Adkins v. Facebook, Inc.

District Court, N.D. California·Decided November 26, 2019·No. 3:18-cv-05982·Unknown

Opinion

FOR THE NORTHERN DISTRICT OF CALIFORNIA STEPHEN ADKINS, an individual and Michigan resident, on behalf of himself and all others similarly situated, No. C 18-05982-WHA Plaintiff, v. ORDER ON MOTION FOR FACEBOOK, INC., CLASS CERTIFICATION AND MOTIONS TO STRIKE Defendant. / INTRODUCTION This is a putative class action by plaintiff Stephen Adkins against defendant Facebook, Inc. Plaintiff asserts a claim for negligence based on Facebook’s alleged faulty security practices in collecting and storing plaintiff’s information. These faulty practices allegedly allowed hackers to break into Facebook’s platform and pilfer the personal information of 29 million Facebook users worldwide, including more than four million users in the United States. The operative complaint seeks relief in the form of a credit monitoring service for the victims, in addition to compensatory, statutory, and punitive damages. The operative complaint also seeks declaratory relief (Amd. Compl. at 48) (Dkt. No. 193). A prior order walked through the coding vulnerability which allowed the data breach (Dkt. No. 153). In brief, when three features on Facebook’s platform interacted, “access tokens” became visible. Similar to a password, access tokens permitted users to enter their by strangers. In this way, the hackers entered 300,000 accounts in September 2018 (Bream Decl. ¶¶ 11–17; Amd. Compl. ¶¶ 95–97, 100) (Dkt. Nos. 97; 193) The hackers ran two separate search queries from within these 300,000 accounts. The first yielded the names and telephone numbers and/or e-mail addresses of fifteen million users worldwide (2.7 million in the United States). The second yielded more sensitive information on fourteen million users worldwide (1.2 million in the United States). The information taken from this second group included names, telephone numbers, e-mail addresses, gender, date of birth, and, to the extent the fields were populated, workplace, education, relationship status, religious views, hometown, self-reported current city, and website. Within this second group, the hackers also obtained the user’s locale and language, the type of device used by the user to access Facebook, the last ten places the user was “tagged” in or “checked into” on Facebook, the people or pages on Facebook followed by the user, and the user’s fifteen most recent searches using the Facebook search bar. The original 300,000 users who had their accounts entered into also had the same information taken as this second group (Bream Decl. ¶¶ 10–12, 18–19). In February 2019, five named plaintiffs filed a consolidated complaint which averred ten claims. An order consolidated eleven putative class action lawsuits filed in this district which arose from this data breach. Following Rule 12 practice, in August 2019, only one named plaintiff, Stephen Adkins, and two claims remained (Dkt. Nos. 76, 78, 96, 108, 113, 115, 153). Plaintiff now seeks to certify a class of all Facebook users whose personal information became part of the September 2018 data breach. Plaintiff seeks certification under Rule 23(b)(2), Rule 23(b)(3), and Rule 23(c)(4). More specifically, plaintiff seeks injunctive relief for a worldwide class under Rule 23(b)(2), namely plaintiff seeks certain changes to Facebook’s security practices to ensure no further harm comes to its users. Plaintiff seeks damages on behalf of a nationwide class under Rule 23(b)(3), related to the diminished value of personal information and for Facebook to provide cash for future credit monitoring. Finally, plaintiff seeks certification of a nationwide class under Rule 23(c)(4) for those who seek additional individual damages resulting from the time spent devoted to the data breach, and who incurred other individual injuries (Dkt. Nos. 193 at 47, 48; 198 at 1). In opposing the class certification motion, Facebook concentrates most of its fire on the Rule 23(b)(3) damages class. Primarily, Facebook opposes on the ground that individual issues would predominate. Facebook also moved to strike two of plaintiff’s expert declarations (Dkt. Nos. 213–15). This order follows oral argument. This order first holds that plaintiff Stephen Adkins has sufficiently established Article III standing because of a substantial risk of identity theft and also because he has lost time due to the breach. Next, this order holds that Identity Theft Expert James Van Dyke’s expert opinion must be excluded because his methodology is unreliable. CPA Ian Ratner’s expert opinion, however, will be allowed. Finally, this order will certify an injunctive class under Rule 23(b)(2). The details now follow. 1. ARTICLE III STANDING. A prior order dated June 21, 2019, held that plaintiff Adkins had sufficiently established standing (Dkt. No. 153 at 12). Then, as now, the only contentious element concerned the injury-in-fact requirement. Then, as now, plaintiff Adkins sufficiently established injury due to a substantial risk of future identity theft and also due to a continuing loss of time, all to follow. A. Substantial Risk of Identity Theft. No social security or credit-card numbers were taken in this hack. The hackers took plaintiff’s name, date of birth, phone number, gender, and hometown, among other information (Dkt. No. 193 ¶ 102). Plaintiff, however, cannot change his date of birth or hometown and would not be expected to change his gender merely on account of a data breach. This information will abide, sensitive, long-term. This sensitivity, combined with the fact that the information was not merely taken, but specifically targeted for theft, continues to confer a basis for standing at this stage. Facebook complains that plaintiff has so far suffered only three phishing e-mails, all of which went directly to his junk folder. But his identity remains at peril, theft-wise. That is enough. A finding of a substantial risk of identity theft does not depend on concrete examples that the stolen information has already been misused. In Krottner v. Starbucks Corporation, “Starbucks sent a letter to . . . affected employees alerting them to the theft and stating that Starbucks had no indication that the private information ha[d] been misused.” 628 F.3d 1139, 1140–41 (9th Cir. 2010) (internal quotation marks and citation omitted). Nevertheless, a credible threat of real and immediate harm had been sufficiently alleged there because the information: (i) had been sensitive and (ii) had been stolen. Id. at 1143. Plaintiff’s risk of identity theft stems from the sensitivity of the information taken combined with its theft. The information taken in Krottner — name, address, social security number — included information sufficiently similar to the information taken here. A social security number, though even worse to lose, is like one’s date of birth, prior history, and gender. They remain with the victim forever, thereby “g[i]v[ing] hackers the means to commit fraud or identity theft.” In re Zappos.com, Inc., 888 F.3d 1020, 1027–29 (9th Cir. 2018), cert. denied sub nom., Zappos.com v. Stevens, 139 S. Ct. 1373 (2019). Information such as this will never go bad, and so, hackers can warehouse this stolen data for years before using it. The substantial risk remains. It is true that in Zappos, our court of appeals mentioned there were concrete examples of identity theft and specific instances of hacked accounts in that data breach, whereas in this case there are none. 888 F.3d at 1027–28. But Zappos also recognized that “[a] person whose [personal information] has been obtained and compromised may not see the full extent of identity theft or identity fraud for years. And it may take some time for the victim to become aware of the theft.” Id. at 1028–29 (internal quotations omitted). Nothing in Zappos suggests that the absence of evidence of misuse kills standing. At this stage, information loss can be deemed sensitive without the victim being yet drained

Free access — add to your briefcase to read the full text and ask questions with AI

Adkins v. Facebook, Inc., (N.D. Cal. 2019).

Adkins v. Facebook, Inc. (Adkins v. Facebook, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Primiano v. Cook
598 F.3d 558 (Ninth Circuit, 2010)
Cassell v. Carrollton
24 U.S. 134 (Supreme Court, 1826)
McGowan v. Maryland
366 U.S. 420 (Supreme Court, 1961)
Baker v. Carr
369 U.S. 186 (Supreme Court, 1962)
Harper v. Virginia Board of Elections
383 U.S. 663 (Supreme Court, 1966)
Joel Ruiz v. Gap, Inc.
380 F. App'x 689 (Ninth Circuit, 2010)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Wal-Mart Stores, Inc. v. Dukes
131 S. Ct. 2541 (Supreme Court, 2011)
Minney v. City of Azusa
330 P.2d 255 (California Court of Appeal, 1958)
Potter v. Firestone Tire & Rubber Co.
863 P.2d 795 (California Supreme Court, 1993)
Ruiz v. Gap, Inc.
622 F. Supp. 2d 908 (N.D. California, 2009)
People v. Mancebo
41 P.3d 556 (California Supreme Court, 2002)
Victor Parsons v. Charles Ryan
754 F.3d 657 (Ninth Circuit, 2014)
Robert Briseno v. Conagra Foods, Inc.
844 F.3d 1121 (Ninth Circuit, 2017)
B.K. v. Thomas Betlach
922 F.3d 957 (Ninth Circuit, 2019)
Valentino v. Carter-Wallace, Inc.
97 F.3d 1227 (Ninth Circuit, 1996)