Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled Sept. 29, 2023

Cheng v. T-Mobile USA Inc.

Judge
P. Castel
Docket
1:22-cv-03996
Court
U.S. District Court · Southern District of New York
Pages
13
Civil ProcedureMotion to DismissTort
In one sentence

In Cheng v. T-Mobile USA Inc., Judge Castel granted T-Mobile’s motion to dismiss Calvin Cheng’s claims arising from a bitcoin scam and closed the case.

Who this affects

Calvin Cheng’s claims against T-Mobile USA, Inc. were dismissed, and the court directed that judgment be entered and the case closed.

What happened

Cheng alleged that someone took control of a T-Mobile customer’s phone account, impersonated that customer on Telegram, and persuaded Cheng to send fifteen bitcoins without receiving payment. He sued T-Mobile, claiming its failure to protect the customer’s account caused his loss.

The court dismissed every claim. It ruled that T-Mobile owed Cheng no legally recognized duty of care, that Cheng did not allege T-Mobile possessed or disclosed his information, that he did not plausibly allege unauthorized computer access, and that his consumer-protection injury was indirect rather than direct.

Judge Castel granted T-Mobile’s motion to dismiss, directed the Clerk to enter judgment, and closed the case.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Cheng v. T-Mobile USA Inc. · No. 1:22-cv-03996
Judge
P. Castel
Date
Sept. 29, 2023

Background

Calvin Cheng alleged that he arranged to sell fifteen bitcoins, worth approximately $750,000, to a person he believed was Brandon Buchanan. According to the Complaint, an unknown person had taken control of Buchanan’s T-Mobile phone account through a SIM-swap attack and then used Buchanan’s Telegram account to impersonate him. Cheng sent the bitcoins to a digital wallet but received no payment.

Cheng sued T-Mobile USA, Inc., Buchanan’s mobile-service provider. He asserted claims under the Federal Communications Act (FCA) and the Computer Fraud and Abuse Act (CFAA), along with New York claims for negligence, consumer deception under New York General Business Law § 349, negligent hiring, retention, and supervision, and gross negligence. T-Mobile moved to dismiss the Complaint under Federal Rule of Civil Procedure 12(b)(6), arguing that the Complaint did not state a legally sufficient claim.

Negligence-Based Claims

The court dismissed the negligence, gross-negligence, and negligent-hiring, retention, and supervision claims because Cheng did not plausibly allege that T-Mobile owed him a duty of care. Applying New York law, the court explained that a negligence claim requires a legally recognized duty, a breach, and injury proximately caused by the breach.

Cheng proposed that T-Mobile owed a duty to people who foreseeably transact business with T-Mobile customers or people whom others believe are T-Mobile customers. The court rejected that proposed duty. It concluded that foreseeability alone does not create a duty to a third party, Cheng had no alleged relationship with T-Mobile, and the proposed duty would reach an excessively broad group of people and create potentially unmanageable liability. The court therefore dismissed all three negligence-based claims.

Federal Communications Act Claim

The court dismissed Cheng’s FCA claim. Cheng alleged that T-Mobile failed to protect confidential information in Buchanan’s account during the SIM-swap attack and therefore caused Cheng’s loss. The court explained that the statutory private claim relied on by Cheng was tied to the unauthorized disclosure of the plaintiff’s own customer information.

The Complaint did not plausibly allege that T-Mobile possessed or failed to protect Cheng’s information. The court distinguished a case in which the plaintiff’s own information was at issue and concluded that Cheng’s allegations were insufficient.

Computer Fraud and Abuse Act Claim

The court dismissed the CFAA claim because Cheng did not plausibly allege unauthorized access. The Complaint alleged that T-Mobile accessed its own records concerning Buchanan’s account and failed to follow security policies that had been added to the account. The court held that violating an internal computer-use policy does not by itself establish that someone accessed a computer without authorization or exceeded authorized access.

The Complaint did not allege that a T-Mobile employee lacked the credentials needed to execute the SIM-swap or accessed computer areas the employee was not permitted to use. The court also concluded that Cheng did not adequately plead that T-Mobile or its agents knowingly accessed a computer without authorization.

New York Consumer-Protection Claim

The court dismissed the claim under New York General Business Law § 349. That statute prohibits deceptive business practices and requires a plaintiff to allege a deceptive practice directed toward consumers that caused actual injury. The court held that Cheng alleged only an indirect or derivative injury: T-Mobile allegedly violated an agreement with Buchanan, which allegedly led to criminal conduct that caused Cheng’s loss.

Because the Complaint did not allege that T-Mobile directly interacted with or directly injured Cheng, the court concluded that the claim lacked the required direct injury. The court also stated that Cheng did not address T-Mobile’s argument about the derivative nature of his injury in his opposition, which provided an additional reason to dismiss the claim.

Disposition

Judge P. Kevin Castel granted T-Mobile’s motion to dismiss. The court stated that the motion was granted as to all claims, directed the Clerk to enter judgment and terminate the motion, and ordered the case closed. The opinion does not state an additional prejudice designation for the dismissal.

The authoritative version

Read the full 13-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.