Allen v. Blackbaud Inc

District Court, D. South Carolina·Decided July 1, 2021·No. 3:20-cv-02930·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF SOUTH CAROLINA COLUMBIA DIVISION

) ) ) Case No.: 3:20-mn-02972-JMC IN RE: BLACKBAUD, INC., ) CUSTOMER DATA BREACH ) MDL No. 2972 LITIGATION ) ) ORDER AND OPINION ) ) ____________________________________)

THIS DOCUMENT RELATES TO: ALL ACTIONS

This matter is before the court on Defendant Blackbaud, Inc.’s (“Blackbaud”) Motion to Dismiss for Lack of Subject Matter Jurisdiction pursuant to Federal Rule of Civil Procedure 12(b)(1) (ECF No. 92). Blackbaud contends that the court lacks subject matter jurisdiction over Plaintiffs’ claims, specifically asserting that Plaintiffs do not have Article III standing because they failed to sufficiently allege that their injuries are traceable to Blackbaud’s conduct. (ECF No. 92- 1 at 7.) For the reasons set forth below, the court DENIES Blackbaud’s Motion (ECF No. 92). I. RELEVANT BACKGROUND Blackbaud is a publicly traded cloud software company incorporated in Delaware and headquartered in Charleston, South Carolina. (ECF No. 77 at 110-11 ¶ 419, 112 ¶ 424.) The company provides data collection and maintenance solutions for administration, fundraising, marketing, and analytics to social good entities such as non-profit organizations, foundations, educational institutions, faith communities, and healthcare organizations. (Id. at 4 ¶ 4, 114 ¶ 430.) As a result of this business model, Blackbaud collects and stores Personally Identifiable Information (“PII”) and Protected Health Information (“PHI”) from its customers’ donors, patients, students, and congregants. (Id. at 3 ¶ 2, 114 ¶ 429.) In this action, Plaintiffs represent a putative class of individuals whose data was provided to Blackbaud’s customers and managed by Blackbaud. (Id. at 6 ¶ 12.) Thus, Plaintiffs are patrons of Blackbaud’s customers rather than direct customers of Blackbaud. (ECF Nos. 92-1 at 9; 109 at 7-8.) Specifically, Plaintiffs allege that Blackbaud collected, stored, and maintained the following categories of their data:

• Name; • Address; • Phone number; • Email address; • Date of birth; • Demographic information; • Social Security Number (“SSN”); • Credit card information; • Bank account information; • Educational history; • Healthcare records; • Insurance information; • Photo identification; • Employer information; • Income information; • Donor contribution information; and • Other private information, including passwords, places of birth, and mothers’ maiden names.

(ECF No. 77 at 113 ¶ 427.) Plaintiffs assert that from February 7, 2020 to May 20, 2020, cybercriminals orchestrated a two-part ransomware attack on Blackbaud’s systems (“Ransomware Attack”). (Id. at 11 ¶ 25.) Cybercriminals first infiltrated Blackbaud’s computer networks, copied Plaintiffs’ data, and held it for ransom. (Id. at 11 ¶ 25, 137 ¶ 496; ECF No. 92-1 at 7.) They then attempted but failed to block Blackbaud from accessing its own systems upon being discovered in May 2020. (Id.) Blackbaud ultimately paid the ransom in an undisclosed amount of Bitcoin in exchange for a commitment that any data previously accessed by the cybercriminals was permanently destroyed. (ECF No. 77 at 9 ¶ 20, 138 ¶ 499; ECF No. 92-1 at 7.) Plaintiffs maintain that the Ransomware Attack resulted from Blackbaud’s “deficient security program[.]” (ECF No. 77 at 117-18 ¶ 439.) They assert that Blackbaud failed to comply with industry and regulatory standards by neglecting to implement security measures to mitigate

the risk of unauthorized access, utilizing outdated servers, storing obsolete data, and maintaining unencrypted data fields . (Id. at 117-18 ¶ 439, 134 ¶ 486, 136 ¶ 491, 142 ¶ 510.) Plaintiffs further allege that after the Ransomware Attack, Blackbaud launched a narrow internal investigation into the attack that analyzed a limited number of Blackbaud systems and did not address the full scope of the attack. (Id. at 143 ¶ 514.) On July 14, 2020, Blackbaud received the investigation report (“Forensic Report”) which acknowledged that “names, addresses, phone numbers, email addresses, dates of birth, and/or SSNs” were disclosed in the breach but stated that the investigation was “unable to detect credit card data while reviewing exfiltrated data[.]” (Id. at 143 ¶ 514 n.112, 144 ¶ 516, 154 ¶ 549.) Plaintiffs claim the Forensic Report “improperly

concludes that no credit card data was exfiltrated” because “such data could have existed in the unexamined database files.” (Id. at 144 ¶ 516.) Plaintiffs contend that Blackbaud failed to provide them with timely and adequate notice of the Ransomware Attack and the extent of the resulting data breach. (Id. at 130-31 ¶ 473.) They claim that they did not receive notice of the Ransomware Attack “until July of 2020 at the earliest[.]” (Id. at 156 ¶ 555.) On July 16, 2020, The NonProfit Times reported that Blackbaud had been the subject of a ransomware attack and data breach and Blackbaud issued a statement about the Ransomware Attack on its website. (Id. at 9 ¶ 20, 138 ¶ 499.) In both disclosures, Blackbaud asserted that the cybercriminals did not access credit card information, bank account information, or SSNs. (Id.) Plaintiffs allege that they subsequently received notices of the Ransomware Attack from various Blackbaud customers at different points in time from July 2020 to January 2021. (See, e.g., id. at 25 ¶ 63, 29 ¶ 82, 32 ¶ 93, 109 ¶ 414.) They maintain that some of the notices stated that

SSNs, credit card data, and bank account information were not accessed during the Ransomware Attack while others stated that SSNs but not credit card data or bank account information were exposed during the Ransomware Attack. (See, e.g., id. at 25 ¶ 64, 29 ¶ 82, 52 ¶ 173, 65 ¶ 230.) Some of the notices also allegedly expressed frustration with Blackbaud’s lack of transparency about the Ransomware Attack. For example, Plaintiffs claim that a data breach notice from the International Refugee Assistance Project notes that “[i]n full transparency, we have been dissatisfied with the level of information provided by Blackbaud following this breach[,]” while a data breach notice from the American Civil Liberties Union states “[i]n all candor, we are frustrated with the lack of information we’ve received from Blackbaud about this incident thus

far.” (Id. at 101 ¶ 378.) Plaintiffs maintain that although Blackbaud initially represented that sensitive information such as SSNs and bank account numbers were not compromised in the Ransomware Attack, Blackbaud informed certain customers in September and October 2020 that SSNs and other sensitive data were in fact stolen in the breach. (Id. at 141-42 ¶ 509.) Additionally, the Form 8-K Blackbaud filed with the Securities and Exchange Commission on September 29, 2020 states that SSNs, bank account information, usernames, and passwords may have been exfiltrated during the Ransomware Attack. (Id. at 12 ¶ 26, 143 ¶ 512.) After the Ransomware Attack was made public, putative class actions arising out of the intrusion into Blackbaud’s systems and subsequent data breach were filed in state and federal courts across the country. (ECF No. 1 at 1.) On December 15, 2020, the Judicial Panel on Multidistrict Litigation consolidated all federal litigation related to the Ransomware Attack into this multidistrict litigation (“MDL”) for coordinated pretrial proceedings.1 (Id. at 3.)

On April 2, 2021, thirty-four (34) named Plaintiffs2 from twenty (20) states filed a Consolidated Class Action Complaint (“CCAC”) alleging that their PII and/or PHI was compromised during the Ransomware Attack. (ECF No. 77.) 3 They assert six (6) claims on behalf of a putative nationwide class as well as ninety-one (91) statutory claims on behalf of putative state subclasses. (Id.

Free access — add to your briefcase to read the full text and ask questions with AI

Allen v. Blackbaud Inc, (D.S.C. 2021).

Allen v. Blackbaud Inc (Allen v. Blackbaud Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell v. Hood
327 U.S. 678 (Supreme Court, 1946)
Baker v. Carr
369 U.S. 186 (Supreme Court, 1962)
O'Shea v. Littleton
414 U.S. 488 (Supreme Court, 1974)
Warth v. Seldin
422 U.S. 490 (Supreme Court, 1975)
FW/PBS, Inc. v. City of Dallas
493 U.S. 215 (Supreme Court, 1990)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Bennett v. Spear
520 U.S. 154 (Supreme Court, 1997)
Arbaugh v. Y & H Corp.
546 U.S. 500 (Supreme Court, 2006)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
CGM, LLC v. BellSouth Telecommunications, Inc.
664 F.3d 46 (Fourth Circuit, 2011)
Jean Resnick v. AvMed, Inc.
693 F.3d 1317 (Eleventh Circuit, 2012)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
United States Ex Rel. Vuyyuru v. Jadhav
555 F.3d 337 (Fourth Circuit, 2009)
Kerns v. United States
585 F.3d 187 (Fourth Circuit, 2009)
Bosland v. Warnock Dodge, Inc.
964 A.2d 741 (Supreme Court of New Jersey, 2009)
City First Mortg. Corp. v. Barton
988 So. 2d 82 (District Court of Appeal of Florida, 2008)
Stutman v. Chemical Bank
731 N.E.2d 608 (New York Court of Appeals, 2000)