Adkins v. Facebook, Inc.

District Court, N.D. California·Decided May 6, 2021·No. 3:18-cv-05982·Unknown

Opinion

1 2 3 4 5 6 7 8 9 UNITED STATES DISTRICT COURT 10 NORTHERN DISTRICT OF CALIFORNIA 11

13 STEPHEN ADKINS, No. C 18–05982 WHA 14 Plaintiff,

15 v. FINAL SETTLEMENT APPROVAL AND ORDER GRANTING IN PART 16 FACEBOOK, INC., AND DENYING IN PART MOTION FOR ATTORNEY’S FEES 17 Defendant.

18 19 20 INTRODUCTION 21 Both sides seek final approval of a class action settlement and class counsel seek a large 22 sum in fees and costs. 23 STATEMENT 24 A coding error allowed hackers to break into the Facebook platform and pilfer the personal 25 information of millions of users in the United States. This came to light in 2018, leading to a 26 flurry of complaints. A prior order explained the coding vulnerability responsible for the data 27 breach (Dkt. 153). In brief, if three particular features on the Facebook platform aligned 1 access to accounts. The compromising of access tokens made millions of users accounts 2 vulnerable to entry (Dkt. 193). 3 A consolidated complaint sought relief in the form of a credit monitoring service for the 4 victims, in addition to compensatory, statutory, and punitive damages, and declaratory relief 5 based on ten claims. To this end, counsel moved to certify a class of users whose information 6 had been compromised. An order declined to certify a damages class but allowed an injunctive 7 relief class. Users were left to pursue damages claims on their own but no one ever filed one 8 (Dkt. 338 at 4). All but two of plaintiffs’ claims were dismissed and by the time the case settled, 9 only one named class representative remained out of the 11 plaintiffs involved in the case after 10 consolidation. The terms of the settlement included commitments by Facebook to prevent future 11 vulnerabilities related specifically to access tokens and consent to be independently monitored. 12 More specifically, Facebook’s security commitments include (Dkt. 315-5 at 27-29):

13 1. Tools to run integrity checks on updates

14 2. Tools for the detection of suspicious patterns in the generation and use of access tokens 15 3. Procedures to contain security incidents related to improper 16 issuance of access tokens

17 4. Automatic alerts for suspicious activity in user growth metrics and reporting on that activity 18 5. Five years of annual SOC2 Type II security assessments of 19 certain products related to security and vulnerability management and an agreement to report the results to the 20 Court and class counsel

21 6. Processes that give applications related to access tokens only the capabilities to perform intended functions, 22 including internal guidance to software engineers for selecting capabilities of applications using access tokens 23 and automatic removal of access token capabilities for applications that do not use those capabilities over a 90-day 24 period

25 7. Certification by Facebook that it eliminated the type of authentication proofs which made user credentials 26 vulnerable

27 8. Commitment to employing at least one senior security 9. Logging issuance and receipt of access tokens to facilitate 1 detection and investigation of compromised access tokens 2 Class counsel also move for attorney’s fees in the amount of $10,700,000 (based on a 3 1.253 multiplier), $1,210,900.75 in costs, a reserve of $15,000 for a data security vendor to 4 monitor compliance with the settlement terms (by way of the SOC2 Type II assessments), and 5 a $5,000 service award for plaintiff Stephen Adkins (Br. at 2–3). 6 ANAYLSIS 7 After the coding error in the Facebook platform exposed users to possible loss of personal 8 information, at least ten civil actions were immediately filed in this district and consolidated. A 9 previous order certified a class seeking injunctive relief but rejected certification of a damages 10 class. A class settlement followed whereby Facebook agreed to maintain certain security fixes 11 almost all of which Facebook would likely have maintained anyway. This order will approve the 12 settlement as fair and adequate in light of the substantial risks of litigation. All damages claims 13 have been preserved but none have been asserted anywhere by any of the millions potentially 14 affected. This order will also grant reasonable attorney’s fees and expenses for class counsel but 15 not for other lawyers. 16 1. PROPOSED CLASS SETTLEMENT FINAL APPROVAL 17 Under FRCP 23(e), the Court must approve any settlement agreement that will bind absent 18 class members. In reviewing a proposed settlement agreement, the district court must perform 19 two tasks: (1) direct notice in a reasonable manner to all class members who would be bound by 20 the proposal; and (2) approve the settlement only after a hearing and on finding that the terms of 21 the agreement are fair, reasonable, and adequate. In determining if a settlement is fair, 22 reasonable, and adequate, district courts take into account (1) the strength of the plaintiffs’ case; 23 (2) the risk, expense, complexity, and likely duration of further litigation; (3) the risk of 24 maintaining class action status throughout the trial; (4) the amount offered in settlement; (5) the 25 extent of discovery completed and the stage of the proceedings; (6) the experience and view of 26 counsel; (7) the presence of a governmental participant; and (8) the reaction of the class 27 1 members to the proposed settlement. In re Online DVD-Rental Antitrust Litig., 779 F.3d 934, 2 944 (9th Cir. 2015). 3 A prior order approved the form, content, and planned distribution of the class notice. The 4 claims administrator has fulfilled the notice plan. This order further finds that notice to class 5 members was adequate. For the following reasons and for the reasons stated in the November 6 2020 order (Dkt. 314), the proposed class settlement is fair, reasonable, and adequate under 7 FRCP 23(e). 8 In considering the strength of plaintiff’s case, this order notes that what Facebook did 9 wrong was not an intentional betrayal of its users for profit. At most Facebook was negligent in 10 allowing a confluence of rare circumstances to open up access tokens to strangers and, arguably, 11 being too slow to catch this vulnerability. The heart of this case was a software coding mistake. 12 Given the many millions of lines of codes, Facebook cannot entirely rid its complex system of all 13 risk of software coding errors. So, the relief obtained herein will not eliminate all future 14 breaches or leaks. Though Facebook reports in supplemental briefing that no further breaches 15 related to access tokens have occurred since putting the settlement measures into place, other 16 intrusions of one sort or another will eventually recur. 17 Class counsel characterize their success achieved by settlement as “momentous.” In the 18 Court’s view the success of the settlement seems modest as best and cosmetic at worst. This will 19 be discussed further in connection with the motion for attorney’s fees. 20 The benefit obtained, however, meets the threshold of adequacy in light of the above 21 explained context, as well as the expense to the parties’ and the drain on resources that would 22 result from continued litigation. 23 These proceedings have been ongoing for more than two years and extensive discovery has 24 been taken, including 20 depositions. There has been a motion to dismiss which was granted in 25 part and denied in part, but no dispositive motions. This makes settlement appropriate given the 26 limited relief that could be awarded even if the case were litigated all the way through trial. 27 One individual responded to the notice of class settlement.

Free access — add to your briefcase to read the full text and ask questions with AI

Adkins v. Facebook, Inc., (N.D. Cal. 2021).

Adkins v. Facebook, Inc. (Adkins v. Facebook, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Theodore H. Frank v. Netflix, Inc.
779 F.3d 934 (Ninth Circuit, 2015)