In re Equifax, Inc.

371 F. Supp. 3d 1150
District Court, N.D. Georgia·Decided January 28, 2019·No. MDL DOCKET NO. 2800; 1:17-md-2800-TWT·Published·Cited by 4 cases

Opinion

THOMAS W. THRASH, JR. United States District Judge

This is a data breach case. It is before the Court on the Defendants' Motion to Dismiss the Financial Institutions' Consolidated Amended Complaint [Doc. 435]. For the reasons set forth below, the Defendants' Motion to Dismiss the Financial Institutions' Consolidated Amended Complaint [Doc. 435] is GRANTED in part and DENIED in part.

I. Background

On September 7, 2017, the Defendant Equifax Inc. announced that it was the subject of one of the largest data breaches in history.1 From mid-May through the end of July 2017, hackers stole the personal information of nearly 150 million Americans (the "Data Breach").2 This personally identifiable information included names, Social Security numbers, birth dates, addresses, driver's license numbers, images of taxpayer ID cards and passports, photographs associated with government-issued identification, payment card information, and more.3 This Data Breach, according to the Plaintiffs, was the direct result of Equifax's disregard for cybersecurity.

Equifax is a Georgia corporation with its principal place of business in Atlanta, Georgia.4 The Defendant Equifax Information Services LLC is a wholly-owned subsidiary of Equifax with its principal place of business in Atlanta, Georgia.5 Equifax Information Services collects and reports consumer information to financial institutions, including the Plaintiffs.6 The Plaintiffs are financial institutions that provide a range of financial services.7 The Plaintiffs depend greatly on the services provided by Equifax and other credit reporting agencies, since the information they provide *1158is necessary to determine the credit-worthiness of their customers.8

According to the Plaintiffs, the Data Breach was the direct result of Equifax's refusal to take the necessary steps to protect the personally identifiable information in its custody. Equifax was warned on numerous occasions that its cybersecurity was dangerously deficient, and that it was vulnerable to data theft and security breaches.9 In fact, Equifax had suffered multiple security breaches in the past, showing that the Data Breach was not an isolated incident.10 However, despite these warnings, Equifax did not take the necessary steps to improve its data security or prepare for the known cybersecurity risks.11

On March 7, 2017, a vulnerability in the Apache Struts software, a popular open source software program, was discovered.12 Equifax used Apache Struts to run a dispute portal website.13 The same day that this vulnerability was announced, the Apache Foundation made available various patches to protect against this vulnerability.14 The Apache Foundation, along with the U.S. Department of Homeland Security, issued public warnings regarding the vulnerability and the need to implement these patches.15 Equifax received these warnings and disseminated them internally, but failed to implement the patch.16 Then, between May 13 and July 30, 2017, hackers exploited this vulnerability to enter Equifax's systems.17 These hackers were able to access multiple databases and exfiltrate sensitive personal information in Equifax's custody.18 In addition to obtaining this personal information, the hackers accessed 209,000 consumer credit card numbers.19 On July 29, 2017, Equifax discovered the Data Breach.20 Equifax's CEO, Richard Smith, was informed of the breach on July 31, 2017.21 On September 7, 2017, Equifax publicly announced that the Data Breach had occurred.22

The Plaintiffs allege that the Data Breach undermined the credit reporting and verification system by exposing this personally identifiable information.23 According to the Plaintiffs, they were harmed because the Data Breach had a significant impact on financial institutions, including the measures they use to authenticate their customers.24 The Plaintiffs were forced to expend resources to assess the impact of the Data Breach and their ability to authenticate customers and detect fraud.25 They have also expended resources establishing new monitoring methods for preventing fraud and will continue to incur costs to develop new modes of *1159preventing such activity.26 Twenty-three of the Plaintiffs also allege that they issued payment cards that were compromised in the Data Breach.27 The Plaintiffs assert claims for negligence, negligence per se, negligent misrepresentation, and claims under various state business practices statutes. The Defendants now move to dismiss.

A. Choice of Law

First, the Court concludes that Georgia law governs this case. This case is before the Court based on diversity jurisdiction. The Court therefore looks to Georgia's choice of law requirements to determine the appropriate rules of decision.28 Georgia follows the traditional approach of lex loci delecti in tort cases, which generally applies the substantive law of the state where the last event occurred necessary to make an actor liable for the alleged tort.29 Usually, this means that the "law of the place of the injury governs rather than the law of the place of the tortious acts allegedly causing the injury."30 However, there is an exception when the law of the foreign state is the common law. "[T]he application of another jurisdiction's laws is limited to statutes and decisions construing those statutes. When no statute is involved, Georgia courts apply the common law as developed in Georgia rather than foreign case law."31 The Plaintiffs identify no foreign statutes that govern their common law claims, therefore the Court will apply Georgia common law.

B. Standing

1. The Financial Institutions

The Defendants contend that the Plaintiffs lack Article III standing.32 In order to establish standing under Article III, a plaintiff must show an injury that is "concrete, particularized, and actual or imminent; fairly traceable to the challenged action; and redressable by a favorable ruling."33 The Supreme Court has held that "threatened injury must be certainly impending to constitute injury in fact, and that allegations of possible future injury are not sufficient."34 The Supreme Court has also noted, however, that standing can be "based on a 'substantial risk' that the harm will occur, which may prompt plaintiffs to reasonably incur costs to mitigate or avoid that harm."35

Free access — add to your briefcase to read the full text and ask questions with AI

In re Equifax, Inc., 371 F. Supp. 3d 1150 (N.D. Ga. 2019).

371 F. Supp. 3d 1150 (In re Equifax, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related