In re: TransUnion, LLC Customer Data Security Breach Litigation

District Court, N.D. Illinois·Decided August 27, 2026·No. 1:25-cv-10320·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION

IN RE: TRANSUNION, LLC CUSTOMER ) DATA SECURITY BREACH LITIGATION ) ) No. 25 C 10320 ) MDL No. 3170 ) Judge Robert W. Gettleman )

MEMORANDUM OPINION & ORDER Plaintiffs in this consolidated class action are individuals who allege that their personally identifiable information (“PII”) was exposed after a data breach. Defendant TransUnion is a credit reporting agency that used defendant Salesforce’s cloud-based customer relationship management (“CRM”) platform to store consumers’ private information, including the PII that was exposed in the data breach. Salesforce moves to sever the claims against it and transfer them to the Northern District of California (Doc. 136). For the reasons below, the court grants the motion in part.1 DISCUSSION A. Motion to Sever Salesforce moves to sever the claims against it under Rule 21. That rule states, among other things, “[t]he court may also sever any claim against a party.” Fed. R. Civ. P. 21. Salesforce argues that the claims against it are discrete and separate from the claims against TransUnion. Because similar claims against Salesforce are already being litigated in the

1 This filing also contains a motion to stay the action against Salesforce pending the resolution of the motion to sever and transfer. This motion was substantively addressed by the court’s minute order staying Salesforce’s responsive pleading deadline (Doc. 157). Northern District of California, Salesforce argues that severance and transfer to that venue will eliminate redundancy and ensure that the claims against it can be resolved in a single, coordinated proceeding.2 See In re Salesforce Customers Security Incidents Litigation, Case No. 3:25-cv-07232-JSC (N.D. Cal. Mar. 30, 2026).

Salesforce also advances a stronger argument: that it was misjoined under Rule 20 in the first place. Salesforce contends that plaintiffs’ claims against it arise from different conduct and different theories of liability from plaintiffs’ claims against TransUnion. According to Salesforce, the allegations against it concern design decisions at the platform level. In contrast, the allegations against TransUnion involve its employees’ vulnerability to phishing techniques.

The bottom line, Salesforce argues, is that because different inquiries and proof are required to adjudicate these claims, joinder was improper under Rule 20. Plaintiffs respond that Salesforce was properly joined as a defendant under Rule 20. Plaintiffs highlight that their complaint alleges a single data breach and that both TransUnion and Salesforce were but-for causes of the data breach. Plaintiffs state that their claims against

Salesforce and TransUnion “arose out of the same transaction [or] occurrence.” Fed. R. Civ. P. 20(a)(2)(A). In addition, plaintiffs identify “question[s] of law or fact common to all defendants [that] will arise in the action.” Fed. R. Civ. P. 20(a)(2)(B). For example, plaintiffs argue that a common question is whether a Salesforce product at issue (Salesforce’s OAuth 2.0 Device Flow protocol) complied with reasonable industry standards. According to plaintiffs, “[t]hat question must be answered both as to Salesforce, whose duty to design a secure platform turned on it, and as to TransUnion, whose duty to vet and monitor third-party platforms hosting consumer data

2 Intervenors, the named plaintiffs in the N.D. Cal. action against Salesforce, largely agree with Salesforce’s position. Doc. 143-2. turned on the same architectural feature.” Thus, plaintiffs argue, Salesforce was properly joined as a defendant because the two requirements of Rule 20(a)(2) were satisfied.

Beyond arguing that joinder was appropriate under Rule 20, plaintiffs argue that severance would be improper for several reasons. First, plaintiffs argue that the Judicial Panel on Multidistrict Litigation (“JPML”) already considered and rejected Salesforce’s request. Second, plaintiffs distinguish this case from the authorities cited by Salesforce on the basis that this case involves “one indivisible injury pleaded under one joint negligence count,” and is thus a “textbook factually-interlinked problem that [the authorities] place beyond the ambit of Rule 21.” Third, plaintiffs argue that severance would destroy the efficiency that the multidistrict

litigation was designed to create. The court begins its analysis by clarifying the relationship between two concepts: misjoinder and severance. Rule 20 provides for the permissive joinder of parties when its requirements are satisfied. Plaintiffs are misjoined when they fail to satisfy either of the requirements of Rule 20. McDowell v. Morgan Stanley & Co., 645 F. Supp. 2d 690, 694 (N.D.

Ill. 2009). When parties are misjoined, Rule 21 authorizes a court to “sever any claim against a party,” and to “on just terms, add or drop a party.” Fed. R. Civ. P. 21; see also Jones v. Culver Franchising Sys., Inc., 12 F. Supp. 3d 1079, 1091 (N.D. Ill. 2013). But Rule 21 also authorizes a court to sever claims when parties are not misjoined. A district court possesses “broad discretion” in determining whether to sever a claim under Rule

21. Rice v. Sunrise Express, Inc., 209 F.3d 1008, 1016 (7th Cir. 2000). “As long as there is a discrete and separate claim, the district court may exercise its discretion and sever it.” Id. A court may sever claims against a party even if Rule 20 is satisfied. Thus, the court’s approach here is not to answer whether Salesforce and TransUnion were properly joined under Rule 20 in the first place, but rather to determine whether the claims against Salesforce should be severed.3, 4

Although the complaint alleges unified “causes of actions” against both Salesforce and TransUnion, the court finds that the complaint asserts separate negligence (and related) claims against Salesforce and TransUnion that arise from distinct alleged conduct. The determination of whether Salesforce and TransUnion are liable to plaintiffs will turn on legal theories and proof that are largely distinct from one another.

The core of plaintiffs’ allegations against Salesforce is that its product allows users to access its CRM platform without having to undergo multi-factor authentication (“MFA”). The core of plaintiff’s claim against Salesforce is that if Salesforce designed its CRM platform better—i.e., required MFA for users to access the CRM—the data breach would never have occurred. This is akin to a design defect claim.5 The proof related to this claim will mostly entail evidence such as emails, reports, code, etc. from within Salesforce that reveal the nature

(and Salesforce’s knowledge) of the alleged defect. In contrast, the core of plaintiffs’ allegations against TransUnion is that the company did not do enough to prevent its employees from being successfully phished or have proper protocols

Free access — add to your briefcase to read the full text and ask questions with AI

In re: TransUnion, LLC Customer Data Security Breach Litigation, (N.D. Ill. 2026).

In re: TransUnion, LLC Customer Data Security Breach Litigation (In re: TransUnion, LLC Customer Data Security Breach Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related