA. It held that the complaint adequately alleged unauthorized access to Google’s servers, which qualify as covered facilities under that statute. The court did not treat the personal computers of Broidy’s wife and executive assistant or BCM’s private computer systems as covered facilities, but it found the allegations about Google’s servers sufficient.
The court also denied the motion as to the Computer Fraud and Abuse Act claim against Chalker, GRA, Mandich, and Garcia and as to the California Comprehensive Computer Data Access and Fraud Act claim against Chalker and GRA. The complaint alleged costs for investigating the attacks, assessing and repairing the affected systems, hiring forensic investigators and security experts, replacing computers and phones, and adding security measures. The court found these allegations sufficient to plead computer-related losses.
Trade-Secret Claims
The court granted the motion with respect to the Defend Trade Secrets Act and California Uniform Trade Secrets Act claims in their entirety. The complaint stated generally that the alleged trade secrets had independent economic value because they were not publicly known and had required significant investment. The court found those allegations too conclusory because they did not identify the information with enough specificity or explain its economic value compared with information available to competitors. The court did not need to decide whether any defendant misappropriated the alleged trade secrets.
RICO Claims
The court granted the motion with respect to the Racketeer Influenced and Corrupt Organizations Act claim and the conspiracy-to-violate-RICO claim in their entirety. It applied collateral estoppel, a rule that prevents a party from relitigating an issue already fully and fairly decided in an earlier proceeding. The court held that an earlier round of this dispute involved the same plaintiffs, enterprise, alleged hacking scheme, RICO claims, and alleged co-conspirators, and that the earlier court had decided that the plaintiffs failed to plead a required pattern of racketeering activity. The court therefore held that the plaintiffs could not relitigate that issue merely by suing different alleged members of the same conspiracy.
California Claims
The court held that the California Uniform Trade Secrets Act did not preempt the remaining California claims because those claims could be based on conduct independent of trade-secret misappropriation. The court denied the motion as to the stolen-property claim against Chalker, GRA, Mandich, and Garcia, finding that the complaint plausibly alleged that electronic information was stolen, that defendants possessed it, and that they knew it was stolen.
The court denied the motion as to the intrusion-upon-seclusion claim against Chalker and GRA. It held that the complaint described unauthorized access to private and sensitive emails and documents, including attorney-client communications, financial information, passwords, and confidential business information, and plausibly alleged an intrusion that would be highly offensive to a reasonable person.
The court also denied the motion as to the civil-conspiracy claim against Chalker, GRA, Mandich, and Garcia. The complaint alleged a common plan, acts taken to further that plan, and resulting harm, including allegations that Chalker and GRA were responsible for the hacking and that defendants destroyed evidence and carried out covert operations.
Disposition
The court granted in part and denied in part the defendants’ motion to dismiss. Specifically, it granted the motion as to all claims against Courtney Chalker; all claims against the foreign corporate defendants; the Defend Trade Secrets Act and California Uniform Trade Secrets Act claims; and the RICO and RICO-conspiracy claims. It denied the motion as to the specified Stored Communications Act, Computer Fraud and Abuse Act, California computer-access, stolen-property, intrusion-upon-seclusion, and civil-conspiracy claims. The clerk was directed to terminate the motion docket entry.
Read the full 32-page opinion on CourtListener, the free public archive maintained by the Free Law Project.