Medicis v. Ally Bank
- Nelson Roman
- 7:21-cv-06799
- U.S. District Court · Southern District of New York
- 19
In Medicis v. Ally Bank, Judge Roman dismissed the amended data-breach class action because De Medicis did not establish standing.
David De Medicis and the proposed class of Ally customers whose usernames and passwords allegedly appeared in website query strings; the order dismissed the amended complaint with prejudice and terminated the action.
What happened
In Medicis v. Ally Bank, David De Medicis claimed Ally Bank and Ally Financial exposed customers’ usernames and passwords through a website coding error. He brought claims including negligence, breach of contract, breach of fiduciary duty, and violations of Virginia and North Carolina laws, seeking relief for himself and a proposed class.
The court ruled that De Medicis had not shown a concrete present injury or a substantial risk of future identity theft or fraud. It found that the account freeze was caused by a litigation hold rather than the coding error, that disputed fraudulent transactions were refunded, and that alleged account-access problems and time spent responding to the incident did not establish a sufficient injury. The court also found that the alleged later misuse was not adequately connected to the coding error, which was inadvertent, followed by password resets and deletion efforts, and not shown to have caused increased fraud.
Judge Roman granted the defendants’ motion to dismiss and dismissed the amended complaint with prejudice. The clerk was directed to terminate the motion and the action.
The detailed version
- Medicis v. Ally Bank · No. 7:21-cv-06799
- Nelson Roman
- Mar. 25, 2024
Background
David De Medicis brought a proposed class action against Ally Bank and Ally Financial, Inc. He alleged that a coding error in the defendants’ website caused customers’ usernames and passwords to be sent to certain entities with business or contractual relationships with the defendants. He alleged that the defendants failed to protect the confidentiality of that information.
The amended complaint asserted negligence, negligence per se, breach of implied contract, breach of fiduciary duty, violations of the Virginia Personal Information Breach Notification Act and the North Carolina Unfair and Deceptive Trade Practices Act, and requests for injunctive and declaratory relief. The defendants moved to dismiss under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). The court had previously dismissed De Medicis’s original complaint without prejudice for failure to establish standing.
Standing and alleged present injuries
The court addressed subject-matter jurisdiction first. To establish Article III standing, a plaintiff must show an injury that is concrete and particularized, fairly traceable to the defendant’s conduct, and likely to be remedied by a favorable decision.
De Medicis alleged several present injuries. He claimed that Ally froze his accounts, preventing him from taking advantage of investment opportunities; that malicious actors made repeated attempts to access his accounts; that he spent time investigating and responding to the incident; that unauthorized actors accessed his Coinbase and Amazon accounts; and that he temporarily lost access to accounts because of fraudulent activity.
The court found these allegations insufficient. It held that the account freeze was caused by a litigation hold, not the coding error, so the alleged lost investment opportunity was not fairly traceable to the defendants’ conduct. The court also found that the Coinbase and Amazon losses had been fully refunded. It concluded that the alleged temporary loss of account access did not show an injury because De Medicis did not allege how the freezes caused a loss. The court adhered to its earlier conclusion that unauthorized access attempts and time spent responding to the incident did not establish a present injury under the circumstances alleged.
Risk of future harm
The court also considered whether De Medicis showed a substantial risk of future identity theft or fraud. It applied factors concerning whether the data exposure resulted from a targeted effort to obtain the data, whether the data had already been misused, and whether the exposed data was sufficiently sensitive to create a high risk of identity theft or fraud.
The court found that the coding error was an inadvertent programming error rather than a targeted attack. The defendants presented evidence that they required potentially affected customers to change their passwords, asked entities that may have received the information to delete it, and found no increased fraudulent or anomalous activity attributable to the coding error. The court also found that usernames and passwords were less sensitive than information posing a high risk of identity theft or fraud.
The court recognized that De Medicis adequately alleged that a compromised password had later been used to access his Coinbase and Amazon accounts, particularly because he had used the same password on those accounts. But it found that the more than one-year gap, the lack of a sufficient causal connection between the alleged “wave” of fraudulent activity and the coding error, and the other factors against him meant that the alleged misuse did not establish a substantial risk of future harm. The court concluded that finding standing would require an unsupported chain of assumptions about how the information was noticed, extracted, passed along, and misused.
Disposition
Judge Nelson S. Román held that De Medicis failed to establish the injury required for Article III standing. The court granted the defendants’ motion to dismiss and dismissed the amended complaint with prejudice. The court directed the clerk to terminate the motion and the action.
Read the full 19-page opinion on CourtListener, the free public archive maintained by the Free Law Project.