Class Action Complaint — Rouse v. LexisNexis Risk Solutions, Inc., No. 1:25-cv-03133 (N.D. Ga.)
- Date
- 2025-06-04
Summary
A class action complaint in Xezakia Rouse v. LexisNexis Risk Solutions, Inc., Case 1:25-cv-03133-TRJ, filed June 4, 2025 as Document 1 in the U.S. District Court for the Northern District of Georgia. The complaint alleges that LexisNexis failed to safeguard personally identifiable information in a data breach it says was discovered on or around December 25, 2024, affecting at least 364,333 persons, and that notice letters were not sent until on or about May 24, 2025. It asserts claims for negligence, unjust enrichment and breach of implied contract, and invokes jurisdiction under 28 U.S.C.§ 1332(d). The prayer for relief seeks damages, attorneys' fees, prejudgment interest and injunctive measures, and the plaintiff demands a jury trial. The 75-page complaint is signed by counsel from Milberg Coleman Bryson Phillips Grossman PLLC and Markovits, Stock & DeMarco, LLC.
Summary drafted by a model from the document's text below and checked by script against that text before publication. It is a navigation aid, not a reading of what the document proves. Where AI is used
Full text
Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 1 of 75 UNITED STATES DISTRICT COURT NORTHERN DISTRICT OF GEORGIA XEZAKIA ROUSE, on behalf of himself and all others similarly situated, Case No. __________ CLASS ACTION COMPLAINT Plaintiff, v. LEXISNEXIS RISK SOLUTIONS, INC., JURY TRIAL DEMANDED Defendant. Plaintiff Xezakia Rouse (“Plaintiff”) brings this Class Action Complaint against LexisNexis Risk Solutions, Inc. (“Defendant” or “LexisNexis”), on behalf of himself and all others similarly situated (“Class Members”), and alleges, upon personal knowledge as to his own actions and his counsels’ investigations, and upon information and belief as to all other matters, as follows: NATURE OF THE ACTION 1. Plaintiff brings this class action against Defendant for its failure to properly secure and safeguard personally identifiable information (“PII” or “Private Information”)1 including, but not limited to names, contact information (such as 1 Personally identifiable information generally incorporates information that can be used to 1 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 2 of 75 phone numbers, postal or email addresses), Social Security numbers, driver’s license numbers or dates of birth. 2. Defendant LexisNexis is one of the world's largest consumer reporting agencies and data brokers, collecting, processing, storing, and selling vast quantities of consumer data to businesses, insurance companies, financial institutions, government agencies, law enforcement, and other organizations across the globe. 3. In its role as a data aggregator and information services provider, Defendant collects and maintains extraordinarily detailed profiles on virtually every adult consumer in the United States, including highly sensitive information such as Social Security numbers, driver's license numbers, dates of birth, current and former addresses, telephone numbers, email addresses, employment information, financial account information, criminal history records, and other personally identifiable information. 4. To provide these services, and in the ordinary course of Defendant LexisNexis Risk Solutions, Inc.’s business, Defendant acquires, possesses, analyzes, and otherwise utilizes Plaintiff’s and putative Class Members’ PII. distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information. 2 C.F.R. § 200.79. At a minimum, it includes all information that on its face expressly identifies an individual. PII also is generally defined to include certain identifiers that do not on its face name an individual, but that are considered to be particularly sensitive and/or valuable if in the wrong hands (for example, Social Security numbers, passport numbers, driver’s license numbers, financial account numbers). 2 Case 1:25-cv-03133-TRJ 5. Document 1 Filed 06/04/25 Page 3 of 75 Defendant generates billions of dollars in revenue by monetizing consumers' Private Information through the sale of consumer reports, background checks, risk assessment products, identity verification services, and fraud prevention tools to its corporate and government clients. 6. With this action, Plaintiff seeks to hold Defendant responsible for the harms it caused and will continue to cause Plaintiff and at least 364,333 2 other similarly situated persons in the massive and preventable cyberattack purportedly discovered by Defendant on or around December 25, 2024, in which cybercriminals infiltrated Defendant’s inadequately protected network servers and accessed and exfiltrated highly sensitive PII belonging to Plaintiff and Class Members which was being kept unprotected (the “Data Breach”). 7. Plaintiff further seeks to hold Defendant responsible for not ensuring that Defendant maintained the PII in a manner consistent with industry standards. 8. On or about May 24, 2025, Defendant notified state Attorneys General and many Class Members about the widespread Data Breach (the “Notice Letter”).3 2 Data Breach Notifications, Office of the Maine Attorney General, https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792a1252b4f8318/782e2159-f2d4-4394-8d03-51bf08a6b3e5.html (last visited May 30, 2025). 3 Sample Notice Letter available at the Office of the Maine Attorney General, https://www.maine.gov/cgi-bin/agviewerad/ret?loc=2634 (last visited May 30, 2025). 3 Case 1:25-cv-03133-TRJ 9. Document 1 Filed 06/04/25 Page 4 of 75 While Defendant claims to have discovered the Data Breach as early as December 25, 2024, Defendant did not begin informing victims of the Data Breach until May 24, 2025, almost 5 months later. Indeed, Plaintiff and Class Members were wholly unaware of the Data Breach until they received Notice Letters from Defendant. During this time, Plaintiff and Class Members were unaware that their sensitive PII had been compromised, and that they were, and continue to be, at significant risk of identity theft and various other forms of personal, social, and financial harm. 10. The Notice Letter provides no further information regarding the Data Breach and only recommends how victims can place a fraud alert or credit freeze on their account and how to sign up for the limited identity monitoring services Defendant offered in response to the Data Breach. The Notice Letter does not explain how the Data Breach occurred, what steps Defendant took following the Data Breach, whether Defendant made any changes to its data security, or most importantly, whether Plaintiff’s and Class Members’ PII remains in the possession of criminals. 11. By acquiring, utilizing, and benefiting from Plaintiff’s and Class Members’ PII for its business purposes, Defendant owed or otherwise assumed common law, contractual, and statutory duties that extended to Plaintiff and Class Members. These duties required Defendant to design and implement adequate data 4 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 5 of 75 security systems to protect Plaintiff’s and Class Members’ PII in its possession and to keep Plaintiff’s and Class Members’ PII confidential, safe, secure, and protected from unauthorized disclosure, access, dissemination, or theft. 12. Defendant breached these duties by failing to implement adequate data security measures and protocols to properly safeguard and protect Plaintiff’s and Class Members’ PII from a foreseeable cyberattack on its systems that resulted in the unauthorized access and theft of Plaintiff’s and Class Members’ PII. 13. Currently, the full extent of the types of PII, the scope of the breach, and the root cause of the Data Breach are all within the exclusive control of Defendant, its agents, counsel, and forensic security vendors at this phase of the litigation. 14. Defendant disregarded the rights of Plaintiff and Class Members by intentionally, willfully, recklessly, and/or negligently failing to take and implement adequate and reasonable measures to ensure that the PII of Plaintiff and Class Members was safeguarded, failing to take available steps to prevent an unauthorized disclosure of data, and failing to follow applicable, required, and appropriate protocols, policies and procedures regarding the encryption of data, even for internal use. As a result, the Plaintiff’s and Class Members’ PII was compromised through disclosure to an unknown and unauthorized criminal third party. 5 Case 1:25-cv-03133-TRJ 15. Document 1 Filed 06/04/25 Page 6 of 75 Upon information and belief, Defendant breached its duties and obligations in one or more of the following ways: (1) failing to design, implement, monitor, and maintain reasonable network safeguards against foreseeable threats; (2) failing to design, implement, and maintain reasonable data retention policies; (3) failing to adequately train staff on data security; (4) failing to comply with industrystandard data security practices; (5) failing to warn Plaintiff and Class Members of Defendant’s inadequate data security practices; (6) failing to encrypt or adequately encrypt the PII; (7) failing to recognize or detect that its network had been compromised and accessed in a timely manner to mitigate the harm; (8) failing to utilize widely available software able to detect and prevent this type of attack, and (9) otherwise failing to secure the hardware using reasonable and effective data security procedures free of foreseeable vulnerabilities and data security incidents. 16. Based on the type of sophisticated and targeted criminal activity, the type of PII involved, and Defendant’s admission that the PII was accessed, it can be concluded that the unauthorized criminal third party was able to successfully target Plaintiff’s and Class Members’ PII, infiltrate and gain access to Defendant’s network, and exfiltrate Plaintiff’s and Class Members’ PII, for the purposes of utilizing or selling the PII for use in future fraud and identity theft related cases. 17. Despite the highly sensitive nature of the information, it collects and maintains, and despite knowing that its vast databases of consumer information 6 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 7 of 75 would be an attractive target for cybercriminals, Defendant failed to implement adequate data security practices consistent with industry standards and federal and state regulations, leaving consumers' Private Information vulnerable to cyberattack. 18. Making matters worse, most consumers whose information was compromised in the Data Breach had no direct relationship with Defendant and were unaware that Defendant was collecting, storing, and selling their Private Information, depriving them of any opportunity to assess the risks or take steps to protect their information. 19. As a result of Defendant’s failures and the Data Breach, Plaintiff’s and Class Members’ identities are now at a current and substantial imminent and ongoing risk of identity theft and shall remain at risk for the rest of their lives. 20. As Defendant instructed, advised, and warned in its Notice Letter discussed below, Plaintiff and Class Members must now closely monitor their financial accounts to guard against future identity theft and fraud. Plaintiff and Class Members have heeded such warnings to mitigate against the imminent risk of future identity theft and financial loss. Such mitigation efforts included and will include into the future: (a) reviewing financial statements; (b) changing passwords; and (c) signing up for credit and identity theft monitoring services. The loss of time and other mitigation costs are tied directly to guarding against and mitigating against the imminent risk of identity theft. 7 Case 1:25-cv-03133-TRJ 21. Document 1 Filed 06/04/25 Page 8 of 75 Plaintiff and Class Members have suffered numerous actual and concrete injuries as a direct result of the Data Breach, including: (a) financial costs incurred mitigating the materialized risk and imminent threat of identity theft; (b) loss of time and loss of productivity incurred mitigating the materialized risk and imminent threat of identity theft; (c) financial costs incurred due to actual identity theft; (d) loss of time incurred due to actual identity theft; (e) loss of time heeding Defendant’s warnings and following its instructions in the Notice Letter; (f) deprivation of value of their PII; (f) invasions of their privacy; and (h) the continued risk to their PII, which remains in the possession of Defendant, and which is subject to further breaches, so long as Defendant fail to undertake appropriate and adequate measures to protect it. 22. Plaintiff brings this action on behalf of all persons whose PII was compromised due to Defendant’s failure to adequately protect Plaintiff’s and Class Members’ PII. Accordingly, Plaintiff brings this action against Defendant seeking redress for its unlawful conduct and asserts claims on behalf of the Class for Negligence, Unjust Enrichment, and Breach of Implied Contract. PARTIES 23. Plaintiff Xezakia Rouse is an adult individual and, at all relevant times herein, a resident and citizen of the state of Ohio, residing in Lebanon, Ohio, in Warren County. 8 Case 1:25-cv-03133-TRJ 24. Document 1 Filed 06/04/25 Page 9 of 75 Defendant LexisNexis Risk Solutions, Inc. is a Georgia corporation with its principal place of business at 1000 Alderman Drive, Alpharetta, Georgia. JURISDICTION AND VENUE 25. This Court has subject matter jurisdiction over this action under 28 U.S.C.§ 1332(d) because this is a class action wherein the amount in controversy exceeds the sum or value of $5,000,000, exclusive of interest and costs, there are more than 100 members in the proposed class, and at least one member of the class, including Plaintiff Rouse, is a citizen of a state different from Defendant. 26. This Court has personal jurisdiction over Defendant because Defendant conducts substantial business in this District, has sufficient minimum contacts with this District, and otherwise purposefully avails itself of the markets in this District through its business operations, such that the exercise of personal jurisdiction would not offend traditional notions of fair play and substantial justice. 27. Venue is proper under 28 U.S.C § 1391(b)(1) because Defendant’s principal place of business is in this District. FACTUAL ALLEGATIONS Background 28. LexisNexis is a leading global provider of information and analytics that claims to help businesses and government agencies make better decisions and improve operational efficiency. 9 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 10 of 75 Defendant is a subsidiary of RELX Inc. (formerly Reed Elsevier), a 29. multinational information and analytics company, and operates as part of the broader LexisNexis family of companies. Defendant's primary business involves collecting, aggregating, 30. analyzing, and selling vast amounts of consumer data to various industries, including insurance, financial services, healthcare, retail, government, law enforcement, and telecommunications. According to its own marketing materials, Defendant maintains one of 31. the world's largest databases of public records, proprietary data, and other consumer information, with billions of records from thousands of sources. In the ordinary course of its business, LexisNexis maintains the PII of 32. its customers, current and past employees, consumers, and others. Defendant's consumer databases include information obtained from 33. numerous sources, including but not limited to: Public records (court records, property records, voter registrations, etc.) • Credit header information from credit reporting agencies • Motor vehicle records • Professional licensing boards • Utility companies • Magazine subscriptions and warranty registrations • Social media and internet activity • Retail purchase histories • Insurance claims data • Healthcare records • 10 Case 1:25-cv-03133-TRJ • Document 1 Filed 06/04/25 Page 11 of 75 Employment records Defendant combines and analyzes this information to create 34. comprehensive profiles on virtually every adult consumer in the United States, which it then packages and sells through various products and services. Defendant's products include, but are not limited to: 35. • • • • • • • • Consumer reports for employment screening Tenant screening reports Insurance underwriting and claims investigation tools Identity verification services Fraud detection and prevention tools Skip tracing and debt collection services Law enforcement investigative tools Risk assessment and predictive analytics Defendant markets itself as a trusted steward of consumer information 36. and emphasizes the security, accuracy, and reliability of its data products and services. On its website and in marketing materials, Defendant makes numerous 37. representations about its commitment to data security and privacy, including claims that it: • • • • • 38. Maintains "industry-leading" security measures Employs "state-of-the-art" technology to protect consumer data Follows "rigorous" security protocols Implements "comprehensive" data protection programs Adheres to all applicable privacy and security regulations Despite these representations, Defendant failed to implement and 11 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 12 of 75 maintain security measures adequate to protect the massive amounts of sensitive consumer information in its possession. The Cyberattack and Data Breach 39. On or about December 25, 2024, unauthorized individuals successfully breached Defendant's computer systems and gained unauthorized access to databases containing Plaintiff’s and consumers' PII. The unauthorized access was the result of a cybersecurity incident.4 40. Upon information and belief, the attackers were able to infiltrate Defendant's systems due to one or more of the security failures described above. 41. LexisNexis took steps to secure its network systems and investigated the nature and scope of the incident with the consultation of third-party cybersecurity professionals and law enforcement. 5 42. Through its investigation, LexisNexis determined that its network and servers were subject to a cyberattack that impacted its network resulting in information on its network being accessed and acquired without authorization.6 43. Upon information and belief, Plaintiff’s and Class Members’ PII was exfiltrated and stolen in the attack. 4 See Notice Letter. 5 Id. 6 Id. 12 Case 1:25-cv-03133-TRJ 44. Document 1 Filed 06/04/25 Page 13 of 75 Furthermore, the investigation determined that the accessed systems contained PII. Upon information and belief, this PII was accessible, unencrypted, unprotected, and vulnerable to acquisition and/or exfiltration by the unauthorized actor. 45. The type of PII accessed by the unauthorized actor in the Data Breach includes names, contact information (such as phone numbers, postal or email addresses), Social Security numbers, driver’s license numbers or dates of birth.7 46. While LexisNexis stated in the Notice Letter that the unusual activity occurred and was discovered on December 25, 2024, LexisNexis did not begin notifying victims until May 24, 2025, almost 5 months after LexisNexis discovered the Data Breach occurred.8 47. Defendant had obligations created by contract, industry standards, common law, and its own promises and representations to keep Plaintiff’s and Class Members’ PII confidential and to protect it from unauthorized access and disclosure. 48. Plaintiff and Class Members provided their PII directly, or indirectly, to Defendant with the reasonable expectation and mutual understanding that 7 Id. 8 Id. 13 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 14 of 75 Defendant would comply with its obligations to keep such information confidential and secure from unauthorized access. 49. Through its Notice Letter, LexisNexis also recognized the actual imminent harm and injury that flowed from the Data Breach, so it encouraged breach victims to take steps to mitigate their risk of identity theft, such as reviewing financial accounts, and reviewing credit reports for possible fraud. 50. LexisNexis has offered abbreviated, non-automatic credit monitoring services to victims thereby identifying the harm posed to Plaintiff and Class Members as a result of the Data Breach, which does not adequately address the lifelong harm that victims face following the Data Breach. Indeed, the Data Breach involves PII that cannot be changed, such as Social Security numbers. 51. Beginning on or around May 24, 2025, Defendant issued Notice Letters to Plaintiff and Class Members. In total, at least 364,333 individuals were impacted by the Data Breach. 9 52. As a result of the Data Breach, Plaintiff and at least 364,333 Class Members suffered ascertainable losses in the form of the loss of the benefit of their bargain, out-of-pocket expenses, and the value of their time reasonably incurred to 9 See Data Breach Notifications, Office of the Maine Attorney General, https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792a1252b4f8318/782e2159-f2d4-4394-8d03-51bf08a6b3e5.html (last visited May 30, 2025). 14 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 15 of 75 remedy or mitigate the effects of the attack and the substantial and imminent risk of identity theft. 53. Defendant waited almost 5 months to disclose the Data Breach to Plaintiff and Class Members. As a result of this delay, Plaintiff and Class Members had no idea their PII had been compromised in the Data Breach, and that they were, and continue to be, at significant risk of identity theft and various other forms of personal, social, and financial harm. The risk will remain for their respective lifetimes. 54. Defendant’s failure to timely detect and report the Data Breach made its consumers vulnerable to identity theft without any warnings to monitor their financial accounts or credit reports to prevent unauthorized use of their PII. 55. This PII was compromised due to Defendant’s negligent and/or careless acts and omissions and the failure to protect the PII of Plaintiff and Class Members. 56. Despite recognizing its duty to do so, on information and belief, Defendant has not implemented reasonable cybersecurity safeguards or policies to protect its consumers’ PII or trained its IT or data security employees to prevent, detect, and stop breaches of its systems. As a result, Defendant leaves significant vulnerabilities in its systems for cybercriminals to exploit and gain access to consumers’ PII. 57. Plaintiff and Class Members directly or indirectly entrusted Defendant 15 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 16 of 75 with sensitive and confidential information, including their PII which includes information that is static, does not change, and can be used to commit myriad financial crimes. 58. Plaintiff and Class Members relied on Defendant to keep their PII confidential and securely maintained, to use their PII for authorized purposes only, and to make only authorized disclosures of this information. Plaintiff and Class Members demand Defendant safeguard their PII. 59. The unencrypted PII of Plaintiff and Class Members will likely end up for sale on the dark web as that is the modus operandi of hackers. In addition, unencrypted PII may fall into the hands of companies that will use the detailed PII for targeted marketing without the approval of Plaintiff and Class Members. In turn, unauthorized individuals can easily access the PII of Plaintiff and Class Members. 60. Defendant did not use reasonable security procedures and practices appropriate to the nature of the sensitive, unencrypted information they were maintaining for Plaintiff and Class Members, causing the exposure of PII. The Data Breach Was Foreseeable 61. Defendant’s data security obligations were particularly important given the substantial increase in cyberattacks and/or data breaches in the finance industry preceding the date of the breach. 62. The data broker industry, including Defendant, has been the subject of 16 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 17 of 75 numerous high-profile data breaches in recent years, putting Defendant on clear notice of the security risks it faced. 63. Cybersecurity experts have repeatedly warned that data brokers like Defendant are prime targets for sophisticated cybercriminal organizations due to the volume and sensitivity of information they maintain. 64. Defendant had access to extensive resources, expertise, and industry knowledge that should have enabled it to implement appropriate security measures. 65. Defendant itself markets cybersecurity and fraud prevention products to other businesses, demonstrating its awareness of the prevalence of cyber threats, the sophistication of modern cybercriminals, the potential consequences of data breaches, and the security measures necessary to protect sensitive information. 66. The security measures necessary to prevent the Data Breach were well- known, commercially reasonable, and would not have imposed an undue burden on Defendant given the billions in revenue it generates from monetizing consumer information. 67. By failing to implement these reasonable security measures, Defendant consciously disregarded the rights and safety of consumers whose information it collected and profited from. Defendant Had an Obligation to Protect the PII 68. Defendant’s failure to adequately secure Plaintiff’s and Class 17 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 18 of 75 Members’ PII breaches duties it owes Plaintiff and Class Members under statutory and common law. Moreover, Plaintiff and Class Members surrendered their highly sensitive personal data to Defendant under the implied condition that Defendant would keep it private and secure. Accordingly, Defendant also has an implied duty to safeguard its data, independent of any statute. 69. Defendant was prohibited by the Federal Trade Commission Act (the “FTC Act”) (15 U.S.C. § 45) from engaging in “unfair or deceptive acts or practices in or affecting commerce.” The Federal Trade Commission (the “FTC”) has concluded that a company’s failure to maintain reasonable and appropriate data security for consumers’ sensitive personal information is an “unfair practice” in violation of the FTC Act. See, e.g., FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015). 70. Therefore, the increase in such attacks, and the attendant risk of future attacks, was widely known to the public and to anyone in Defendant’s industry, including Defendant. 71. In addition to its obligations under federal and state laws, Defendant owed a duty to Plaintiff and Class Members to exercise reasonable care in obtaining, retaining, securing, safeguarding, deleting, and protecting the PII in Defendant’s possession from being compromised, lost, stolen, accessed, and misused by unauthorized persons. Defendant owed a duty to Plaintiff and Class Members to 18 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 19 of 75 provide reasonable security, including consistency with industry standards and requirements, and to ensure that its computer systems, networks, and protocols adequately protected the PII of Plaintiff and Class Members. 72. Defendant owed a duty to Plaintiff and Class Members to design, maintain, and test its computer systems, servers, and networks to ensure that the PII in its possession was adequately secured and protected. 73. Defendant owed a duty to Plaintiff and Class Members to create and implement reasonable data security practices and procedures to protect the PII in its possession, including not sharing information with other entities who maintained substandard data security systems. 74. Defendant owed a duty to Plaintiff and Class Members to implement processes that would immediately detect a breach on its data security systems in a timely manner. 75. Defendant owed a duty to Plaintiff and Class Members to act upon data security warnings and alerts in a timely fashion. 76. Defendant owed a duty to Plaintiff and Class Members to disclose if its computer systems and data security practices were inadequate to safeguard individuals’ PII from theft because such an inadequacy would be a material fact in the decision to entrust this PII to Defendant. 77. Defendant owed a duty of care to Plaintiff and Class Members because 19 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 20 of 75 they were foreseeable and probable victims of any inadequate data security practices. 78. Defendant owed a duty to Plaintiff and Class Members to encrypt and/or more reliably encrypt Plaintiff’s and Class Members’ PII and monitor user behavior and activity in order to identify possible threats. 79. At all relevant times, Defendant knew, or reasonably should have known, of the importance of safeguarding the PII of Plaintiff and Class Members and the foreseeable consequences that would occur if Defendant’s data security system was breached, including, specifically, the significant costs that would be imposed on Plaintiff and Class Members as a result of a breach. 80. Defendant was, or should have been, fully aware of the unique type and the significant volume of data on Defendant’s network, amounting to, at least, tens of thousands of individuals’ PII, and, thus, the significant number of individuals who would be harmed by the exposure of the unencrypted data. Value of PII 81. The PII of individuals remains of high value to criminals, as evidenced by the prices criminals will pay through the Dark Web. Numerous sources cite Dark Web pricing for stolen identity credentials. For example, personal information can be sold at a price ranging from $40 to $200, and bank details have a price range of 20 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 21 of 75 $50 to $200. 10 Experian reports that a stolen credit or debit card number can sell for $5 to $110 on the dark web. 11 Criminals can also purchase access to entire company data breaches from $999 to $4,995.12 82. Based on the foregoing, the information compromised in the Data Breach, including full names matched with Social Security numbers, is significantly more valuable than the loss of, for example, credit card information in a retailer data breach because, there, victims can cancel or close credit and debit card accounts. The information compromised in this Data Breach is impossible to “close” and difficult, if not impossible, to change. 83. This data demands a much higher price on the black market. Martin Walter, senior director at cybersecurity firm RedSeal, explained, “Compared to credit card information, personally identifiable information and Social Security numbers are worth more than 10x on the black market.”13 10 Anita George, Your personal data is for sale on the dark web. Here’s how much it costs, Digital Trends (Oct. 16, 2019), https://www.digitaltrends.com/computing/personal-data-sold-on-thedark-web-how-much-it-costs/ (last visited May 30, 2025). 11 Brian Stack, Here’s How Much Your Personal Information Is Selling for on the Dark Web, Experian (Dec. 6, 2017), https://www.experian.com/blogs/ask-experian/heres-how-much-yourpersonal-information-is-selling-for-on-the-dark-web/ (last visited May 30, 2025). 12 In the Dark, VPNOverview, 2019, available at: https://vpnoverview.com/privacy/anonymousbrowsing/in-the-dark/ (last visited May 30, 2025). 13 Time Greene, Anthem Hack: Personal Data Stolen Sells for 10x Price of Stolen Credit Card Numbers, IT World, (Feb. 6, 2015), available at: https://www.networkworld.com/article/935334/anthem-hack-personal-data-stolen-sells-for-10xprice-of-stolen-credit-card-numbers.html (last visited May 30, 2025). 21 Case 1:25-cv-03133-TRJ 84. Document 1 Filed 06/04/25 Page 22 of 75 Among other forms of fraud, identity thieves may obtain driver’s licenses, government benefits, medical services, and housing or even give false information to police. 85. The fraudulent activity resulting from the Data Breach may not come to light for years as there may be a time lag between when harm occurs versus when it is discovered, and also between when the PII is stolen and when it is used. According to the U.S. Government Accountability Office (“GAO”), which conducted a study regarding data breaches: [L]aw enforcement officials told us that in some cases, stolen data may be held for up to a year or more before being used to commit identity theft. Further, once stolen data has been sold or posted on the Web, fraudulent use of that information may continue for years. As a result, studies that attempt to measure the harm resulting from data breaches cannot necessarily rule out all future harm. 14 86. At all relevant times, Defendant knew, or reasonably should have known, of the importance of safeguarding the PII of Plaintiff and Class Members, including Social Security numbers, and of the foreseeable consequences that would occur if Defendant’s data security system was breached, including, specifically, the significant costs that would be imposed on Plaintiff and Class Members as a result of a breach. 14 Report to Congressional Requesters, GAO, at 29 (June 2007), available at: https://www.gao.gov/assets/gao-07-737.pdf (last visited May 30, 2025). 22 Case 1:25-cv-03133-TRJ 87. Document 1 Filed 06/04/25 Page 23 of 75 Plaintiff and Class Members now face a lifetime of constant surveillance of their financial and personal records, credit monitoring, and loss of rights. Class Members are incurring and will continue to incur such damages in addition to any fraudulent use of their PII. 88. Defendant has acknowledged the risk and harm caused to Plaintiff and Class Members as a result of the Data Breach. Defendant, to date, has offered Plaintiff and Class Members abbreviated, non-automatic credit monitoring services. The limited credit monitoring is inadequate to protect Plaintiff and Class Members from the threats they face for years to come, particularly in light of the PII at issue here. Moreover, Defendant put the burden squarely on Plaintiff and Class Members to enroll in the inadequate monitoring services. Defendant Failed to Properly Protect Plaintiff’s and Class Members’ PII 89. Defendant could have prevented this Data Breach by properly securing and encrypting the systems containing the PII of Plaintiff and Class Members. Alternatively, Defendant could have destroyed the data, especially for individuals with whom it had not had a relationship for a period of time. 90. Defendant’s negligence in safeguarding the PII of Plaintiff and Class Members is exacerbated by the repeated warnings and alerts directed to companies like Defendant to protect and secure sensitive data they possess. 23 Case 1:25-cv-03133-TRJ 91. Document 1 Filed 06/04/25 Page 24 of 75 Despite the prevalence of public announcements of data breach and data security compromises, Defendant failed to take appropriate steps to protect the PII of Plaintiff and Class Members from being compromised. 92. The Federal Trade Commission (“FTC”) defines identity theft as “a fraud committed or attempted using the identifying information of another person without authority.” The FTC describes “identifying information” as “any name or number that may be used, alone or in conjunction with any other information, to identify a specific person,” including, among other things, “[n]ame, Social Security number, date of birth, official State or government issued driver’s license or identification number, alien registration number, government passport number, employer or taxpayer identification number.” 15 93. The ramifications of Defendant’s failure to keep secure the PII of Plaintiff and Class Members are long lasting and severe. Once PII is stolen, fraudulent use of that information and damage to victims may continue for their respective lifetimes. 94. To prevent and detect unauthorized cyber-attacks, Defendant could and should have implemented, as recommended by the United States Government, the 15 See generally Fighting Identity Theft With the Red Flags Rule: A How-To Guide for Business, FED. TRADE COMM., https://www.ftc.gov/business-guidance/resources/fighting-identity-theft-redflags-rule-how-guide-business (last visited May 30, 2025). 24 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 25 of 75 following measures: • Implement an awareness and training program. Because end users are targets, employees and individuals should be aware of the threat of ransomware and how it is delivered. • Enable strong spam filters to prevent phishing emails from reaching the end users and authenticate inbound email using technologies like Sender Policy Framework (SPF), Domain Message Authentication Reporting and Conformance (DMARC), and DomainKeys Identified Mail (DKIM) to prevent email spoofing. • Scan all incoming and outgoing emails to detect threats and filter executable files from reaching end users. • Configure firewalls to block access to known malicious IP addresses. • Patch operating systems, software, and firmware on devices. Consider using a centralized patch management system. • Set anti-virus and anti-malware programs to conduct regular scans automatically. • Manage the use of privileged accounts based on the principle of least privilege: no users should be assigned administrative access unless absolutely needed; and those with a need for administrator accounts should only use them when necessary. • Configure access controls—including file, directory, and network share permissions—with least privilege in mind. If a user only needs to read specific files, the user should not have write access to those files, directories, or shares. • Disable macro scripts from office files transmitted via email. Consider using Office Viewer software to open Microsoft Office files transmitted via email instead of full office suite applications. 25 Case 1:25-cv-03133-TRJ 95. Document 1 Filed 06/04/25 Page 26 of 75 • Implement Software Restriction Policies (SRP) or other controls to prevent programs from executing from common ransomware locations, such as temporary folders supporting popular Internet browsers or compression/decompression programs, including the AppData/LocalAppData folder. • Consider disabling Remote Desktop protocol (RDP) if it is not being used. • Use application whitelisting, which only allows systems to execute programs known and permitted by security policy. • Execute operating system environments or specific programs in a virtualized environment. • Categorize data based on organizational value and implement physical and logical separation of networks and data for different organizational units. 16 To prevent and detect cyber-attacks, including the cyber-attack that resulted in the Data Breach, Defendant could and should have implemented, as recommended by the United States Cybersecurity & Infrastructure Security Agency, the following measures: • Update and patch your computer. Ensure your applications and operating systems (OSs) have been updated with the latest patches. Vulnerable applications and OSs are the target of most ransomware attacks…. • Use caution with links and when entering website addresses. Be careful when clicking directly on links in emails, even if the sender appears to be someone you know. Attempt to independently verify website addresses (e.g., contact your organization’s helpdesk, search the 16 Federal Bureau of Investigation. Ransomware Prevention and Response for CISOs. FBI, 2020. https://www.fbi.gov/file-repository/ransomware-prevention-and-response-for-cisos.pdf (last visited June 2, 2025). 26 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 27 of 75 internet for the sender organization’s website or the topic mentioned in the email). Pay attention to the website addresses you click on, as well as those you enter yourself. Malicious website addresses often appear almost identical to legitimate sites, often using a slight variation in spelling or a different domain (e.g., .com instead of .net)…. • Open email attachments with caution. Be wary of opening email attachments, even from senders you think you know, particularly when attachments are compressed files or ZIP files. • Keep your personal information safe. Check a website’s security to ensure the information you submit is encrypted before you provide it…. • Verify email senders. If you are unsure whether or not an email is legitimate, try to verify the email’s legitimacy by contacting the sender directly. Do not click on any links in the email. If possible, use a previous (legitimate) email to ensure the contact information you have for the sender is authentic before you contact them. • Inform yourself. Keep yourself informed about recent cybersecurity threats and up to date on ransomware techniques. You can find information about known phishing attacks on the Anti-Phishing Working Group website. You may also want to sign up for CISA product notifications, which will alert you when a new Alert, Analysis Report, Bulletin, Current Activity, or Tip has been published. • Use and maintain preventative software programs. Install antivirus software, firewalls, and email filters—and keep them updated—to reduce malicious network traffic….17 96. To prevent and detect cyber-attacks, including the cyber-attack that resulted in the Data Breach, Defendant could and should have implemented, as recommended by the Microsoft Threat Protection Intelligence Team, the following 17 See Security Tip (ST19-001) Protecting Against Ransomware (original release date Apr. 11, 2019), available at https://www.cisa.gov/news-events/news/protecting-against-ransomware (last visited May 30, 2025). 27 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 28 of 75 measures: Secure internet-facing assets • Apply the latest security updates. • Use threat and vulnerability management. • Perform regular audit; remove privileged credentials. Thoroughly investigate and remediate alerts • Prioritize and treat commodity malware infections as potential full compromise. Include IT Pros in security discussions • Ensure collaboration among [security operations], [security admins], and [information technology] admins to configure servers and other endpoints securely. Build credential hygiene • Use [multifactor authentication] or [network level authentication] and use strong, randomized, just-in-time local admin passwords. Apply principle of least privilege • • • • Monitor for adversarial activities. Hunt for brute force attempts. Monitor for cleanup of Event Logs. Analyze logon events. Harden infrastructure • • • • Use Windows Defender Firewall. Enable tamper protection. Enable cloud-delivered protection. Turn on attack surface reduction rules and [Antimalware Scan 28 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 29 of 75 Interface] for Office [Visual Basic for Applications].18 97. Moreover, given that Defendant was storing the PII of Plaintiff and Class Members, Defendant could and should have implemented all of the above measures to prevent and detect cyberattacks. 98. The occurrence of the Data Breach indicates that Defendant failed to adequately implement one or more of the above measures to prevent cyberattacks, resulting in the Data Breach and the exposure of the PII of Plaintiff and Class Members. 99. As a result of computer systems in need of security upgrades, inadequate procedures for handling email phishing attacks, viruses, malignant computer code, hacking attacks, Defendant negligently and unlawfully failed to safeguard Plaintiff’s and Class Members’ PII. 100. Because Defendant failed to properly protect and safeguard Plaintiff’s and Class Members’ PII, an unauthorized third party was able to access Defendant’s network, and access Defendant’s database and system configuration files and exfiltrate that data. Defendant Failed to Comply with Industry Standards 18 See Human-operated ransomware attacks: A preventable disaster, Microsoft (Mar. 5, 2020). https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-apreventable-disaster/ (last visited May 30, 2025). 29 Case 1:25-cv-03133-TRJ 101. Document 1 Filed 06/04/25 Page 30 of 75 As shown above, experts studying cyber security routinely identify companies in the Information services industry as being particularly vulnerable to cyberattacks because of the value of the PII which they collect and maintain. 102. Several best practices have been identified that at a minimum should be implemented by Information services service providers like Defendant, including, but not limited to: educating all employees; strong passwords; multi-layer security, including firewalls, anti-virus, and anti-malware software; encryption, making data unreadable without a key; multi-factor authentication; backup data; and limiting which employees can access sensitive data. 103. Other best cybersecurity practices that are standard in the Information services industry include installing appropriate malware detection software; monitoring and limiting the network ports; protecting web browsers and email management systems; setting up network systems such as firewalls, switches, and routers; monitoring and protection of physical security systems; protection against any possible communication system; and training staff regarding critical points. 104. Defendant failed to meet the minimum standards of any of the following frameworks: the NIST Cybersecurity Framework Version 1.1 (including without limitation PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-5, PR.AC-6, PR.AC-7, PR.AT-1, PR.DS-1, PR.DS-5, PR.PT-1, PR.PT-3, DE.CM-1, DE.CM-4, DE.CM-7, DE.CM-8, and RS.CO-2), and the Center for Internet Security’s Critical Security 30 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 31 of 75 Controls (CIS CSC), which are all established standards in reasonable cybersecurity readiness. 105. The foregoing frameworks are existing and applicable industry standards in the Information services industry, and Defendant failed to comply with these accepted standards, thereby opening the door to and causing the Data Breach. 106. Upon information and belief, Defendant failed to comply with one or more of the foregoing industry standards. Defendant’s Negligent Acts and Breaches 107. Defendant participated in and controlled the process of gathering the PII from Plaintiff and Class Members. 108. Defendant therefore assumed and otherwise owed duties and obligations to Plaintiff and Class Members to take reasonable measures to protect the information, including the duty of oversight, training, instruction, testing of the data security policies and network systems. Defendant breached these obligations to Plaintiff and Class Members and/or was otherwise negligent because it failed to properly implement data security systems and policies for its Information services network that would adequately safeguard Plaintiff’s and Class Members’ PII. Upon information and belief, Defendant’s unlawful conduct included, but is not limited to, one or more of the following acts and/or omissions: a. Failing to design and maintain an adequate data security system to 31 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 32 of 75 reduce the risk of data breaches and protect Plaintiff’s and Class Members’ PII. b. Failing to properly monitor its data security systems for data security vulnerabilities and risk. c. Failing to test and assess the adequacy of its data security system. d. Failing to develop adequate training programs related to the proper handling of emails and email security practices. e. Failing to develop and put into place uniform procedures and data security protections for its network. f. Failing to adequately fund and allocate resources for the adequate design, operation, maintenance, and updating necessary to meet industry standards for data security protection. g. Failing to ensure or otherwise require that it was compliant with FTC guidelines for cybersecurity. h. Failing to ensure or otherwise require that it was adhering to one or more of industry standards for cybersecurity discussed above. i. Failing to implement or update antivirus and malware protection software in need of security updating. j. Failing to require encryption or adequate encryption on its data systems. k. Otherwise negligently and unlawfully failing to safeguard Plaintiff’s and Class Members’ PII provided to Defendant, which in turn allowed cyberthieves to access its IT systems. COMMON INJURIES & DAMAGES 109. As result of Defendant’s ineffective and inadequate data security practices, Plaintiff and Class Members now face a present and ongoing risk of fraud 32 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 33 of 75 and identity theft. 110. Due to the Data Breach, and the foreseeable consequences of PII ending up in the possession of criminals, the risk of identity theft to Plaintiff and Class Members has materialized and is imminent, and Plaintiff and Class Members have all sustained actual injuries and damages, including: (a) invasion of privacy; (b) “out of pocket” costs incurred mitigating the materialized risk and imminent threat of identity theft; (c) loss of time and loss of productivity incurred mitigating the materialized risk and imminent threat of identity theft risk; (d) “out of pocket” costs incurred due to actual identity theft; (e) loss of time incurred due to actual identity theft; (f) loss of time due to increased spam and targeted marketing emails; (g) the loss of benefit of the bargain (price premium damages); (h) diminution or loss of value of their PII; and (i) the continued risk to their PII, which remains in Defendant’s possession, and which is subject to further breaches, so long as Defendant fail to undertake appropriate and adequate measures to protect Plaintiff’s and Class Members’ PII. The Risk of Identity Theft to Plaintiff and Class Members Is Present and Ongoing 111. The link between a data breach and the risk of identity theft is simple and well established. Criminals acquire and steal PII to monetize the information. Criminals monetize the data by selling the stolen information on the black market to 33 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 34 of 75 other criminals who then utilize the information to commit a variety of identity theft related crimes discussed below. 112. Because a person’s identity is akin to a puzzle with multiple data points, the more accurate pieces of data an identity thief obtains about a person, the easier it is for the thief to take on the victim’s identity – or track the victim to attempt other hacking crimes against the individual to obtain more data to perfect a crime. 113. For example, armed with just a name and date of birth, a data thief can utilize a hacking technique referred to as “social engineering” to obtain even more information about a victim’s identity, such as a person’s login credentials or Social Security number. Social engineering is a form of hacking whereby a data thief uses previously acquired information to manipulate and trick individuals into disclosing additional confidential or personal information through means such as spam phone calls and text messages or phishing emails. Data breaches are often the starting point for these additional targeted attacks on the victims. 114. The Dark Web is an unindexed layer of the internet that requires special software or authentication to access.19 Criminals in particular favor the dark web as it offers a degree of anonymity to visitors and website publishers. Unlike the traditional or ‘surface’ web, Dark Web users need to know the web address of the 19 Louis DeNicola, What Is the Dark Web?, Experian (May 12, 2021), https://www.experian.com/blogs/ask-experian/what-is-the-dark-web/ (last visited May 30, 2025). 34 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 35 of 75 website they wish to visit in advance. For example, on the surface web, the CIA’s web address is cia.gov, but on the dark web the CIA’s web address is ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion.20 This prevents Dark Web marketplaces from being easily monitored by authorities or accessed by those not in the know. 115. A sophisticated black market exists on the dark web where criminals can buy or sell malware, firearms, drugs, and frequently, personal and medical information like the PII at issue here.21 The anonymity of the dark web lends itself well to those who would seek to do financial harm to others.22The digital character of PII stolen in data breaches lends itself to dark web transactions because it is immediately transmissible over the internet and the buyer and seller can retain their anonymity. The sale of a firearm or drugs on the other hand requires a physical delivery address. Nefarious actors can readily purchase usernames and passwords for online streaming services, stolen financial information and account login credentials, and Social Security numbers, dates of birth, and medical information. As Microsoft warns “[t]he anonymity of the dark web lends itself well to those who 20 Id. 21 What is the Dark Web? – Microsoft 365 (July 15, 2022), https://www.microsoft.com/enus/microsoft-365-life-hacks/privacy-and-safety/what-is-the-dark-web (last visited May 30, 2025). 22 Id. 35 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 36 of 75 would seek to do financial harm to others.” 23 116. Social Security numbers, for example, are among the worst kind of personal information to have stolen because they may be put to numerous serious fraudulent uses and are difficult for an individual to change. The Social Security Administration stresses that the loss of an individual’s Social Security number, as is the case here, can lead to identity theft and extensive financial fraud: “A dishonest person who has your Social Security number can use it to get other personal information about you. Identity thieves can use your number and your good credit to apply for more credit in your name. Then, they use the credit cards and don’t pay the bills, it damages your credit. You may not find out that someone is using your number until you’re turned down for credit, or you begin to get calls from unknown creditors demanding payment for items you never bought. Someone illegally using your Social Security number and assuming your identity can cause a lot of problems. What’s more, it is no easy task to change or cancel a stolen Social Security number. An individual cannot obtain a new Social Security number without significant paperwork and evidence of actual misuse. In other words, preventive action to defend against the possibility of misuse of a Social Security number is not permitted; an individual must show evidence of actual, ongoing fraud activity to obtain a new number.” 24 117. Even then, a new Social Security number may not be effective, as “[t]he credit bureaus and banks are able to link the new number very quickly to the old number, so all of that old bad information is quickly inherited into the new Social 23 Id. 24 Social Security Administration. (2018). Identity theft and your Social Security number (SSA Publication No. 05-10064). https://www.ssa.gov/pubs/EN-05-10064.pdf 36 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 37 of 75 Security number.” 25 118. Identity thieves can also use Social Security numbers to obtain a driver’s license or official identification card in the victim’s name but with the thief’s picture; use the victim’s name and Social Security number to obtain government benefits 26; or file a fraudulent tax return using the victim’s information. In addition, identity thieves may obtain a job using the victim’s Social Security number, rent a house or receive medical services in the victim’s name, and may even give the victim’s personal information to police during an arrest resulting in an arrest warrant being issued in the victim’s name. And the Social Security Administration has warned that identity thieves can use an individual’s Social Security number to apply for additional credit lines.27 119. According to the FBI’s Internet Crime Complaint Center (IC3) 2019 Internet Crime Report, Internet-enabled crimes reached their highest number of complaints and dollar losses that year, resulting in more than $3.5 billion in losses 25 Brian Naylor, Victims of Social Security Number Theft Find It’s Hard to Bounce Back, NPR (Feb. 9, 2015), http://www.npr.org/2015/02/09/384875839/data-stolen-by-anthem-s-hackers-hasmillions-worrying-about-identity-theft (last visited May 30, 2025). 26 See U.S. Government Accountability Office. (2002). Social Security Numbers: Government Benefits from SSN Use but Could Provide Better Safeguards (GAO Publication No. GAO-02352). https://www.gao.gov/assets/a234457.html (last visited May 30, 2025). 27 Identity Theft and Your Social Security Number, Social Security Administration, 1 (2021), https://www.ssa.gov/pubs/EN-05-10064.pdf (last visited May 30, 2025). 37 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 38 of 75 to individuals and business victims. 28 120. Further, according to the same report, “rapid reporting can help law enforcement stop fraudulent transactions before a victim loses the money for good.” 29 Defendant did not rapidly report to Plaintiff and Class Members that their PII had been stolen. 121. Victims of identity theft also often suffer embarrassment, blackmail, or harassment in person or online, and/or experience financial losses resulting from fraudulently opened accounts or misuse of existing accounts. 122. In addition to out-of-pocket expenses that can exceed thousands of dollars and the emotional toll identity theft can take, some victims have to spend a considerable time repairing the damage caused by the theft of their PII. Victims of new account identity theft will likely have to spend time correcting fraudulent information in their credit reports and continuously monitor their reports for future inaccuracies, close existing bank/credit accounts, open new ones, and dispute charges with creditors. 123. Further complicating the issues faced by victims of identity theft, data thieves may wait years before attempting to use the stolen PII. To protect themselves, 28 See 2019 Internet Crime Report, FBI (Feb. 11, 2020), https://www.fbi.gov/news/stories/2019internet-crime-report-released-021120 (last visited May 30, 2025). 29 Id. 38 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 39 of 75 Plaintiff and Class Members will need to remain vigilant against unauthorized data use for years or even decades to come. 124. The Federal Trade Commission (“FTC”) has also recognized that consumer data is a new and valuable form of currency. In an FTC roundtable presentation, former Commissioner Pamela Jones Harbour stated that “most consumers cannot begin to comprehend the types and amount of information collected by businesses, or why their information may be commercially valuable. Data is currency. The larger the data set, the greater potential for analysis — and profit.”30 125. The FTC has also issued numerous guidelines for businesses that highlight the importance of reasonable data security practices. The FTC has noted the need to factor data security into all business decision-making. According to the FTC, data security requires: (1) encrypting information stored on computer networks; (2) retaining payment card information only as long as necessary; (3) properly disposing of personal information that is no longer needed; (4) limiting administrative access to business systems; (5) using industry-tested and accepted methods for securing data; (6) monitoring activity on networks to uncover 30 Statement of FTC Commissioner Pamela Jones Harbour (Remarks Before FTC Exploring Privacy Roundtable), FTC (Dec. 7, 2009), https://www.ftc.gov/sites/default/files/documents/public_statements/remarks-ftc-exploringprivacy-roundtable/091207privacyroundtable.pdf (last visited May 30, 2025). 39 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 40 of 75 unapproved activity; (7) verifying that privacy and security features function properly; (8) testing for common vulnerabilities; and (9) updating and patching third-party software.31 126. According to the FTC, unauthorized PII disclosures are extremely damaging to consumers’ finances, credit history and reputation, and can take time, money, and patience to resolve the fallout. The FTC treats the failure to employ reasonable and appropriate measures to protect against unauthorized access to confidential consumer data as an unfair act or practice prohibited by Section 5(a) of the FTC Act. 32 127. Defendant’s failure to properly notify Plaintiff and Class Members of the Data Breach exacerbated Plaintiff’s and Class Members’ injury by depriving them of the earliest ability to take appropriate measures to protect their PII and take other necessary steps to mitigate the harm caused by the Data Breach. Loss of Time to Mitigate the Risk of Identify Theft and Fraud 128. As a result of the recognized risk of identity theft, when a Data Breach occurs, and an individual is notified by a company that their PII was compromised, 31 See generally Federal Trade Commission. (2015). Start with Security: A Guide for Business. https://www.ftc.gov/business-guidance/resources/start-security-guide-business (last visited May 30, 2025). 32 See, e.g., Protecting Personal Information: A Guide for Business, FTC, https://www.ftc.gov/news-events/news/press-releases/2016/07/commission-finds-labmd-liableunfair-data-security-practices (last visited May 30, 2025). 40 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 41 of 75 as in this Data Breach, the reasonable person is expected to take steps and spend time to address the dangerous situation, learn about the breach, and otherwise mitigate the risk of becoming a victim of identity theft or fraud. Failure to spend time taking steps to review accounts or credit reports could expose the individual to greater financial harm – yet, the resource and asset of time has been lost. 129. Thus, due to Defendant’s admitted recognition of the actual and imminent risk of identity theft, Defendant offered Plaintiff and Class Members abbreviated, limited, and non-automatic credit monitoring services. 130. Plaintiff and Class Members have spent, and will spend additional time in the future, on a variety of prudent actions, such as placing “freezes” and “alerts” with credit reporting agencies, contacting financial institutions, closing or modifying financial accounts, changing passwords, reviewing and monitoring credit reports and accounts for unauthorized activity, and filing police reports, which may take years to discover and detect. 131. Plaintiff’s mitigation efforts are consistent with the U.S. Government Accountability Office that released a report in 2007 regarding data breaches (“GAO Report”) in which it noted that victims of identity theft will face “substantial costs and time to repair the damage to their good name and credit record.”33 33 See U.S. GOV’T ACCOUNTABILITY OFF., GAO-07-737, PERSONAL INFORMATION: DATA 41 Case 1:25-cv-03133-TRJ 132. Document 1 Filed 06/04/25 Page 42 of 75 Plaintiff’s mitigation efforts are also consistent with the steps that FTC recommends that data breach victims take to protect their personal and financial information after a data breach, including: contacting one of the credit bureaus to place a fraud alert (and consider an extended fraud alert that lasts for seven years if someone steals their identity), reviewing their credit reports, contacting companies to remove fraudulent charges from their accounts, placing a credit freeze on their credit, and correcting their credit reports.34 133. A study by Identity Theft Resource Center shows the multitude of harms caused by fraudulent use of personal and financial information: 35 BREACHES ARE FREQUENT, BUT EVIDENCE OF RESULTING IDENTITY THEFT IS LIMITED; HOWEVER, THE FULL EXTENT IS UNKNOWN (2007) (“GAO Report”), at 2 available at https://www.gao.gov/new.items/d07737.pdf (last visited May 30, 2025). 34 See Federal Trade Commission, IdentityTheft.gov, https://www.identitytheft.gov/Steps (last visited May 30, 2025). 35 “Credit Card and ID Theft Statistics” by Jason Steele, 10/24/2017, https://web.archive.org/web/20190304002224/https://www.creditcards.com/credit-cardnews/credit-card-security-id-theft-fraud-statistics-1276.php (last visited May 30, 2025). 42 at: Case 1:25-cv-03133-TRJ 134. Document 1 Filed 06/04/25 Page 43 of 75 Indeed, the FTC recommends that identity theft victims take several steps and spend time to protect their personal and financial information after a data breach, including contacting one of the credit bureaus to place a fraud alert (consider an extended fraud alert that lasts for 7 years if someone steals their identity), reviewing their credit reports, contacting companies to remove fraudulent charges from their accounts, placing a credit freeze on their credit, and correcting their credit reports.36 Diminution of Value of the PII 36 See Federal Trade Commission, IdentityTheft.gov, https://www.identitytheft.gov/Steps (last visited May 30, 2025). 43 Case 1:25-cv-03133-TRJ 135. Document 1 Filed 06/04/25 Page 44 of 75 PII is a valuable property right.37 Its value is axiomatic, considering the value of Big Data in corporate America and the consequences of cyber thefts include heavy prison sentences. Even this obvious risk to reward analysis illustrates beyond doubt that PII has considerable market value. 136. For example, drug manufacturers, medical device manufacturers, pharmacies, hospitals, and other healthcare service providers often purchase PII/PHI on the black market for the purpose of target-marketing their products and services to the physical maladies of the data breach victims themselves. 137. PII can sell for as much as $363 per record according to the Infosec Institute. 38 138. Medical information is especially valuable to identity thieves. Cybersecurity firm Trustwave calculated the black-market value of medical records at $250 each.39 37 See, e.g., John T. Soma, et al, Corporate Privacy Trend: The “Value” of Personally Identifiable Information (“PII”) Equals the “Value" of Financial Assets, 15 Rich. J.L. & Tech. 11, at *2-4 (2009) (“PII, which companies obtain at little cost, has quantifiable value that is rapidly reaching a level comparable to the value of traditional financial assets.”) (citations omitted), available at https://scholarship.richmond.edu/cgi/viewcontent.cgi?article=1310&context=jolt. 38 See Ashiq Ja, Hackers Selling Healthcare Data in the Black Market, InfoSec (July 27, 2015), https://resources.infosecinstitute.com/topic/hackers-selling-healthcare-data-in-the-black-market/ (last visited May 30, 2025). 39 Paul Ndrag, Medical records are the hottest items on the dark web, Fierce Healthcare (Jan. 26, 2021), https://www.fiercehealthcare.com/hospitals/industry-voices-forget-credit-card-numbersmedical-records-are-hottest-items-dark-web (last visited May 30, 2025). 44 Case 1:25-cv-03133-TRJ 139. Document 1 Filed 06/04/25 Page 45 of 75 An active and robust legitimate marketplace for PII also exists. In 2019, the data brokering industry was worth roughly $200 billion.40 In fact, the data marketplace is so sophisticated that consumers can actually sell their non-public information directly to a data broker who in turn aggregates the information and provides it to marketers or app developers. 41, 42 Consumers who agree to provide their web browsing history to the Nielsen Corporation can receive up to $60.00 a year.43 140. As a result of the Data Breach, Plaintiff’s and Class Members’ PII, which has an inherent market value in both legitimate and dark markets, has been damaged and diminished in its value by its unauthorized and potential release onto the Dark Web, where it may soon be available and holds significant value for the threat actors. Future Cost of Credit and Identity Theft Monitoring Is Reasonable and Necessary 141. To date, Defendant has done little to provide Plaintiff and Class 40 David Lazarus, Column: Shadowy data brokers make the most of their invisibility cloak, LA Times (Nov. 5, 2019), https://www.latimes.com/business/story/2019-11-05/column-data-brokers (last visited May 30, 2025). 41 See, e.g., https://datacoup.com/. 42 See, e.g., https://digi.me/features. 43 Nielsen Computer & Mobile Panel, Frequently Asked Questions, available at https://computermobilepanel.nielsen.com/ui/US/en/faqen.html (last visited May 30, 2025). 45 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 46 of 75 Members with relief for the damages they have suffered as a result of the Data Breach. 142. The abbreviated, limited, and non-automatic credit monitoring offered to Plaintiffs and Class Members whose PII was compromised is wholly inadequate as it fails to provide for the fact that victims of data breaches and other unauthorized disclosures commonly face ongoing identity theft and financial fraud for the remainder of their lives. Defendant also places the burden squarely on Plaintiff and Class Members by requiring them to independently sign up for that service, as opposed to automatically enrolling all victims of this Data Breach. 143. Given the type of targeted attack in this case and sophisticated criminal activity, the type of PII, and the modus operandi of cybercriminals, there is a strong probability that entire batches of stolen information have been placed, or will be placed, on the black market/Dark Web for sale and purchase by criminals intending to utilize the PII for identity theft crimes – e.g., opening bank accounts in the victims’ names to make purchases or to launder money; file false tax returns; take out loans or lines of credit; or file false unemployment claims. 144. It must be noted there may be a substantial time lag – measured in years – between when harm occurs versus when it is discovered, and also between when PII and/or financial information is stolen and when it is used. 145. Such fraud may go undetected until debt collection calls commence 46 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 47 of 75 months, or even years, later. An individual may not know that his or her Social Security Number was used to file for unemployment benefits until law enforcement notifies the individual’s employer of the suspected fraud. Fraudulent tax returns are typically discovered only when an individual’s authentic tax return is rejected. 146. Furthermore, the information accessed and disseminated in the Data Breach is significantly more valuable than the loss of, for example, credit card information in a retailer data breach, where victims can easily cancel or close credit and debit card accounts. 44 The information disclosed in this Data Breach is impossible to “close” and difficult, if not impossible, to change (such as Social Security numbers). 147. Consequently, Plaintiff and Class Members are at a present and ongoing risk of fraud and identity theft for many years into the future. 148. The retail cost of credit monitoring and identity theft monitoring can cost around $200 a year, or more, per Class Member. This is a reasonable and necessary cost to protect Class Members from the risk of identity theft that arose from Defendant’s Data Breach. This is a future cost for a minimum of five years that Plaintiff and Class Members would not need to bear but for Defendant’s failure to 44 See Jesse Damiani, Your Social Security Number Costs $4 On The Dark Web, New Report Finds, FORBES (Mar. 25, 2020), https://www.forbes.com/sites/jessedamiani/2020/03/25/your-socialsecurity-number-costs-4-on-the-dark-web-new-report-finds/?sh=6a44b6d513f1 (last visited May 30, 2025. 47 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 48 of 75 safeguard their PII. Injunctive Relief Is Necessary to Protect Against Future Data Breaches 149. Moreover, Plaintiff and Class Members have an interest in ensuring that their PII, which is believed to remain in the possession of Defendant, is protected from further breaches by the implementation of security measures and safeguards, including but not limited to, making sure that the storage of data or documents containing PII is not accessible online and that access to such data is password protected. Plaintiff’s Individual Experience Plaintiff Xezakia Rouse’s Experience 150. Plaintiff Rouse was sent a Notice Letter dated May 24, 2025, informing him that Defendant had experienced a Data Breach and that Plaintiff’s PII was compromised in the breach. 151. At the time of the Data Breach, Defendant retained Plaintiff Rouse’s PII in its system. 152. Defendant was in possession of Plaintiff’s PII before, during, and after the Data Breach. 153. As a result of the Data Breach, Plaintiff Rouse spent time dealing with the consequences of the Data Breach, which includes placing a security freeze on his credit reports, verifying the legitimacy of the Notice of Data Breach, self48 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 49 of 75 monitoring his accounts and/or credit reports to ensure no fraudulent activity has occurred. This time has been lost forever and cannot be recaptured. Moreover, this time was spent at Defendant’s direction by way of the Notice Letter where Defendant advised Plaintiff Rouse to mitigate his damages by, among other things, freezing his credit accounts and monitoring his accounts for fraudulent activity. 154. Plaintiff Rouse is a cautious person and is therefore very careful about sharing his sensitive PII. As a result, he has never knowingly transmitted unencrypted sensitive PII over the internet or any other unsecured source. Plaintiff Rouse stores any documents containing his PII in a safe and secure location or destroys the documents. Moreover, Plaintiff Rouse diligently chooses unique usernames and passwords for his various online accounts, changing and refreshing them as needed to ensure his information is as protected as it can be. 155. The Data Breach caused Plaintiff Rouse to suffer a loss of privacy. 156. Plaintiff Rouse has also experienced an increase in the number of spam calls and emails since the Data Breach. 157. The Data Breach has caused Plaintiff Rouse to suffer imminent and impending injury arising from the substantially increased risk of additional future fraud, identity theft, and misuse resulting from his PII being placed in the hands of criminals. 158. The loss of privacy and substantial present risk of additional imminent 49 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 50 of 75 harm have caused Plaintiff Rouse to suffer stress, fear, and anxiety as Plaintiff Rouse is very concerned that his sensitive PII is now in the hands of data thieves and shall remain that way for the remainder of his lifetime and there is nothing Plaintiff Rouse can do to retrieve his stolen PII from the cyber-criminals. 159. Plaintiff Rouse is aware of no other source from which the theft of his PII could have come. He regularly takes steps to safeguard his own PII in his own control. 160. Given the time Plaintiff Rouse has lost investigating this data breach, taking steps to understand its full scope, determining the appropriate remedial steps, contacting counsel, etc., coupled with Plaintiff Rouse’s resultant and naturally foreseeable fears/concerns for the use of Plaintiff Rouse’s valuable PII, the damages articulated more specifically above are far from the full extent of the harm thereto. CLASS ALLEGATIONS 161. Plaintiff brings this nationwide class action on behalf of himself and on behalf of others similarly situated pursuant to Rule 23(b)(2), 23(b)(3), and 23(c)(4) of the Federal Rules of Civil Procedure. 162. The Nationwide Class that Plaintiff seeks to represent is defined as follows: All persons in the United States who were impacted by the Data Breach publicly announced by Defendant in May 2025 (the “Class”). 50 Case 1:25-cv-03133-TRJ 163. Document 1 Filed 06/04/25 Page 51 of 75 Excluded from the Class are the following individuals and/or entities: Defendant and Defendant’s parents, subsidiaries, affiliates, officers and directors, and any entity in which Defendant has a controlling interest; all individuals who make a timely election to be excluded from this proceeding using the correct protocol for opting out; any and all federal, state or local governments, including but not limited to their departments, agencies, divisions, bureaus, boards, sections, groups, counsels and/or subdivisions; and all judges assigned to hear any aspect of this litigation, as well as their immediate family members. 164. Plaintiff reserves the right to modify or amend the definition of the proposed classes before the Court determines whether certification is appropriate. 165. Numerosity, Fed R. Civ. P. 23(a)(1): Class Members are so numerous that joinder of all members is impracticable. Upon information and belief, there are at least multiple thousands of individuals who were notified by Defendant of the Data Breach. According to the report submitted to the Maine Attorney General’s office, 364,333 individuals had their PII compromised in this Data Breach. 45 The identities of Class Members are ascertainable through Defendant’s records, Class Members’ records, publication notice, self-identification, and other means. 45 See Data Breach Notifications, Office of the Maine Attorney General, https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792a1252b4f8318/782e2159-f2d4-4394-8d03-51bf08a6b3e5.html (last visited May 30, 2025). 51 Case 1:25-cv-03133-TRJ 166. Document 1 Filed 06/04/25 Page 52 of 75 Commonality, Fed. R. Civ. P. 23(a)(2) and (b)(3): Questions of law and fact common to the Classes exist and predominate over any questions affecting only individual Class Members. These include: a. Whether and to what extent Defendant had a duty to protect the PII of Plaintiff and Class Members. b. Whether Defendant had duties not to disclose the PII of Plaintiff and Class Members to unauthorized third parties. c. Whether Defendant had duties not to use the PII of Plaintiff and Class Members for non-business purposes. d. Whether Defendant failed to adequately safeguard the PII of Plaintiff and Class Members. e. Whether and when Defendant actually learned of the Data Breach. f. Whether Defendant adequately, promptly, and accurately informed Plaintiff and Class Members that their PII had been compromised. g. Whether Defendant violated the law by failing to promptly notify Plaintiff and Class Members that their PII had been compromised. h. Whether Defendant failed to implement and maintain reasonable security procedures and practices appropriate to the nature and scope of the information compromised in the Data Breach. i. Whether Defendant adequately addressed and fixed the vulnerabilities 52 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 53 of 75 which permitted the Data Breach to occur. j. Whether Defendant engaged in unfair, unlawful, or deceptive practices by failing to safeguard the PII of Plaintiff and Class Members. k. Whether Defendant violated the consumer protection statutes invoked herein. l. Whether Plaintiff and Class Members are entitled to actual, consequential, and/or nominal damages as a result of Defendant’s wrongful conduct. m. Whether Plaintiff and Class Members are entitled to restitution as a result of Defendant’s wrongful conduct; and n. Whether Plaintiff and Class Members are entitled to injunctive relief to redress the imminent and currently ongoing harm faced as a result of the Data Breach. 167. Typicality, Fed. R. Civ. P. 23(a)(3): Plaintiff’s claims are typical of those of other Class Members because all had their PII compromised as a result of the Data Breach, due to Defendant’s misfeasance. 168. Policies Generally Applicable to the Class: This class action is also appropriate for certification because Defendant has acted or refused to act on grounds generally applicable to the Class, thereby requiring the Court’s imposition of uniform relief to ensure compatible standards of conduct toward the Class 53 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 54 of 75 Members and making final injunctive relief appropriate with respect to the Class as a whole. Defendant’s policies challenged herein apply to and affect Class Members uniformly and Plaintiff’s challenge of these policies hinges on Defendant’s conduct with respect to the Class as a whole, not on facts or law applicable only to Plaintiff. 169. Adequacy, Fed. R. Civ. P. 23(a)(4): Plaintiff will fairly and adequately represent and protect the interests of the Class Members in that Plaintiff has no disabling conflicts of interest that would be antagonistic to those of the other Members of the Class. Plaintiff seeks no relief that is antagonistic or adverse to the Members of the Class and the infringement of the rights and the damages Plaintiff has suffered are typical of other Class Members. Plaintiff has also retained counsel experienced in complex class action litigation, and Plaintiff intends to prosecute this action vigorously. 170. Superiority and Manageability, Fed. R. Civ. P. 23(b)(3): Class litigation is an appropriate method for fair and efficient adjudication of the claims involved. Class action treatment is superior to all other available methods for the fair and efficient adjudication of the controversy alleged herein; it will permit a large number of Class Members to prosecute their common claims in a single forum simultaneously, efficiently, and without the unnecessary duplication of evidence, effort, and expense that hundreds of individual actions would require. Class action treatment will permit the adjudication of relatively modest claims by certain Class 54 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 55 of 75 Members, who could not individually afford to litigate a complex claim against large corporations, like Defendant. Further, even for those Class Members who could afford to litigate such a claim, it would still be economically impractical and impose a burden on the courts. 171. The nature of this action and the nature of laws available to Plaintiff and Class Members make the use of the class action device a particularly efficient and appropriate procedure to afford relief to Plaintiff and Class Members for the wrongs alleged because Defendant would necessarily gain an unconscionable advantage since they would be able to exploit and overwhelm the limited resources of each individual Class Member with superior financial and legal resources; the costs of individual suits could unreasonably consume the amounts that would be recovered; proof of a common course of conduct to which Plaintiff was exposed is representative of that experienced by the Class and will establish the right of each Class Member to recover on the cause of action alleged; and individual actions would create a risk of inconsistent results and would be unnecessary and duplicative of this litigation. 172. The litigation of the claims brought herein is manageable. Defendant’s uniform conduct, the consistent provisions of the relevant laws, and the ascertainable identities of Class Members demonstrate that there would be no significant manageability problems with prosecuting this lawsuit as a class action. 55 Case 1:25-cv-03133-TRJ 173. Document 1 Filed 06/04/25 Page 56 of 75 Adequate notice can be given to Class Members directly using information maintained in Defendant’s records. 174. Unless a Class-wide injunction is issued, Defendant may continue in its failure to properly secure the PII of Class Members, Defendant may continue to refuse to provide proper notification to Class Members regarding the Data Breach, and Defendant may continue to act unlawfully as set forth in this Complaint. 175. Further, Defendant has acted or refused to act on grounds generally applicable to the Classes and, accordingly, final injunctive or corresponding declaratory relief with regard to the Class Members as a whole is appropriate under Rule 23(b)(2) of the Federal Rules of Civil Procedure. 176. Likewise, particular issues under Rule 23(c)(4) are appropriate for certification because such claims present only particular, common issues, the resolution of which would advance the disposition of this matter and the parties’ interests therein. Such particular issues include, but are not limited to: a. Whether Defendant owed a legal duty to Plaintiff and Class Members to exercise due care in collecting, storing, using, and safeguarding their PII. b. Whether Defendant breached a legal duty to Plaintiff and Class Members to exercise due care in collecting, storing, using, and safeguarding their PII. 56 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 57 of 75 c. Whether Defendant failed to comply with its own policies and applicable laws, regulations, and industry standards relating to data security. d. Whether an implied contract existed between Defendant on the one hand, and Plaintiff and Class Members on the other, and the terms of that implied contract. e. Whether Defendant breached the implied contract. f. Whether Defendant adequately and accurately informed Plaintiff and Class Members that their PII had been compromised. g. Whether Defendant failed to implement and maintain reasonable security procedures and practices appropriate to the nature and scope of the information compromised in the Data Breach. h. Whether Defendant engaged in unfair, unlawful, or deceptive practices by failing to safeguard the PII of Plaintiff and Class Members. i. Whether Class Members are entitled to actual, consequential, and/or nominal damages, and/or injunctive relief as a result of Defendant’s wrongful conduct. CAUSES OF ACTION COUNT I NEGLIGENCE (On Behalf of Plaintiff and the Class) 57 Case 1:25-cv-03133-TRJ 177. Document 1 Filed 06/04/25 Page 58 of 75 Plaintiff re-alleges and incorporates by reference herein all of the allegations contained in 1 through 176. 178. Plaintiff and the Class entrusted Defendant with their PII. 179. Plaintiff and the Class entrusted their PII to Defendant on the premise and with the understanding that Defendant would safeguard their information, use their PII for business purposes only, and/or not disclose their PII to unauthorized third parties. 180. Defendant has full knowledge of the sensitivity of the PII and the types of harm that Plaintiff and the Class could and would suffer if the PII were wrongfully disclosed. 181. Defendant knew or reasonably should have known that the failure to exercise due care in the collecting, storing, and using of the PII of Plaintiff and the Class involved an unreasonable risk of harm to Plaintiff and the Class, even if the harm occurred through the criminal acts of a third party. 182. Defendant had a duty to exercise reasonable care in safeguarding, securing, and protecting such information from being compromised, lost, stolen, misused, and/or disclosed to unauthorized parties. This duty includes, among other things, designing, maintaining, and testing Defendant’s security protocols to ensure that the PII of Plaintiff and the Class in Defendant’s possession was adequately 58 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 59 of 75 secured and protected. 183. Defendant also had a duty to exercise appropriate clearinghouse practices to remove PII it was no longer required to retain. 184. Defendant also had a duty to have procedures in place to detect and prevent the improper access and misuse of the PII of Plaintiff and the Class. 185. Defendant’s duty to use reasonable security measures arose as a result of the special relationship that existed between Defendant and Plaintiff and the Class. That special relationship arose because Plaintiff and the Class entrusted Defendant, either directly or indirectly, with their confidential PII, a necessary part of obtaining services from Defendant. 186. Defendant was subject to an “independent duty,” untethered to any contract between Defendant and Plaintiff or the Class. 187. A breach of security, unauthorized access, and resulting injury to Plaintiff and the Class was reasonably foreseeable, particularly in light of Defendant’s inadequate security practices. 188. Plaintiff and the Class were the foreseeable and probable victims of any inadequate security practices and procedures. Defendant knew or should have known of the inherent risks in collecting and storing the PII of Plaintiff and the Class, the critical importance of providing adequate security of that PII, and the necessity for encrypting PII stored on Defendant’s systems. 59 Case 1:25-cv-03133-TRJ 189. Document 1 Filed 06/04/25 Page 60 of 75 Defendant’s own conduct created a foreseeable risk of harm to Plaintiff and the Class. Defendant’s misconduct included, but was not limited to, its failure to take the steps and opportunities to prevent the Data Breach as set forth herein. Defendant’s misconduct also included its decisions not to comply with industry standards for the safekeeping of the PII of Plaintiff and the Class, including basic encryption techniques freely available to Defendant. 190. Plaintiff and the Class had no ability to protect their PII that was in, and possibly remains in, Defendant’s possession. 191. Defendant was in a position to protect against the harm suffered by Plaintiff and the Class as a result of the Data Breach. 192. Defendant had and continues to have a duty to adequately disclose that the PII of Plaintiff and the Class within Defendant’s possession might have been compromised, how it was compromised, and precisely the types of data that were compromised and when. Such notice was necessary to allow Plaintiff and the Class to take steps to prevent, mitigate, and repair any identity theft and the fraudulent use of their PII by third parties. 193. Defendant had a duty to employ proper procedures to prevent the unauthorized dissemination of the PII of Plaintiff and the Class. 194. Defendant has admitted that the PII of Plaintiff and the Class was wrongfully lost and disclosed to unauthorized third persons as a result of the Data 60 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 61 of 75 Breach. 195. Defendant, through its actions and/or omissions, unlawfully breached its duties to Plaintiff and the Class by failing to implement industry protocols and exercise reasonable care in protecting and safeguarding the PII of Plaintiff and the Class during the time the PII was within Defendant’s possession or control. 196. Defendant improperly and inadequately safeguarded the PII of Plaintiff and the Class in deviation of standard industry rules, regulations, and practices at the time of the Data Breach. 197. Defendant failed to heed industry warnings and alerts to provide adequate safeguards to protect the PII of Plaintiff and the Class in the face of increased risk of theft. 198. Defendant, through its actions and/or omissions, unlawfully breached its duty to Plaintiff and the Class by failing to have appropriate procedures in place to detect and prevent dissemination of PII. 199. Defendant breached its duty to exercise appropriate clearinghouse practices by failing to remove PII that It Was no longer required to retain pursuant to regulations. 200. Defendant, through its actions and/or omissions, unlawfully breached its duty to adequately and timely disclose to Plaintiff and the Class the existence and scope of the Data Breach. 61 Case 1:25-cv-03133-TRJ 201. Document 1 Filed 06/04/25 Page 62 of 75 But for Defendant’s wrongful and negligent breach of duties owed to Plaintiff and the Nationwide Class, the PII of Plaintiff and the Class would not have been compromised. 202. There is a close causal connection between Defendant’s failure to implement security measures to protect the PII of Plaintiff and the Class and the harm, or risk of imminent harm, suffered by Plaintiff and the Nationwide Class. The PII of Plaintiff and the Class was lost and accessed as the proximate result of Defendant’s failure to exercise reasonable care in safeguarding such PII by adopting, implementing, and maintaining appropriate security measures. 203. Additionally, Section 5 of the FTC Act prohibits “unfair . . . practices in or affecting commerce,” including, as interpreted and enforced by the FTC, the unfair act or practice by businesses, such as Defendant, of failing to use reasonable measures to protect PII. The FTC publications and orders described above also form part of the basis of Defendant’s duty in this regard. 204. Defendant violated Section 5 of the FTC Act by failing to use reasonable measures to protect PII and not complying with applicable industry standards, as described in detail herein. Defendant’s conduct was particularly unreasonable given the nature and amount of PII it obtained and stored and the foreseeable consequences of the immense damages that would result to Plaintiff and the Class. 62 Case 1:25-cv-03133-TRJ 205. Document 1 Filed 06/04/25 Page 63 of 75 Defendant’s violation of Section 5 of the FTC Act constitutes negligence. 206. Plaintiff and the Class are within the class of persons that the FTC Act was intended to protect. 207. The harm that occurred as a result of the Data Breach is the type of harm the FTC Act was intended to guard against. The FTC has pursued enforcement actions against businesses, which, as a result of its failure to employ reasonable data security measures and avoid unfair and deceptive practices, caused the same harm as that suffered by Plaintiff and the Class. 208. As a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will suffer injury, including but not limited to: (i) actual identity theft; (ii) the loss of the opportunity of how their PII is used; (iii) the compromise, publication, and/or theft of their PII; (iv) out-of-pocket expenses associated with the prevention, detection, and recovery from identity theft, tax fraud, and/or unauthorized use of their PII; (v) lost opportunity costs associated with effort expended and the loss of productivity addressing and attempting to mitigate the present and continuing consequences of the Data Breach, including but not limited to efforts spent researching how to prevent, detect, contest, and recover from tax fraud and identity theft; (vi) costs associated with placing freezes on credit reports; (vii) the continued risk to their PII, which remain in Defendant’s possession and is 63 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 64 of 75 subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the PII of Plaintiff and the Class; and (viii) present and continuing costs in terms of time, effort, and money that has been and will be expended to prevent, detect, contest, and repair the impact of the PII compromised as a result of the Data Breach for the remainder of the lives of Plaintiff and the Class. 209. As a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will continue to suffer other forms of injury and/or harm, including, but not limited to, anxiety, emotional distress, loss of privacy, and other economic and non-economic losses. 210. Additionally, as a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will suffer the continued risks of exposure of their PII, which remain in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the PII in its continued possession. 211. As a direct and proximate result of Defendant’s negligence, Plaintiff and the Class are entitled to recover actual, consequential, and nominal damages. COUNT II BREACH OF IMPLIED CONTRACT (On behalf of Plaintiff and the Class) 212. Plaintiff re-alleges and incorporates by reference herein all of the 64 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 65 of 75 allegations contained in 1 through 176. 213. The PII of Plaintiff and Class Members, including full names and Social Security numbers, was provided and entrusted to Defendant. 214. Plaintiff and Class Members provided their PII to Defendant, either directly or indirectly, through Defendant’s clients, as part of Defendant’s regular business practices. 215. Plaintiff and the Class entrusted their PII to Defendant. In doing so, Plaintiff and the Class entered into implied contracts with Defendant by which Defendant agreed to safeguard and protect such information, to keep such information secure and confidential, and to timely and accurately notify Plaintiff and the Class if their data had been breached and compromised or stolen. As a condition of obtaining services and being employed by Defendant’s clients, Plaintiff and Class Members provided and entrusted their PII. In so doing, Plaintiff and Class Members entered into implied contracts with Defendant by which Defendant agreed to safeguard and protect such information, to keep such information secure and confidential, and to timely and accurately notify Plaintiff and Class Members if their data had been breached and compromised or stolen. 216. A meeting of the minds occurred when Plaintiff and Class Members agreed to, and did, provide their PII to Defendant and/or Defendant’s clients with the reasonable understanding that their PII would be adequately protected by any 65 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 66 of 75 business associates, like Defendant, from foreseeable threats. This inherent understanding exists independent of any other law or contractual obligation any time that highly sensitive PII is exchanged as a condition of receiving services. It is common sense that but for this implicit and/or explicit agreement, Plaintiff and Class Members would not have provided their PII. 217. Defendant separately has contractual obligations arising from and/or supported by the consumer facing statements in its Privacy Policy. 218. Plaintiff and Class Members fully performed their obligations under the implied contracts with Defendant. 219. Defendant breached the implied contracts it made with Plaintiff and Class Members by failing to safeguard and protect their PII and by failing to provide timely and accurate notice that PII was compromised as a result of the Data Breach. 220. As a direct and proximate result of Defendant’s above-described breach of implied contract, Plaintiff and Class Members have suffered (and will continue to suffer) ongoing, imminent, and impending threat of identity theft crimes, fraud, and abuse, resulting in monetary loss and economic harm; actual identity theft crimes, fraud, and abuse, resulting in monetary loss and economic harm; loss of the confidentiality of the stolen confidential data; the illegal sale of the compromised data on the dark web; expenses and/or time spent on credit monitoring and identity theft insurance; time spent scrutinizing bank statements, credit card statements, and 66 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 67 of 75 credit reports; expenses and/or time spent initiating fraud alerts, decreased credit scores and ratings; lost work time; and other economic and non-economic harm. 221. As a result of Defendant’s breach of implied contract, Plaintiff and Class Members are entitled to and demand actual, consequential, and nominal damages. COUNT III Unjust Enrichment (On behalf of Plaintiff and the Class) 222. Plaintiff re-alleges and incorporates by reference herein all of the allegations contained in 1 through 176. Notwithstanding, Plaintiff brings this claim in the alternative to any claim for breach of contractual obligations. 223. Defendant benefited from receiving Plaintiff’s and Class Members’ PII by its ability to retain and use that information for its own benefit. Defendant understood this benefit. 224. Defendant enriched itself by saving the costs they reasonably should have expended on data security measures to secure Plaintiff’s and Class Members’ PII. 225. Defendant was also enriched from the value of Plaintiff’s and Class Members’ PII. PII has independent value as a form of intangible property. Defendant also derives value from this information because it allows Defendant to operate its business and generate revenue. 67 Case 1:25-cv-03133-TRJ 226. Document 1 Filed 06/04/25 Page 68 of 75 Instead of providing a reasonable level of security that would have prevented the Data Breach, Defendant instead calculated to avoid its data security obligations at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures. Plaintiff and Class Members, on the other hand, suffered as a direct and proximate result of Defendant’s failure to provide the requisite security. 227. Under the principles of equity and good conscience, Defendant should not be permitted to retain the monetary value of the benefit belonging to Plaintiff and Class Members, because Defendant failed to implement appropriate data management and security measures that are mandated by industry standards. 228. Defendant acquired the monetary benefit and PII through inequitable means in that they failed to disclose the inadequate security practices previously alleged. 229. If Plaintiff and Class Members knew that Defendant had not secured their PII, they would not have agreed to provide their PII to Defendant. 230. Plaintiff and Class Members have no adequate remedy at law. 231. As a direct and proximate result of Defendant’s conduct, Plaintiff and Class Members have suffered and will suffer injury, including but not limited to: (i) actual identity theft; (ii) the loss of the opportunity how their PII is used; (iii) the compromise, publication, and/or theft of their PII; (iv) out-of-pocket expenses 68 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 69 of 75 associated with the prevention, detection, and recovery from identity theft, and/or unauthorized use of their PII; (v) lost opportunity costs associated with effort expended and the loss of productivity addressing and attempting to mitigate the actual and future consequences of the Data Breach, including but not limited to efforts spent researching how to prevent, detect, contest, and recover from identity theft; (vi) the continued risk to their PII, which remains in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the PII in their continued possession and (vii) future costs in terms of time, effort, and money that will be expended to prevent, detect, contest, and repair the impact of the PII compromised as a result of the Data Breach for the remainder of the lives of Plaintiff and Class Members. 232. As a direct and proximate result of Defendant’s conduct, Plaintiff and Class Members have suffered and will continue to suffer other forms of injury and/or harm. 233. Defendant should be compelled to disgorge into a common fund or constructive trust, for the benefit of Plaintiff and Class Members, proceeds that it unjustly received from them. 69 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 70 of 75 PRAYER FOR RELIEF WHEREFORE, Plaintiff, on behalf of themselves and Class Members, request judgment against Defendant and that the Court grant the following: A. For an Order certifying the Classes, and appointing Plaintiff and his Counsel to represent the Class. B. For equitable relief enjoining Defendant from engaging in the wrongful conduct complained of herein pertaining to the misuse and/or disclosure of the PII of Plaintiff and Class Members, and from refusing to issue prompt, complete, any accurate disclosures to Plaintiff and Class Members. C. For injunctive relief requested by Plaintiff, including, but not limited to, injunctive and other equitable relief as is necessary to protect the interests of Plaintiff and Class Members, including but not limited to an order: i. prohibiting Defendant from engaging in the wrongful and unlawful acts described herein. ii. requiring Defendant to protect, including through encryption, all data collected through the course of its business in accordance with all applicable regulations, industry standards, and federal, state, or 70 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 71 of 75 local laws. iii. requiring Defendant to delete, destroy, and purge the PII of Plaintiff and Class Members unless Defendant can provide to the Court reasonable justification for the retention and use of such information when weighed against the privacy interests of Plaintiff and Class Members. iv. requiring Defendant to implement and maintain a comprehensive Information Security Program designed to protect the confidentiality and integrity of the PII of Plaintiff and Class Members. v. prohibiting Defendant from maintaining the PII of Plaintiff and Class Members on a cloud-based database. vi. requiring Defendant to engage independent third-party security auditors/penetration testers as well as internal security personnel to conduct testing, including simulated attacks, penetration tests, and audits on Defendant’s systems on a periodic basis, and ordering Defendant to promptly correct any problems or issues detected by such third-party security auditors. vii. requiring Defendant to engage independent third-party security auditors and internal personnel to run automated security 71 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 72 of 75 monitoring. viii. requiring Defendant to audit, test, and train its security personnel regarding any new or modified procedures. ix. requiring Defendant to segment data by, among other things, creating firewalls and access controls so that if one area of Defendant’s network is compromised, hackers cannot gain access to other portions of Defendant’s systems. x. requiring Defendant to conduct regular database scanning and securing checks. xi. requiring Defendant to establish an information security training program that includes at least annual information security training for all employees, with additional training to be provided as appropriate based upon the employees’ respective responsibilities with handling PII, as well as protecting the PII of Plaintiff and Class Members. xii. requiring Defendant to routinely and continually conduct internal training and education, and on an annual basis to inform internal security personnel how to identify and contain a breach when it occurs and what to do in response to a breach. xiii. requiring Defendant to implement a system of tests to assess its 72 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 73 of 75 respective employees’ knowledge of the education programs discussed in the preceding subparagraphs, as well as randomly and periodically testing employees’ compliance with Defendant’s policies, programs, and systems for protecting personal identifying information. xiv. requiring Defendant to implement, maintain, regularly review, and revise as necessary a threat management program designed to appropriately monitor Defendant’s information networks for threats, both internal and external, and assess whether monitoring tools are appropriately configured, tested, and updated. xv. requiring Defendant to meaningfully educate all Class Members about the threats that they face as a result of the loss of their confidential personal identifying information to third parties, as well as the steps affected individuals must take to protect themselves. xvi. requiring Defendant to implement logging and monitoring programs sufficient to track traffic to and from Defendant’s servers; and for a period of 10 years, appointing a qualified and independent third party assessor to conduct a SOC 2 Type 2 attestation on an annual basis to evaluate Defendant’s compliance with the terms of the Court’s final judgment, to provide such report to the Court and to 73 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 74 of 75 counsel for the class, and to report any deficiencies with compliance of the Court’s final judgment; D. For an award of damages, including, but not limited to, actual, consequential, and nominal damages, as allowed by law in an amount to be determined. E. For an award of attorneys’ fees, costs, and litigation expenses, as allowed by law. F. For prejudgment interest on all amounts awarded; and G. Such other and further relief as this Court may deem just and proper. DEMAND FOR JURY TRIAL Plaintiff hereby demands that this matter be tried before a jury. Date: June 4, 2025 Respectfully submitted, /s/ Casondra Turner Casondra Turner (GA Bar No. 418426) MILBERG COLEMAN BRYSON PHILLIPS GROSSMAN PLLC 800 S. Gay Street, Suite 1100 Knoxville, TN 37929 Telephone: (866) 252-0878 Fax: (771) 772-3086 cturner@milberg.com 74 Case 1:25-cv-03133-TRJ Document 1 Filed 06/04/25 Page 75 of 75 Terence R. Coates (pro hac vice forthcoming) Justin C. Walker (pro hac vice forthcoming) MARKOVITS, STOCK & DEMARCO, LLC 119 East Court Street, Suite 530 Cincinnati, OH 45202 Phone: (513) 651-3700 Fax: (513) 665-0219 tcoates@msdlegal.com jwalker@msdlegal.com Counsel for Plaintiff and Putative Class 75
File and source
- File
- gov.uscourts.gand.344889.1.0.pdf
- Size
- 691,211 bytes
- SHA-256
- 44567cf4afa188830c626ed93a31f858c531da05fbe211419ea37d6a978b578d
- Our copy
- gov.uscourts.gand.344889.1.0.pdf
- Original
- www.courtlistener.com