In re Salesforce Customers Security Incident Litigation
Opinion
In re Salesforce Customers Security Incident Case No. 25-cv-07232-JSC Litigation ORDER RE: DEFENDANT’S MOTION Re: Dkt. No. 86
Plaintiffs, on behalf of themselves and putative classes, bring various claims against Defendants arising from an alleged data breach which compromised Plaintiffs’ personal information. (Dkt. No. 81.)1 Defendant Salesforce, Inc. moves to dismiss Plaintiffs’ consolidated complaint, arguing Plaintiffs do not plausibly allege they have Article III standing and Plaintiffs do not state claims for negligence under California law or for violations of California, Illinois, and Washington state statutes. (Dkt. No. 86.) Having carefully considered the parties’ written submissions and having had the benefit of oral argument on September 10, 2026, the Court GRANTS in part and DENIES in part Defendant’s motion for the reasons set forth below. Defendant Salesforce, Inc. is a publicly traded company which provides a software, Salesforce, “the world’s largest customer relationship management (‘CRM’) platform[.]” (Dkt. No. 81 ¶¶ 2, 10.) “Salesforce’s clients use the Salesforce CRM platform to store the information they collect about their customers and employees (e.g., Plaintiffs and Class Members), including on cloud servers maintained by Salesforce.” (Id. ¶ 2.) “Salesforce manages the servers that hold the information provided by its clients” and “Salesforce accepts responsibility for securing the overall ‘infrastructure’ of the Salesforce CRM and platform.” (Id. ¶¶ 6, 42.) “As a condition of doing business, Salesforce requires that its clients entrust it with highly sensitive [personal identifying information (‘PII’)] belonging to their customers[.]” (Id. ¶ 3.) Plaintiffs are customers and employees of three companies “which used Salesforce’s platform to collect, organize, store, and maintain Plaintiffs’ and Class Members’ sensitive data.” (Id. ¶ 15.) Those three companies are: Allianz Life Insurance Company of North America (“Allianz”), Farmers Group, Inc. (“Farmers”), and TransUnion, LLC (“TransUnion”). (Id. ¶¶ 12- 14.) Eight named plaintiffs are Allianz customers or employees, two are Farmers customers or employees, and eight are TransUnion customers or employees. (Id. ¶¶ 18-35.) Since late 2024, a group named “SLH” began hacking into the Salesforce platform by “exploit[ing …] a mechanism built into” the platform known as “OAuth tokens.” (Id. ¶¶ 48, 50.) “Salesforce issues” those OAuth tokens “[w]hen a company connects” a third-party application “to its Salesforce account.” (Id.) Essentially, a third-party application uses OAuth tokens in lieu of a traditional username and password and a token “functions like an all-access keycard: it allows the third-party application to read, export, and in some cases modify data inside Salesforce whenever it needs to, without the user ever having to log in again.” (See id. ¶¶ 48, 50.) Salesforce had “lax security of OAuth tokens.” (Id. ¶ 49.) Specifically, Salesforce “failed to adequately vet” and “audit[]” third-party applications and did not implement “three straightforward” measures which are “standard practice on comparable cloud platforms” and would have made “OAuth tokens more secure.” (Id. ¶¶ 53, 54.) “By designing its platform to be easily accessible to numerous unverified third-party vendors, Salesforce became a target of cybercriminals: a platform with millions of sensitive records and its doors wide open.” (Id. ¶ 49.) The SLH group “recognized that Salesforce had weak access controls related to OAuth tokens” and began “targeting organizations” like Allianz, Farmers, and TransUnion that “used Salesforce as their CRM platform.” (Id. ¶¶ 47, 48.) In broad strokes, SLH’s hack worked as follows. SLH first used a “malicious application” to generate an 8-character code which could “employee by phone, posing as a member of the target company’s IT department or help desk, and instructed the employee to navigate to Salesforce’s verification page and enter the code.” (Id.) If the employee complied and entered the code, the Salesforce platform “issued an access token (i.e., a key) to the attacker[]” which gave the attacker “access to the victim organization’s Salesforce environment with all of the permissions the employee had configured[.]” (Id. ¶ 51.) Ultimately, SLH’s method of exploiting employees and OAuth tokens “bypassed multi-factor authentication entirely,” “established persistent access” to victim organizations’ data, and allowed cybercriminals to “conduct bulk data exports of dozens of Salesforce’s clients data held on Salesforce’s platform” “from approximately March 2025 through at least August 2025[.]” (Id. ¶¶ 51, 52.) “The Data Breach compromised millions of people’s PII.” (Id. ¶ 60.) After bulk downloading data from Salesforce’s clients such as Allianz, Farmers, and TransUnion, SLH “posted dozens of samples or full datasets” of stolen data on the Internet. (Id. ¶ 61.) Allianz, Farmers, and TransUnion have “admitted” the data compromised includes various forms of PII, including Social Security Numbers (“SSN”), names, addresses, dates of birth, and driver’s license numbers. (Id. ¶ 64.) Plaintiffs allege various harms flowing from the data breach. All named plaintiffs allege they (1) received a “data breach Notice Letter from” one of the three hacked companies; (2) are now subject to a “present and continuing risk of fraud, identify theft, and misuse resulting from” the data breach; and (3) to mitigate those risks, they “invested” varying degrees of “time, resources, and energy to safeguard their identities, information, and accounts, and will need to continue to do so for years to come.” (See generally id. ¶¶ 68, 105-209.) Some Plaintiffs allege suspicious, fraudulent, and/or attempted fraudulent activity has occurred on their bank accounts or credit cards, and some allege they were “forced” to get a new credit card. (See, e.g., id. ¶¶ 108, 140-42, 162-164, 168-172, 176-178.) Additionally, Plaintiffs have monitored and mitigated those risks of harm in various ways. Every named plaintiff alleges they have spent time “reviewing financial accounts and credit reports for instances of fraud,” while some allege efforts like “placing a credit freeze,” “changing passwords,” and “setting up virtual cards to replace use of of time they have spent on monitoring and mitigation efforts, and the estimates range anywhere from “over three hours” total to “ten hours per week.” (See, e.g., id. ¶¶ 109, 140, 182.) Defendant moves to dismiss Plaintiffs’ complaint under Federal Rules of Civil Procedure 12(b)(1) and (b)(6). Defendant asserts Plaintiffs have not plausibly alleged they have Article III standing or claims for negligence or for violations of California’s Consumer Privacy Act, Illinois’ Consumer Fraud Act, and Washington’s Consumer Protection Act.2 I. Article III Standing Article III standing requires Plaintiffs allege (1) they suffered an “injury in fact,” (2) “a causal connection between the injury and the conduct complained of,” and (3) the injury will “likely … be redressed by a favorable decision.” Lujan v. Defenders of Wildlife, 504 U.S. 555, 560–61 (1992) (cleaned up). An injury-in-fact must be “concrete and particularized” and “actual or imminent, not conjectural or hypothetical.” Id. at 560 (cleaned up). Additionally, to satisfy the causation prong, the alleged injury must be “fairly … trace[able] to the challenged action of the defendant, and not th[e] result [of] the independent of some third party not before the court.” Id. at 560–61 (quoting Simon v. Eastern Ky. Welfare Rts. Org., 426 U.S. 26, 41–42 (1976)). So, Defendant’s burden is to show drawing all reasonable inferences in Plaintiffs’
Free access — add to your briefcase to read the full text and ask questions with AI
In re Salesforce Customers Security Incident Case No. 25-cv-07232-JSC Litigation ORDER RE: DEFENDANT’S MOTION Re: Dkt. No. 86
Plaintiffs, on behalf of themselves and putative classes, bring various claims against Defendants arising from an alleged data breach which compromised Plaintiffs’ personal information. (Dkt. No. 81.)1 Defendant Salesforce, Inc. moves to dismiss Plaintiffs’ consolidated complaint, arguing Plaintiffs do not plausibly allege they have Article III standing and Plaintiffs do not state claims for negligence under California law or for violations of California, Illinois, and Washington state statutes. (Dkt. No. 86.) Having carefully considered the parties’ written submissions and having had the benefit of oral argument on September 10, 2026, the Court GRANTS in part and DENIES in part Defendant’s motion for the reasons set forth below. Defendant Salesforce, Inc. is a publicly traded company which provides a software, Salesforce, “the world’s largest customer relationship management (‘CRM’) platform[.]” (Dkt. No. 81 ¶¶ 2, 10.) “Salesforce’s clients use the Salesforce CRM platform to store the information they collect about their customers and employees (e.g., Plaintiffs and Class Members), including on cloud servers maintained by Salesforce.” (Id. ¶ 2.) “Salesforce manages the servers that hold the information provided by its clients” and “Salesforce accepts responsibility for securing the overall ‘infrastructure’ of the Salesforce CRM and platform.” (Id. ¶¶ 6, 42.) “As a condition of doing business, Salesforce requires that its clients entrust it with highly sensitive [personal identifying information (‘PII’)] belonging to their customers[.]” (Id. ¶ 3.) Plaintiffs are customers and employees of three companies “which used Salesforce’s platform to collect, organize, store, and maintain Plaintiffs’ and Class Members’ sensitive data.” (Id. ¶ 15.) Those three companies are: Allianz Life Insurance Company of North America (“Allianz”), Farmers Group, Inc. (“Farmers”), and TransUnion, LLC (“TransUnion”). (Id. ¶¶ 12- 14.) Eight named plaintiffs are Allianz customers or employees, two are Farmers customers or employees, and eight are TransUnion customers or employees. (Id. ¶¶ 18-35.) Since late 2024, a group named “SLH” began hacking into the Salesforce platform by “exploit[ing …] a mechanism built into” the platform known as “OAuth tokens.” (Id. ¶¶ 48, 50.) “Salesforce issues” those OAuth tokens “[w]hen a company connects” a third-party application “to its Salesforce account.” (Id.) Essentially, a third-party application uses OAuth tokens in lieu of a traditional username and password and a token “functions like an all-access keycard: it allows the third-party application to read, export, and in some cases modify data inside Salesforce whenever it needs to, without the user ever having to log in again.” (See id. ¶¶ 48, 50.) Salesforce had “lax security of OAuth tokens.” (Id. ¶ 49.) Specifically, Salesforce “failed to adequately vet” and “audit[]” third-party applications and did not implement “three straightforward” measures which are “standard practice on comparable cloud platforms” and would have made “OAuth tokens more secure.” (Id. ¶¶ 53, 54.) “By designing its platform to be easily accessible to numerous unverified third-party vendors, Salesforce became a target of cybercriminals: a platform with millions of sensitive records and its doors wide open.” (Id. ¶ 49.) The SLH group “recognized that Salesforce had weak access controls related to OAuth tokens” and began “targeting organizations” like Allianz, Farmers, and TransUnion that “used Salesforce as their CRM platform.” (Id. ¶¶ 47, 48.) In broad strokes, SLH’s hack worked as follows. SLH first used a “malicious application” to generate an 8-character code which could “employee by phone, posing as a member of the target company’s IT department or help desk, and instructed the employee to navigate to Salesforce’s verification page and enter the code.” (Id.) If the employee complied and entered the code, the Salesforce platform “issued an access token (i.e., a key) to the attacker[]” which gave the attacker “access to the victim organization’s Salesforce environment with all of the permissions the employee had configured[.]” (Id. ¶ 51.) Ultimately, SLH’s method of exploiting employees and OAuth tokens “bypassed multi-factor authentication entirely,” “established persistent access” to victim organizations’ data, and allowed cybercriminals to “conduct bulk data exports of dozens of Salesforce’s clients data held on Salesforce’s platform” “from approximately March 2025 through at least August 2025[.]” (Id. ¶¶ 51, 52.) “The Data Breach compromised millions of people’s PII.” (Id. ¶ 60.) After bulk downloading data from Salesforce’s clients such as Allianz, Farmers, and TransUnion, SLH “posted dozens of samples or full datasets” of stolen data on the Internet. (Id. ¶ 61.) Allianz, Farmers, and TransUnion have “admitted” the data compromised includes various forms of PII, including Social Security Numbers (“SSN”), names, addresses, dates of birth, and driver’s license numbers. (Id. ¶ 64.) Plaintiffs allege various harms flowing from the data breach. All named plaintiffs allege they (1) received a “data breach Notice Letter from” one of the three hacked companies; (2) are now subject to a “present and continuing risk of fraud, identify theft, and misuse resulting from” the data breach; and (3) to mitigate those risks, they “invested” varying degrees of “time, resources, and energy to safeguard their identities, information, and accounts, and will need to continue to do so for years to come.” (See generally id. ¶¶ 68, 105-209.) Some Plaintiffs allege suspicious, fraudulent, and/or attempted fraudulent activity has occurred on their bank accounts or credit cards, and some allege they were “forced” to get a new credit card. (See, e.g., id. ¶¶ 108, 140-42, 162-164, 168-172, 176-178.) Additionally, Plaintiffs have monitored and mitigated those risks of harm in various ways. Every named plaintiff alleges they have spent time “reviewing financial accounts and credit reports for instances of fraud,” while some allege efforts like “placing a credit freeze,” “changing passwords,” and “setting up virtual cards to replace use of of time they have spent on monitoring and mitigation efforts, and the estimates range anywhere from “over three hours” total to “ten hours per week.” (See, e.g., id. ¶¶ 109, 140, 182.) Defendant moves to dismiss Plaintiffs’ complaint under Federal Rules of Civil Procedure 12(b)(1) and (b)(6). Defendant asserts Plaintiffs have not plausibly alleged they have Article III standing or claims for negligence or for violations of California’s Consumer Privacy Act, Illinois’ Consumer Fraud Act, and Washington’s Consumer Protection Act.2 I. Article III Standing Article III standing requires Plaintiffs allege (1) they suffered an “injury in fact,” (2) “a causal connection between the injury and the conduct complained of,” and (3) the injury will “likely … be redressed by a favorable decision.” Lujan v. Defenders of Wildlife, 504 U.S. 555, 560–61 (1992) (cleaned up). An injury-in-fact must be “concrete and particularized” and “actual or imminent, not conjectural or hypothetical.” Id. at 560 (cleaned up). Additionally, to satisfy the causation prong, the alleged injury must be “fairly … trace[able] to the challenged action of the defendant, and not th[e] result [of] the independent of some third party not before the court.” Id. at 560–61 (quoting Simon v. Eastern Ky. Welfare Rts. Org., 426 U.S. 26, 41–42 (1976)). So, Defendant’s burden is to show drawing all reasonable inferences in Plaintiffs’ favor from the complaint, Plaintiffs’ allegations do not support an inference the elements of Article III standing are met. Defendant asserts Plaintiffs’ allegations about a risk of future harm are too speculative to satisfy the injury-in-fact requirement and Plaintiffs’ injuries are not fairly traceable to Salesforce’s conduct. The Court disagrees. A. Plaintiffs Plausibly Allege an Injury-In-Fact “To establish Article III standing, an injury must be ‘concrete, particularized, and actual or imminent[.]’” Clapper v. Amnesty Int’l USA, 568 U.S. 398, 409 (2013) (quoting Monsanto Co. v. Geertson Seed Farms, 561 U.S. 139, 149 (2010)). Here, every plaintiff alleges the data breach has
2 Plaintiffs withdrew their claims for violations of the California Customer Records Act, the subjected them to a “present and continuing risk of fraud, identify theft, and misuse” of their personal information and to mitigate those risks, they “invested” varying amounts of “time, resources, and energy to safeguard their identities, information, and accounts, and will need to continue to do so for years to come.” (See generally Dkt. No. 81 ¶¶ 68, 105-209.) In other words, Plaintiffs allege a risk of future harm and they have incurred costs to monitor and mitigate those risks. Plaintiffs allege various facts to support the allegation they are at risk of identity theft and fraud. Every named plaintiff alleges they “received a data breach Notice Letter from” one of the three Salesforce client companies between July 2025 and September 2025. (Id. ¶¶ 105-209.) As relevant here, the Notice Letter from Allianz states:
What Happened? On July 16, 2025, a malicious threat actor gained access to a cloud-based system used by Allianz Life. The threat actor was able to obtain certain personal information related to Allianz Life customers, financial professionals, and select Allianz Life employees. We took immediate action to contain and mitigate the issue. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed. […]
What Information Was Involved? The affected data may have included your name, address, date of birth and Social Security number. (Dkt. No. 87 at 1, citing https://oag.ca.gov/system/files/ELN- 24798%20Allianz%20Life%20Ins%20Adult%20CM%2024M%20CA%20r2prf.pdf.) And the Notice Letter from Farmers states:
WHAT HAPPENED? On May 30, 2025, one of Farmers’ third-party vendors alerted Farmers to suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing Farmers customer information (the “Incident”). […] After learning of the activity, Farmers immediately launched a comprehensive investigation to determine the nature and scope of the Incident[. …] The in-depth investigation determined that an unauthorized actor accessed the vendor’s database on May 29, 2025, and acquired certain data. With the assistance of a third-party data- review expert, Farmers conducted a comprehensive review to determine what data had been accessed and acquired, whether the data contained personal information, and to whom the personal information belonged. On July 24, 2025, the review determined that some of your personal information was subject to unauthorized access and acquisition. of your personal information were involved: [redaction] (Id., citing https://oag.ca.gov/system/files/FIE%20Sample%20Notification%20Letter_All%20States_0.pdf.) “Based on the Notice Letter” they received, eight plaintiffs allege they “reasonably believe[]” their “name, address, date of birth, and SSN were compromised in the Data Breach[.]” (Id. ¶¶ 105, 111, 117, 122, 132, 137, 143, 154.) By contrast, nine named plaintiffs3 do not allege they “reasonably believe[]” their information was compromised, and instead allege they received a Notice Letter which “informed” them or “informed [them] unequivocally” that certain categories of information “were compromised in the Data Breach.” (Id. ¶¶ 148, 159, 165, 173, 179, 185, 192, 198, 204.) Of the plaintiffs who “reasonably believe[]” their information was compromised, seven4 do not specifically allege examples of their information being misused as other plaintiffs allege, e.g., their information was “exposed on the dark web,” “unauthorized charges” on their credit card, or “attempted fraudulent activity.” (Id. ¶¶ 105, 111, 117, 122, 132, 137, 143, 154; see, e.g., id. ¶¶ 152, 163, 169.) Six of those seven plaintiffs received a letter from Allianz; the seventh plaintiff received a letter from Farmers. Defendant argues Plaintiffs do not plausibly allege an injury-in-fact because they rely on “speculative allegations about a ‘risk’ of potential future harm[.]” (Dkt. No. 86 at 12.) Separately, Defendant asserts seven plaintiffs in particular “fail to allege any injury at all.” (Id. at 17.) Defendant singles out the seven plaintiffs who do not allege examples of misuse, and instead allege they “reasonably believe[]” their information was compromised based on the Notice Letter they received from Allianz or Farmers. Defendant emphasizes the letters do not “confirm[] that any specific information was stolen, let alone misused” because the letters use phrases like “the 3 Ten plaintiffs use the phrase “informed” or “informed […] unequivocally.” Those plaintiffs are Mr. Garcia, Ms. Dean, Mr. Doyle, Mr. Gilhooly, Mr. Koplitz, Mr. Keith, Ms. Lovell, Mr. Pettersen, Ms. Tomas, and Mr. Zurawskyj. One of these ten plaintiffs, Mr. Koplitz, alleges both “the Notice Letter informed” him that certain information was “compromised” and he “reasonably believes” that information was compromised “[b]ased on the Notice Letter.” (Dkt. No. 81 ¶ 132.) 4 These seven plaintiffs are Mr. Carter, Ms. Goldstein, Ms. Hansch, Ms. LaMarre, Mr. Kim, Mr. Koplitz, and Ms. Taylor. Another named plaintiff, Mr. Stockton, alleges he “reasonably believes” his information was compromised and “he received a notice from his bank, Chase, that attempted affected data may have included …” and “your personal information was subject to unauthorized access[.]” (Id. at 19 (emphasis in motion).) The Court disagrees on all points. i. All Plaintiffs Plausibly Allege a Sufficient Risk of Harm The Ninth Circuit has twice held allegations of a risk of future identity theft are sufficient to confer Article III standing. First, in Krottner v. Starbucks Corp., 628 F.3d 1139 (9th Cir. 2010), someone stole a laptop containing roughly 97,000 Starbucks employees’ “unencrypted names, addresses, and social security numbers.” Id. at 1140. “Starbucks sent a letter to […] affected employees alerting them to the theft and stating that Starbucks had ‘no indication that the private information ha[d] been misused.’” Id. at 1140–41. The Ninth Circuit held the plaintiffs’ “increased risk of future identity theft” “sufficiently alleged an injury-in-fact for purposes of Article III standing” because the alleged risk constituted a “‘credible threat of harm’ […] that is ‘both real and immediate, not conjectural or hypothetical.’” Id. at 1142–43 (quoting Cent. Delta Water Agency v. United States, 306 F.3d 938, 950 (9th Cir. 2002) and City of Los Angeles v. Lyons, 461 U.S. 95, 102 (1983)). Subsequently, In re Zappos.com, Inc., 888 F.3d 1020 (9th Cir. 2018) held plaintiffs satisfied the injury-in-fact requirement when they alleged a “data breach put them at risk of identity theft.” Id. at 1023. There, “hackers breached the servers” of a company and “stole [customers’] names, account numbers, passwords, email addresses, […] addresses, telephone numbers, and credit and debit card information,” then the company “sent an email to its customers, notifying them of the theft of their PII.” Id. The Ninth Circuit held Krottner “remains binding” after the Supreme Court’s decision in Clapper, “Krottner control[led] the result” of the case, and the plaintiffs “sufficiently alleged an injury in fact under Krottner […] based on a substantial risk that the […] hackers will commit identity fraud or identity theft.” Id. at 1026–27, 29. Applying Krottner and Zappos.com here, drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations plausibly support an inference they have suffered a “substantial risk” of identity fraud or identity theft. Id. at 1029. Every plaintiff alleges they received a notice from Allianz, Farmers, or TransUnion describing the data breach. (See generally Dkt. No. 81 ¶¶ 64, 68, 105-209.) information” and “[t]he affected data may have included your name, address, date or birth, and Social Security number.” (Id. ¶ 64 & n.34; Dkt. No. 87 at 1.) Farmers’ letter explained “an unauthorized actor […] acquired certain data” and Farmers “determined that some of your personal information was subject to unauthorized access and acquisition.” (Id.) Although the publicly available version of Farmers’ letter is redacted, Plaintiffs allege the Farmers hack compromised their “[n]ames, addresses, dates of birth, driver’s license numbers, and the last four digits of SSNs.” (Dkt. No. 81 ¶ 64.) And while Plaintiffs do not link to or attach TransUnion’s letter as an exhibit, all TransUnion Plaintiffs allege the letter “informed [them] unequivocally that [their] date of birth and SSN were compromised in the Data Breach.” (Id. ¶¶ 159, 165, 173, 179, 185, 192, 198, 204.) Drawing inferences in Plaintiffs’ favor, that each company sent a letter to Plaintiffs describing the data breach and specific types of sensitive information disclosed supports an inference Plaintiffs are at risk of future identity theft and fraud. Additionally, drawing inferences in Plaintiffs’ favor, Plaintiffs plausibly allege facts supporting an inference the risk of identity theft and fraud is a “credible threat of harm […] that is both real and immediate, not conjectural or hypothetical.” Krottner, 628 F.3d at 1142–43 (cleaned up). Plaintiffs specifically allege how SSNs and driver’s license numbers are used to commit identity theft and fraud. (See Dkt. No. 81 ¶¶ 65, 66.) Plaintiffs also allege the SLH group “posted samples of data stolen from Salesforce,” demanded “Salesforce pay a ransom,” then “posted dozens of samples or full data sets […] on the Internet” in a way that is “available for download[.]” (Id. ¶ 61.) Several plaintiffs, including two Allianz plaintiffs and nearly every TransUnion plaintiff, also allege examples of actual or attempted misuse of their personal information after the data breach, e.g., they “received notice” of “unauthorized charges” on their credit card, “attempted fraudulent activity,” or “an unauthorized inquiry […] made in [their] name for a new credit card.” (Id. ¶¶ 105, 141, 169-170, 177, 190, 196, 202, 208.) Four plaintiffs– including Mr. Garcia, a Farmers plaintiff, and three TransUnion plaintiffs–expressly allege their personal information has been found in the dark web, where there is a “thriving market” for “stolen PII.” (Id. ¶¶ 71, 152 (“Plaintiff Garcia was told by a monitoring service that his SSN was discovered that her confidential information was on the dark web.”); 183 (“Plaintiff [Keith] learned through Nord NVP that his PII was published on the dark web.”) 189 (“Plaintiff Lovell[’s …] credit monitoring service […] discovered her confidential information on the dark web.”)) Drawing inferences in Plaintiffs’ favor, these facts are sufficient to support an inference the risk of identity theft and fraud is “real and immediate, not conjectural or hypothetical.” Krottner, 628 F.3d at 1142–43 (cleaned up). Defendant contends under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), Plaintiffs’ alleged risk of future injury is not sufficiently “concrete” for any named plaintiff to seek damages. Not so. Here, every plaintiff alleges they have spent time, energy, and resources monitoring and mitigating the risks of identity theft and fraud. Therefore, unlike TransUnion, Plaintiffs allege they are “independently harmed by their exposure to the risk itself—that is, that they suffered some other injury […] from the mere risk” of future injury. Id. at 437. Clapper, too, is inapposite. There, the plaintiffs asserted they suffered an injury-in-fact based on a threat of future surveillance and costs incurred as a reaction to the risk of surveillance, and the Court rejected both theories because plaintiffs’ evidence “amount[ed] to mere speculation” that the asserted future injury would occur. 568 U.S. at 410–14; see id. at 416 (rejecting the plaintiffs’ theory regarding costs “[b]ecause” future harm was not sufficiently imminent.) Clapper is therefore distinguishable because as explained above, Plaintiffs’ allegations permit an inference the risk of future identity fraud and theft is “real and immediate,” not speculative. Krottner, 628 F.3d at 1142–43 (cleaned up). So, because Plaintiffs allege they incurred monitoring and mitigation costs as a reaction to a real and immediate risk, Plaintiffs allege “sufficiently concrete” harms for injury-in-fact purposes “even if” the risk itself has not yet resulted in, for example, Plaintiffs becoming victims of a successful identity fraud scheme. Monsanto, 561 U.S. at 155; see also Clapper, 568 U.S. at 420 (distinguishing Monsanto on the ground “respondents in the present case present no concrete evidence to substantiate their fears, but instead rest on mere conjecture about possible governmental actions.”) And, after Clapper was decided, the Ninth Circuit held Knotter “remains binding” and “controls the result” of a case where plaintiffs alleged a future risk ii. The Seven Identified Plaintiffs Plausibly Allege a Sufficient Risk of Harm Drawing inferences in Plaintiffs’ favor, those risks are “real and immediate” even for seven plaintiffs who do not allege misuse of their personal information. As noted above, one of those plaintiffs is a Farmers customer, Mr. Muro. Six are Allianz plaintiffs. Allianz’s letter told these plaintiffs “a malicious threat actor […] was able to obtain […] personal information” and “[t]he affected data may have included your name, address, date or birth, and Social Security number.” (Id. ¶ 64 & n.34; Dkt. No. 87 at 1 (emphasis added).) Plaintiffs allege how that affected data can be used to commit identity fraud, and two other Allianz plaintiffs allege “attempted fraudulent activity” following the data breach which “forced” them to get a new credit card or credit card number.” (Dkt. No. 81 ¶¶ 108, 141.) Therefore, drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations are sufficient to support an inference all Allianz plaintiffs have a “real and immediate” risk of identity theft and fraud. The same is true of the seventh plaintiff, Mr. Muro, a Farmers customer. As noted above, Farmers’ Notice Letter informed Mr. Muro “an unauthorized actor […] acquired certain data” and Farmers “determined that some of your personal information was subject to unauthorized access and acquisition.” (Dkt. No. 87 at 1.) Plaintiffs separately allege that information includes “[n]ames, addresses, dates of birth, driver’s license numbers, and the last four digits of SSNs.” (Dkt. No. 81 ¶ 64.) Moreover, the only other Farmers plaintiff, Mr. Garcia, alleges he “was told by a monitoring service that his SSN was exposed on the dark web.” (Id. ¶ 152.) Drawing inferences in Plaintiffs’ favor, Mr. Muro’s highly sensitive personal information was acquired by the bad actors. Further, that Mr. Garcia’s SSN was exposed on the dark web is sufficient to support an inference Mr. Muro is at risk of identity theft because Plaintiffs specifically allege “[i]n similar breach cases involving a centralized repository of data affecting multiple customers who use the repository, when information from one customer appears on the dark web, breached data from other customers has typically followed or has already been sold” and “given that the dark web is designed to conceal users’ activities, the task of detecting, monitoring, and redressing information appears on the dark web following a data breach (i.e., Garcia’s SSN, stolen from Farmers), that “typically” means data belonging to other victims of the same data breach (i.e., Mr. Muro) will be, or has already been sold, on the dark web. (See id.) Accepting that allegation as true, and drawing inferences in Plaintiffs’ favor, Plaintiffs allege facts sufficient to support an inference Mr. Muro’s risk of identity theft and fraud is “real and immediate, not conjectural or hypothetical.” Krottner, 628 F.3d at 1142–43 (cleaned up). Defendant’s argument the Allianz and Farmers letters do not “confirm[] that any specific information was stolen, let alone misused” (Dkt. No. 86 at 19) is unavailing. Defendant urges the Allianz letter used the phrase “the affected data may have included …” and the Farmers letter stated “some” “personal information was subject to unauthorized access and acquisition[.]” (Dkt. No. 86 at 19 (first and third emphasis in motion).) The Allianz letter specifically states cybercriminals were “able to obtain personal information.” (Dkt. No. 81 ¶ 64 & n.34; Dkt. No. 87 at 1.) Therefore, the letter’s subsequent phrasing regarding what types of personal information that “may” include does not compel the inference the Allianz plaintiffs do not face a real and immediate risk of identity fraud; rather, drawing inferences in Plaintiffs’ favor, the word “may” supports an inference each Allianz plaintiff’s sensitive information was stolen from Allianz. Similarly, the Farmers letter’s use of the phrases “some” and “subject to” does not defeat an inference Mr. Muro faces a real and immediate risk of identity fraud because Mr. Muro specifically alleges he “provided” “his driver’s license number and address […] to Farmers,” the letter says threat actors “acquired certain data,” Mr. Garcia (the only other Farmers plaintiff) alleges his SSN was exposed on the dark web, and Plaintiffs essentially allege the exposure of Mr. Garcia’s information “typically” means Mr. Muro’s information is or will be on the dark web. (See Dkt. No. 81 ¶¶ 63, 64 & n.34, 152, 154; Dkt. No. 87 at 1.) Defendant’s reliance on Greenstein v. Noblr Reciprocal Exchange, 2024 WL 3886977 (9th Cir. Aug. 21, 2024) is misplaced. Defendant cites Greenstein to essentially argue Allianz’s and Farmers’ letters do not support an inference sensitive information was stolen from the six Allianz plaintiffs and Mr. Muro. There, the court held two plaintiffs did not allege an injury-in-fact information was actually stolen” in a data breach. Id. at *2. The court explained the plaintiffs’
allegations rely heavily on a notice Noblr sent to 97,633 individuals— including Plaintiffs—several months after the attack. But the description of the attack provided in the Notice, which accounts for the bulk of the factual allegations included in the complaint, is ultimately insufficient to establish that Plaintiffs’ driver's license numbers were stolen. While the Notice does confirm that “the attackers were able to access driver's license numbers,” it stops short of confirming that any individual recipient of the Notice had his or her driver's license number stolen. It does not confirm which or how many driver's license numbers were accessed, nor does it confirm whether the driver's license numbers of all 97,633 recipients of the Notice were taken from Noblr’s website. Instead, in explaining “[w]hat [i]nformation [w]as [i]nvolved,” the Notice states only that each recipient’s “name, driver’s license number, and address may have been accessed.” (emphasis added). After reading the Notice, all that a reasonable reader would know for certain is that Noblr suffered a cyberattack, some driver's license numbers were taken as a result, and his own driver's license number may (or may not) have been among those stolen. Aside from the factual allegations pulled from the Notice, Plaintiffs provide no additional allegations that might provide a credible basis to conclude their driver’s license numbers were taken. Id. at *1-2. Greenstein is unpublished and distinguishable in two respects. First, unlike the Greenstein Notice, the Allianz and Farmers letters supply a “credible basis to conclude” those seven plaintiffs sensitive information “w[as] taken.” Id. at *2. Whereas Greenstein’s Notice stated “each recipient’s ‘name, driver’s license number, and address may have been accessed,’” id. (first emphasis in original), Allianz’s letter says hackers were actually “able to obtain personal information” and Farmers’ letter explains “personal information was subject to unauthorized access and acquisition” then specifies the “types of your personal information” which “were involved.” (Dkt. No. 81 ¶ 64 & n.34; Dkt. No. 87 at 1 (emphasis added).) Second, Plaintiffs rely on more than just “allegations pulled from the Notice[s]” to allege their sensitive information was among the information stolen. Greenstein, 2024 WL 3886977, at *2. For instance, Plaintiffs specifically allege hackers downloaded “bulk data,” as opposed to merely “accessed” data, and cite numerous news articles describing the cyberattack and the information stolen. (See Dkt. No. 81 ¶¶ 52, 91; see generally id. ¶¶ 61-64 & n. 29-36.) B. Plaintiffs Plausibly Allege Injuries Fairly Traceable to Defendant’s Conduct “To survive a motion to dismiss for lack of constitutional standing, plaintiffs must establish a ‘line of causation’ between defendant[’s] action and their alleged harm that is more than ‘attenuated.’” Maya v. Centex Corp., 658 F.3d 1060, 1070 (9th Cir. 2011) (quoting Allen v. Wright, 468 U.S. 737, 757 (1984)). “A causation chain does not fail simply because it has several ‘links,’ provided those links are ‘not hypothetical or tenuous’ and remain ‘plausib[le].’” Id. (quoting Nat’l Audobon Soc., Inc. v. Davis, 304 F.3d 835, 849 (9th Cir. 2002)). Here, Defendant argues Plaintiffs’ injuries are not fairly traceable to Defendant’s conduct because “every alleged injury depends on acts by third parties,” namely cybercriminals, Salesforce’s customers who hosted Plaintiffs’ data, and employees of those customers who were tricked by cybercriminals. (Dkt. No. 86 at 17.) The Court disagrees. Drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations support a plausible inference there is a “‘line of causation’ between defendant[’s] action and their alleged harm that is more than ‘attenuated.’” Maya, 658 F.3d at 1070 (quoting Allen, 468 U.S. at 757). The alleged line of causation is fairly straightforward: Salesforce “failed to” take specific steps to make “OAuth tokens more secure,” making “its platform […] easily accessible to numerous unverified third- party vendors[.]” (Dkt. No. 81 ¶¶ 49, 53, 54.) Three actions which Salesforce failed to take are allegedly “standard practice.” (Id.) Consequently, cybercriminals “recognized” Salesforce’s “lax security” and began “targeting organizations that used Salesforce as their CRM platform,” which caused the data breach and Plaintiffs’ injuries. (Id. ¶¶ 47-49.) That third parties like cybercriminals and Salesforce’s clients’ employees are part of the causal chain does not mean the links in the causal chain are too attenuated to confer Article III standing because Plaintiffs’ allegations support an inference Salesforce’ “lax security” with OAuth tokens is the enabling, underlying cause of the data breach. In that sense, drawing inferences in Plaintiffs’ favor, Plaintiffs’ injuries are fairly traceable to Salesforce’s conduct. Relatedly, Defendant’s argument “Plaintiffs do not allege that cybercriminals bypassed Salesforce security controls or exploited Salesforce systems to access Plaintiffs’ PII” (Dkt. No. 86 at 18) is plainly into” the Salesforce platform, “Salesforce issues” those tokens, and the SLH group’s exploitation of OAuth tokens “bypassed multi-factor authentication entirely[.]” (Dkt. No. 81 ¶¶ 48-51.) Accepting those allegations as true, and drawing inferences in Plaintiffs’ favor, Plaintiffs have plausibly alleged a sufficiently strong causal chain between Plaintiffs’ injuries and Defendant’s failure to implement steps to make OAuth tokens more secure. Defendant’s cited cases do not persuade. Of Defendant’s cited cases addressing Article III’s causation requirement, only two are binding authority. The first, WildEarth Guardians v. United States Forest Serv., 70 F.4th 1212 (9th Cir. 2023), is inapposite because it applied rules specific to government-agency defendants. See id. at 1216–17; id. at 1217–18 (applying cases “[w]here an essential element of standing depends on the reaction of a third party to the requested government action or inaction”) (cleaned up) (emphasis added). The second case, Simon, is also inapposite because it held the plaintiffs’ injuries were not fairly traceable to the defendants’ conduct because the alleged connection required “[s]peculative inferences.” 426 U.S. at 45. But here, the connection between Plaintiffs’ injuries and Salesforce’s conduct does not require speculative inferences. Rather, as explained above, Plaintiffs allege a line of causation where each causal link is plausible and not attenuated. Defendant’s remaining cases–Williams v. Sisolak, 2024 WL 194180 (9th Cir. Jan. 18, 2024) and Al-Sadhan v. Twitter Inc., 2024 WL 536311 (N.D. Cal. Feb. 9, 2024)–fare no better. Defendant cites both cases for the argument Article III’s causation requirement is not satisfied when there are “numerous third parties whose independent decisions collectively have a significant effect on plaintiffs’ injuries.” (Dkt. No. 86 at 16 (cleaned up).) Neither case applied that rule to a data breach. Nor does Defendant cite a case applying that rule to a theory analogous to Plaintiffs’ here: Salesforce’s “lax security” was the enabling, underlying cause of Plaintiffs’ injuries. Rather, Williams addressed “claims based on government action or inaction” and held the plaintiffs did not allege Article III standing under WildEarth. 2024 WL 194180 at *1-2. And Al- Sadhan held a plaintiff’s own “decisions, undertaken on her own volition, effected her injuries and broke the chain of causation” between her injuries and the defendant’s conduct. 2024 WL 536311 Accordingly, Defendant has not met its burden to show drawing all inferences in Plaintiffs’ favor, Plaintiffs’ allegations do not permit an inference Plaintiffs’ injuries are fairly traceable to Defendant’s conduct. II. Negligence (Count I) Defendant moves to dismiss Plaintiffs’ California-state-law negligence claim.5 Under California law, “[t]o establish a cause of action for negligence, the plaintiff must show that the defendant had a duty to use due care, that he breached that duty, and that the breach was the proximate or legal cause of the resulting injury.” Brown v. USA Taekwondo, 11 Cal. 5th 204, 213 (2021) (cleaned up). Defendant asserts Plaintiffs do not plausibly allege the elements of duty, breach, causation, and damages. A. Duty Under California law, the “‘general rule’ governing duty is set forth in Civil Code section 1714,” which “establishes the default rule that each person has a duty to exercise, in his or her activities, reasonable care for the safety of others.” Id. at 213–14 (cleaned up). Section 1714 “imposes a general duty of care on a defendant only when it is the defendant who has created a risk of harm to the plaintiff, including when the defendant is responsible for making the plaintiff’s position worse.” Id. at 214 (cleaned up). A separate rule, the so-called “no-duty-to-protect rule,” provides “one owes no duty to control the conduct of another, nor to warn those endangered by such conduct.” Id. at 214–15. For example, “a person who stumbles upon someone drowning generally has no legal duty to help the victim. The same rule applies to a person who stumbles upon a mugging, for as a general matter, there is no duty to act to protect others from the conduct of third parties.” Id. (cleaned up). So, summarizing these two general rules, Brown held “[w]here the defendant has neither
5 Defendant also argues California law does not govern the non-California Plaintiffs’ negligence claims under California’s three-step “governmental interest” test. See McCann v. Foster Wheeler LLC, 48 Cal. 4th 68, 87–88 (2010). The Court defers the choice-of-law question to a later stage, given the parties’ briefing on California’s governmental-interest test is supposed to compare the relevant substantive law and interests of four states, is short and insufficient. (See Dkt. No. 86 at performed an act that increases the risk of injury to the plaintiff nor sits in a relation to the parties that creates an affirmative duty to protect the plaintiff from harm, […] our cases have uniformly held the defendant owes no legal duty to the plaintiff.” Id. at 216. Here, Plaintiffs assert Salesforce owed them a duty of care because Salesforce’s conduct created a foreseeable risk of harm with respect to Plaintiffs’ personal information, and, “[i]n the alternative, Salesforce had a duty of care given its special relationship with Plaintiffs[.]” (Dkt. No. 81 ¶ 92; Dkt. No. 92 at 14-15.) Defendant argues Plaintiffs have not alleged a duty of care because “Brown does not eliminate the special relationship requirement to impose liability from third-party conduct.” (Dkt. No. 96 at 7.) In other words, Defendant’s motion is premised on the idea Plaintiffs must “allege [a] special relationship […] to plead a duty” under California law. (Id.) That premise is incorrect. “[A]ll persons are required to use ordinary care to prevent others from being injured as the result of their conduct.” Weirum v. RKO Gen., Inc., 15 Cal. 3d 40, 46 (1975). In Weirum, the California Supreme Court held a radio broadcaster breached that duty by essentially encouraging listeners to race around Los Angeles, which caused a listener to get in a car crash and kill someone. Id. at 43–47. The court reasoned the broadcaster owed a duty of care to the decedent with respect to “the foreseeable consequences of his acts,” which included “reckless conduct by youthful [listeners] stimulated by defendant’s broadcast.” Id. at 47. The broadcaster argued it “owed no duty of care to [the] decedent,” urging “absent a special relationship, an actor is under no duty to control the conduct of third parties,” but the court rejected that argument, explaining “this rule has no application if the plaintiff’s complaint […] is grounded upon an affirmative act which created an undue risk of harm.” Id. at 48. Defendant’s Reply brief does not address Weirum’s clear statement of California law: the “special relationship […] rule has no application if the plaintiff’s complaint […] is grounded upon an affirmative act which created an undue risk of harm.”6 Id.; (Dkt. No. 96 at 7-8.) 6 Defendant’s sole rejoinder is “liability rested on the broadcaster’s creation of ‘an undue risk of harm’ to members of the public, not merely the foreseeability of third-party criminal or negligent So, here, given Plaintiffs allege Salesforce’s “affirmative act[s]” in designing its platform “created an undue risk of harm,” Plaintiffs are not required to allege they had a special relationship with Salesforce to plead a duty. Weirum, 15 Cal. 3d at 48. Rather, under California law, Plaintiffs may–and do–plead a duty under the theory Salesforce’s conduct created a foreseeable risk of harm by third parties. Accordingly, the Court denies Defendant’s motion on the ground Plaintiffs must allege a special relationship. B. Breach Broadly speaking, Defendant contends Plaintiffs do not plausibly allege a breach because Plaintiffs do not explain “what Salesforce did wrong and how that conduct caused the alleged harm.” (Dkt. No. 86 at 24.) Specifically, Defendant argues (1) “Plaintiffs do not identify any specific vulnerability in Salesforce’s systems that the cybercriminals allegedly exploited” and instead Plaintiffs allege “cybercriminals gained access through […] social engineering,” (2) “Plaintiffs’ vague, conclusory allegations that Salesforce ‘failed to adequately’ protect their information […] rely on generalized allegations of inadequate data security,” (3) “Plaintiffs fail to identify any non-conclusory actions Salesforce—as opposed to [Salesforce’s] Customers— supposedly should have or could have taken to secure Plaintiffs’ data or explain how any such action could have prevented the social engineering attacks,” and (4) “Plaintiffs cannot point to any communication or notice from Salesforce to support a finding of any breach by Salesforce.” (Id. at 25.) The Court disagrees on all four points. Drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations support a plausible inference Defendant breached a duty of care with respect to Plaintiffs’ personal information. Plaintiffs
Customers’ employees into authorizing a malicious application.” (See Dkt. No. 96 at 7 (quoting Weirum, 15 Cal. 3d at 48).) Defendant’s argument is unclear. To the extent Defendant argues Plaintiffs have not alleged an “undue risk of harm” like the risk in Weirum, the Court disagrees because drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations permit an inference the risk of identity theft, fraud, and misuse resulting from a data breach is undue. See Weirum, 15 Cal. 3d at 47 (“Liability is imposed only if the risk of harm resulting from the act is deemed unreasonable—i.e., if the gravity and likelihood of the danger outweigh the utility of the conduct involved.”); (see, e.g., Dkt. No. 81 ¶¶ 65-80 (explaining how identity theft and fraud occurs, the difficulties in redressing identity theft, and many ways threat actors can misuse victims’ sensitive allege cybercriminals gained access to sensitive data by “exploit[ing] Salesforce’s lax security of OAuth tokens.” (Dkt. No. 81 ¶ 49.) Plaintiffs allege many technical details behind how OAuth tokens work, including how these tokens are “a mechanism built into” the Salesforce platform, “Salesforce issues” the tokens to “third-party applications,” and a token “allows the third-party application to read, export, and in some cases modify data inside Salesforce […] without the user ever having to log in again.” (Id. ¶¶ 48, 50.) Consistent with these technical details, Plaintiffs allege Defendant breached its duty of care by “failing to adequately vet” and “audit[]” third-party applications and “by failing to implement any of three straightforward options for making its OAuth tokens more secure, each of which is standard practice on comparable cloud platforms[.]” (Id. ¶ 53.) Then, in three separate paragraphs, Plaintiffs detail those “straightforward options,” namely “Salesforce could have made tokens expire automatically,” “required tokens to rotate automatically,” and/or “tied tokens to specific devices.” (Id. ¶ 53(a)-(c).) Given the sheer level of detail of Plaintiffs’ allegations, Defendant’s arguments do not persuade. First, Plaintiffs do, in fact, “identify a[] specific vulnerability” in Salesforce’s systems. (Dkt. No. 86 at 25.) The alleged vulnerability is OAuth tokens. That this vulnerability was exploited in tandem with social engineering tactics to work does not mean Salesforce did not breach a duty of care. Second, Plaintiffs’ detailed allegations about the ways Salesforce could have made OAuth tokens more secure are not “vague, conclusory,” or “generalized.” (Id.) Third, Plaintiffs expressly allege “Salesforce issues” OAuth tokens and “Salesforce could have” taken “any of” the three options “for making its OAuth tokens more secure.” (Dkt. No. 81 ¶¶ 48, 50, 53, 53(a)-(c) (emphasis added).) Therefore, Defendant’s suggestion “Plaintiffs fail to identify […] actions Salesforce—as opposed to [Salesforce’s] Customers—supposedly should have or could have taken to secure Plaintiffs’ data” (Dkt. No. 86 at 25) is without merit. Relatedly, Plaintiffs’ allegations about those three options support an inference Salesforce’s implementation of those steps would have made OAuth tokens more secure. (See, e.g., Dkt. No. 81 ¶ 52(b) (“Salesforce could have required tokens to rotate automatically. […] Had it done so, a stolen token would have become worthless the first time the legitimate application used it, because Salesforce would have (“Salesforce could have tied tokens to specific devices. […] Every time the token is used, the holder must prove it still possesses the matching private key. An attacker who steals the token itself gets nothing: without the private key from the original device, the token cannot be used anywhere else.”)) Finally, given these detailed allegations are sufficient to support an inference Defendant breached its duty of care, Plaintiffs need not rely on a specific “communication or notice” to support an inference of breach. (Dkt. No. 86 at 25.) Accordingly, the Court denies Defendant’s motion on these grounds. C. Causation Defendant argues Plaintiffs do not allege Salesforce’s conduct proximately caused their injuries because the hacks into Salesforce’s clients were “carried out by […] using social engineering” tactics. (Dkt. No. 86 at 26.) Not so. Under California law,
[a]n actor may be liable if the actor’s negligence is a substantial factor in causing an injury, and the actor is not relieved of liability because of the intervening act of a third person if [the] act was reasonably foreseeable at the time of the original negligent conduct. The foreseeability required is of the risk of harm, not of the particular intervening act. Rosencrans v. Domer Images, Ltd., 192 Cal. App. 4th 1072, 1087 (2024) (emphasis added) (cleaned up). As explained above, Plaintiffs’ alleged causal connection is fairly straightforward: Salesforce failed to vet third-party applications and failed to take three steps which would have made OAuth tokens more secure, cybercriminals recognized and exploited that lax security, and Plaintiffs’ injuries ensued. That the cybercriminals exploited that lax security in tandem with another tactic like social engineering does not defeat an inference Salesforce’s actions were a substantial factor in causing Plaintiffs’ injuries because drawing inferences in Plaintiffs’ favor, Plaintiffs allege facts sufficient to support an inference the risk of a data breach by third parties was foreseeable. (See, e.g., Dkt. No. 81 ¶¶ 81 (citing reports stating “60% of the world’s corporate data is stored in the cloud, which makes the cloud a very attractive target for hackers” and “[i]n 2023, over 80% of data breaches involved data stored in the cloud[]”), 82 (citing recent examples of industry data breaches)); Rosencrans, 192 Cal. App. 4th at 1087 (“The foreseeability required is of the risk of harm, not of the particular intervening act.’”) (cleaned up); Baton v. Ledger SAS, 740 F. Supp. 3d 847, 910 (N.D. Cal. Jul. 16, 2024) (collecting “data breaches cases[] where users’ data was stolen by hackers” and the court held “causation exists when protections are inadequate”). D. Damages Defendant contends seven plaintiffs “(Goldstein, Hansch, LaMarre, Kim, Koplitz, Taylor, and Muro) fail to sufficiently plead any cognizable injury” because they merely allege an increased risk of future harm and that they have undertaken monitoring and mitigation efforts. (Dkt. No. 86 at 26.) For example, unlike the other named plaintiffs, these seven plaintiffs do not allege they have seen unauthorized charges or suspicious or fraudulent activity on their bank accounts following the data breach. (See Dkt. No. 81 ¶¶ 111-136, 143-147, 154-158.) As the Ninth Circuit has summarized in an unpublished opinion, “California courts have not considered whether time and money spent on credit monitoring as the result of the theft of personal information are damages sufficient to support a negligence claim.” Ruiz v. Gap, Inc., 380 F. App’x 689, 691 (9th Cir. 2010).
California has long held that “[i]t is fundamental that a negligent act is not actionable unless it results in injury to another.” California also holds that “[n]ominal damages, to vindicate a technical right, cannot be recovered in a negligence action, where no actual loss has occurred.” In addition, in different contexts, the California courts have indicated that the mere threat of future harm is insufficient. Id. (internal citations omitted). The court noted, however, “California has recognized monitoring costs as sufficient to state a negligence claim in the context of exposure to toxic chemicals.” Id. at 691 & n.1. So, the court assumed without deciding “such damages are cognizable” and held the plaintiff “failed to establish a genuine issue of material fact on whether he suffered damages because he offered no evidence on the amount of time and money he spent on the credit monitoring[.]” Id. at 691. Defendant cites various federal district court cases relying on Ruiz and applying similar reasoning. For example, Holly v. Alta Newport Hosp., Inc., 612 F. Supp. 3d 1017 (C.D. Cal. Apr. 10, 2020) held “negligence claims do require actual damages,” then dismissed the plaintiff’s negligence claims because she did not “allege[] how any credit monitoring was reasonable and necessary” and her allegations of emotional distress, damages, and increased risk of identity theft were “conclusory,” “vague,” and “too speculative.” Id. at 1026–27. For those holdings, Holly’s only citation to California law was to the portion of Ruiz (quoted above) which cited a 1958 case holding nominal damages are not cognizable under negligence claims. See id. Similarly, Castillo v. Seagate Tech., LLC, 2016 WL 9280242 (N.D. Cal. Sep. 14, 2016) held “[n]egligence claims […] require […] a cognizable, nonspeculative harm” and dismissed claims by plaintiffs who were “merely considering purchasing” identity protection services and “who claim only that they may incur expenses in the future[.]” Id. at *4. Castillo cited only one California case for this holding, Jordache Enterprises Inc. v. Brobeck, Pheger & Harrison, 18 Cal. 4th 739 (1998). That case, which Ruiz cited, held “nominal damages, speculative harm, and the mere threat of future harm are not actual injury” as the term “actual injury” was used in a statute of limitations for legal malpractice claims. Id. at 742–43. The Court denies Defendant’s motion on this basis. On a motion to dismiss, it is Defendant’s burden to show Plaintiffs do not state a negligence claim as a matter of law. Yet Defendant’s cited cases do not show, as a matter of California law, the seven identified Plaintiffs’ injuries are not cognizable in negligence claims. Even assuming California law requires Plaintiffs to allege a non-speculative risk of future harm to state a negligence claim, as explained above, drawing inferences in Plaintiffs’ favor, Plaintiffs allege facts sufficient to support an inference these seven plaintiffs’ risk of future identity theft, fraud, and misuse is not speculative. III. California Consumer Privacy Act (“CCPA”) Claim (Count II) Plaintiffs’ second cause of action alleges Salesforce violated the CCPA, which provides a cause of action for “any consumer whose […] personal information […] is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of [a] business’ violation of the duty to implement and maintain reasonable security procedures and practices” regarding the personal information. Cal. Civ. Code § 1798.150(a)(1). Defendant argues it is not a “business” under the CCPA. As relevant here, the statute applies to a “business” which (1) “collects consumers’ personal information,” and (2) “alone, or information[.]” Id. § 1798.140(d)(1). The CCPA defines “collects” as, among other things, “obtaining, receiving, or accessing any personal information pertaining to a consumer by any means. This includes receiving information from the consumer, either actively or passively[.]” Id. § 1798.140(f). And the statute further defines “processing” personal information as “any operation or set of operations that are performed on personal information […] whether or not by automated means.” Id. § 1798.140(y). Defendant contends (1) it does not “directly collect consumers’ personal information” and (2) “does not make decisions” about the “purposes and means of processing” that information. (Dkt. No. 86 at 29; Dkt. No. 96 at 12-13 (emphasis added).) The Court disagrees. A. Collects Personal Information Drawing inferences in Plaintiffs’ favor, Plaintiffs allege facts sufficient to support an inference Salesforce “collects” Plaintiffs’ personal information. Plaintiffs allege Salesforce “requires that its clients” provide it with sensitive data, and “Salesforce manages the servers that hold the information provided by its clients.” (Dkt. No. 81 ¶¶ 3, 42.) That alone is sufficient to support an inference Salesforce collects Plaintiffs’ personal information. Defendant’s insistence it did not “directly collect” that information from Plaintiffs’ is unavailing because the CCPA does not require a business “directly” collect information. Rather the CCPA’s definition of “collects” includes “passively” receiving the information and “obtaining, receiving, or accessing [Plaintiffs’] personal information […] by any means.” Cal. Civ. Code § 1798.140(f) (emphasis added). B. Determines the Purposes and Means of Processing Drawing inferences in Plaintiffs’ favor, Plaintiffs also allege facts sufficient to support an inference Salesforce “alone, or jointly with others, determines the purposes and means of processing consumers’ personal information.” Id. § 1798.140(d)(1). Defendant’s argument requires piecing together two parts of the CCPA: the phrase “determines the purposes and means of processing” personal information and the definition of “processing.” So, Defendant’s burden is to show drawing inferences in Plaintiffs’ favor, Plaintiffs’ allegations do not support an inference Salesforce either “alone, or jointly with others, determines the purposes and means” of “any Defendant has not met that burden. Plaintiffs allege Salesforce uses a “shared responsibility model to protect sensitive data.” (Dkt. No. 81 ¶ 6 (cleaned up).) Under that model, “Salesforce determines how that sensitive data is managed and processed, recommends ways to leverage it through the company’s [AI] tools, […] uses it to advance Salesforce’s own […] business objectives.” (Id. ¶ 3.) For example, Plaintiffs quote Salesforce’s website as saying the company uses “predictive AI, generative AI, and agentic AI across the Customer 360 service” in support of the allegation Salesforce “determines […] the manner in which the PII belonging to its corporate clients’ consumers and employees […] is managed, processed, and stored.” (Id. ¶ 44.) Plaintiffs also quote Salesforce’s “Main Services Agreement with its clients” which “obligates Salesforce to,” among other things, “maintain appropriate administrative, physical, and technical safeguards” for customers’ data. (Id. ¶ 45.) These allegations are sufficient to support an inference Salesforce either “alone, or jointly with others, determines the purposes and means” of “any operation […] performed on personal information.” Cal. Civ. Code §§ 1798.140(d)(1), (y). To begin, the phrase “any operation […] performed on personal information” is broad. Id. § 1798.140(y). Plaintiffs plausibly allege Salesforce “perform[s]” many “operation[s]” on personal information, including “manag[ing]” data, “stor[ing]” data, “leverag[ing]” data through three types of AI, and making various “safeguards” for customers’ data. (Dkt. No. 81 ¶¶ 3, 44-45.) Next, Plaintiffs plausibly allege Salesforce “determines the purposes and means of” those operations. Cal. Civ. Code § 1798.140(d)(1). For example, the allegation Salesforce “uses” and “leverages” AI “tools” to “determine[ …] the manner in which PII […] is managed, processed and stored” (Dkt. No. 81 ¶¶ 3, 44) plausibly supports an inference Salesforce determines the “means” of operations such as storage and management. And the allegation Salesforce “design[ed] and administer[ed] its platform infrastructure” (id. ¶ 6) plausibly supports an inference Salesforce determined the means and purposes of various “safeguards” for data. Finally, that Salesforce created the platform infrastructure, coupled with allegations of a “shared responsibility model,” plausibly supports an inference Salesforce made these determinations either “alone, or jointly with others[.]” Cal. Civ. Defendant’s sole cited case, In re Accellion, Inc. Data Breach Litigation, 713 F. Supp. 3d 623 (N.D. Cal. Jan. 29, 2024), is unpersuasive. There, the court held allegations a company “developed, marketed, and sold a file sharing transfer software product […] does not indicate that [the company] would be making decisions about […] data” because “[t]he relevant CCPA inquiry is […] whether Accellion determined how and why Plaintiffs’ PII was transmitted.” Id. at 641 (cleaned up). In re Accellion’s interpretation of the CCPA is unpersuasive. The question is not whether Salesforce made choices about why information was “transmitted” because transmitting is just one type of “operation” which can be “performed on personal information.” Cal. Civ. Code § 1798.140(y). Rather, the question is whether drawing all inferences in Plaintiffs’ favor, Salesforce determined how and why “any operation or set of operations” was “performed on personal information[.]” See id. §§ 1798.140(d)(1), (y) (emphasis added). Defendant has not met its burden of showing the answer to that question is “no,” because it does not engage with the CCPA’s broad definition of “processing” personal information. Accordingly, the Court denies Defendant’s motion as to Plaintiffs’ CCPA claim.7 IV. Illinois Consumer Fraud Act Claim (Count V) Four named plaintiffs are Illinois citizens and allege violations of the Illinois Consumer Fraud and Deceptive Business Practices Act (“ICFA”). The ICFA prohibits “unfair or deceptive acts or practices, including but not limited to the use or employment of any deception fraud, false pretense, false promise, [and] misrepresentation” or “concealment” of “any material fact.” 815 Ill. Comp. Stat § 505/2. Although Plaintiffs’ complaint expressly alleges “Illinois Plaintiffs […] were misled by misrepresentations or omissions,” (Dkt. No. 81 ¶¶ 285-287), Plaintiffs’ Opposition confirms “the gravamen of Plaintiffs’ allegations is Salesforce’s unfair and unlawful failure to secure their PII, not deceptive practices” or fraud. (Dkt. No. 91 at 23.) So, to the extent Plaintiffs’ complaint alleges ICFA fraud-based claims, the Court grants Defendant’s motion as to those claims.
7 Defendant moves to dismiss Plaintiffs’ negligence per se claim based on deficiencies in Separately, Defendant briefly asserts Plaintiffs’ ICFA claim must be dismissed because Plaintiffs’ claim does not have a sufficient connection to Illinois under Avery v. State Farm Mut. Auto Ins. Co., 216 Ill. 2d 100 (2005). There, the Illinois Supreme Court held ICFA does not “apply to fraudulent transactions which take place outside Illinois.” Id. at 185. As the court explained:
a plaintiff may pursue a private cause of action under the Consumer Fraud Act if the circumstances that relate to the disputed transaction occur primarily and substantially in Illinois. In adopting this holding, we recognize that there is no single formula or bright-line test for determining whether a transaction occurs within this state. Rather, each case must be decided on its own facts. Id. at 187. In ascertaining the state in which a transaction took place for ICFA purposes, courts may consider “where a company policy is created,” the plaintiff’s state of residence, where the plaintiff’s relevant actions occurred, where the “[d]amage to” the plaintiff occurred, “the defendant’s principal place of business,” and where “[t]he alleged deception […] occurred.” See id. at 187–90. Here, drawing all inferences in Plaintiffs’ favor, Plaintiffs’ allegations permit an inference the relevant “circumstances that relate to the dispute[ …] occur[red] primarily and substantially in Illinois.” Id. at 187. Four named plaintiffs allege they are Illinois citizens. (Dkt. No. 81 ¶¶ 22, 28, 30, 33.) Additionally, Plaintiffs allege TransUnion’s “principal place of business [is] in Chicago, Illinois.” (See id. ¶¶ 14, 28-35.) So, for the four named plaintiffs who bring ICFA claims, an Illinois resident provided their personal information to an Illinois company. And given Plaintiffs allege TransUnion’s principal place of business is in Chicago, Plaintiffs’ allegations permit an inference the company’s decisions relevant to Plaintiffs’ claims occurred in Illinois. Although Defendant is correct Salesforce’s conduct did not allegedly occur in Illinois, that “there is no single formula or bright-line test” means Defendant’s conduct is not dispositive. See Avery, 216 Ill. 2d at 187; see also id. at 186 (cautioning “focusing solely on [one] fact can create questionable results.”) So, Defendant has not shown, drawing inferences in Plaintiffs’ favor, the relevant circumstances did not occur “primarily and substantially in Illinois” such that Plaintiffs’ Accordingly, the Court grants Defendant’s motion as to Plaintiffs’ fraud-based ICFA claims, but otherwise denies the motion as to the ICFA claims. V. Washington Consumer Protection Act (“WCPA”) Claims (Count VII) Two named plaintiffs, Ms. Taylor and Mr. Carter, are Washington citizens and allege violations of the WCPA, which prohibits “[u]nfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce[.]” RCW 19.86.020. A WCPA claim requires Plaintiffs to “establish five distinct elements: (1) unfair or deceptive act or practice; (2) occurring in trade or commerce; (3) public interest impact; (4) injury to plaintiff in his or her business or property; [and] (5) causation.” Hangman Ridge Training Stables, Inc. v. Safeco Title Ins. Co., 105 Wash. 2d 778, 780 (1986). Regarding the “injury to […] business or property” element, the Washington Supreme Court has explained:
Personal injuries, as opposed to injuries to “business or property,” are not compensable and do not satisfy the injury requirement. Thus, damages for mental distress, embarrassment, and inconvenience are not recoverable under the CPA. However, the injury requirement is met upon proof the plaintiff’s property interest or money is diminished because of the unlawful conduct even if the expenses caused by the statutory violation are minimal. Pecuniary losses occasioned by inconvenience may be recoverable as actual damages. Panag v. Farmers Ins. Co. of Washington, 166 Wash. 2d 27, 57–58 (2009) (internal citations omitted). Additionally, “injury is distinct from damages. Monetary damages need not be proved; unquantifiable damages may suffice,” including unquantifiable harms arising from “loss of frequent flier miles,” “loss of goodwill,” “damage to professional reputation,” and “injury by delay in refund of money.” Id. at 58 (cleaned up). As relevant here, Plaintiffs’ WCPA claims allege Salesforce’s conduct caused various injuries, including (i) invasion of privacy; (ii) theft of their PII; (iii) uncompensated value of their PII; (iv) lost time associated with attempting to mitigate the actual consequences of the Data Breach; (v) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vi) actual misuse of the compromised data; (vii) nominal damages; and (viii) the continued risk to their PII, which is subject to further unauthorized disclosures so long as Salesforce fails to undertake appropriate and adequate measures to protect their PII. (Dkt. No. 81 ¶ 239.) Defendant moves to dismiss the WCPA claims, asserting three of those injuries–“invasion of privacy” and “lost time” and “opportunity costs” from mitigating harms of the data breach–are “not recoverable” under the WCPA.8 (Dkt. No. 86 at 34.) Additionally, Defendant contends Plaintiffs do not sufficiently allege Salesforce’s conduct caused those three injuries because Ms. Taylor “does not allege any theft or misuse or that she was informed that her information was actually compromised instead, her injuries arise from her assumption that her PII was compromised and her decision to take mitigation efforts,” and Mr. Carter “vaguely alleges attempted fraudulent activity without linking it to Salesforce’s actions. (Id. at 34-35 (cleaned up).) The Court agrees, in part, and grants Defendant’s motion as to Plaintiffs’ “invasion of privacy” injury. Plaintiffs’ Opposition does not discuss the “invasion of privacy” injury. (See generally Dkt. No. 91.) As one district court explained, “an invasion of privacy is a ‘personal’ injury, rather than a ‘business or property’ injury […] because the concept of privacy by its very nature is inherently personal, not pecuniary.” Gragg v. Orange Cab Co., 942 F. Supp. 2d 1111, 1118–19 (W.D. Wash. 2013) (quoting Panag, 166 Wash. 2d at 57). So, Defendant has met its burden to show, drawing all inferences in Plaintiffs’ favor, Plaintiffs’ allegations do not plausibly support an inference an “invasion of privacy” injury is cognizable under the WCPA as a matter of law. However, the Court denies Defendant’s motion as to Plaintiffs’ “lost time” and “lost opportunity cost” injuries. Defendant’s motion relies solely on Gragg’s holding an “alleged injury of ‘aggravation and annoyance’ does not support a [W]CPA claim” because “[t]hose feelings are plainly personal injuries, not business or property injuries.” Id. at 1119. But that portion of Gragg is inapposite; Plaintiffs’ allegation they “lost time” and “opportunity cost[s]” mitigating the risks of a data breach are not “feelings” like “aggravation and annoyance.” Id. If anything, the time, 8 Defendant’s motion does not mention Plaintiffs’ other injuries. In Reply, Defendant argues, for the first time, Plaintiffs’ “other alleged damages are either unrecoverable or lack sufficient detail resources, and energy spent mitigating risks like identity theft, fraud, and misuse of one’s personal information are akin to pecuniary injuries or “unquantifiable damages.” See Panag, 166 Wash. 2d at 58 (collecting cases where such damages “may suffice,” including allegations of “deceptive brokerage of frequent flier miles” and “injury by delay in refund of money”). So, Defendant has not met its burden to show, drawing inferences in Plaintiffs’ favor, Plaintiffs’ alleged “lost time” and “lost opportunity cost” injuries are not cognizable as a matter of law. Nor has Defendant shown, drawing inferences in Plaintiffs’ favor, Ms. Taylor and Mr. Carter do not plausibly allege Salesforce’s conduct caused their mitigation-related injuries. As explained above, Plaintiffs’ allegations plausibly support an inference Salesforce’s conduct caused the data breach into Allianz, Farmer, and TransUnion. Mr. Carter alleges he “received a data breach Notice Letter from Allianz in or around July 2025” and, based on the letter, he “reasonably believes that his name, address, date of birth, and SSN were compromised in the Data Breach (all of which he had provided to Allianz).” (Dkt. No. 81 ¶ 105.) Ms. Taylor’s allegations are almost identical, except she received her letter from Allianz a month later. (Id. ¶ 143.) Therefore, Defendant’s insistence Ms. Taylor does not plausibly allege causation because her “injuries arise from her assumption that her PII was compromised” does not persuade; the allegation she received a notice letter following the data breach plausibly supports an inference Salesforce’s conduct caused her mitigation-related injuries. Similarly, although Mr. Taylor does not directly state the attempted fraudulent activity on his account was caused by Salesforce’s data breach, that the activity occurred after the data breach supports an inference of causation. Therefore, drawing inferences in both plaintiffs’ favor, Ms. Taylor and Mr. Carter allege facts sufficient to support an inference Salesforce’s conduct caused them to lose time and opportunity costs in attempting to mitigate the harms of the data breach. So, the Court grants Defendant’s motion as to Plaintiffs’ WCPA claims to the extent they rely on an “invasion of privacy” injury, but otherwise denies Defendant’s motion as to Plaintiffs’ WCPA claims. ] the extent they are based on fraud and Plaintiffs’ WCPA claims to the extent they are based on an 2 “invasion of privacy” injury. The Court otherwise denies the motion. 3 This Order disposes of Docket No. 86. 5 Dated: September 14, 2026 6 7 ne ACQUELINE SCOTT CORLE 8 United States District Judge 9 10 1] a 12
13 14
15 16
Z 18 19 20 21 22 23 24 25 26 27 28
In re Salesforce Customers Security Incident Litigation (In re Salesforce Customers Security Incident Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.