Fraser v. Mint Mobile, LLC

District Court, N.D. California·Decided April 27, 2022·No. 3:22-cv-00138·Unknown

Opinion

NORTHERN DISTRICT OF CALIFORNIA

Plaintiff, No. C 22-00138 WHA

v.

MINT MOBILE, LLC, ORDER RE MOTION TO DISMISS Defendant.

Hackers took cell phone users’ information from their carrier and this information was used to port plaintiff’s cellular service to another carrier whereupon a criminal pretending to be plaintiff acquired access to and then drained plaintiff’s cryptocurrency account maintained by a cryptocurrency exchange. The issue is the extent to which the carrier is liable for the lost funds once held by the cryptocurrency exchange. For the following reasons, the motion to dismiss is GRANTED IN PART and DENIED IN PART. Defendant Mint Mobile, LLC is a mobile virtual network operator that currently uses T- Mobile’s network infrastructure to provide wireless cellular services to its customers. One of those customers was plaintiff Daniel Fraser. This action involves three incidents that eventually led to the theft of Fraser’s cryptocurrency, held by a non-party cryptocurrency exchange. First, between June 8, 2021, and June 10, 2021, Mint (the mobile carrier) suffered a large-scale data breach. The leak exposed the personal identifying information (PII) of many of its cellphone customers, including their names, addresses, email addresses, phone numbers, account numbers, and passwords. Fraser was one of the customers affected by the breach (Compl. ¶¶ 3, 12). Second, criminals purportedly used the information exposed in the data breach to hijack Fraser’s cellphone service. SIM hijacking represents a growing crime in telecommunications. A subscriber identity module, or “SIM” card, authenticates a cellphone subscription. Switch the SIM card from an old phone into a new phone and the cellular service shifts to the new device. Relevant here, SIM porting, or port-out fraud, is a genus of SIM hijacking where a criminal, posing as the victim, opens an account with a carrier different from that of the hacked carrier and arranges for the victim’s cellular service to be transferred to the new carrier and put under control of the criminal. On June 11, 2021, an unknown criminal ported Fraser’s cellular service with Mint to another service provider, Metro by T-Mobile. Fraser alleges that the earlier Mint data breach exposed all the information needed to port out his service. Additionally, Fraser alleges that, three days before his service was fraudulently ported to the other provider, he had implemented a PIN verification feature on his Mint account to enhance his electronic security with two-factor authentication, i.e., making changes to his account required both a password and a pin verification code. Fraser alleges that Mint bypassed this enhanced security when it allowed the porting out of his account. All of this occurred before Mint notified affected customers of the breach on July 9, 2021 (Compl. ¶¶ 2–6, 37–43, 59–66). Third, Fraser’s cryptocurrency account (with a completely separate firm) was then hacked and his assets stolen. Besides the loss of one’s cell service, port-out fraud places the victim’s other personal accounts at risk as well. Personal accounts — e.g., for email, banking, account holder to recover access to their account when, for example, they forget their password. In many instances, all the account holder needs to do to regain access to their account is verify their identity by entering a pin number automatically sent to their phone via their cellular service (like the pin verification Fraser put on his Mint account). This means once a criminal successfully ports a victim’s cellphone service, the criminal acquires a key to steal the victim’s identity and access a variety of the victim’s accounts (so long as the criminal has other, basic information regarding the victim’s accounts, such as the email address used to maintain the account) (Compl. ¶¶ 1, 49, 59 62–67). Fraser had an account with Ledger, a specific cryptocurrency exchange, where he stored his cryptocurrency. He alleges that the combination of Mint’s data breach (which occurred from June 8 through June 10) and the fraudulent SIM port (which occurred on June 11 at 8:08 a.m.) provided criminals with all the information and access required to hack into and drain his Ledger account (Compl. ¶ 63). As a result, starting on June 11 at 9:19 a.m., a criminal began to drain Fraser’s Ledger account, and eventually stole the equivalent of $466,000.00 in cryptocurrency (Compl. ¶¶ 59–67). Fraser filed this lawsuit to hold Mint responsible for its purported role in the theft of his cryptocurrency. Fraser broadly asserts claims for violation of the Federal Communications Act, violations of California Business & Professions Code Section 17200, negligence, and breach of contract. He does not assert his claims on behalf of a putative class. Now, Mint moves to dismiss the complaint for failure to state a claim. At the hearing, Mint withdrew its motion to dismiss the prayer for injunctive relief pursuant to the Federal Communications Act as well as its motion to compel arbitration. This order follows full briefing and oral argument. A motion to dismiss tests the legal sufficiency of the complaint. To survive a motion to dismiss under Rule 12(b)(6), a complaint must contain sufficient factual matter, accepted as true, to state a claim for relief that is plausible on its face. A claim is facially plausible when there are sufficient factual allegations to draw a reasonable inference that the defendant is must take all of the factual allegations in the complaint as true, it is “not bound to accept as true a legal conclusion couched as a factual allegation.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007). “Factual allegations must be enough to raise a right to relief above the speculative level.” Ibid. 1. PROXIMATE CAUSE (ALL COUNTS). Mint argues that the complaint fails to adequately allege the data breach and SIM port proximately caused the theft of Fraser’s cryptocurrency from a third-party, and that the complaint should be dismissed in its entirety (Br. 6). This order disagrees. “It is a well established principle of the common law that in all cases of loss, we are to attribute it to the proximate cause, and not to any remote cause.” Bank of Am. Corp. v. City of Miami, 137 S. Ct. 1296, 1305 (2017) (cleaned up). Generally, the proximate cause requirement “bars suits for alleged harm that is ‘too remote’ from the defendant’s unlawful conduct.” Lexmark Int’l, Inc. v. Static Control Components, Inc., 572 U.S. 118, 133 (2014). Under California law, proximate cause has two aspects. The first is cause in fact, sometimes referred to as but-for causation. Under the substantial factor test, which generally subsumes but-for causation, a cause in fact is an act or omission that was a substantial factor in bringing about the plaintiff’s harm. The second aspect of proximate cause incorporates considerations of public policy. “These additional limitations are related not only to the degree of connection between the conduct and the injury, but also with public policy.” State Dep’t of State Hosps. v. Super. Ct., 61 Cal. 4th 339, 352–53 (2015) (quotation omitted); Frausto v. Dep’t of Cal. Highway Patrol, 53 Cal. App. 5th 973, 996 (2020). “Ordinarily, proximate cause is a question of fact which cannot be decided as a matter of law from the allegations of a complaint. Nevertheless, where the facts are such that the only reasonable conclusion is an absence of causation, the question is one of law, not of fact.” State Hosps., 61 Cal. 4th at 353 (cleaned up). First, Mint argues that “holes in [p]laintiff’s conclusory chain of causation overcome proximate causation” (Br. 8). The complaint, however, adequately explains how the access needed to drain Fraser’s Ledger account. The data breach exposed, among other information, Fraser’s name, address, telephone number, email address, and Mint password. Moreover, the data breach did not merely expose some of Fraser’s PII, it purportedly revea

Free access — add to your briefcase to read the full text and ask questions with AI

Fraser v. Mint Mobile, LLC, (N.D. Cal. 2022).

Fraser v. Mint Mobile, LLC (Fraser v. Mint Mobile, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Franklin v. Gwinnett County Public Schools
503 U.S. 60 (Supreme Court, 1992)
Watters v. Wachovia Bank, N. A.
550 U.S. 1 (Supreme Court, 2007)
Whittlestone, Inc. v. Handi-Craft Co.
618 F.3d 970 (Ninth Circuit, 2010)
Retired Employees Ass'n of Orange County, Inc. v. County of Orange
266 P.3d 287 (California Supreme Court, 2011)
Chanda v. Federal Home Loans Corp.
215 Cal. App. 4th 746 (California Court of Appeal, 2013)
White v. Ultramar, Inc.
981 P.2d 944 (California Supreme Court, 1999)
Potter v. Firestone Tire & Rubber Co.
863 P.2d 795 (California Supreme Court, 1993)
Corales v. Bennett
567 F.3d 554 (Ninth Circuit, 2009)
J'Aire Corp. v. Gregory
598 P.2d 60 (California Supreme Court, 1979)
Applied Equipment Corp. v. Litton Saudi Arabia Ltd.
869 P.2d 454 (California Supreme Court, 1994)
Seely v. White Motor Co.
403 P.2d 145 (California Supreme Court, 1965)
LVRC HOLDINGS LCC v. Brekka
581 F.3d 1127 (Ninth Circuit, 2009)
Bigbee v. Pacific Telephone & Telegraph Co.
665 P.2d 947 (California Supreme Court, 1983)
Martinez v. Pacific Bell
225 Cal. App. 3d 1557 (California Court of Appeal, 1990)
Careau & Co. v. Security Pacific Business Credit, Inc.
222 Cal. App. 3d 1371 (California Court of Appeal, 1990)
Hae Won Lee v. Bank of America
218 Cal. App. 3d 914 (California Court of Appeal, 1990)
SHERSHER v. Superior Court
65 Cal. Rptr. 3d 634 (California Court of Appeal, 2007)
Tomaselli v. Transamerica Insurance
25 Cal. App. 4th 1269 (California Court of Appeal, 1994)