In re Equifax, Inc.

362 F. Supp. 3d 1295
District Court, N.D. Georgia·Decided January 28, 2019·No. MDL DOCKET NO. 2800; 1:17-md-2800-TWT·Published·Cited by 44 cases

Opinion

THOMAS W. THRASH, JR., United States District Judge

This is a data breach case. It is before the Court on the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425]. For the reasons set forth below, the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425] is GRANTED in part and DENIED in part.

I. Background

On September 7, 2017, the Defendant Equifax Inc. announced that it was the subject of one of the largest data breaches in history.1 From mid-May through the end of July 2017, hackers stole the personal and financial information of nearly 150 million Americans.2 During this time period, Equifax failed to detect the hackers' presence in its systems, allowing the hackers to exfiltrate massive amounts of sensitive personal data that was in the company's custody.3 This data breach ("Data Breach") is unprecedented - it affected almost half of the entire American population.4 The Data Breach was also severe in terms of the type of information that the hackers were able to obtain. The hackers stole at least 146.6 million names, 146.6 million dates of birth, 145.5 million Social Security numbers, 99 million addresses, 17.6 million driver's license numbers, 209,000 credit card numbers, and 97,500 tax identification numbers.5 This is extremely sensitive personal information. Using this information, identity thieves can create fake identities, fraudulently obtain loans and tax refunds, and destroy a consumer's credit-worthiness.6

Equifax Inc. is a Georgia corporation with its principal place of business in Atlanta, *1309Georgia.7 Equifax is the parent company of the Defendants Equifax Information Services LLC and Equifax Consumer Services LLC.8 Both of those subsidiary companies are Georgia limited liability companies, with their principal places of business in Atlanta, Georgia.9 The Defendants operate together as an integrated consumer reporting agency.10 The Plaintiffs are 96 consumers who allege that they have been injured by the Data Breach. They allege that they are suffering a "present, immediate, imminent, and continuing increased risk of harm" due to the compromise of their personally identifiable information in the Data Breach.11 The Plaintiffs seek to represent a class of those similarly situated consumers in the United States who were injured by the Data Breach.12

Equifax's business model entails aggregating data relating to consumers from various sources, compiling that data into credit reports, and selling those reports to lenders, financial companies, employers, and others.13 Credit reporting agencies are "linchpins" of the nation's financial system due to the importance of credit reports in decisions to extend credit.14 Equifax also sells this information directly to consumers, allowing consumers to purchase their credit files and credit scores.15 In recent years, Equifax has worked to rapidly grow its business. Recognizing the value in obtaining massive troves of consumer data, Equifax has aggressively acquired companies with the goal of expanding into new markets and acquiring new sources of data.16 Equifax now maintains information on over 820 million individuals and 91 million businesses worldwide.17

Equifax recognized the importance of data security, and the value of the data in its custody to cybercriminals. Equifax observed other major, well-publicized data breaches, including those at Target, Home Depot, Anthem, and its competitor Experian.18 Equifax held itself out as a leader in confronting such threats, offering "data breach solutions" to businesses.19 It also acquired two identity theft protection companies, Trusted ID and ID Watchdog.20 Equifax was also the subject of several prior data breaches. From 2010 on, Equifax suffered several different data breach incidents highlighting deficiencies in its cybersecurity protocol.21 Given these prior breaches, cybersecurity experts concluded that Equifax was susceptible to a major data breach.22 Analyses of Equifax's cybersecurity demonstrated that it lacked basic maintenance techniques that are *1310highly relevant to potential data breaches.23 However, despite these risks, Equifax did little to improve its cybersecurity practices. Equifax's leaders afforded low priority to cybersecurity, spending a small fraction of the company's budget on cybersecurity.24

Free access — add to your briefcase to read the full text and ask questions with AI

In re Equifax, Inc., 362 F. Supp. 3d 1295 (N.D. Ga. 2019).

362 F. Supp. 3d 1295 (In re Equifax, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related