Gerber v. Twitter, Inc.

District Court, N.D. California·Decided March 29, 2024·No. 4:23-cv-00186·Unknown

Opinion

STEPHEN GERBER, et al., Case No. 4:23-cv-00186-KAW

Plaintiffs, ORDER GRANTING IN PART AND DENYING IN PART MOTION TO v. DISMISS CONSOLIDATED AMENDED CLASS ACTION COMPLAINT TWITTER, INC., et al., Re: Dkt. No. 40 Defendants.

On June 6, 2023, Defendant X Corp., as successor in interest to Twitter, Inc. (collectively “Twitter”), filed a motion to dismiss Plaintiffs’ consolidated class action complaint. On February 15, 2023, the Court held a hearing, and, after considering the legal arguments made, GRANTS IN PART AND DENIES IN PART Defendant’s motion to dismiss. Twitter is a social media platform where users can post and engage with short-form commentary, called “Tweets,” which may include text, images, or video. (Consolidated Class Action Compl., “CCAC,” Dkt. No. 36 ¶¶ 2, 28-30.) Each user must create a username and display name, which are displayed publicly and associate the user with their activity on the Twitter platform. (CCAC ¶ 32.) Twitter invites users to operate on its platform by using pseudonymous user and display names, thereby allowing users to share and access information and engage freely and anonymously. (CCAC ¶¶ 41-44.) While Twitter does not charge its users, it realizes billions of dollars in annual revenues from the highly valuable data generated by its users. (CCAC ¶ 31.) In order to sign up for an account on the Twitter platform, a prospective user is required to: (1) enter into a User Agreement, and (2) provide certain personal information, including name, Agreement, includes the Terms of Service (“TOS”), the Privacy Policy, the Twitter Rules and Policies, and all incorporated policies. (See CCAC ¶¶ 33-35.) As a result, prior to accessing the Twitter platform and using Twitter’s services, Plaintiffs entered into the User Agreement with Twitter, including the Privacy Policy, and provided Twitter with their PII, as requested by Twitter and subject to Twitter’s representations set forth in the Privacy Policy. (CCAC ¶¶ 97, 118-34.) The Privacy Policy states in detail how user data, including PII, will be used and who will have access to that data. (CCAC ¶¶ 37-39, 122-26.) From around June 2021 through January 2022, a defect in Twitter’s application programming interface (“API”) allowed threat actors to access and obtain PII associated with an estimated 200 million Twitter users. (CCAC ¶¶ 6, 19, 23, 26, 39, 46, 60.) It is unclear from publicly available information whether the person(s) that took advantage of the API vulnerability were external threat actors or had internal access at Twitter. (CCAC ¶¶ 46, 75(b), 75(g), 80, 83, 93, 97.) The information extracted through the API defect consists of information associated with users’ Twitter account (username, display name, and account creation data), together with the users’ PII (email address and phone number). (CCAC ¶ 46.) This data was offered for sale, on more than one occasion, and/or leaked on the dark web between August 2022 and January 2023. Id. Plaintiffs contend that the Data Breach does not represent an isolated incident, but, rather, was the foreseeable result of the reckless way that Twitter has chosen to operate its business. As early as 2010, Twitter came under scrutiny from the Federal Trade Commission (“FTC”) for its data privacy failures, resulting in the entry of a 2011 consent order (the “FTC Order”), which Twitter has continued to violate (despite being subject to it for over a decade), including with respect to the Data Breach. (CCAC ¶¶ 7, 83-90.) Recently, Twitter’s former Head of Security, Peiter Zatko, filed a whistleblower complaint and testified before Congress regarding the dangerous and pervasive lack of both internal and external data security at Twitter. (CCAC ¶¶ 73- 77.) Zatko provided comprehensive reports to the Twitter Board of Directors and executives regarding his data security concerns, but Twitter allegedly failed and refused to implement even giving rise to the Data Breach occurred. (CCAC ¶¶ 46, 73.) Plaintiffs allege that had they known that Twitter failed to implement reasonable and adequate data security measures, they would not have created Twitter accounts or would not have provided their PII that was disclosed in the Data Breach to Twitter. (CCAC ¶¶ 19, 23, 26.) Plaintiff Weitzman alleges that she has spent time monitoring her various accounts to detect and prevent any misuses of her PII, which she would not have had to expend if not for the Data Breach. (CACC ¶ 26.) Plaintiffs further contend that the Data Breach has also caused specific and unique harm to Twitter’s impacted users that accepted its invitation to operate on its platform anonymously through the use of pseudonyms, such as Plaintiffs Gerber and Cohen, as the data available as a result enables any person with access to it to readily ascertain the identity of the person associated with a pseudonymous Twitter account and their related activity on the platform. (CCAC ¶¶ 49, 65, 104.) On April 20, 2023, Plaintiffs filed the consolidated class action complaint alleging eight causes of action for breach of contract, negligence, negligence per se, gross negligence, unjust enrichment, violation of California Unfair Competition Law (Cal. Bus. & Prof. Code § 17200), violation of the California Consumers Legal Remedies Act (Cal. Civil Code § 1750), and declaratory judgment. On June 6, 2023, Defendant filed a motion to dismiss. (Def.’s Mot., Dkt. No. 40.) On July 20, 2023, Plaintiffs filed an opposition. (Pls.’ Opp’n, Dkt. No. 45.) On September 8, 2023, Defendant filed a reply. (Def.’s Reply, Dkt. No. 55.) A. Motion to Dismiss Under Federal Rule of Civil Procedure 12(b)(6), a party may file a motion to dismiss based on the failure to state a claim upon which relief may be granted. A motion to dismiss under Rule 12(b)(6) tests the legal sufficiency of the claims asserted in the complaint. Navarro v. Block, 250 F.3d 729, 732 (9th Cir. 2001). In considering such a motion, a court must “accept as true all of the factual allegations contained in the complaint,” Erickson v. Pardus, 551 U.S. 89, 94 (2007) (per curiam) (citation there is an absence of “sufficient factual matter to state a facially plausible claim to relief.” Shroyer v. New Cingular Wireless Servs., Inc., 622 F.3d 1035, 1041 (9th Cir. 2010) (citing Ashcroft v. Iqbal, 556 U.S. 662, 677-78 (2009); Navarro, 250 F.3d at 732) (internal quotation marks omitted). A claim is plausible on its face when a plaintiff “pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 556 U.S. at 678 (citation omitted). In other words, the facts alleged must demonstrate “more than labels and conclusions, and a formulaic recitation of the elements of a cause of action will not do.” Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007). “Threadbare recitals of the elements of a cause of action” and “conclusory statements” are inadequate. Iqbal, 556 U.S. at 678; see also Epstein v. Wash. Energy Co., 83 F.3d 1136, 1140 (9th Cir. 1996) (“[C]onclusory allegations of law and unwarranted inferences are insufficient to defeat a motion to dismiss for failure to state a claim.”). “The plausibility standard is not akin to a probability requirement, but it asks for more than a sheer possibility that a defendant has acted unlaw

Free access — add to your briefcase to read the full text and ask questions with AI

Gerber v. Twitter, Inc., (N.D. Cal. 2024).

Gerber v. Twitter, Inc. (Gerber v. Twitter, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Erickson v. Pardus
551 U.S. 89 (Supreme Court, 2007)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Shroyer v. New Cingular Wireless Services, Inc.
622 F.3d 1035 (Ninth Circuit, 2010)
United States v. Filemon Bernal-Obeso
989 F.2d 331 (Ninth Circuit, 1993)
Gary Davis v. Hsbc Bank Nevada, N.A.
691 F.3d 1152 (Ninth Circuit, 2012)
Tyrrell v. Taylor
394 F. Supp. 9 (E.D. Pennsylvania, 1975)
Merrill v. Navegar, Inc.
28 P.3d 116 (California Supreme Court, 2001)
Kwikset Corp. v. Superior Court
246 P.3d 877 (California Supreme Court, 2011)
Food Safety Net Services v. Eco Safe Systems USA, Inc.
209 Cal. App. 4th 1118 (California Court of Appeal, 2012)
Lopez v. Smith
203 F.3d 1122 (Ninth Circuit, 2000)
Lee v. City of Los Angeles
250 F.3d 668 (Ninth Circuit, 2001)
In re Yahoo! Inc. Customer Data Sec. Breach Litig.
313 F. Supp. 3d 1113 (N.D. California, 2018)
Whitney v. Brann
394 F. Supp. 1 (D. Delaware, 1975)