Adkins v. Facebook, Inc.

District Court, N.D. California·Decided May 6, 2021·No. 3:18-cv-05982·Unknown

Opinion

NORTHERN DISTRICT OF CALIFORNIA

No. C 18–05982 WHA Plaintiff,

v. FINAL SETTLEMENT APPROVAL AND ORDER GRANTING IN PART FACEBOOK, INC., AND DENYING IN PART MOTION FOR ATTORNEY’S FEES Defendant.

Both sides seek final approval of a class action settlement and class counsel seek a large sum in fees and costs. A coding error allowed hackers to break into the Facebook platform and pilfer the personal information of millions of users in the United States. This came to light in 2018, leading to a flurry of complaints. A prior order explained the coding vulnerability responsible for the data breach (Dkt. 153). In brief, if three particular features on the Facebook platform aligned access to accounts. The compromising of access tokens made millions of users accounts vulnerable to entry (Dkt. 193). A consolidated complaint sought relief in the form of a credit monitoring service for the victims, in addition to compensatory, statutory, and punitive damages, and declaratory relief based on ten claims. To this end, counsel moved to certify a class of users whose information had been compromised. An order declined to certify a damages class but allowed an injunctive relief class. Users were left to pursue damages claims on their own but no one ever filed one (Dkt. 338 at 4). All but two of plaintiffs’ claims were dismissed and by the time the case settled, only one named class representative remained out of the 11 plaintiffs involved in the case after consolidation. The terms of the settlement included commitments by Facebook to prevent future vulnerabilities related specifically to access tokens and consent to be independently monitored. More specifically, Facebook’s security commitments include (Dkt. 315-5 at 27-29):

1. Tools to run integrity checks on updates

2. Tools for the detection of suspicious patterns in the generation and use of access tokens 3. Procedures to contain security incidents related to improper issuance of access tokens

4. Automatic alerts for suspicious activity in user growth metrics and reporting on that activity 5. Five years of annual SOC2 Type II security assessments of certain products related to security and vulnerability management and an agreement to report the results to the Court and class counsel

6. Processes that give applications related to access tokens only the capabilities to perform intended functions, including internal guidance to software engineers for selecting capabilities of applications using access tokens and automatic removal of access token capabilities for applications that do not use those capabilities over a 90-day period

7. Certification by Facebook that it eliminated the type of authentication proofs which made user credentials vulnerable

8. Commitment to employing at least one senior security 9. Logging issuance and receipt of access tokens to facilitate detection and investigation of compromised access tokens Class counsel also move for attorney’s fees in the amount of $10,700,000 (based on a 1.253 multiplier), $1,210,900.75 in costs, a reserve of $15,000 for a data security vendor to monitor compliance with the settlement terms (by way of the SOC2 Type II assessments), and a $5,000 service award for plaintiff Stephen Adkins (Br. at 2–3). ANAYLSIS After the coding error in the Facebook platform exposed users to possible loss of personal information, at least ten civil actions were immediately filed in this district and consolidated. A previous order certified a class seeking injunctive relief but rejected certification of a damages class. A class settlement followed whereby Facebook agreed to maintain certain security fixes almost all of which Facebook would likely have maintained anyway. This order will approve the settlement as fair and adequate in light of the substantial risks of litigation. All damages claims have been preserved but none have been asserted anywhere by any of the millions potentially affected. This order will also grant reasonable attorney’s fees and expenses for class counsel but not for other lawyers. 1. PROPOSED CLASS SETTLEMENT FINAL APPROVAL Under FRCP 23(e), the Court must approve any settlement agreement that will bind absent class members. In reviewing a proposed settlement agreement, the district court must perform two tasks: (1) direct notice in a reasonable manner to all class members who would be bound by the proposal; and (2) approve the settlement only after a hearing and on finding that the terms of the agreement are fair, reasonable, and adequate. In determining if a settlement is fair, reasonable, and adequate, district courts take into account (1) the strength of the plaintiffs’ case; (2) the risk, expense, complexity, and likely duration of further litigation; (3) the risk of maintaining class action status throughout the trial; (4) the amount offered in settlement; (5) the extent of discovery completed and the stage of the proceedings; (6) the experience and view of counsel; (7) the presence of a governmental participant; and (8) the reaction of the class members to the proposed settlement. In re Online DVD-Rental Antitrust Litig., 779 F.3d 934, 944 (9th Cir. 2015). A prior order approved the form, content, and planned distribution of the class notice. The claims administrator has fulfilled the notice plan. This order further finds that notice to class members was adequate. For the following reasons and for the reasons stated in the November 2020 order (Dkt. 314), the proposed class settlement is fair, reasonable, and adequate under FRCP 23(e). In considering the strength of plaintiff’s case, this order notes that what Facebook did wrong was not an intentional betrayal of its users for profit. At most Facebook was negligent in allowing a confluence of rare circumstances to open up access tokens to strangers and, arguably, being too slow to catch this vulnerability. The heart of this case was a software coding mistake. Given the many millions of lines of codes, Facebook cannot entirely rid its complex system of all risk of software coding errors. So, the relief obtained herein will not eliminate all future breaches or leaks. Though Facebook reports in supplemental briefing that no further breaches related to access tokens have occurred since putting the settlement measures into place, other intrusions of one sort or another will eventually recur. Class counsel characterize their success achieved by settlement as “momentous.” In the Court’s view the success of the settlement seems modest as best and cosmetic at worst. This will be discussed further in connection with the motion for attorney’s fees. The benefit obtained, however, meets the threshold of adequacy in light of the above explained context, as well as the expense to the parties’ and the drain on resources that would result from continued litigation. These proceedings have been ongoing for more than two years and extensive discovery has been taken, including 20 depositions. There has been a motion to dismiss which was granted in part and denied in part, but no dispositive motions. This makes settlement appropriate given the limited relief that could be awarded even if the case were litigated all the way through trial. One individual responded to the notice of class settlement. The objector claims her Facebook submitted a declaration stating the class notice administrator, Angeion Group, LLC, searched data provided by Facebook and could not verify that the objector was a class member (Dkt. 327-2 at 2). Angeion was unable to contact the objector with the email and phone number provided in the objection (Dkt. 327-2 at 2). The objection raises no poin

Free access — add to your briefcase to read the full text and ask questions with AI

Adkins v. Facebook, Inc., (N.D. Cal. 2021).

Adkins v. Facebook, Inc. (Adkins v. Facebook, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Theodore H. Frank v. Netflix, Inc.
779 F.3d 934 (Ninth Circuit, 2015)