In re Salesforce Customers Security Incident Litigation

District Court, N.D. California·Decided September 14, 2026·No. 3:25-cv-07232·Unknown

Opinion

In re Salesforce Customers Security Incident Case No. 25-cv-07232-JSC Litigation ORDER RE: DEFENDANT’S MOTION Re: Dkt. No. 86

Plaintiffs, on behalf of themselves and putative classes, bring various claims against Defendants arising from an alleged data breach which compromised Plaintiffs’ personal information. (Dkt. No. 81.)1 Defendant Salesforce, Inc. moves to dismiss Plaintiffs’ consolidated complaint, arguing Plaintiffs do not plausibly allege they have Article III standing and Plaintiffs do not state claims for negligence under California law or for violations of California, Illinois, and Washington state statutes. (Dkt. No. 86.) Having carefully considered the parties’ written submissions and having had the benefit of oral argument on September 10, 2026, the Court GRANTS in part and DENIES in part Defendant’s motion for the reasons set forth below. Defendant Salesforce, Inc. is a publicly traded company which provides a software, Salesforce, “the world’s largest customer relationship management (‘CRM’) platform[.]” (Dkt. No. 81 ¶¶ 2, 10.) “Salesforce’s clients use the Salesforce CRM platform to store the information they collect about their customers and employees (e.g., Plaintiffs and Class Members), including on cloud servers maintained by Salesforce.” (Id. ¶ 2.) “Salesforce manages the servers that hold the information provided by its clients” and “Salesforce accepts responsibility for securing the overall ‘infrastructure’ of the Salesforce CRM and platform.” (Id. ¶¶ 6, 42.) “As a condition of doing business, Salesforce requires that its clients entrust it with highly sensitive [personal identifying information (‘PII’)] belonging to their customers[.]” (Id. ¶ 3.) Plaintiffs are customers and employees of three companies “which used Salesforce’s platform to collect, organize, store, and maintain Plaintiffs’ and Class Members’ sensitive data.” (Id. ¶ 15.) Those three companies are: Allianz Life Insurance Company of North America (“Allianz”), Farmers Group, Inc. (“Farmers”), and TransUnion, LLC (“TransUnion”). (Id. ¶¶ 12- 14.) Eight named plaintiffs are Allianz customers or employees, two are Farmers customers or employees, and eight are TransUnion customers or employees. (Id. ¶¶ 18-35.) Since late 2024, a group named “SLH” began hacking into the Salesforce platform by “exploit[ing …] a mechanism built into” the platform known as “OAuth tokens.” (Id. ¶¶ 48, 50.) “Salesforce issues” those OAuth tokens “[w]hen a company connects” a third-party application “to its Salesforce account.” (Id.) Essentially, a third-party application uses OAuth tokens in lieu of a traditional username and password and a token “functions like an all-access keycard: it allows the third-party application to read, export, and in some cases modify data inside Salesforce whenever it needs to, without the user ever having to log in again.” (See id. ¶¶ 48, 50.) Salesforce had “lax security of OAuth tokens.” (Id. ¶ 49.) Specifically, Salesforce “failed to adequately vet” and “audit[]” third-party applications and did not implement “three straightforward” measures which are “standard practice on comparable cloud platforms” and would have made “OAuth tokens more secure.” (Id. ¶¶ 53, 54.) “By designing its platform to be easily accessible to numerous unverified third-party vendors, Salesforce became a target of cybercriminals: a platform with millions of sensitive records and its doors wide open.” (Id. ¶ 49.) The SLH group “recognized that Salesforce had weak access controls related to OAuth tokens” and began “targeting organizations” like Allianz, Farmers, and TransUnion that “used Salesforce as their CRM platform.” (Id. ¶¶ 47, 48.) In broad strokes, SLH’s hack worked as follows. SLH first used a “malicious application” to generate an 8-character code which could “employee by phone, posing as a member of the target company’s IT department or help desk, and instructed the employee to navigate to Salesforce’s verification page and enter the code.” (Id.) If the employee complied and entered the code, the Salesforce platform “issued an access token (i.e., a key) to the attacker[]” which gave the attacker “access to the victim organization’s Salesforce environment with all of the permissions the employee had configured[.]” (Id. ¶ 51.) Ultimately, SLH’s method of exploiting employees and OAuth tokens “bypassed multi-factor authentication entirely,” “established persistent access” to victim organizations’ data, and allowed cybercriminals to “conduct bulk data exports of dozens of Salesforce’s clients data held on Salesforce’s platform” “from approximately March 2025 through at least August 2025[.]” (Id. ¶¶ 51, 52.) “The Data Breach compromised millions of people’s PII.” (Id. ¶ 60.) After bulk downloading data from Salesforce’s clients such as Allianz, Farmers, and TransUnion, SLH “posted dozens of samples or full datasets” of stolen data on the Internet. (Id. ¶ 61.) Allianz, Farmers, and TransUnion have “admitted” the data compromised includes various forms of PII, including Social Security Numbers (“SSN”), names, addresses, dates of birth, and driver’s license numbers. (Id. ¶ 64.) Plaintiffs allege various harms flowing from the data breach. All named plaintiffs allege they (1) received a “data breach Notice Letter from” one of the three hacked companies; (2) are now subject to a “present and continuing risk of fraud, identify theft, and misuse resulting from” the data breach; and (3) to mitigate those risks, they “invested” varying degrees of “time, resources, and energy to safeguard their identities, information, and accounts, and will need to continue to do so for years to come.” (See generally id. ¶¶ 68, 105-209.) Some Plaintiffs allege suspicious, fraudulent, and/or attempted fraudulent activity has occurred on their bank accounts or credit cards, and some allege they were “forced” to get a new credit card. (See, e.g., id. ¶¶ 108, 140-42, 162-164, 168-172, 176-178.) Additionally, Plaintiffs have monitored and mitigated those risks of harm in various ways. Every named plaintiff alleges they have spent time “reviewing financial accounts and credit reports for instances of fraud,” while some allege efforts like “placing a credit freeze,” “changing passwords,” and “setting up virtual cards to replace use of of time they have spent on monitoring and mitigation efforts, and the estimates range anywhere from “over three hours” total to “ten hours per week.” (See, e.g., id. ¶¶ 109, 140, 182.) Defendant moves to dismiss Plaintiffs’ complaint under Federal Rules of Civil Procedure 12(b)(1) and (b)(6). Defendant asserts Plaintiffs have not plausibly alleged they have Article III standing or claims for negligence or for violations of California’s Consumer Privacy Act, Illinois’ Consumer Fraud Act, and Washington’s Consumer Protection Act.2 I. Article III Standing Article III standing requires Plaintiffs allege (1) they suffered an “injury in fact,” (2) “a causal connection between the injury and the conduct complained of,” and (3) the injury will “likely … be redressed by a favorable decision.” Lujan v. Defenders of Wildlife, 504 U.S. 555, 560–61 (1992) (cleaned up). An injury-in-fact must be “concrete and particularized” and “actual or imminent, not conjectural or hypothetical.” Id. at 560 (cleaned up). Additionally, to satisfy the causation prong, the alleged injury must be “fairly … trace[able] to the challenged action of the defendant, and not th[e] result [of] the independent of some third party not before the court.” Id. at 560–61 (quoting Simon v. Eastern Ky. Welfare Rts. Org., 426 U.S. 26, 41–42 (1976)). So, Defendant’s burden is to show drawing all reasonable inferences in Plaintiffs’

Free access — add to your briefcase to read the full text and ask questions with AI

In re Salesforce Customers Security Incident Litigation, (N.D. Cal. 2026).

In re Salesforce Customers Security Incident Litigation (In re Salesforce Customers Security Incident Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

City of Los Angeles v. Lyons
461 U.S. 95 (Supreme Court, 1983)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Monsanto Co. v. Geertson Seed Farms
561 U.S. 139 (Supreme Court, 2010)
Maya v. Centex Corp.
658 F.3d 1060 (Ninth Circuit, 2011)
Jarrow Formulas, Inc. v. Nutrition Now, Inc.
304 F.3d 829 (Ninth Circuit, 2002)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Weirum v. RKO General, Inc.
539 P.2d 36 (California Supreme Court, 1975)
Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance
719 P.2d 531 (Washington Supreme Court, 1986)
Avery v. State Farm Mutual Automobile Insurance
835 N.E.2d 801 (Illinois Supreme Court, 2005)
McCann v. Foster Wheeler LLC
225 P.3d 516 (California Supreme Court, 2010)
Panag v. Farmers Ins. Co. of Washington
204 P.3d 885 (Washington Supreme Court, 2009)
TransUnion LLC v. Ramirez
594 U.S. 413 (Supreme Court, 2021)
Jordache Enterprises Inc. v. Brobeck
18 Cal. 4th 739 (California Supreme Court, 1998)
Rosencrans v. Dover Images, Ltd.
192 Cal. App. 4th 1072 (California Court of Appeal, 2011)
Gragg v. Orange Cab Co.
942 F. Supp. 2d 1111 (W.D. Washington, 2013)
Wildearth Guardians v. Usfs
70 F.4th 1212 (Ninth Circuit, 2023)