IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF VIRGINIA Alexandria Division
) ) In re Drivestream, Inc. ) Data Breach Litigation ) Civil Action No. 1:26-cv-00713 (AJT/LRV) ) ) ) ) )
MEMORANDUM OPINION AND ORDER
Before the Court is a Motion to Dismiss by Defendant Drivestream Inc. (“Drivestream” or “Defendant”) [Doc. No. 15] (the “Motion”), in which it moves to dismiss the Amended Complaint under Rule 12(b)(1) for lack of Article III standing, and under Rule 12(b)(6) for failure to state a claim. The Court held a hearing on the Motion on August 5, 2026, following which it took it under advisement. Upon consideration of the Motion, the memoranda in support thereof, [Doc. Nos. 16, 32] and in opposition thereto, [Doc. No. 25], and for the reasons stated below, the Motion is GRANTED under Rule 12(b)(1) for lack of jurisdiction.1 I. BACKGROUND Shayla O’Connor and Charline Bess (“Plaintiffs”) bring this putative class action Complaint against Drivestream for its alleged failure to protect their highly sensitive personal identifiable information (“PII”) and protected health information (“PHI”). The Amended Complaint asserts seven causes of action: (1) negligence; (2) negligence per se; (3) breach of implied contract; (4) invasion of privacy; (5) unjust enrichment; (6) breach of fiduciary duty; and
1 Because the Court grants Drivestream’s 12(b)(1) jurisdictional motion to dismiss, it need not address the merits of its Rule 12(b)(6) motion to dismiss for failure to state a claim. (7) requests a declaratory judgment. [Doc. No. 14]. The Amended Complaint alleges the following facts: Drivestream is a consulting firm that provides Oracle cloud consulting services. Id. ¶ 2. As part of its business, Drivestream receives and maintains employee data, including PII and PHI,
from its customers. Id. ¶ 15. Drivestream’s customers in this case were Saint Mary’s College, Indiana (the former employer of Plaintiff Shayla O’Connor) and Virginia Wesleyan University (the employer of Plaintiff Charlene Bess). Id. ¶¶ 41, 59. On or around December 9, 2024, Drivestream discovered suspicious activity within its data center and later determined that between December 4 and December 9, 2024, unauthorized actors accessed its files, which contained Plaintiffs’ and Class Members’ PII/PHI, and downloaded some of those files. Id. ¶¶ 19–23. On January 7, 2025, Akira, a cybercriminal group on which the FBI has issued public warnings, posted on the dark web that “Drivestream is a management and IT consulting firm specializing in migrating the enterprise business processes of large and medium sized businesses
to the Cloud,” and that Akira is “ready to upload more than 80 GB of private corporate documents including: SSNs, family contacts, contact numbers and e-mail addresses of employees and customers, driver licenses, passports etc.” Id. ¶¶ 35–37. On January 15, 2026 and February 27, 2026, Plaintiffs O’Connor and Bess received their respective notices from Drivestream, in a letter stating that an unauthorized actor accessed its systems between December 4–9, 2024, and downloaded certain files. [Doc. Nos. 14-1, 14-2]. The letter noted that the following types of information related to Plaintiffs have been impacted by this incident: date of birth, Social Security number, financial account information, and health insurance information, but there was “no indication that [Plaintiffs’] information was subject to actual or attempted misuse as a result of this incident.” Id. The letter provided Plaintiffs “12 months of complimentary access to credit monitoring and identity protection services.” Id. Plaintiffs allege “on information and belief” that “Akira published the PII/PHI of Plaintiffs and Class Members on the dark web on or after January 7, 2025,” and “sold the PII/PHI of
Plaintiffs and Class Members to other cybercriminals through the dark web on or after January 7, 2025.” [Doc. No. 14] ¶¶ 38–39. Based on that allegation, Plaintiffs allege injuries stemming from Defendant’s alleged failure to maintain adequate cybersecurity safeguards, including spending time monitoring financial accounts, reviewing credit reports, and undertaking protective measures to mitigate the consequences of the data breach, and experiencing increased spam and scam communications causing them to suffer stress, anxiety, and concern regarding the misuse of their compromised PII/PHI. Id. ¶¶ 50–53; 69–72. Plaintiffs further allege that they suffered loss of privacy, loss of control over their PII/PHI, diminution in the value of their PII/PHI, and a substantial and ongoing risk of identity theft and fraud. Id. ¶¶ 48–58, 67–77, 149–150. Plaintiffs seek monetary damages, and declaratory and injunctive relief. Id. at 46.
II. LEGAL STANDARD A motion to dismiss pursuant to Fed. R. Civ. P. 12(b)(1) challenges a court’s jurisdiction over the subject matter of the suit. The motion may attack the court’s subject matter jurisdiction either as a facial challenge by arguing that the “complaint simply fails to allege facts upon which subject matter jurisdiction can be based,” or as a factual challenge by arguing “that the jurisdictional allegations of the complaint are not true.” Kerns v. United States, 585 F.3d 187, 192 (4th Cir. 2009). Where, as here, a defendant makes a challenge to the face of the complaint, the question is whether “the complaint fails to allege facts upon which the court can base jurisdiction.” Kuntze v. Josh Enterprises, Inc., 365 F. Supp. 3d 630, 635–36 (E.D. Va. 2019). Under that standard, a court is “required to accept all of the complaint’s factual allegations as true.” Id. III. DISCUSSION Drivestream moves to dismiss the Amended Complaint on the grounds that it fails to allege
any concrete injuries that are fairly traceable to Drivestream’s data breach, and therefore Plaintiffs cannot establish the Article III standing necessary for the Court to exercise jurisdiction over their claims. [Doc. No. 16]. Article III of the Constitution “limits the jurisdiction of federal courts to ‘Cases’ and ‘Controversies,’” U.S. Const. art. III, § 2, cl. 1, which requires plaintiffs to have a “personal stake”—known as “standing”—in the suit they bring. TransUnion LLC v. Ramirez, 594 U.S. 413, 423 (2021). To demonstrate standing, a plaintiff must sufficiently allege three elements: (1) they suffered an injury-in-fact that was concrete and particularized and either actual or imminent; (2) there was a causal connection between the injury and the defendant’s conduct (i.e. traceability); and (3) the injury was likely to be redressable by a favorable judicial decision. Lujan v. Defs. of
Free access — add to your briefcase to read the full text and ask questions with AI
IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF VIRGINIA Alexandria Division
) ) In re Drivestream, Inc. ) Data Breach Litigation ) Civil Action No. 1:26-cv-00713 (AJT/LRV) ) ) ) ) )
MEMORANDUM OPINION AND ORDER
Before the Court is a Motion to Dismiss by Defendant Drivestream Inc. (“Drivestream” or “Defendant”) [Doc. No. 15] (the “Motion”), in which it moves to dismiss the Amended Complaint under Rule 12(b)(1) for lack of Article III standing, and under Rule 12(b)(6) for failure to state a claim. The Court held a hearing on the Motion on August 5, 2026, following which it took it under advisement. Upon consideration of the Motion, the memoranda in support thereof, [Doc. Nos. 16, 32] and in opposition thereto, [Doc. No. 25], and for the reasons stated below, the Motion is GRANTED under Rule 12(b)(1) for lack of jurisdiction.1 I. BACKGROUND Shayla O’Connor and Charline Bess (“Plaintiffs”) bring this putative class action Complaint against Drivestream for its alleged failure to protect their highly sensitive personal identifiable information (“PII”) and protected health information (“PHI”). The Amended Complaint asserts seven causes of action: (1) negligence; (2) negligence per se; (3) breach of implied contract; (4) invasion of privacy; (5) unjust enrichment; (6) breach of fiduciary duty; and
1 Because the Court grants Drivestream’s 12(b)(1) jurisdictional motion to dismiss, it need not address the merits of its Rule 12(b)(6) motion to dismiss for failure to state a claim. (7) requests a declaratory judgment. [Doc. No. 14]. The Amended Complaint alleges the following facts: Drivestream is a consulting firm that provides Oracle cloud consulting services. Id. ¶ 2. As part of its business, Drivestream receives and maintains employee data, including PII and PHI,
from its customers. Id. ¶ 15. Drivestream’s customers in this case were Saint Mary’s College, Indiana (the former employer of Plaintiff Shayla O’Connor) and Virginia Wesleyan University (the employer of Plaintiff Charlene Bess). Id. ¶¶ 41, 59. On or around December 9, 2024, Drivestream discovered suspicious activity within its data center and later determined that between December 4 and December 9, 2024, unauthorized actors accessed its files, which contained Plaintiffs’ and Class Members’ PII/PHI, and downloaded some of those files. Id. ¶¶ 19–23. On January 7, 2025, Akira, a cybercriminal group on which the FBI has issued public warnings, posted on the dark web that “Drivestream is a management and IT consulting firm specializing in migrating the enterprise business processes of large and medium sized businesses
to the Cloud,” and that Akira is “ready to upload more than 80 GB of private corporate documents including: SSNs, family contacts, contact numbers and e-mail addresses of employees and customers, driver licenses, passports etc.” Id. ¶¶ 35–37. On January 15, 2026 and February 27, 2026, Plaintiffs O’Connor and Bess received their respective notices from Drivestream, in a letter stating that an unauthorized actor accessed its systems between December 4–9, 2024, and downloaded certain files. [Doc. Nos. 14-1, 14-2]. The letter noted that the following types of information related to Plaintiffs have been impacted by this incident: date of birth, Social Security number, financial account information, and health insurance information, but there was “no indication that [Plaintiffs’] information was subject to actual or attempted misuse as a result of this incident.” Id. The letter provided Plaintiffs “12 months of complimentary access to credit monitoring and identity protection services.” Id. Plaintiffs allege “on information and belief” that “Akira published the PII/PHI of Plaintiffs and Class Members on the dark web on or after January 7, 2025,” and “sold the PII/PHI of
Plaintiffs and Class Members to other cybercriminals through the dark web on or after January 7, 2025.” [Doc. No. 14] ¶¶ 38–39. Based on that allegation, Plaintiffs allege injuries stemming from Defendant’s alleged failure to maintain adequate cybersecurity safeguards, including spending time monitoring financial accounts, reviewing credit reports, and undertaking protective measures to mitigate the consequences of the data breach, and experiencing increased spam and scam communications causing them to suffer stress, anxiety, and concern regarding the misuse of their compromised PII/PHI. Id. ¶¶ 50–53; 69–72. Plaintiffs further allege that they suffered loss of privacy, loss of control over their PII/PHI, diminution in the value of their PII/PHI, and a substantial and ongoing risk of identity theft and fraud. Id. ¶¶ 48–58, 67–77, 149–150. Plaintiffs seek monetary damages, and declaratory and injunctive relief. Id. at 46.
II. LEGAL STANDARD A motion to dismiss pursuant to Fed. R. Civ. P. 12(b)(1) challenges a court’s jurisdiction over the subject matter of the suit. The motion may attack the court’s subject matter jurisdiction either as a facial challenge by arguing that the “complaint simply fails to allege facts upon which subject matter jurisdiction can be based,” or as a factual challenge by arguing “that the jurisdictional allegations of the complaint are not true.” Kerns v. United States, 585 F.3d 187, 192 (4th Cir. 2009). Where, as here, a defendant makes a challenge to the face of the complaint, the question is whether “the complaint fails to allege facts upon which the court can base jurisdiction.” Kuntze v. Josh Enterprises, Inc., 365 F. Supp. 3d 630, 635–36 (E.D. Va. 2019). Under that standard, a court is “required to accept all of the complaint’s factual allegations as true.” Id. III. DISCUSSION Drivestream moves to dismiss the Amended Complaint on the grounds that it fails to allege
any concrete injuries that are fairly traceable to Drivestream’s data breach, and therefore Plaintiffs cannot establish the Article III standing necessary for the Court to exercise jurisdiction over their claims. [Doc. No. 16]. Article III of the Constitution “limits the jurisdiction of federal courts to ‘Cases’ and ‘Controversies,’” U.S. Const. art. III, § 2, cl. 1, which requires plaintiffs to have a “personal stake”—known as “standing”—in the suit they bring. TransUnion LLC v. Ramirez, 594 U.S. 413, 423 (2021). To demonstrate standing, a plaintiff must sufficiently allege three elements: (1) they suffered an injury-in-fact that was concrete and particularized and either actual or imminent; (2) there was a causal connection between the injury and the defendant’s conduct (i.e. traceability); and (3) the injury was likely to be redressable by a favorable judicial decision. Lujan v. Defs. of
Wildlife, 504 U.S. 555, 560–61 (1992). In a class action, the Court analyzes standing based on the allegations of personal injury made by the named plaintiffs. See Doe v. Obama, 631 F.3d 157, 160 (4th Cir. 2011). In the Fourth Circuit, three decisions clarify the contours of Article III standing in data breach cases. In Beck v. McDonald, the Fourth Circuit addressed incidents where a laptop and boxes—containing personal information concerning patients, including partial social security numbers, names, dates of birth, and physical descriptions—had been stolen. 848 F.3d 262, 267– 268 (4th Cir. 2017). However, the missing data was never misused, and there was no evidence that a thief intentionally targeted the personal information on the laptops or even accessed it. Id. at 274. As a result, the Fourth Circuit affirmed the district court’s dismissal of one category of plaintiffs on the pleadings, finding that they lacked standing because allegations of an enhanced risk of future identity theft were “too speculative” without evidence of misuse. Id. Accepting as true the allegations that the laptop and pathology reports had been stolen, the court reasoned that the data
breaches had occurred three to four years before and there was no allegation that the information contained on the stolen laptop had been accessed or misused or that the plaintiffs suffered identity theft, or that the thief even stole the laptop with the intent to steal the plaintiffs private information. Id. at 275. For these reasons, the Fourth Circuit reasoned that for the Plaintiffs to suffer the harm of identity theft that they feared, the chain of possibilities was too “attenuated” to confer standing. Nor were Plaintiffs’ allegations sufficient to establish a “substantial risk” of harm. Id. In Hutton v. Nat’l Bd. of Exam’rs in Optometry, Inc., the Fourth Circuit reached the opposite result, clarifying Beck’s holding and providing further guidance for data breach actions. 892 F.3d 613, 621–22 (4th Cir. 2018). In contrast to the plaintiffs in Beck, the Hutton complaint alleged that they had already suffered actual harm in the form of identity theft and credit card
fraud. For these reasons, the Fourth Court held that the plaintiffs had been concretely injured by the data breach because the fraudsters used—and attempted to use—the Plaintiffs’ personal information to open credit card accounts without their knowledge or approval. Id. And most recently, in Holmes v. Elephant Insurance Company, the Fourth Circuit held “that the public disclosure of private information tort makes concrete the intangible harm suffered when information that the plaintiff would justifiably prefer to tightly control is released into the open.” Holmes v. Elephant Ins. Co., 156 F.4th 413, 425 (4th Cir. 2025), cert. dismissed, No. (R46- 15 / OT 2025), 2026 WL 1729979 (U.S. May 22, 2026). Nevertheless, while finding one’s private information on the dark web is a cognizable injury since it is analogous to the common law tort of public disclosure of private information, the Fourth Circuit held that any claim alleging future misuse of that data is not cognizable as an injury absent an allegation that the data had been obtained and misused by hackers. Id. at 428–29. In that respect, the Fourth Circuit held that plaintiffs’ claim that further future misuse was imminent was too speculative because even though
the plaintiffs found their driver’s license numbers listed on the dark web, thereby alleging a cognizable injury that their private information had been disclosed, they had not alleged that their driver’s license numbers had been misused by the hackers, and any future harm would come from the intervening actions of independent malicious actors. Id. at 430. The Fourth Court further reasoned that the plaintiffs’ alleged injuries rested on a “speculative chain of possibilities” because “no particular piece of personal information is guaranteed to be seen or sold” and there was the further link in the chain that even if the bad actor obtained the hacked driver’s license numbers, the hackers would need to aggregate that information with other data in order to impersonate them. Id. at 431. In sum, plaintiffs’ alleged injuries would take place “only if other intervening malicious actors acquire[d] their driver’s license numbers from the dark web and also acquire[d] other pieces
of their personal information and [did] so before their driver’s license numbers change[d],” and therefore fell “far short of establishing a ‘substantial risk’ of harm.” Id. (emphasis in original). Plaintiffs Beck and O’Connor assert Article III standing on the grounds that the data breach of Drivestream’s network inflicted six injuries-in-fact: (1) the public disclosure of private facts; (2) targeted scam messages and phone calls; (3) the “increased risk” of future misuse of their personal information by other malicious actors; (4) the lost time and effort spent trying to mitigate the fallout of the data breach; (5) the emotional distress and time spent monitoring their financial records to mitigate the likelihood of future harm; and (6) the lost benefit of the bargain. [Doc. No. 25] at 7–17. The Court addresses each alleged injury below. (1) Public Disclosure of Private Facts Plaintiffs’ claim that they have suffered a concrete privacy injury is based on their allegation that their PII/PHI was published and sold on the dark web. [Doc. No. 25] at 9–11. The sole support for that claim is an allegation that “[o]n information and belief, Akira published the
PII/PHI of Plaintiffs and Class Members on the dark web on or after January 7, 2025,” which, in turn, appears to be based on the letters they received from Drivestream, stating that an unauthorized actor accessed its systems that contained Plaintiffs’ information, and Akira’s post on the dark web that it was “ready to upload more than 80 GB of private corporate documents [obtained from Drivestream] including: SSNs, family contacts, contact numbers and e-mail addresses of employees and customers, driver licenses, passports etc.” [Doc. No. 14] ¶¶ 19–20, 34–40. But the relied upon letter from Drivestream states that there was “no indication that [Plaintiffs’] information was subject to actual or attempted misuse as a result of this incident[],” [Doc. Nos. 14-1; 14-2]; and the Amended Complaint contains no allegation that Plaintiffs in fact located their private information on the dark web despite the Amended Complaint’s reference to a unique site
on the dark web maintained by Akira which “name[s] victims and post[s] sample data to prove the validity of the breach.” [Doc. No. 14] ¶ 36. Plaintiffs also do not allege finding their data on this repository, or anywhere else. Nevertheless, they argue that they are not required “to plumb the dark web’s depths to find their data before they can establish standing,” [Doc. No. 25] at 10. The Fourth Circuit made clear in Holmes that for the public disclosure of private information to constitute a concrete injury to confer standing, the plaintiffs must plausibly allege that their private information is “generally accessible.” Holmes, 156 F.4th at 425. In Holmes, the Fourth Circuit declined to find a concrete injury-in-fact for two of the named plaintiffs who, unlike the other plaintiffs who had alleged actually finding their driver’s license numbers listed on the dark web, had “not provide[d] any reason to think that their driver’s license numbers [were] now generally accessible, and therefore the harm allegedly suffered by those two plaintiffs “does not bear a close relationship to the harm addressed by the public-disclosure tort.” Id. The Plaintiffs’ allegation “on information and belief” that their PII/PHI has been posted on the dark web, without
more, does not plausibly allege a concrete injury sufficient to establish standing. (2) Increase in Spam Text Messages and Phone Calls Plaintiffs next argue that the alleged increase in spam text messages and phone calls that they experienced is a concrete injury. [Doc. No. 25] at 11. The Fourth Circuit has recognized that receiving unsolicited mail, which closely parallels the tort of loss of privacy, is a cognizable injury to confer standing. Garey v. James S. Farrin, P.C., 35 F.4th 917, 922 (4th Cir. 2022). But while the alleged increase in spam text messages and phone calls can similarly invade an individual’s privacy to constitute an injury-in-fact, Plaintiffs have not pleaded any facts that plausibly connect this alleged increase to Drivestream. See Lujan, 504 U.S. at 560–61. Indeed, the letters Plaintiffs received from Drivestream following the data breach, attached to the Complaint, do not mention
phone numbers among the categories of information that may have been impacted by the data breach, See [Doc. Nos. 14-1; 14-2] (“Our investigation determined that the following type of information . . . may have been impacted by this incident: date of birth, Social Security number, financial account information, and health insurance information, in combination with your name.”). Confronting this precise scenario in Holmes, where the plaintiffs had not alleged that the compromised information in the data breach included cell phone numbers, the Fourth Circuit affirmed the district court’s determination that the plaintiff had failed to adequately allege traceability for his alleged injury that he experienced an uptick in spam texts and calls to his phone. Holmes, 156 F.4th at 420 n.3.2 (3) Future Injury Plaintiffs also argue that they “face a substantial risk of future injury stemming from the
Data Breach, and that risk establishes a concrete injury-in-fact” to support Article III standing. [Doc. No. 25] at 12. In support of this claim, Plaintiffs point to their allegation that “Akira is an especially notorious cybercriminal group” on which the FBI released a joint report warning the public about Akira’s nefarious practices, which includes maintaining “a dark web leaks blog where they name victims and post sample data to prove the validity of the breach,” and often “publish[ing] the data on their site which other criminals can use to exploit.” [Doc. No. 14] ¶¶ 34– 36. But while the Fourth Circuit has recognized that a future risk of injury can provide an injury in fact to support standing if there is a “substantial risk” of future harm, see Beck v. McDonald, 848 F.3d at 430, it has also made clear that Plaintiffs must plausibly allege that future misuse of that data is imminent. See Holmes, 156 F.4th at 428–29 (absent allegations that hackers actually
obtained information from the dark web, any future harm is “speculative” and cannot supply the injury-in-fact needed for Article III standing). Here, the Amended Complaint contains no allegation that Plaintiffs’ data was ever obtained by Akira or any other hacker, let alone misused by malicious actors in the one-and-a-half years since the data breach took place. In sum, any future injury to Plaintiffs requires the Court to take several inferential leaps: (1) Plaintiffs’ specific PII/PHI was actually downloaded by Akira; (2) Akira’s announcement on the dark web reliably indicated its intent to leak and sell data to hackers;
2 Further undercutting the adequacy of Plaintiffs’ standing based on an “increase” in spam texts and phone calls is the lack of information concerning how the post-data breach level of spam texts and phone calls compared to the pre-breach level of spam texts and phone calls Plaintiffs had been receiving. (3) Plaintiffs’ specific PII/PHI was among the data actually published by Akira; (4) that data was sold to a hacker; and (5) a hacker actually used that information to impersonate Plaintiffs. The Fourth Circuit on a similar fact pattern found this precise chain of possibilities too “speculative” to confer standing for the alleged injury of future misuse of data, reiterating the rule that “plaintiffs
cannot just assert that all this might happen; they must allege facts allowing us to conclude that for some particular plaintiff, the combined probability of that speculative chain materializing surpasses at least 33%.” Id. at 430–32 (emphasis in original) (“To be sure, hackers list personal information on the dark web in the hope that someone will buy it. But no particular piece of personal information is guaranteed to be seen or sold, just as no particular item on Craigslist or eBay is guaranteed to be seen or sold.”); see also Beck, 848 F.3d at 267, 275 (“[T]he mere theft of [] items, without more, cannot confer Article III standing.”). For these reasons, Plaintiffs have not plausibly alleged that they are at risk of an imminent injury. (4) Lost Time and Effort and Emotional Distress Plaintiffs contend that their lost time and effort in mitigating the data breach consequences,
and the associated emotional distress, confer standing. [Doc. No. 25] at 14–17. But these alleged injuries rise and fall on whether the data breach itself is a sufficiently concrete injury since the Fourth Circuit has held that the “lack of imminent injury prevents the plaintiffs from bootstrapping their way into standing for damages solely by expending time or alleging emotional distress.” Holmes, 156 F.4th at 428 (“We hold that if time spent and emotional distress felt are concrete injuries, they may serve as the sole basis for standing to recover damages only when incurred in response to a separate imminent harm. They do not suffice for standing on their own.”) (emphasis in original); Hutton, 892 F.3d at 622 (noting that costs incurred to mitigate or avoid future harm confer standing only when a substantial risk of harm exists). In sum, absent a separate concrete and imminent injury, neither the lost time and effort nor the emotional distress that Plaintiffs have allegedly experienced as a result of the data breach can confer standing on their own. (5) Lost Benefit of the Bargain Finally, Plaintiffs contend that they have plausibly alleged the breach of an implied contract
to protect Plaintiffs’ PII/PHI, and therefore can establish an injury through their “lost benefit of the bargain.” [Doc. No. 25] at 16–17. As an initial matter, Plaintiffs do not cite, and the Court is not aware of any, Fourth Circuit authority on whether a plaintiff can establish standing in the data breach context based on the lost benefit of the bargain. However, this Court previously considered, and rejected, a similar theory of standing in Podroykin v. Am. Armed Forces Mut. Aid Ass’n, making clear that a benefit-of-the-bargain theory should be rejected “where plaintiffs have not alleged that the value of the goods and services they purchased was diminished as a result of the data breach.” 634 F. Supp. 3d 265, 272 (E.D. Va. 2022) (quoting Chambliss v. Carefirst, Inc., 189 F. Supp. 3d 564, 572 (D. Md. 2016)). The Court “rejected the proposition that an individual’s personal identifying information has an independent monetary value,” and further noted that “even
courts that are willing to consider diminution in the value of PII as a basis for standing” only “do so when there are allegations of some concrete injury.” Id. (holding that plaintiff had failed to establish that his PII had been misused, let alone that the value of his PII had been diminished). Likewise, here, Plaintiffs do not allege any diminution in the value in their PHI/PII to confer standing under their lost benefit of the bargain theory. See In re Cap. One Consumer Data Sec. Breach Litig., 488 F.Supp. 3d 374, 403 (E.D. Va. 2020) (“Even assuming that Plaintiffs’ PII has monetary value, Plaintiffs do not allege any facts explaining how their PII became less valuable as a result of the breach.”) (emphasis in original). Accordingly, Plaintiffs cannot establish a concrete injury based on their alleged lost benefit of the bargain. Stripped to their substance, Plaintiffs’ claims are based on essentially nothing more than the fact of a data breach into a system that contained their personal identifying information. As the Fourth Circuit and other courts have made clear, that fact alone is insufficient to establish Article III standing. For the above reasons, Plaintiffs lack standing as to all Counts in the Amended Complaint, and the Court must dismiss the Amended Complaint for lack of jurisdiction. IV. CONCLUSION For the above reasons, it is hereby ORDERED that the Motion to Dismiss be, and the same hereby is, GRANTED pursuant to Fed. R. Civ. P 12(b)(1) for lack of subject matter jurisdiction; and is otherwise DENIED as moot; and the Amended Complaint is DISMISSED. The Clerk is directed to enter judgment in Defendant’s favor pursuant to Fed. R. Civ. P. 58, forward copies of this Order to counsel of record, and close this civil action.
Alexandria, Virginia Sy August 21, 2026 Antho renga United/Siptes District Judge