Class Action Complaint — Baker v. LexisNexis Risk Solutions Inc., No. 1:25-cv-03131 (N.D. Ga.)
- Date
- 2025-06-04
Summary
A class action complaint filed June 4, 2025 by Bruce H. Baker against LexisNexis Risk Solutions Inc. in the U.S. District Court for the Northern District of Georgia, Case 1:25-cv-03131-TRJ, Document 1. The complaint alleges that the defendant failed to safeguard customers' private information, including names, contact information, Social Security numbers, driver's license numbers and dates of birth, which it says was taken in a data breach at a third-party service provider. It quotes a notice letter stating that on April 1, 2025 the company learned that on December 25, 2024 an unauthorized third party acquired certain LNRS data. The complaint asserts jurisdiction under the Class Action Fairness Act, 28 U.S.C. § 1332(d)(2), and faults the timing and detail of the notice. It seeks injunctive relief, damages, attorneys' fees and a jury trial, and runs 55 pages.
Summary drafted by a model from the document's text below and checked by script against that text before publication. It is a navigation aid, not a reading of what the document proves. Where AI is used
Full text
Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 1 of 55 IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF GEORGIA BRUCE H. BAKER, Case No. ______ on behalf of himself and all others similarly situated, Plaintiff, CLASS ACTION COMPLAINT JURY TRIAL DEMANDED v. LEXISNEXIS RISK SOLUTIONS INC., Defendant. CLASS ACTION COMPLAINT Plaintiff Bruce H. Baker (“Plaintiff”) brings this Class Action Complaint against Defendant LexisNexis Risk Solutions Inc. (“Defendant” or “LNRS”) individually and on behalf of all others similarly situated, and allege, upon personal knowledge as to his own actions and his counsel’s investigation, and upon information and belief as to all other matters, as follows: INTRODUCTION 1. This class action arises out of the recent data breach (“Data Breach”) involving Defendant, a global data and analytics company. 2. Plaintiff brings this Complaint against Defendant for its failure to properly secure and safeguard the personally identifiable information that it collected and maintained as part of its regular business practices, including Plaintiff’s and Class Members’ names, contact information (such as phone number, postal or email address) Social Security numbers, driver’s license numbers, and dates of birth (collectively defined herein as “Private Information”). Case 1:25-cv-03131-TRJ 3. Document 1 Filed 06/04/25 Page 2 of 55 As part of the Data Breach, cybercriminals targeted and exfiltrated data from Defendant’s third-party service provider that hosts a portion of the data it collects. 4. Though Defendant has not identified the third-party service provider, the entity has been independently identified as GitHub.1 Moreover, Defendant should have known that GitHub was a particularly vulnerable company to entrust the Class’s Private Information to. Indeed, GitHub suffered another data breach just last year.2 5. Upon information and belief, customers of Defendant are required to entrust Defendant with sensitive, non-public Private Information, without which Defendant could not perform its regular business activities. Defendant retains this information for at least many years and even after the customer-service provider relationship has ended. 6. By obtaining, collecting, using, and deriving a benefit from the Private Information of Plaintiff and Class Members, Defendant assumed legal and equitable duties to those individuals to protect and safeguard that information from unauthorized access and intrusion. 7. Defendant failed to adequately protect Plaintiff’s and Class Members’ Private Information––and failed to even encrypt or redact this highly sensitive information. This unencrypted, unredacted Private Information was compromised due to Defendant’s negligent and/or careless acts and omissions and its utter failure to protect Plaintiff’s and Class Members’ sensitive data. Hackers targeted and obtained Plaintiff’s and Class Members’ Private Information because of its value in exploiting and stealing the identities of Plaintiff and Class Members. The 1 Ionut Arghire, 364,000 Impacted by Data Breach at LexisNexis Risk Solutions, SECURITY WEEK (May 28, 2025), https://www.securityweek.com/364000-impacted-by-data-breach-atlexisnexis-risk-solutions. 2 Twingate Team, GitHub Data Breach: What & How it Happened? (June 28, 2024), https://www.twingate.com/blog/tips/GitHub-data-breach. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 3 of 55 present and continuing risk of identity theft and fraud to victims of the Data Breach will remain for their respective lifetimes. 8. In breaching its duties to properly safeguard Plaintiff’s and Class Members’ Private Information and give them timely, adequate notice of the Data Breach’s occurrence, Defendant’s conduct amounts to negligence and/or recklessness and violates federal and state statutes. 9. Plaintiff brings this action on behalf of all persons whose Private Information was compromised as a result of Defendant’s failure to: (i) adequately protect the Private Information of Plaintiff and Class Members; (ii) warn Plaintiff and Class Members of Defendant’s inadequate information security practices; and (iii) effectively secure hardware containing protected Private Information using reasonable and effective security procedures free of vulnerabilities and incidents. Defendant’s conduct amounts at least to negligence and violates federal and state statutes. 10. Defendant disregarded the rights of Plaintiff and Class Members by intentionally, willfully, recklessly, or negligently failing to implement and maintain adequate and reasonable measures to ensure that the Private Information of Plaintiff and Class Members was safeguarded, failing to take available steps to prevent an unauthorized disclosure of data, and failing to follow applicable, required, and appropriate protocols, policies, and procedures regarding the encryption of data, even for internal use. As a result, the Private Information of Plaintiff and Class Members was compromised through disclosure to an unknown and unauthorized third party. Plaintiff and Class Members have a continuing interest in ensuring that their information is and remains safe, and they should be entitled to injunctive and other equitable relief. 11. Plaintiff and Class Members have suffered injury as a result of Defendant’s conduct. These injuries include: (i) invasion of privacy; (ii) theft of their Private Information; (iii) Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 4 of 55 lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) loss of benefit of the bargain; (vi) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vii) invasion of their privacy; (viii) nominal damages; and (ix) the continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse; and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. 12. Plaintiff seeks to remedy these harms and prevent any future data compromise on behalf of himself and all similarly situated persons whose personal data was compromised and stolen as a result of the Data Breach and who remain at risk due to Defendant’s inadequate data security practices. PARTIES 13. Plaintiff Bruce H. Baker is a natural resident and citizen of Missouri. 14. Defendant LexisNexis Risk Solutions, Inc. is a corporation organized under the state laws of Georgia with its principal place of business located in Alpharetta, Georgia. JURISDICTION AND VENUE 15. The Court has subject matter jurisdiction over this action under the Class Action Fairness Act, 28 U.S.C. § 1332(d)(2). The amount in controversy exceeds $5 million, exclusive of interest and costs. The number of class members is over 100, and at least one Class member is a citizen of a state that is diverse from Defendant’s citizenship, namely the Plaintiff. Thus, minimal diversity exists under 28 U.S.C. § 1332(d)(2)(A). Case 1:25-cv-03131-TRJ 16. Document 1 Filed 06/04/25 Page 5 of 55 This Court has personal jurisdiction over Defendant LNRS, because its principal place of business in Georgia, and it does a significant amount of business in Georgia. 17. Venue is proper in this Court pursuant to 28 U.S.C. § 1391(a)(1) because LNRS has its principal place of business located in this District, and a substantial part of the events giving rise to this action occurred in this District. FACTUAL ALLEGATIONS Background of Defendant. 18. Defendant is a global data and analytics company in Alpharetta, GA. 19. Plaintiff and Class Members are current/former customers of Defendant. 20. As a condition of receiving services from LNRS, Plaintiff and Class Members were required to provide Defendant with their sensitive and confidential Private Information, including their name, contact information (such as phone number, postal or email address), Social Security number, driver's license number or date of birth. 21. The information held by Defendant and the third-party service provider in their computer systems at the time of the Data Breach included the unencrypted Private Information of Plaintiff and Class Members. 22. Upon information and belief, Defendant made promises and representations to its current/former customers, including Plaintiff and Class Members, that the Private Information collected from them as a condition of receiving services would be kept safe and confidential, that the privacy of that information would be maintained, and that Defendant would delete any sensitive information after it was no longer required to maintain it. 23. Plaintiff and Class Members provided their Private Information to Defendant with the reasonable expectation and on the mutual understanding that Defendant would comply with its Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 6 of 55 obligations to keep such information confidential and secure from unauthorized access. Defendant is also obligated to ensure any third parties that it shares Plaintiff’s and Class Members’ Private Information with, implements reasonable cybersecurity measures. 24. Plaintiff and Class Members have taken reasonable steps to maintain the confidentiality of their Private Information. Plaintiff and Class Members relied on the sophistication of Defendant to keep their Private Information confidential and securely maintained, to use this information for necessary purposes only, and to make only authorized disclosures of this information. Plaintiff and Class Members value the confidentiality of their Private Information and demand security to safeguard their Private Information. 25. Defendant had a duty to adopt reasonable measures to protect the Private Information of Plaintiff and Class Members from involuntary disclosure to third parties. Defendant has a legal duty to keep its customers’ Private Information safe and confidential. 26. Defendant had obligations created by FTC Act, contract, industry standards, and representations made to Plaintiff and Class Members, to keep their Private Information confidential and to protect it from unauthorized access and disclosure. 27. Defendant derived a substantial economic benefit from collecting Plaintiff’s and Class Members’ Private Information. Without the required submission of Private Information, Defendant could not perform the services it provides. 28. By obtaining, collecting, using, and deriving a benefit from Plaintiff’s and Class Members’ Private Information, Defendant assumed legal and equitable duties and knew or should have known that it was responsible for protecting Plaintiff’s and Class Members’ Private Information from disclosure. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 7 of 55 The Data Breach. 29. Starting on or about May 24, 2025, Defendant began sending Plaintiff and other victims of the Data Breach a letter (the “Notice Letter”), informing them that: What Happened? On April 1, 2025, we learned that on December 25, 2024, an unauthorized third party acquired certain LNRS data from a third-party platform used for software development. The issue did not affect LNRS's own networks or systems. Based on our review of the impacted data, we have determined that certain of your personal information was affected. What Information Was Involved? The types of impacted personal information varied by affected individual, and could have included name, contact information (such as phone number, postal or email address), Social Security number, driver's license number or date of birth. 34 30. Omitted from the Notice Letter were the identity of the cybercriminals who perpetrated this Data Breach, the details of the root cause of the Data Breach, the vulnerabilities exploited, and the remedial measures undertaken to ensure such a breach does not occur again. To date, these critical facts have not been explained or clarified to Plaintiff and Class Members, who retain a vested interest in ensuring that their Private Information remains protected. 31. This “disclosure” amounts to no real disclosure at all, as it fails to inform, with any degree of specificity, Plaintiff and Class Members of the Data Breach’s critical facts. Without these details, Plaintiff’s and Class Members’ ability to mitigate the harms resulting from the Data Breach is severely diminished. 32. Despite Defendant’s intentional opacity about the root cause of this incident, several facts may be gleaned from the Notice Letter, including: a) that this Data Breach was the work of cybercriminals; b) that the cybercriminals first infiltrated Defendant’s networks and 3 The “Notice Letter”, attached hereto as Exhibit A. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 8 of 55 systems, and downloaded data from the networks and systems (aka exfiltrated data, or in layperson’s terms “stole” data; and c) that once inside Defendant’s networks and systems, the cybercriminals targeted information including Plaintiff’s and Class Members’ names, Social Security numbers, and bank account information for download and theft. 33. To be clear – there are numerous issues with LNRS’s Data Breach, but the deficiencies in the Data Breach notification letter exacerbate the circumstances for victims of the Data Breach: (1) LNRS waited over five months to notice Plaintiff and Class members of the Data Breach; (2) LNRS fails to state whether it was able to contain or end the cybersecurity threat, leaving victims to fear whether the Private Information that LNRS continues to maintain is secure; and (3) LNRS fails to state how the breach itself occurred. All of this information is vital to victims of a data breach, let alone a data breach of this magnitude due to the sensitivity and wide array of information compromised in this specific breach. 34. Moreover, in its Notice Letter, Defendant failed to specify whether it undertook any efforts to contact the Class Members whose data was accessed and acquired in the Data Breach to inquire whether any of the Class Members suffered misuse of their data, whether Class Members should report their misuse to Defendant, and whether Defendant set up any mechanism for Class Members to report any misuse of their data. 35. Furthermore, Defendant’s delay in notifying Plaintiff and Class members of the Data Breach is in direct violation of Defendant’s responsibilities under the data breach notification statute in Georgia. See GA Code § 10-1-912 which requires that the disclosure notification be made “without unreasonable delay”5. 5 While the definition of “reasonable” differs from state to state, the range is between 30-60 days. Defendant failed to meet this requirement by over 90 days. Case 1:25-cv-03131-TRJ 36. Document 1 Filed 06/04/25 Page 9 of 55 Defendant did not use reasonable security procedures and practices appropriate to the nature of the sensitive information they were maintaining for Plaintiff and Class Members, causing the exposure of Private Information, such as encrypting the information or instructing its service providers to delete the Private Information when it is no longer needed. 37. The attacker targeted, accessed, and acquired files in Defendant’s computer systems containing unencrypted Private Information of Plaintiff and Class Members, including their names, Social Security numbers, and bank account information. Plaintiff’s and Class Members’ Private Information was accessed and stolen in the Data Breach. 38. Plaintiff further believes that his Private Information and that of Class Members, was subsequently sold on the dark web following the Data Breach, as that is the modus operandi of cybercriminals that commit cyber-attacks of this type. Data Breaches Are Preventable. 39. Defendant could have prevented this Data Breach by, among other things, properly encrypting or otherwise protecting their equipment and computer files containing Private Information. 40. As explained by the Federal Bureau of Investigation, “[p]revention is the most effective defense against ransomware and it is critical to take precautions for protection.”6 41. To prevent and detect cyber-attacks, Defendant could and should have implemented, as recommended by the United States Government, the following measures: ● Implement an awareness and training program. Because end users are targets, employees and individuals should be aware of the threat of ransomware and how it is delivered. 6 How to Protect Your Networks from RANSOMWARE, at 3, available at: https://www.fbi.gov/file-repository/ransomware-prevention-and-response-for-cisos.pdf/view (last visited June 3, 2025). Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 10 of 55 ● Enable strong spam filters to prevent phishing emails from reaching the end users and authenticate inbound email using technologies like Sender Policy Framework (SPF), Domain Message Authentication Reporting and Conformance (DMARC), and DomainKeys Identified Mail (DKIM) to prevent email spoofing. ● Scan all incoming and outgoing emails to detect threats and filter executable files from reaching end users. ● Configure firewalls to block access to known malicious IP addresses. ● Patch operating systems, software, and firmware on devices. Consider using a centralized patch management system. ● Set anti-virus and anti-malware programs to conduct regular scans automatically. ● Manage the use of privileged accounts based on the principle of least privilege: no users should be assigned administrative access unless absolutely needed; and those with a need for administrator accounts should only use them when necessary. ● Configure access controls—including file, directory, and network share permissions— with least privilege in mind. If a user only needs to read specific files, the user should not have write access to those files, directories, or shares. ● Disable macro scripts from office files transmitted via email. Consider using Office Viewer software to open Microsoft Office files transmitted via email instead of full office suite applications. ● Implement Software Restriction Policies (SRP) or other controls to prevent programs from executing from common ransomware locations, such as temporary folders supporting popular Internet browsers or compression/decompression programs, including the AppData/LocalAppData folder. ● Consider disabling Remote Desktop protocol (RDP) if it is not being used. ● Use application whitelisting, which only allows systems to execute programs known and permitted by security policy. ● Execute operating system environments or specific programs in a virtualized environment. ● Categorize data based on organizational value and implement physical and logical separation of networks and data for different organizational units.7 7 Id. at 3-4. Case 1:25-cv-03131-TRJ 42. Document 1 Filed 06/04/25 Page 11 of 55 To prevent and detect cyber-attacks or ransomware attacks, Defendant could and should have implemented, as recommended by the Microsoft Threat Protection Intelligence Team, the following measures: Secure internet-facing assets - Apply latest security updates Use threat and vulnerability management Perform regular audit; remove privileged credentials; Thoroughly investigate and remediate alerts - Prioritize and treat commodity malware infections as potential full compromise; Include IT Pros in security discussions - Ensure collaboration among [security operations], [security admins], and [information technology] admins to configure servers and other endpoints securely; Build credential hygiene - Use [multifactor authentication] or [network level authentication] and use strong, randomized, just-in-time local admin passwords; Apply principle of least-privilege - Monitor for adversarial activities Hunt for brute force attempts Monitor for cleanup of Event Logs Analyze logon events; Harden infrastructure - 8 Use Windows Defender Firewall Enable tamper protection Enable cloud-delivered protection Turn on attack surface reduction rules and [Antimalware Scan Interface] for Office [Visual Basic for Applications].8 See Human-operated ransomware attacks: A preventable disaster (Mar 5, 2020), available at: https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-apreventable-disaster/ (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 43. Document 1 Filed 06/04/25 Page 12 of 55 Given that Defendant was storing the sensitive Private Information of its current/former customers, Defendant could and should have implemented all of the above measures to prevent and detect cyberattacks. 44. The occurrence of the Data Breach indicates that Defendant failed to adequately implement one or more of the above measures to prevent cyberattacks, resulting in the Data Breach and the exposure of the Private Information of, upon information and belief, thousands of thousands of individuals, including that of Plaintiff and Class Members. Defendant Acquires, Collects, and Stores Plaintiff’s and Class Members’ Private Information 45. As a condition of receiving services from LNRS, Plaintiff and Class Members were required to give their sensitive and confidential Private Information to Defendant. 46. Defendant retains and stores this information and derives a substantial economic benefit from the Private Information that it collects. But for the collection of Plaintiff’s and Class Members’ Private Information, Defendant would be unable to perform its services. 47. By obtaining, collecting, and storing the Private Information of Plaintiff and Class Members, Defendant assumed legal and equitable duties and knew or should have known that they were responsible for protecting the Private Information from disclosure. 48. Plaintiff and Class Members have taken reasonable steps to maintain the confidentiality of their Private Information and relied on Defendant to keep their Private Information confidential and maintained securely, to use this information for business purposes only, and to make only authorized disclosures of this information. Case 1:25-cv-03131-TRJ 49. Document 1 Filed 06/04/25 Page 13 of 55 Defendant could have prevented this Data Breach by properly securing and encrypting the files and file servers containing the Private Information of Plaintiff and Class Members. Defendant Knew or Should Have Known of the Risk Because Companies in Possession of Private Information are Particularly Susceptible to Cyber Attacks. 50. Data thieves regularly target companies like Defendant's due to the highly sensitive information that they custody. Defendant knew and understood that unprotected Private Information is valuable and highly sought after by criminal parties who seek to illegally monetize that Private Information through unauthorized access. 51. Defendant's data security obligations were particularly important given the substantial increase in cyber-attacks and/or data breaches targeting entities that collect and store Private Information and other sensitive information, like Defendant, preceding the date of the breach. 52. In 2023, an all-time high for data compromises occurred, with 3,205 compromises affecting 353,027,892 total victims.9 53. In light of recent high profile data breaches at other industry leading companies, including T-Mobile, USA (37 million records, February-March 2023), 23andMe, Inc. (20 million records, October 2023), Wilton Reassurance Company (1.4 million records, June 2023), NCB Management Services, Inc. (1 million records, February 2023), Defendant knew or should have known that the Private Information that it collected and maintained would be targeted by cybercriminals. 9 See 2023 Data Breach Annual Report, IDENTITY THEFT RESOURCE CENTER (Jan. 2024); https://www.idtheftcenter.org/wp-content/uploads/2024/01/ITRC_2023-Annual-Data-BreachReport.pdf . (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 54. Document 1 Filed 06/04/25 Page 14 of 55 Additionally, as companies became more dependent on computer systems to run their business,10 e.g., working remotely as a result of the Covid-19 pandemic, and the Internet of Things (“IoT”), the danger posed by cybercriminals is magnified, thereby highlighting the need for adequate administrative, physical, and technical safeguards.11 55. As a custodian of Private Information, Defendant knew, or should have known, the importance of safeguarding the Private Information entrusted to it by Plaintiff and Class members, and of the foreseeable consequences if its data security systems were breached, including the significant costs imposed on Plaintiff and Class Members as a result of a breach. 56. Despite the prevalence of public announcements of data breach and data security compromises, Defendant failed to take appropriate steps to protect the Private Information of Plaintiff and Class Members from being compromised. 57. At all relevant times, Defendant knew, or reasonably should have known, of the importance of safeguarding the Private Information of Plaintiff and Class Members and of the foreseeable consequences that would occur if Defendant's data security system was breached, including, specifically, the significant costs that would be imposed on Plaintiff and Class Members as a result of a breach. 58. Defendant was, or should have been, fully aware of the unique type and the significant volume of data on Defendant's server(s), amounting to thousands of individuals’ detailed, Private Information, and, thus, the significant number of individuals who would be harmed by the exposure of the unencrypted data.12 10 https://www.federalreserve.gov/econres/notes/feds-notes/implications-of-cyber-risk-forfinancial-stability-20220512.html (last visited June 3, 2025). 11 https://www.picussecurity.com/key-threats-and-cyber-risks-facing-financial-services-andbanking-firms-in-2022 (last visited June 3, 2025). 12 https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792- Case 1:25-cv-03131-TRJ 59. Document 1 Filed 06/04/25 Page 15 of 55 The injuries to Plaintiff and Class Members were directly and proximately caused by Defendant's failure to implement or maintain adequate data security measures for the Private Information of Plaintiff and Class Members. 60. The ramifications of Defendant's failure to keep secure the Private Information of Plaintiff and Class Members are long lasting and severe. Once Private Information is stolen, fraudulent use of that information and damage to victims may continue for years. 61. As a company in possession of Plaintiff’s and Class Members’ Private Information, Defendant knew, or should have known, the importance of safeguarding the Private Information entrusted to it by Plaintiff and Class Members and of the foreseeable consequences if its data security systems were breached. This includes the significant costs imposed on Plaintiff and Class Members as a result of a breach. Nevertheless, Defendant failed to take adequate cybersecurity measures to prevent the Data Breach. Value of Personally Identifying Information. 62. The Federal Trade Commission (“FTC”) defines identity theft as “a fraud committed or attempted using the identifying information of another person without authority.”13 The FTC describes “identifying information” as “any name or number that may be used, alone or in conjunction with any other information, to identify a specific person,” including, among other things, “[n]ame, Social Security number, date of birth, official State or government issued driver’s license or identification number, alien registration number, government passport number, employee-benefit management company or taxpayer identification number.”14 a1252b4f8318/d16941f7-1e1e-4625-9a16-437a13f4f948.html (last visited June 3, 2025). 13 14 17 C.F.R. § 248.201 (2013). Id. Case 1:25-cv-03131-TRJ 63. Document 1 Filed 06/04/25 Page 16 of 55 The Private Information of individuals remains of high value to criminals, as evidenced by the prices they will pay through the dark web. Numerous sources cite dark web pricing for stolen identity credentials.15 For example, Personal Information can be sold at a price ranging from $40 to $200.16 Criminals can also purchase access to entire company data breaches from $900 to $4,500.17 64. Based on the foregoing, the information compromised in the Data Breach is significantly more valuable than the loss of, for example, credit card information in a data breach because, there, victims can cancel or close credit and debit card accounts. The information compromised in this Data Breach is impossible to “close” and difficult, if not impossible, to change—name and Social Security number. 65. This data demands a much higher price on the black market. Martin Walter, senior director at cybersecurity firm RedSeal, explained, “Compared to credit card information, personally identifiable information and Social Security numbers are worth more than 10x on the black market.”18 66. Among other forms of fraud, identity thieves may obtain driver’s licenses, government benefits, medical services, and housing or even give false information to police. 15 Your personal data is for sale on the dark web. Here’s how much it costs, Digital Trends, Oct. 16, 2019, available at: https://www.digitaltrends.com/computing/personal-data-sold-on-the-darkweb-how-much-it-costs/ (last visited June 3, 2025). 16 Here’s How Much Your Personal Information Is Selling for on the Dark Web, Experian, Dec. 6, 2017, available at: https://www.experian.com/blogs/ask-experian/heres-how-much-yourpersonal-information-is-selling-for-on-the-dark-web/ (last visited June 3, 2025). 17 In the Dark, VPNOverview, 2019, available at: https://vpnoverview.com/privacy/anonymousbrowsing/in-the-dark/ (last visited June 3, 2025). 18 Tim Greene, Anthem Hack: Personal Data Stolen Sells for 10x Price of Stolen Credit Card Numbers, IT World, (Feb. 6, 2015), available at: https://www.networkworld.com/article/2880366/anthem-hack-personal-data-stolen-sells-for-10xprice-of-stolen-credit-card-numbers.html (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 67. Document 1 Filed 06/04/25 Page 17 of 55 The fraudulent activity resulting from the Data Breach may not come to light for years. There may be a time lag between when harm occurs versus when it is discovered, and also between when Private Information is stolen and when it is used. According to the U.S. Government Accountability Office (“GAO”), which conducted a study regarding data breaches: [L]aw enforcement officials told us that in some cases, stolen data may be held for up to a year or more before being used to commit identity theft. Further, once stolen data have been sold or posted on the Web, fraudulent use of that information may continue for years. As a result, studies that attempt to measure the harm resulting from data breaches cannot necessarily rule out all future harm.19 68. Plaintiff and Class Members now face years of constant surveillance of their financial and personal records, monitoring, and loss of rights. The Class is incurring and will continue to incur such damages in addition to any fraudulent use of their Private Information. Defendant Fails to Comply with FTC Guidelines. 69. The Federal Trade Commission (“FTC”) has promulgated numerous guides for businesses which highlight the importance of implementing reasonable data security practices. According to the FTC, the need for data security should be factored into all business decisionmaking. 70. In 2016, the FTC updated its publication, Protecting Personal Information: A Guide for Business, which established cyber-security guidelines for businesses. These guidelines note that businesses should protect the personal customer information that they keep; properly dispose of personal information that is no longer needed; encrypt information stored on computer networks; understand their network’s vulnerabilities; and implement policies to correct any security problems.20 19 Report to Congressional Requesters, GAO, at 29 (June 2007), available at: https://www.gao.gov/assets/gao-07-737.pdf (last visited June 3, 2025). 20 Protecting Personal Information: A Guide for Business, Federal Trade Commission (2016). Case 1:25-cv-03131-TRJ 71. Document 1 Filed 06/04/25 Page 18 of 55 The guidelines also recommend that businesses use an intrusion detection system to expose a breach as soon as it occurs; monitor all incoming traffic for activity indicating someone is attempting to hack the system; watch for large amounts of data being transmitted from the system; and have a response plan ready in the event of a breach.21 72. The FTC further recommends that companies not maintain Private Information longer than is needed for authorization of a transaction; limit access to sensitive data; require complex passwords to be used on networks; use industry-tested methods for security; monitor for suspicious activity on the network; and verify that third-party service providers have implemented reasonable security measures. 73. The FTC has brought enforcement actions against businesses for failing to adequately and reasonably protect customer data, treating the failure to employ reasonable and appropriate measures to protect against unauthorized access to confidential customer data as an unfair act or practice prohibited by Section 5 of the Federal Trade Commission Act (“FTCA”), 15 U.S.C. § 45. Orders resulting from these actions further clarify the measures businesses must take to meet their data security obligations. 74. These FTC enforcement actions include actions against companies in possession of Private Information, like Defendant. 75. Section 5 of the FTC Act, 15 U.S.C. § 45, prohibits “unfair . . . practices in or affecting commerce,” including, as interpreted and enforced by the FTC, the unfair act or practice by businesses, such as Defendant, of failing to use reasonable measures to protect Private Available at https://www.ftc.gov/system/files/documents/plain-language/pdf-0136_protetingpersonal-information.pdf (last visited June 3, 2025). 21 Id. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 19 of 55 Information. The FTC publications and orders described above also form part of the basis of Defendant’s duty in this regard. 76. Defendant failed to properly implement basic data security practices. 77. Defendant’s failure to employ reasonable and appropriate measures to protect against unauthorized access to customers’ Private Information or to comply with applicable industry standards constitutes an unfair act or practice prohibited by Section 5 of the FTC Act, 15 U.S.C. § 45. 78. Upon information and belief, Defendant was at all times fully aware of its obligation to protect the Private Information of its customers, Defendant was also aware of the significant repercussions that would result from its failure to do so. Accordingly, Defendant’s conduct was particularly unreasonable given the nature and amount of Private Information it obtained and stored and the foreseeable consequences of the immense damages that would result to Plaintiff and the Class. Defendant Fails to Comply with Industry Standards. 79. As noted above, experts studying cyber security routinely companies in possession of Private Information as being particularly vulnerable to cyberattacks because of the value of the Private Information which they collect and maintain. 80. Several best practices have been identified that, at a minimum, should be implemented by companies in possession of Private Information, like Defendant, including but not limited to: educating all employees; strong passwords; multi-layer security, including firewalls, anti-virus, and anti-malware software; encryption, making data unreadable without a key; multifactor authentication; backup data and limiting which employees can access sensitive data. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 20 of 55 Defendant failed to follow these industry best practices, including a failure to implement multifactor authentication. 81. Other best cybersecurity practices that are standard for companies like Defendant include installing appropriate malware detection software; monitoring and limiting the network ports; protecting web browsers and email management systems; setting up network systems such as firewalls, switches and routers; monitoring and protection of physical security systems; protection against any possible communication system; training staff regarding critical points. Defendant failed to follow these cybersecurity best practices, including failure to train staff. 82. Defendant failed to meet the minimum standards of any of the following frameworks: the NIST Cybersecurity Framework Version 2.0 (including without limitation PR.AA-01, PR.AA.-02, PR.AA-03, PR.AA-04, PR.AA-05, PR.AT-01, PR.DS-01, PR-DS-02, PR.DS-10, PR.PS-01, PR.PS-02, PR.PS-05, PR.IR-01, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, and RS.CO-04), and the Center for Internet Security’s Critical Security Controls (CIS CSC), which are all established standards in reasonable cybersecurity readiness. 83. These foregoing frameworks are existing and applicable industry standards for companies in possession of Private Information to safeguard their customers’ data, and upon information and belief, Defendant failed to comply with at least one––or all––of these accepted standards, thereby opening the door to the threat actor and causing the Data Breach. Common Injuries and Damages. 84. As a result of Defendant’s ineffective and inadequate data security practices, the Data Breach, and the foreseeable consequences of Private Information ending up in the possession of criminals, the risk of identity theft to the Plaintiff and Class Members has materialized and is imminent, and Plaintiff and Class Members have all sustained actual injuries and damages, Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 21 of 55 including: (i) invasion of privacy; (ii) theft of their Private Information; (iii) lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) loss of benefit of the bargain; (vi) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vii) nominal damages; and (viii) the continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse; and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. The Data Breach Increases Victims’ Risk of Identity Theft. 85. The unencrypted Private Information of Plaintiff and Class Members will end up for sale on the dark web as that is the modus operandi of hackers. 86. Unencrypted Private Information may also fall into the hands of companies that will use the detailed Private Information for targeted marketing without the approval of Plaintiff and Class Members. Simply put, unauthorized individuals can easily access the Private Information of Plaintiff and Class Members. 87. The link between a data breach and the risk of identity theft is simple and well established. Criminals acquire and steal Private Information to monetize the information. Criminals monetize the data by selling the stolen information on the black market to other criminals who then utilize the information to commit a variety of identity theft related crimes discussed below. 88. Plaintiff’s and Class Members’ Private Information is of great value to hackers and cyber criminals, and the data stolen in the Data Breach has been used and will continue to be used Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 22 of 55 in a variety of sordid ways for criminals to exploit Plaintiff and Class Members and to profit off their misfortune. 89. Due to the risk of one’s Social Security number being exposed, state legislatures have passed laws in recognition of the risk: “[t]he social security number can be used as a tool to perpetuate fraud against a person and to acquire sensitive personal, financial, medical, and familial information, the release of which could cause great financial or personal harm to an individual. While the social security number was intended to be used solely for the administration of the federal Social Security System, over time this unique numeric identifier has been used extensively for identity verification purposes[.]”22 90. Moreover, “SSNs have been central to the American identity infrastructure for years, being used as a key identifier[.] . . . U.S. banking processes have also had SSNs baked into their identification process for years. In fact, SSNs have been the gold standard for identifying and verifying the credit history of prospective customers.”23 91. “Despite the risk of fraud associated with the theft of Social Security numbers, just five of the nation’s largest 25 banks have stopped using the numbers to verify a customer’s identity after the initial account setup[.]”24 Accordingly, since Social Security numbers are frequently used to verify an individual’s identity after logging onto an account or attempting a transaction, “[h]aving access to your Social Security number may be enough to help a thief steal money from your bank account”25 22 See N.C. Gen. Stat. § 132-1.10(1). See https://www.americanbanker.com/opinion/banks-need-to-stop-relying-on-social-securitynumbers (last visited June 3, 2025). 24 See https://archive.nytimes.com/bucks.blogs.nytimes.com/2013/03/20/just-5-banks-prohibituse-of-social-security-numbers/ (last visited June 3, 2025). 25 See https://www.credit.com/blog/5-things-an-identity-thief-can-do-with-your-social-securitynumber-108597/ (last visited June 3, 2025). 23 Case 1:25-cv-03131-TRJ 92. Document 1 Filed 06/04/25 Page 23 of 55 One such example of criminals piecing together bits and pieces of compromised Private Information for profit is the development of “Fullz” packages.26 93. With “Fullz” packages, cyber-criminals can cross-reference two sources of Private Information to marry unregulated data available elsewhere to criminally stolen data with an astonishingly complete scope and degree of accuracy in order to assemble complete dossiers on individuals. 94. The development of “Fullz” packages means here that the stolen Private Information from the Data Breach can easily be used to link and identify it to Plaintiff’s and Class Members’ phone numbers, email addresses, and other unregulated sources and identifiers. In other words, even if certain information such as emails, phone numbers, or credit card numbers may not be included in the Private Information that was exfiltrated in the Data Breach, criminals may still easily create a Fullz package and sell it at a higher price to unscrupulous operators and criminals (such as illegal and scam telemarketers) over and over. 26 “Fullz” is fraudster speak for data that includes the information of the victim, including, but not limited to, the name, address, credit card information, social security number, date of birth, and more. As a rule of thumb, the more information you have on a victim, the more money that can be made off of those credentials. Fullz are usually pricier than standard credit card credentials, commanding up to $100 per record (or more) on the dark web. Fullz can be cashed out (turning credentials into money) in various ways, including performing bank transactions over the phone with the required authentication details in-hand. Even “dead Fullz,” which are Fullz credentials associated with credit cards that are no longer valid, can still be used for numerous purposes, including tax refund scams, ordering credit cards on behalf of the victim, or opening a “mule account” (an account that will accept a fraudulent money transfer from a compromised account) without the victim’s knowledge. See, e.g., Brian Krebs, Medical Records for Sale in Underground Stolen From Texas Life Insurance Firm, Krebs on Security (Sep. 18, 2014), https://krebsonsecuritv.eom/2014/09/medical-records-for-sale-in-underground-stolen-fromtexas-life-insurance-](https://krebsonsecuritv.eom/2014/09/medical-records-for-sale-inunderground-stolen-from-texas-life-insurance-finn/ (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 95. Document 1 Filed 06/04/25 Page 24 of 55 The existence and prevalence of “Fullz” packages means that the Private Information stolen from the data breach can easily be linked to the unregulated data (like contact information) of Plaintiff and the other Class Members. 96. Thus, even if certain information (such as contact information) was not stolen in the data breach, criminals can still easily create a comprehensive “Fullz” package. 97. Then, this comprehensive dossier can be sold—and then resold in perpetuity—to crooked operators and other criminals (like illegal and scam telemarketers). Loss of Time to Mitigate the Risk of Identity Theft and Fraud. 98. As a result of the recognized risk of identity theft, when a Data Breach occurs, and an individual is notified by a company that their Private Information was compromised, as in this Data Breach, the reasonable person is expected to take steps and spend time to address the dangerous situation, learn about the breach, and otherwise mitigate the risk of becoming a victim of identity theft of fraud. Failure to spend time taking steps to review accounts or credit reports could expose the individual to greater financial harm – yet the resource and asset of time has been lost. 99. Thus, due to the actual and imminent risk of identity theft, Defendant, in its Notice Letter instructs Plaintiff and Class Members to protect themselves by reviewing account statements and monitoring their credit reports, in addition to enrolling in the offered free credit monitoring program. 100. Defendant’s extensive suggestion of steps that Plaintiff and Class Members must take in order to protect themselves from identity theft and/or fraud demonstrates the significant time that Plaintiff and Class Members must undertake in response to the Data Breach. Plaintiff’s and Class Members’ time is highly valuable and irreplaceable, and accordingly, Plaintiff and Class Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 25 of 55 Members suffered actual injury and damages in the form of lost time that they spent on mitigation activities in response to the Data Breach and at the direction of Defendant’s Notice Letter. 101. Plaintiff and Class Members have spent, and will spend additional time in the future, on a variety of prudent actions, such as researching and verifying the legitimacy of the Data Breach, freezing their payment cards, contacting credit bureaus to place freezes on their accounts, and monitoring their financial accounts for any indication of fraudulent activity, which may take years to detect. Accordingly, the Data Breach has caused Plaintiff and Class Members to suffer actual injury in the form of lost time—which cannot be recaptured—spent on mitigation activities. 102. Plaintiff’s mitigation efforts are consistent with the U.S. Government Accountability Office that released a report in 2007 regarding data breaches (“GAO Report”) in which it noted that victims of identity theft will face “substantial costs and time to repair the damage to their good name and credit record.”27 103. Plaintiff’s mitigation efforts are also consistent with the steps that FTC recommends that data breach victims take several steps to protect their personal and financial information after a data breach, including: contacting one of the credit bureaus to place a fraud alert (consider an extended fraud alert that lasts for seven years if someone steals their identity), reviewing their credit reports, contacting companies to remove fraudulent charges from their accounts, placing a credit freeze on their credit, and correcting their credit reports.28 27 See United States Government Accountability Office, GAO-07-737, Personal Information: Data Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited; However, the Full Extent Is Unknown (June 2007), https://www.gao.gov/new.items/d07737.pdf. (last visited June 3, 2025). 28 See Federal Trade Commission, Identity Theft.gov, https://www.identitytheft.gov/Steps (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 104. Document 1 Filed 06/04/25 Page 26 of 55 And for those Class Members who experience actual identity theft and fraud, the United States Government Accountability Office released a report in 2007 regarding data breaches (“GAO Report”) in which it noted that victims of identity theft will face “substantial costs and time to repair the damage to their good name and credit record.”[4] Diminution of Value of Private Information. 105. Private Information is a valuable property right.29 Its value is axiomatic, considering the value of Big Data in corporate America and the consequences of cyber thefts include heavy prison sentences. Even this obvious risk to reward analysis illustrates beyond doubt that Private Information has considerable market value. 106. Sensitive Private Information can sell for as much as $363 per record according to the Infosec Institute.30 107. An active and robust legitimate marketplace for Private Information also exists. In 2019, the data brokering industry was worth roughly $200 billion.31 In fact, the data marketplace is so sophisticated that consumers can actually sell their non-public information directly to a data broker who in turn aggregates the information and provides it to marketers or app developers.32,33 29 See “Data Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited; However, the Full Extent Is Unknown,” p. 2, U.S. Government Accountability Office, June 2007, https://www.gao.gov/new.items/d07737.pdf (last visited June 3, 2025) (“GAO Report”). 30 See, e.g., John T. Soma, et al, Corporate Privacy Trend: The “Value” of Personally Identifiable Information (“PII”) Equals the “Value" of Financial Assets, 15 Rich. J.L. & Tech. 11, at *3-4 (2009) (“PII, which companies obtain at little cost, has quantifiable value that is rapidly reaching a level comparable to the value of traditional financial assets.”) (citations omitted). (last visited June 3, 2025). 31 See Ashiq Ja, Hackers Selling Healthcare Data in the Black Market, InfoSec (July 27, 2015), https://resources.infosecinstitute.com/topic/hackers-selling-healthcare-data-in-the-black-market/ (last visited June 3, 2025). 32 https://www.latimes.com/business/story/2019-11-05/column-data-brokers (last visited June 3, 2025). 33 https://datacoup.com/ (last visited June 3, 2025). Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 27 of 55 Consumers who agree to provide their web browsing history to the Nielsen Corporation can receive up to $50.00 a year.34 108. As a result of the Data Breach, Plaintiff’s and Class Members’ Private Information, which has an inherent market value in both legitimate and dark markets, has been damaged and diminished by its compromise and unauthorized release. However, this transfer of value occurred without any consideration paid to Plaintiff or Class Members for their property, resulting in an economic loss. Moreover, the Private Information is now readily available, and the rarity of the Data has been lost, thereby causing additional loss of value. 109. At all relevant times, Defendant knew, or reasonably should have known, of the importance of safeguarding the Private Information of Plaintiff and Class Members, and of the foreseeable consequences that would occur if Defendant’s data security system was breached, including, specifically, the significant costs that would be imposed on Plaintiff and Class Members as a result of a breach. 110. The fraudulent activity resulting from the Data Breach may not come to light for 111. Plaintiff and Class Members now face years of constant surveillance of their years. financial and personal records, monitoring, and loss of rights. The Class is incurring and will continue to incur such damages in addition to any fraudulent use of their Private Information. 112. Defendant was, or should have been, fully aware of the unique type and the significant volume of data on Defendant’s network, amounting to, upon information and belief, thousands to tens of thousands of individuals’ detailed personal information and, thus, the significant number of individuals who would be harmed by the exposure of the unencrypted data. 34 https://digi.me/what-is-digime/ (last visited June 3, 2025). Case 1:25-cv-03131-TRJ 113. Document 1 Filed 06/04/25 Page 28 of 55 The injuries to Plaintiff and Class Members were directly and proximately caused by Defendant’s failure to implement or maintain adequate data security measures for the Private Information of Plaintiff and Class Members. Future Costs of Credit and Identity Theft Monitoring is Reasonable and Necessary. 114. Given the type of targeted attack, the sophisticated criminal activity, and the type of Private Information involved in this case, there is a strong probability that entire batches of stolen information have been placed, or will be placed, on the black market/dark web for sale and purchase by criminals intending to utilize the Private Information for identity theft crimes –e.g., opening bank accounts in the victims’ names to make purchases or to launder money; file false tax returns; take out loans or lines of credit; or file false unemployment claims. 115. Such fraud may go undetected until debt collection calls commence months, or even years, later. An individual may not know that his or her Private Information was used to file for unemployment benefits until law enforcement notifies the individual’s employee-benefit management company of the suspected fraud. Fraudulent tax returns are typically discovered only when an individual’s authentic tax return is rejected. 116. Consequently, Plaintiff and Class Members are at an increased risk of fraud and identity theft for many years into the future. 117. The retail cost of credit monitoring and identity theft monitoring can cost around $200 a year per Class Member. This is reasonable and necessary cost to monitor to protect Class Members from the risk of identity theft that arose from Defendant’s Data Breach. Loss of Benefit of the Bargain. 118. Furthermore, Defendant’s poor data security deprived Plaintiff and Class Members of the benefit of their bargain. When agreeing to provide Defendant with their Private Information Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 29 of 55 as a condition of receiving services from Defendant, Plaintiff and other reasonable customers understood and expected that Defendant would properly safeguard and protect their Private Information, when in fact, Defendant did not provide the expected data security. Accordingly, Plaintiff and Class Members received services of a lesser value than what they reasonably expected to receive under the bargains they struck with Defendant. Plaintiff Baker’s Experience 119. Plaintiff Bruce H. Baker is a customer of Defendant. 120. Upon information and belief, as a condition of receiving services, Plaintiff Baker was required to provide LNRS with his Private Information. 121. Upon information and belief, at the time of the Data Breach, Defendant and its service provider retained Plaintiff Baker’s Private Information in their systems. 122. Plaintiff Baker is very careful about sharing his sensitive Private Information. Plaintiff Baker stores any documents containing his Private Information in a safe and secure location. He has never knowingly transmitted unencrypted sensitive Private Information over the internet or any other unsecured source. 123. Plaintiff Baker provided his Private Information to Defendant and trusted the company would use reasonable measures to protect it according to Defendant’s internal policies, as well as state and federal law. 124. Plaintiff Baker reasonably understood that a portion of the funds paid to Defendant would be used to pay for adequate cybersecurity and protection of Private Information. 125. Plaintiff Baker received the Notice Letter, by U.S. mail, directly from Defendant, dated May 24, 2025. According to the Notice Letter, Plaintiff Baker’s Private Information was improperly accessed and obtained by unauthorized third parties, including his Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 30 of 55 name, Social Security number, driver’s license number, date of birth, and contact information such as phone number, and postal or email address. 126. As a result of the Data Breach, and at the direction of Defendant’s Notice Letter, which instructs Plaintiff Baker to monitor his free credit report for any authorized activity, Plaintiff Baker made reasonable efforts to mitigate the impact of the Data Breach, including but not limited to monitoring his financial accounts for any indication of fraudulent activity, which may take years to detect. 127. In fact, Plaintiff Baker has suffered actual injury as he has experienced a serious uptick in spam texts and phone calls since the exposure of his Private Information in the Data Breach. 128. Plaintiff Baker has spent significant time on mitigation activities in response to the Data Breach, including but not limited to blocking all numbers that he has received spam texts and calls from. 129. As a result of the Data Breach, Plaintiff Baker spent valuable time that he otherwise would have spent on other activities, including but not limited to work and/or recreation. This time has been lost forever and cannot be recaptured. 130. Subsequent to the Data Breach, Plaintiff Baker has suffered numerous, substantial injuries including, but not limited to: (i) invasion of privacy; (ii) theft of his Private Information; (iii) lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vi) nominal damages; and (vii) the continued and certainly increased risk to his Private Information, which: (a) remains unencrypted and available for unauthorized third Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 31 of 55 parties to access and abuse; and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. 131. The Data Breach has caused Plaintiff Baker to suffer fear, anxiety, and stress, which has been compounded by the fact that Defendant has still not fully informed his of key details about the Data Breach’s occurrence. 132. As a result of the Data Breach, Plaintiff Baker anticipates spending additional considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach. 133. As a result of the Data Breach, Plaintiff Baker is at a present risk and will continue to be at increased risk of identity theft and fraud for years to come. 134. Plaintiff Baker has a continuing interest in ensuring that his Private Information, which, upon information and belief, remains backed up in Defendant’s possession, is protected and safeguarded from future breaches. CLASS ACTION ALLEGATIONS 135. Plaintiff brings this nationwide class action on behalf of himself and on behalf of all others similarly situated pursuant to Federal Rule of Civil Procedure 23(a), 23(b)(1), 23(b)(2), and 23(b)(3). 136. The Class that Plaintiff seeks to represent is defined as follows: Nationwide Class: All individuals residing in the United States whose Private Information was accessed and/or acquired by an unauthorized party as a result of the data breach, including those who received notice of the Data Breach (the “Class”). 137. Excluded from the Class are the following individuals and/or entities: Defendant and Defendant’s parents, subsidiaries, affiliates, officers and directors, and any entity in which Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 32 of 55 Defendant have a controlling interest; all individuals who make a timely election to be excluded from this proceeding using the correct protocol for opting out; and all judges assigned to hear any aspect of this litigation, as well as their immediate family members. 138. Plaintiff reserves the right to amend the definitions of the Class or Subclass or add a Class or Subclass if further information and discovery indicate that the definitions of the Class should be narrowed, expanded, or otherwise modified. 139. The proposed Class meets the criteria for certification under Federal Rule of Civil Procedure 23(a), 23(b)(1), 23(b)(2), and 23(b)(3). 140. Numerosity. The members of the Class are so numerous that joinder of all members is impracticable, if not completely impossible. Although the precise number of individuals is currently unknown to Plaintiff and exclusively in the possession of Defendant, upon information and belief, thousands of individuals were impacted. The Class is apparently identifiable within Defendant’s records, and Defendant has already identified these individuals (as evidenced by sending them breach notification letters). 141. Common questions of law and fact exist as to all members of the Class and predominate over any questions affecting solely individual members of the Class. Among the questions of law and fact common to the Class that predominate over questions which may affect individual Class members, including the following: a. Whether and to what extent Defendant had a duty to protect the Private Information of Plaintiff and Class Members; b. Whether Defendant had respective duties not to disclose the Private Information of Plaintiff and Class Members to unauthorized third parties; Case 1:25-cv-03131-TRJ c. Document 1 Filed 06/04/25 Page 33 of 55 Whether Defendant had respective duties not to use the Private Information of Plaintiff and Class Members for non-business purposes; d. Whether Defendant failed to adequately safeguard the Private Information of Plaintiff and Class Members; e. Whether and when Defendant actually learned of the Data Breach; f. Whether Defendant adequately, promptly, and accurately informed Plaintiff and Class Members that their Private Information had been compromised; g. Whether Defendant violated the law by failing to promptly notify Plaintiff and Class Members that their Private Information had been compromised; h. Whether Defendant failed to implement and maintain reasonable security procedures and practices appropriate to the nature and scope of the information compromised in the Data Breach; i. Whether Defendant adequately addressed and fixed the vulnerabilities which permitted the Data Breach to occur; j. Whether Plaintiff and Class Members are entitled to actual damages and/or nominal damages as a result of Defendant’s wrongful conduct; and, k. Whether Plaintiff and Class Members are entitled to injunctive relief to redress the imminent and currently ongoing harm faced as a result of the Data Breach. 142. Typicality. Plaintiff’s claims are typical of those of the other members of the Class because Plaintiff, like every other Class Member, were exposed to virtually identical conduct and now suffer from the same violations of the law as each other member of the Class. 143. Policies Generally Applicable to the Class. This class action is also appropriate for certification because Defendant acted or refused to act on grounds generally applicable to the Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 34 of 55 Class, thereby requiring the Court’s imposition of uniform relief to ensure compatible standards of conduct toward the Class Members and making final injunctive relief appropriate with respect to the Class as a whole. Defendant’s policies challenged herein apply to and affect Class Members uniformly and Plaintiff’s challenge of these policies hinges on Defendant’s conduct with respect to the Class as a whole, not on facts or law applicable only to Plaintiff. 144. Adequacy. Plaintiff will fairly and adequately represent and protect the interests of the Class Members in that they have no disabling conflicts of interest that would be antagonistic to those of the other Class Members. Plaintiff seeks no relief that is antagonistic or adverse to the Class Members and the infringement of the rights and the damages they have suffered are typical of other Class Members. Plaintiff have retained counsel experienced in complex class action and data breach litigation, and Plaintiff intend to prosecute this action vigorously. 145. Superiority and Manageability. The class litigation is an appropriate method for fair and efficient adjudication of the claims involved. Class action treatment is superior to all other available methods for the fair and efficient adjudication of the controversy alleged herein; it will permit a large number of Class Members to prosecute their common claims in a single forum simultaneously, efficiently, and without the unnecessary duplication of evidence, effort, and expense that hundreds of individual actions would require. Class action treatment will permit the adjudication of relatively modest claims by certain Class Members, who could not individually afford to litigate a complex claim against large corporations, like Defendant. Further, even for those Class Members who could afford to litigate such a claim, it would still be economically impractical and impose a burden on the courts. 146. The nature of this action and the nature of laws available to Plaintiff and Class Members make the use of the class action device a particularly efficient and appropriate procedure Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 35 of 55 to afford relief to Plaintiff and Class Members for the wrongs alleged because Defendant would necessarily gain an unconscionable advantage since they would be able to exploit and overwhelm the limited resources of each individual Class Member with superior financial and legal resources; the costs of individual suits could unreasonably consume the amounts that would be recovered; proof of a common course of conduct to which Plaintiff were exposed is representative of that experienced by the Class and will establish the right of each Class Member to recover on the cause of action alleged; and individual actions would create a risk of inconsistent results and would be unnecessary and duplicative of this litigation. 147. The litigation of the claims brought herein is manageable. Defendant’s uniform conduct, the consistent provisions of the relevant laws, and the ascertainable identities of Class Members demonstrates that there would be no significant manageability problems with prosecuting this lawsuit as a class action. 148. Adequate notice can be given to Class Members directly using information maintained in Defendant’s records. 149. Unless a Class-wide injunction is issued, Defendant may continue in its failure to properly secure the Private Information of Class Members, Defendant may continue to refuse to provide proper notification to Class Members regarding the Data Breach, and Defendant may continue to act unlawfully as set forth in this Complaint. 150. Further, Defendant has acted on grounds that apply generally to the Class as a whole, so that class certification, injunctive relief, and corresponding declaratory relief are appropriate on a class- wide basis. 151. Likewise, particular issues under Federal Rule of Civil Procedure 23 are appropriate for certification because such claims present only particular, common issues, the Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 36 of 55 resolution of which would advance the disposition of this matter and the parties’ interests therein. Such particular issues include, but are not limited to: a. Whether Defendant failed to timely notify the Plaintiff and the class of the Data Breach; b. Whether Defendant owed a legal duty to Plaintiff and the Class to exercise due care in collecting, storing, and safeguarding their Private Information; c. Whether Defendant’s security measures to protect their data systems were reasonable in light of best practices recommended by data security experts; d. Whether Defendant’s failure to institute adequate protective security measures amounted to negligence; e. Whether Defendant failed to take commercially reasonable steps to safeguard its customers’ Private Information; and, f. Whether adherence to FTC data security recommendations, and measures recommended by data security experts would have reasonably prevented the Data Breach. CAUSES OF ACTION COUNT I NEGLIGENCE (On Behalf of Plaintiff and the Class) 152. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. 153. Defendant requires its customers, including Plaintiff and Class Members, to submit non-public Private Information in the ordinary course of providing its services. Case 1:25-cv-03131-TRJ 154. Document 1 Filed 06/04/25 Page 37 of 55 Defendant gathered and stored the Private Information of Plaintiff and Class Members as part of its business of soliciting its clients, which solicitations and services affect commerce. 155. Plaintiff and Class Members entrusted Defendant with their Private Information with the understanding that Defendant would safeguard their information. 156. Defendant had full knowledge of the sensitivity of the Private Information and the types of harm that Plaintiff and Class Members could and would suffer if the Private Information were wrongfully disclosed. 157. By assuming the responsibility to collect and store this data, and in fact doing so, and sharing it and using it for commercial gain, Defendant had a duty of care to use reasonable means to secure and to prevent disclosure of the information, and to safeguard the information from theft. 158. Defendant had a duty to employ reasonable security measures under Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, which prohibits “unfair . . . practices in or affecting commerce,” including, as interpreted and enforced by the FTC, the unfair practice of failing to use reasonable measures to protect confidential data. 159. Defendant also had a duty to ensure that any third parties that it shares Plaintiff’s and Class Members’ Private Information with, implements reasonable cybersecurity measures. 160. Defendant owed a duty of care to Plaintiff and Class Members to provide data security consistent with industry standards and other requirements discussed herein, and to ensure that its systems and networks, and the personnel responsible for them, adequately protected the Private Information. Case 1:25-cv-03131-TRJ 161. Document 1 Filed 06/04/25 Page 38 of 55 Defendant's duty of care to use reasonable security measures arose as a result of the special relationship that existed between Defendant and Plaintiff and Class Members. That special relationship arose because Plaintiff and the Class entrusted Defendant with their confidential Private Information, a necessary part of obtaining services from Defendant. 162. Defendant’s duty to use reasonable care in protecting confidential data arose not only as a result of the statutes and regulations described above, but also because Defendant is bound by industry standards to protect confidential Private Information. 163. Defendant was subject to an “independent duty,” untethered to any contract between Defendant and Plaintiff or the Class. 164. Defendant also had a duty to exercise appropriate clearinghouse practices to remove former customers’ Private Information it was no longer required to retain pursuant to regulations. 165. Moreover, Defendant had a duty to promptly and adequately notify Plaintiff and the Class of the Data Breach. 166. Defendant had and continues to have a duty to adequately disclose that the Private Information of Plaintiff and the Class within Defendant’s possession might have been compromised, how it was compromised, and precisely the types of data that were compromised and when. Such notice was necessary to allow Plaintiff and the Class to take steps to prevent, mitigate, and repair any identity theft and the fraudulent use of their Private Information by third parties. 167. Defendant breached its duties, pursuant to the FTC Act and other applicable standards, and thus was negligent, by failing to use reasonable measures to protect Class Members’ Private Information. The specific negligent acts and omissions committed by Defendant include, but are not limited to, the following: Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 39 of 55 a. Failing to adopt, implement, and maintain adequate security measures to safeguard Class Members’ Private Information; b. Failing to adequately monitor the security of their networks and systems; c. Allowing unauthorized access to Class Members’ Private Information; d. Failing to detect in a timely manner that Class Members’ Private Information had been compromised; e. Failing to remove former customers’ Private Information it was no longer required to retain pursuant to regulations, and; f. Failing to timely and adequately notify Class Members about the Data Breach’s occurrence and scope, so that they could take appropriate steps to mitigate the potential for identity theft and other damages. 168. Defendant violated Section 5 of the FTC Act by failing to use reasonable measures to protect Private Information and not complying with applicable industry standards, as described in detail herein. Defendant’s conduct was particularly unreasonable given the nature and amount of Private Information it obtained and stored and the foreseeable consequences of the immense damages that would result to Plaintiff and the Class. 169. Defendant’s violation of Section 5 of the FTC Act constitutes negligence. 170. Plaintiff and Class Members were within the class of persons the Federal Trade Commission Act was intended to protect and the type of harm that resulted from the Data Breach was the type of harm the statute was intended to guard against. 171. The FTC has pursued enforcement actions against businesses, which, as a result of their failure to employ reasonable data security measures and avoid unfair and deceptive practices, caused the same harm as that suffered by Plaintiff and the Class. Case 1:25-cv-03131-TRJ 172. Document 1 Filed 06/04/25 Page 40 of 55 A breach of security, unauthorized access, and resulting injury to Plaintiff and the Class was reasonably foreseeable, particularly in light of Defendant’s inadequate security practices. 173. It was foreseeable that Defendant’s failure to use reasonable measures to protect Class Members’ Private Information would result in injury to Class Members. Further, the breach of security was reasonably foreseeable given the known high frequency of cyberattacks and data breaches targeting companies in possession of Private Information. 174. Defendant has full knowledge of the sensitivity of the Private Information and the types of harm that Plaintiff and the Class could and would suffer if the Private Information were wrongfully disclosed. 175. Plaintiff and the Class were the foreseeable and probable victims of any inadequate security practices and procedures. Defendant knew or should have known of the inherent risks in collecting and storing the Private Information of Plaintiff and the Class, the critical importance of providing adequate security of that Private Information, and the necessity for encrypting Private Information stored on Defendant’s systems. 176. It was therefore foreseeable that the failure to adequately safeguard Class Members’ Private Information would result in one or more types of injuries to Class Members. 177. Plaintiff and the Class had no ability to protect their Private Information that was in, and possibly remains in, Defendant’s possession. 178. Defendant was in a position to protect against the harm suffered by Plaintiff and the Class as a result of the Data Breach. 179. Defendant’s duty extended to protecting Plaintiff and the Class from the risk of foreseeable criminal conduct of third parties, which has been recognized in situations where the Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 41 of 55 actor’s own conduct or misconduct exposes another to the risk or defeats protections put in place to guard against the risk, or where the parties are in a special relationship. See Restatement (Second) of Torts § 302B. Numerous courts and legislatures have also recognized the existence of a specific duty to reasonably safeguard personal information. 180. Defendant has admitted that the Private Information of Plaintiff and the Class was wrongfully lost and disclosed to unauthorized third persons as a result of the Data Breach. 181. But for Defendant’s wrongful and negligent breach of duties owed to Plaintiff and the Class, the Private Information of Plaintiff and the Class would not have been compromised. 182. There is a close causal connection between Defendant’s failure to implement security measures to protect the Private Information of Plaintiff and the Class and the harm, or risk of imminent harm, suffered by Plaintiff and the Class. The Private Information of Plaintiff and the Class was lost and accessed as the proximate result of Defendant’s failure to exercise reasonable care in safeguarding such Private Information by adopting, implementing, and maintaining appropriate security measures. 183. As a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will suffer injury, including but not limited to: (i) invasion of privacy; (ii) theft of their Private Information; (iii) lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) loss of benefit of the bargain; (vi) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vii) actual misuse of the compromised data consisting of an increase in spam calls, texts, and/or emails; (viii) invasion of their privacy; (ix) nominal damages; and (x) the continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse; Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 42 of 55 and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. 184. As a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will continue to suffer other forms of injury and/or harm, including, but not limited to, anxiety, emotional distress, loss of privacy, and other economic and non-economic losses. 185. Additionally, as a direct and proximate result of Defendant’s negligence, Plaintiff and the Class have suffered and will suffer the continued risks of exposure of their Private Information, which remain in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information in its continued possession. 186. Plaintiff and Class Members are entitled to compensatory and consequential damages suffered as a result of the Data Breach. 187. Defendant’s negligent conduct is ongoing, in that it still holds the Private Information of Plaintiff and Class Members in an unsafe and insecure manner. 188. Plaintiff and Class Members are also entitled to injunctive relief requiring Defendant to (i) strengthen its data security systems and monitoring procedures; (ii) submit to future annual audits of those systems and monitoring procedures; and (iii) continue to provide adequate credit monitoring to all Class Members. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 43 of 55 COUNT II NEGLIGENCE PER SE (On Behalf of Plaintiff and the Class) 189. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. 190. Section 5 of the FTC Act, 15 U.S.C. § 45, prohibits “unfair . . . practices in or affecting commerce” including, as interpreted and enforced by the FTC, the unfair act or practice by Defendant of failing to use reasonable measures to protect Private Information. Various FTC publications and orders also form the basis of Defendant’s duty. 191. Defendant violated Section 5 of the FTC Act (and similar state statutes) by failing to use reasonable measures to protect Private Information and not complying with industry standards. Defendant’s conduct was particularly unreasonable given the nature and amount of Private Information obtained and stored and the foreseeable consequences of a data breach on Defendant’s systems. 192. Defendant’s violation of Section 5 of the FTC Act (and similar state statutes) constitutes negligence per se. 193. Plaintiff and Class members are consumers within the class of persons Section 5 of the FTC Act (and similar state statutes) were intended to protect. 194. Moreover, the harm that has occurred is the type of harm the FTC Act (and similar state statutes) was intended to guard against. Indeed, the FTC has pursued over fifty enforcement actions against businesses which, as a result of their failure to employ reasonable data security measures and avoid unfair and deceptive practices, caused the same harm suffered by Plaintiff and Class Members. Case 1:25-cv-03131-TRJ 195. Document 1 Filed 06/04/25 Page 44 of 55 As a direct and proximate result of Defendant’s conduct, Plaintiff and Class Members have suffered or will suffer injury, including but not limited to: (i) invasion of privacy; (ii) theft of their Private Information; (iii) lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) loss of benefit of the bargain; (vi) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vii) actual misuse of the compromised data consisting of an increase in spam calls, texts, and/or emails; (viii) invasion of privacy; (ix) nominal damages; and (x) the continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse; and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. 196. Plaintiff and Class Members have been injured and are entitled to damages in an amount to be proven at trial. COUNT III BREACH OF IMPLIED CONTRACT (On Behalf of Plaintiff and the Class) 197. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. 198. Defendant offered to provide services to its customers, including Plaintiff and Class members, in exchange for payment. 199. Defendant also required Plaintiff and the Class members to provide their Private Information as a condition of receiving services. Case 1:25-cv-03131-TRJ 200. Document 1 Filed 06/04/25 Page 45 of 55 In turn, Defendant impliedly promised to protect Plaintiff’s and Class members’ Private Information through adequate data security measures, including by virtue of the promises in its privacy policies.35 201. Plaintiff and the Class members accepted Defendant’s offer by providing Private Information to Defendant in exchange for receiving services. 202. Plaintiff and Class members would not have entrusted their Private Information to Defendant but for the above-described agreement with Defendant. 203. Defendant materially breached its agreement(s) with Plaintiff and Class members by failing to safeguard such Private Information, violating industry standards necessarily incorporated in the agreement. 204. Plaintiff and Class members have performed under the relevant agreements, or such performance was waived by the conduct of Defendant. 205. The covenant of good faith and fair dealing is an element of every contract. All such contracts impose on each party a duty of good faith and fair dealing. The parties must act with honesty in fact in the conduct or transactions concerned. Good faith and fair dealing, in connection with executing contracts and discharging performance and other duties according to their terms, means preserving the spirit—not merely the letter—of the bargain. Put differently, the parties to a contract are mutually obligated to comply with the substance of their contract along with its form. 206. Defendant’s conduct as alleged herein also violated the implied covenant of good faith and fair dealing inherent in every contract. 35 See https://risk.lexisnexis.com/corporate/privacy-policy (“We use a variety of administrative, physician, and technical security measure to help safeguard your personal information.”) (last accessed June 3, 2025) Case 1:25-cv-03131-TRJ 207. Document 1 Filed 06/04/25 Page 46 of 55 The losses and damages Plaintiff and Class members sustained as described herein were the direct and proximate result of Defendant’s breach of the implied contracts with them, including breach of the implied covenant of good faith and fair dealing. 208. Plaintiff and the Class were harmed by Defendant’s breach of its contracts, as such breach is alleged herein, and are entitled to the losses and damages they have sustained as a direct and proximate result thereof. 209. Plaintiff and Class Members are also entitled to their costs and attorney’s fees incurred in this action. COUNT IV UNJUST ENRICHMENT (On Behalf of Plaintiff and the Class) 210. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. 211. This Count is pleaded in the alternative to the breach of implied contract (Count 212. Plaintiff and Class Members conferred a monetary benefit on Defendant. III). Specifically, they provided Defendant with their Private Information. In exchange, Plaintiff and Class Members should have had their Private Information protected with adequate data security. 213. Defendant knew that Plaintiff and Class Members conferred a benefit upon it and has accepted and retained that benefit by accepting and retaining the Private Information entrusted to it. Defendant profited from Plaintiff’s retained data and used Plaintiff’s and Class Members’ Private Information for business purposes. Case 1:25-cv-03131-TRJ 214. Document 1 Filed 06/04/25 Page 47 of 55 Defendant failed to secure Plaintiff’s and Class Members’ Private Information and, therefore, did not fully compensate Plaintiff or Class Members for the value that their Private Information provided. 215. Defendant acquired the Private Information through inequitable record retention as it failed to investigate and/or disclose the inadequate data security practices previously alleged. 216. If Plaintiff and Class Members had known that Defendant would not use adequate data security practices, procedures, and protocols to adequately monitor, supervise, and secure their Private Information, they would have entrusted their Private Information to Defendant. 217. Plaintiff and Class Members have no adequate remedy at law. 218. Defendant enriched itself by saving the costs it reasonably should have expended on data security measures to secure Plaintiff’s and Class Members’ Personal Information. Instead of providing a reasonable level of security that would have prevented the hacking incident, Defendant instead calculated to increase its own profit at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures and diverting those funds to its own profit. Plaintiff and Class Members, on the other hand, suffered as a direct and proximate result of Defendant’s decision to prioritize its own profits over the requisite security and the safety of their Private Information. 219. Under the circumstances, it would be unjust for Defendant to be permitted to retain any of the benefits that Plaintiff and Class Members conferred upon it. 220. As a direct and proximate result of Defendant’s conduct, Plaintiff and Class Members have suffered and will suffer injury, including but not limited to: (i) invasion of privacy; (ii) theft of their Private Information; (iii) lost or diminished value of Private Information; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 48 of 55 Data Breach; (v) loss of benefit of the bargain; (vi) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vii) actual misuse of the compromised data consisting of an increase in spam calls, texts, and/or emails; (viii) invasion of privacy; (ix)nominal damages; and (x) the continued and certainly increased risk to their Private Information, which: (a) remains unencrypted and available for unauthorized third parties to access and abuse; and (b) remains backed up in Defendant’s possession and is subject to further unauthorized disclosures so long as Defendant fails to undertake appropriate and adequate measures to protect the Private Information. 221. Plaintiff and Class Members are entitled to full refunds, restitution, and/or damages from Defendant and/or an order proportionally disgorging all profits, benefits, and other compensation obtained by Defendant from its wrongful conduct. This can be accomplished by establishing a constructive trust from which the Plaintiff and Class Members may seek restitution or compensation. 222. Plaintiff and Class Members may not have an adequate remedy at law against Defendant, and accordingly, they plead this claim for unjust enrichment in addition to, or in the alternative to, other claims pleaded herein. COUNT V BREACH OF FIDUCIARY DUTY (On Behalf of Plaintiff and the Class) 223. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. 224. Given the relationship between Defendant and Plaintiff and Class members, where Defendant became guardian of Plaintiff’s and Class members’ Private Information, Defendant became a fiduciary by its undertaking and guardianship of the Private Information, to act primarily Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 49 of 55 for Plaintiff and Class members, (1) for the safeguarding of Plaintiff and Class members’ Private Information; (2) to timely notify Plaintiff and Class members of a Data Breach and disclosure; and (3) to maintain complete and accurate records of what information (and where) Defendant did and does store. 225. Defendant has a fiduciary duty to act for the benefit of Plaintiff and Class members upon matters within the scope of Defendant’s relationship with them—especially to secure their Private Information. 226. Because of the highly sensitive nature of the Private Information, Plaintiff and Class members (or their third-party agents) would not have entrusted Defendant, or anyone in Defendant’s position, to retain their Private Information had they known the reality of Defendant’s inadequate data security practices. 227. Defendant breached its fiduciary duties to Plaintiff and Class members by failing to sufficiently encrypt or otherwise protect Plaintiff’s and Class members’ Private Information. 228. Defendant also breached its fiduciary duties to Plaintiff and Class members by failing to diligently discover, investigate, and give notice of the Data Breach in a reasonable and practicable period. 229. As a direct and proximate result of Defendant’s breach of its fiduciary duties, Plaintiff and Class members have suffered and will continue to suffer numerous injuries (as detailed supra). COUNT VI DECLARATORY JUDGMENT (On Behalf of Plaintiff and the Class) 230. Plaintiff re-alleges and incorporates by reference all of the allegations contained in paragraphs 1 through 151, as if fully set forth herein. Case 1:25-cv-03131-TRJ 231. Document 1 Filed 06/04/25 Page 50 of 55 Under the Declaratory Judgment Act, 28 U.S.C. §§ 2201, et seq., this Court is authorized to enter a judgment declaring the rights and legal relations of the parties and to grant further necessary relief. Furthermore, the Court has broad authority to restrain acts, such as those alleged herein, which are tortious, and which violate the terms of the federal and state statutes described above. 232. An actual controversy has arisen in the wake of the Data Breach at issue regarding Defendant’s common law and other duties to act reasonably with respect to employing reasonable data security. Plaintiff alleges Defendant’s actions in this respect were inadequate and unreasonable and, upon information and belief, remain inadequate and unreasonable. Additionally, Plaintiff and the Class continue to suffer injury due to the continued and ongoing threat of new or additional fraud against them or on their accounts using the stolen data. 233. Under its authority under the Declaratory Judgment Act, this Court should enter a judgment declaring, among other things, the following: a. Defendant continues to owe a legal duty to employ reasonable data security to secure the Private Information it possesses, and to notify impacted individuals of the Data Breach under the common law and Section 5 of the FTC Act; b. Defendant continues to breach its duty by failing to employ reasonable measures to secure its customers’ personal and financial information; and c. Defendant’s breach of its legal duty continues to cause harm to Plaintiff and the Class. 234. The Court should also issue corresponding injunctive relief requiring Defendant to employ adequate security protocols consistent with industry standards to protect its customers’ (i.e., Plaintiff’s and the Class’s) data. 235. If an injunction is not issued, Plaintiff and the Class will suffer irreparable injury and lack an adequate legal remedy in the event of another breach of Defendant’s data systems. If Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 51 of 55 another breach of Defendant’s data systems occurs, Plaintiff and the Class will not have an adequate remedy at law because many of the resulting injuries are not readily quantified in full and they will be forced to bring multiple lawsuits to rectify the same conduct. Simply put, monetary damages, while warranted to compensate Plaintiff and the Class for their out-of-pocket and other damages that are legally quantifiable and provable, do not cover the full extent of injuries suffered by Plaintiff and the Class, which include monetary damages that are not legally quantifiable or provable. 236. The hardship to Plaintiff and the Class if an injunction is not issued exceeds the hardship to Defendant if an injunction is issued. 237. Issuance of the requested injunction will not disserve the public interest. To the contrary, such an injunction would benefit the public by preventing another data breach, thus eliminating the injuries that would result to Plaintiff, the Class, and the public at large. PRAYER FOR RELIEF WHEREFORE, Plaintiff, on behalf of himself and all Class Members, request judgment against Defendant and that the Court grants the following: A. For an order certifying the Class, as defined herein, and appointing Plaintiff and his Counsel to represent the Class; B. For equitable relief enjoining Defendant from engaging in the wrongful conduct complained of herein pertaining to the misuse and/or disclosure of the Private Information of Plaintiff and Class Members, and from refusing to issue prompt, complete, any accurate disclosures to Plaintiff and Class Members; C. For injunctive relief requested by Plaintiff, including but not limited to, injunctive and other equitable relief as is necessary to protect the interests of Plaintiff and Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 52 of 55 Class Members, including but not limited to an order: i. prohibiting Defendant from engaging in the wrongful and unlawful acts described herein; ii. requiring Defendant to protect, including through encryption, all data collected through the course of its business in accordance with all applicable regulations, industry standards, and federal, state, or local laws. iii. requiring Defendant to delete, destroy, and purge the personal identifying information of Plaintiff and Class Members unless Defendant can provide to the Court reasonable justification for the retention and use of such information when weighed against the privacy interests of Plaintiff and Class Members; iv. requiring Defendant to implement and maintain a comprehensive Information Security Program designed to protect the confidentiality and integrity of the Private Information of Plaintiff and Class Members; v. prohibiting Defendant from maintaining the Private Information of Plaintiff and Class Members on a cloud-based database; Vi. requiring Defendant to engage independent third-party security auditors/penetration testers as well as internal security personnel to conduct testing, including simulated attacks, penetration tests, and audits on Defendant’s systems on a periodic basis, and ordering Defendant to promptly correct any problems or issues detected by such third-party security auditors; vii. requiring Defendant to engage independent third-party security auditors and Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 53 of 55 internal personnel to run automated security monitoring; viii. requiring Defendant to audit, test, and train its security personnel regarding any new or modified procedures; ix. requiring Defendant to segment data by, among other things, creating firewalls and access controls so that if one area of Defendant’s network is compromised, hackers cannot gain access to other portions of Defendant’s systems; x. requiring Defendant to conduct regular database scanning and securing checks; xi. requiring Defendant to establish an information security training program that includes at least annual information security training for all employees, with additional training to be provided as appropriate based upon the employees’ respective responsibilities with handling personal identifying information, as well as protecting the personal identifying information of Plaintiff and Class Members; xii. requiring Defendant to conduct internal training and education routinely and continually, and on an annual basis to inform internal security personnel how to identify and contain a breach when it occurs and what to do in response to a breach; xiii. requiring Defendant to implement a system of tests to assess its clients’ employees’ knowledge of the education programs discussed in the preceding subparagraphs, as well as randomly and periodically testing employees’ compliance with Defendant’s policies, programs, and systems Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 54 of 55 for protecting personal identifying information; xiv. requiring Defendant to implement, maintain, regularly review, and revise as necessary a threat management program designed to appropriately monitor Defendant’s information networks for threats, both internal and external, and assess whether monitoring tools are appropriately configured, tested, and updated; xv. requiring Defendant to meaningfully educate all Class Members about the threats that they face as a result of the loss of their confidential Private Information to third parties, as well as the steps affected individuals must take to protect themselves; xvi. requiring Defendant to implement logging and monitoring programs sufficient to track traffic to and from Defendant’s servers; and for a period of 10 years, appointing a qualified and independent third-party assessor to conduct a SOC 2 Type 2 attestation on an annual basis to evaluate Defendant’s compliance with the terms of the Court’s final judgment, to provide such report to the Court and to counsel for the class, and to report any deficiencies with compliance of the Court’s final judgment; D. For an award of damages, including actual, nominal, and consequential damages, as allowed by law in an amount to be determined; E. For an award of attorneys’ fees and costs as allowed by law; F. For prejudgment interest on all amounts awarded; and G. Such other and further relief as this Court may deem just and proper. Case 1:25-cv-03131-TRJ Document 1 Filed 06/04/25 Page 55 of 55 JURY TRIAL DEMANDED Plaintiff, individually and on behalf of the Class, hereby demands a trial by jury on all claims so triable. Dated: June 4, 2025 SHAMIS & GENTILE P.A. /s/ Andrew Shamis Andrew J. Shamis, Esq. (GA Bar No 494196) ashamis@shamisgentile.com 14 NE 1st Ave., Suite 705 Miami, Florida 33132 Tel: (305) 479-2299
File and source
- File
- gov.uscourts.gand.344828.1.0.pdf
- Size
- 313,156 bytes
- SHA-256
- 08a388e1b4632268590f070ada68b5d501e29ae06deb8eddb3e9c11b3c1fd048
- Our copy
- gov.uscourts.gand.344828.1.0.pdf
- Original
- www.courtlistener.com