IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION
IN RE: TRANSUNION, LLC CUSTOMER ) DATA SECURITY BREACH LITIGATION ) ) No. 25 C 10320 ) MDL No. 3170 ) Judge Robert W. Gettleman )
MEMORANDUM OPINION & ORDER Plaintiffs in this consolidated class action are individuals who allege that their personally identifiable information (“PII”) was exposed after a data breach. Defendant TransUnion is a credit reporting agency that used defendant Salesforce’s cloud-based customer relationship management (“CRM”) platform to store consumers’ private information, including the PII that was exposed in the data breach. Salesforce moves to sever the claims against it and transfer them to the Northern District of California (Doc. 136). For the reasons below, the court grants the motion in part.1 DISCUSSION A. Motion to Sever Salesforce moves to sever the claims against it under Rule 21. That rule states, among other things, “[t]he court may also sever any claim against a party.” Fed. R. Civ. P. 21. Salesforce argues that the claims against it are discrete and separate from the claims against TransUnion. Because similar claims against Salesforce are already being litigated in the
1 This filing also contains a motion to stay the action against Salesforce pending the resolution of the motion to sever and transfer. This motion was substantively addressed by the court’s minute order staying Salesforce’s responsive pleading deadline (Doc. 157). Northern District of California, Salesforce argues that severance and transfer to that venue will eliminate redundancy and ensure that the claims against it can be resolved in a single, coordinated proceeding.2 See In re Salesforce Customers Security Incidents Litigation, Case No. 3:25-cv-07232-JSC (N.D. Cal. Mar. 30, 2026).
Salesforce also advances a stronger argument: that it was misjoined under Rule 20 in the first place. Salesforce contends that plaintiffs’ claims against it arise from different conduct and different theories of liability from plaintiffs’ claims against TransUnion. According to Salesforce, the allegations against it concern design decisions at the platform level. In contrast, the allegations against TransUnion involve its employees’ vulnerability to phishing techniques.
The bottom line, Salesforce argues, is that because different inquiries and proof are required to adjudicate these claims, joinder was improper under Rule 20. Plaintiffs respond that Salesforce was properly joined as a defendant under Rule 20. Plaintiffs highlight that their complaint alleges a single data breach and that both TransUnion and Salesforce were but-for causes of the data breach. Plaintiffs state that their claims against
Salesforce and TransUnion “arose out of the same transaction [or] occurrence.” Fed. R. Civ. P. 20(a)(2)(A). In addition, plaintiffs identify “question[s] of law or fact common to all defendants [that] will arise in the action.” Fed. R. Civ. P. 20(a)(2)(B). For example, plaintiffs argue that a common question is whether a Salesforce product at issue (Salesforce’s OAuth 2.0 Device Flow protocol) complied with reasonable industry standards. According to plaintiffs, “[t]hat question must be answered both as to Salesforce, whose duty to design a secure platform turned on it, and as to TransUnion, whose duty to vet and monitor third-party platforms hosting consumer data
2 Intervenors, the named plaintiffs in the N.D. Cal. action against Salesforce, largely agree with Salesforce’s position. Doc. 143-2. turned on the same architectural feature.” Thus, plaintiffs argue, Salesforce was properly joined as a defendant because the two requirements of Rule 20(a)(2) were satisfied.
Beyond arguing that joinder was appropriate under Rule 20, plaintiffs argue that severance would be improper for several reasons. First, plaintiffs argue that the Judicial Panel on Multidistrict Litigation (“JPML”) already considered and rejected Salesforce’s request. Second, plaintiffs distinguish this case from the authorities cited by Salesforce on the basis that this case involves “one indivisible injury pleaded under one joint negligence count,” and is thus a “textbook factually-interlinked problem that [the authorities] place beyond the ambit of Rule 21.” Third, plaintiffs argue that severance would destroy the efficiency that the multidistrict
litigation was designed to create. The court begins its analysis by clarifying the relationship between two concepts: misjoinder and severance. Rule 20 provides for the permissive joinder of parties when its requirements are satisfied. Plaintiffs are misjoined when they fail to satisfy either of the requirements of Rule 20. McDowell v. Morgan Stanley & Co., 645 F. Supp. 2d 690, 694 (N.D.
Ill. 2009). When parties are misjoined, Rule 21 authorizes a court to “sever any claim against a party,” and to “on just terms, add or drop a party.” Fed. R. Civ. P. 21; see also Jones v. Culver Franchising Sys., Inc., 12 F. Supp. 3d 1079, 1091 (N.D. Ill. 2013). But Rule 21 also authorizes a court to sever claims when parties are not misjoined. A district court possesses “broad discretion” in determining whether to sever a claim under Rule
21. Rice v. Sunrise Express, Inc., 209 F.3d 1008, 1016 (7th Cir. 2000). “As long as there is a discrete and separate claim, the district court may exercise its discretion and sever it.” Id. A court may sever claims against a party even if Rule 20 is satisfied. Thus, the court’s approach here is not to answer whether Salesforce and TransUnion were properly joined under Rule 20 in the first place, but rather to determine whether the claims against Salesforce should be severed.3, 4
Although the complaint alleges unified “causes of actions” against both Salesforce and TransUnion, the court finds that the complaint asserts separate negligence (and related) claims against Salesforce and TransUnion that arise from distinct alleged conduct. The determination of whether Salesforce and TransUnion are liable to plaintiffs will turn on legal theories and proof that are largely distinct from one another.
The core of plaintiffs’ allegations against Salesforce is that its product allows users to access its CRM platform without having to undergo multi-factor authentication (“MFA”). The core of plaintiff’s claim against Salesforce is that if Salesforce designed its CRM platform better—i.e., required MFA for users to access the CRM—the data breach would never have occurred. This is akin to a design defect claim.5 The proof related to this claim will mostly entail evidence such as emails, reports, code, etc. from within Salesforce that reveal the nature
(and Salesforce’s knowledge) of the alleged defect. In contrast, the core of plaintiffs’ allegations against TransUnion is that the company did not do enough to prevent its employees from being successfully phished or have proper protocols
Free access — add to your briefcase to read the full text and ask questions with AI
IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION
IN RE: TRANSUNION, LLC CUSTOMER ) DATA SECURITY BREACH LITIGATION ) ) No. 25 C 10320 ) MDL No. 3170 ) Judge Robert W. Gettleman )
MEMORANDUM OPINION & ORDER Plaintiffs in this consolidated class action are individuals who allege that their personally identifiable information (“PII”) was exposed after a data breach. Defendant TransUnion is a credit reporting agency that used defendant Salesforce’s cloud-based customer relationship management (“CRM”) platform to store consumers’ private information, including the PII that was exposed in the data breach. Salesforce moves to sever the claims against it and transfer them to the Northern District of California (Doc. 136). For the reasons below, the court grants the motion in part.1 DISCUSSION A. Motion to Sever Salesforce moves to sever the claims against it under Rule 21. That rule states, among other things, “[t]he court may also sever any claim against a party.” Fed. R. Civ. P. 21. Salesforce argues that the claims against it are discrete and separate from the claims against TransUnion. Because similar claims against Salesforce are already being litigated in the
1 This filing also contains a motion to stay the action against Salesforce pending the resolution of the motion to sever and transfer. This motion was substantively addressed by the court’s minute order staying Salesforce’s responsive pleading deadline (Doc. 157). Northern District of California, Salesforce argues that severance and transfer to that venue will eliminate redundancy and ensure that the claims against it can be resolved in a single, coordinated proceeding.2 See In re Salesforce Customers Security Incidents Litigation, Case No. 3:25-cv-07232-JSC (N.D. Cal. Mar. 30, 2026).
Salesforce also advances a stronger argument: that it was misjoined under Rule 20 in the first place. Salesforce contends that plaintiffs’ claims against it arise from different conduct and different theories of liability from plaintiffs’ claims against TransUnion. According to Salesforce, the allegations against it concern design decisions at the platform level. In contrast, the allegations against TransUnion involve its employees’ vulnerability to phishing techniques.
The bottom line, Salesforce argues, is that because different inquiries and proof are required to adjudicate these claims, joinder was improper under Rule 20. Plaintiffs respond that Salesforce was properly joined as a defendant under Rule 20. Plaintiffs highlight that their complaint alleges a single data breach and that both TransUnion and Salesforce were but-for causes of the data breach. Plaintiffs state that their claims against
Salesforce and TransUnion “arose out of the same transaction [or] occurrence.” Fed. R. Civ. P. 20(a)(2)(A). In addition, plaintiffs identify “question[s] of law or fact common to all defendants [that] will arise in the action.” Fed. R. Civ. P. 20(a)(2)(B). For example, plaintiffs argue that a common question is whether a Salesforce product at issue (Salesforce’s OAuth 2.0 Device Flow protocol) complied with reasonable industry standards. According to plaintiffs, “[t]hat question must be answered both as to Salesforce, whose duty to design a secure platform turned on it, and as to TransUnion, whose duty to vet and monitor third-party platforms hosting consumer data
2 Intervenors, the named plaintiffs in the N.D. Cal. action against Salesforce, largely agree with Salesforce’s position. Doc. 143-2. turned on the same architectural feature.” Thus, plaintiffs argue, Salesforce was properly joined as a defendant because the two requirements of Rule 20(a)(2) were satisfied.
Beyond arguing that joinder was appropriate under Rule 20, plaintiffs argue that severance would be improper for several reasons. First, plaintiffs argue that the Judicial Panel on Multidistrict Litigation (“JPML”) already considered and rejected Salesforce’s request. Second, plaintiffs distinguish this case from the authorities cited by Salesforce on the basis that this case involves “one indivisible injury pleaded under one joint negligence count,” and is thus a “textbook factually-interlinked problem that [the authorities] place beyond the ambit of Rule 21.” Third, plaintiffs argue that severance would destroy the efficiency that the multidistrict
litigation was designed to create. The court begins its analysis by clarifying the relationship between two concepts: misjoinder and severance. Rule 20 provides for the permissive joinder of parties when its requirements are satisfied. Plaintiffs are misjoined when they fail to satisfy either of the requirements of Rule 20. McDowell v. Morgan Stanley & Co., 645 F. Supp. 2d 690, 694 (N.D.
Ill. 2009). When parties are misjoined, Rule 21 authorizes a court to “sever any claim against a party,” and to “on just terms, add or drop a party.” Fed. R. Civ. P. 21; see also Jones v. Culver Franchising Sys., Inc., 12 F. Supp. 3d 1079, 1091 (N.D. Ill. 2013). But Rule 21 also authorizes a court to sever claims when parties are not misjoined. A district court possesses “broad discretion” in determining whether to sever a claim under Rule
21. Rice v. Sunrise Express, Inc., 209 F.3d 1008, 1016 (7th Cir. 2000). “As long as there is a discrete and separate claim, the district court may exercise its discretion and sever it.” Id. A court may sever claims against a party even if Rule 20 is satisfied. Thus, the court’s approach here is not to answer whether Salesforce and TransUnion were properly joined under Rule 20 in the first place, but rather to determine whether the claims against Salesforce should be severed.3, 4
Although the complaint alleges unified “causes of actions” against both Salesforce and TransUnion, the court finds that the complaint asserts separate negligence (and related) claims against Salesforce and TransUnion that arise from distinct alleged conduct. The determination of whether Salesforce and TransUnion are liable to plaintiffs will turn on legal theories and proof that are largely distinct from one another.
The core of plaintiffs’ allegations against Salesforce is that its product allows users to access its CRM platform without having to undergo multi-factor authentication (“MFA”). The core of plaintiff’s claim against Salesforce is that if Salesforce designed its CRM platform better—i.e., required MFA for users to access the CRM—the data breach would never have occurred. This is akin to a design defect claim.5 The proof related to this claim will mostly entail evidence such as emails, reports, code, etc. from within Salesforce that reveal the nature
(and Salesforce’s knowledge) of the alleged defect. In contrast, the core of plaintiffs’ allegations against TransUnion is that the company did not do enough to prevent its employees from being successfully phished or have proper protocols
3 Although a portion of the parties’ briefing concerns the question that this court need not answer (whether joinder was proper in the first place), the content of those arguments is nevertheless relevant to the question that the court does answer: whether the claims against Salesforce should be severed.
4 The court’s understanding is that the JPML foresaw that this court would make such a determination. In re Salesforce, Inc., Customer Data Sec. Breach Litig., 813 F. Supp. 3d 1355, 1360 (J.P.M.L. 2025) (stating that “[s]hould Judge Gettleman find separation and remand of claims against non-TransUnion defendants inappropriate, he may use any number of case management techniques to ensure that litigation of those claims does not conflict with the proceedings against those non-TransUnion defendants pending elsewhere.”)
5 The court recognizes that plaintiffs plead this as a negligence claim, not a products liability claim. in place to identify and respond to an ongoing data breach. This claim, unlike the design defect claim, turns on TransUnion’s employee training protocols and other organization-level IT safeguards. The gap between the claims against Salesforce and TransUnion is illustrated by one of plaintiff’s arguments against transfer (an issue that will be discussed in more detail below).
Plaintiffs argue that “[a]s set forth above and in the Complaint, the material events underlying the data breach occurred in the Northern District of Illinois when cybercriminals contacted TransUnion U.S. consumer support operations (located in Chicago) and instructed two call center agents to download a malicious application.” As the court sees it, the proof surrounding this series of events—the core of the claim against TransUnion—will have little to do with Salesforce. Instead, the proof related to this claim will entail evidence of TransUnion’s employee training and internal data security protocols.
Because the court foresees that the claims against Salesforce and TransUnion will turn on largely separate legal theories and proof, the court finds that it is appropriate to sever the claims against Salesforce. Severance will serve judicial economy because an ongoing action in the Northern District of California contains claims against Salesforce that are largely similar to the claims that plaintiffs allege here. See In re Salesforce Customers Security Incident Litig., No. 3:25-cv-07232-JSC (N.D. Cal. Mar. 30, 2026).
B. Motion to Transfer
Salesforce moves to transfer the severed actions against it to the Northern District of California under 28 U.S.C. § 1404(a). Under 28 U.S.C. § 1404(a), a district court “[f]or the convenience of parties and witnesses, in the interest of justice… may transfer any civil action to any other district or division where it might have been brought.” The court cannot transfer cases that were not originally filed in the Northern District of Illinois under § 1404, because it is precluded from doing so under §1407, the multidistrict litigation statute. In Lexecon Inc. v. Milberg Weiss Bershad Hynes & Lerach, 523 U.S. 26, 41 n.4 (1998), the Supreme Court held that “the statutory language of § 1407 precludes a transferee court from granting any § 1404(a) motion.” Consequently, the court will address the motion to transfer by separate order.
CONCLUSION
For the above reasons, Salesforce’s motion to sever the claims against it and transfer them to the Northern District of California (Doc. 136) is granted in part. The court will sever the claims against Salesforce. Salesforce is directed to, by September 10, 2026, file a table listing: (1) each case in this MDL in which Salesforce is a defendant; and (2) for each of those cases, the transferor court (the original court in which the case was filed). After Salesforce files this table, the court will issue an order addressing the logistics of severing the claims against Salesforce, an order addressing transfer of cases filed in the Northern District of Illinois, and an order addressing transfer of cases originally filed elsewhere and transferred to this court via the JPML. ENTER:
United States District Judge DATE: August 27, 2026