In re Under Armour, Inc. Data Incident Litigation
Opinion
IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND
* IN RE UNDER ARMOUR, INC. * DATA INCIDENT LITIGATION * * * Civil Case No.: SAG-25-03857 * * * * * * * * * * * * * * MEMORANDUM OPINION
Four plaintiffs brought three separate actions against Under Armour, Inc. (“UA” or “Defendant”), individually and on behalf of those similarly situated, alleging injuries from a ransomware attack of UA’s computer system, which contained their personal information. ECF 7. The separate actions were consolidated into the instant case, in which eight individuals, bringing suit on behalf of themselves and all others similarly situated (“Plaintiffs”), filed the Consolidated Class Action Complaint (“CCAC”) on March 6, 2026. ECF 19. The CCAC alleges common law negligence and contract claims on behalf of all Plaintiffs, along with a violation of the Maryland Consumer Protection Act on behalf of Plaintiffs who reside in Maryland. Id. UA has filed a Motion to Dismiss the CCAC. ECF 29. Plaintiffs oppose the motion, ECF 32, and UA filed a reply, ECF 33. This Court has reviewed the filings and finds that no hearing is necessary. See Loc. R. 105.6 (D. Md. 2025). For the reasons explained below, the Motion will be granted in part and denied in part. I. BACKGROUND The following facts are derived from Plaintiffs’ CCAC, ECF 19, and are assumed to be true for the purpose of the motion to dismiss. UA is a Maryland-based corporation, and an “inventor, marketer, and distributor of branded athletic performance apparel, footwear, and accessories.” Id. ¶ 22. It “operates a global retail and e‑commerce business, with online stores, mobile apps, loyalty programs, and other digital services.” Id. ¶ 27. In the course of its business, UA “collects and stores vast quantities of Personal Information from customers and employees.” Id. This “Personal Information” includes “email addresses, phone numbers, gender, dates of birth,
passport information, zip codes, location data for cities and regions, deep‑link tracking entries, and identifiers tied to user accounts and transactions.” Id. ¶ 2. The Data Breach In November, 2025, Everest, a ransomware gang, “infiltrated Under Armour’s systems and stole approximately 343 GB of internal company data, including the personal data of over 72 million Under Armour consumers and employees.” Id. ¶ 1. Everest gave UA a seven-day window to meet a ransom demand for the data, id. ¶ 41, and when UA did not pay the ransom, Everest “leaked the unique records of 72 million individuals on the dark web.” Id. ¶ 43. Sources, “including TechCrunch, Have I Been Pwned, BankInfoSecurity, Hackread, SentryBay, and Bitedefender … confirm that a dataset containing information for approximately 72 million Under Armour
accounts has been posted on the dark web and tied to the Everest ransomware group.” Id. ¶ 3. “On information and belief,” Plaintiffs allege that Everest and other actors have: • Advertised Plaintiffs’ and Class Members’ Personal Information on dark‑web forums and marketplaces; • Bundled Plaintiffs’ and Class Members’ stolen Personal Information— including names, email addresses, phone numbers, dates of birth, passport information, location and store‑preference data, and detailed purchase and browsing histories—into saleable “profiles”; and • Sold and distributed those profiles to other criminal actors.
Id. ¶ 64. UA has not provided notice of the breach to any customers or employees whose Personal Information may have been affected. Id. ¶ 44. Plaintiffs’ Injuries Named Plaintiffs are eight former employees or customers of UA, or both. Plaintiffs allege that they suffered the following actual injuries and damages from UA’s data breach: (a) lost time and money related to monitoring [their] accounts and credit reports for fraudulent activity, (b) loss of privacy due to [their] Personal Information being accessed and stolen by cybercriminals; (c) loss of the benefit of the bargain because Under Armour did not adequately protect [their] Personal Information; (d) emotional distress because identity thieves now possess [their] Personal Information; (e) imminent and impending injury arising from the increased risk of fraud and identity theft now that [their] Personal Information has likely been stolen and published on the dark web; (f) diminution in the value of [their] Personal Information, a form of intangible property that Under Armour obtained from [Plaintiffs]; and (g) other economic and non-economic harm.
Id. ¶¶ 157, 167, 179, 192, 207, 217, 229, 240. Further, all named Plaintiffs anticipate “spending considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach.” Id. ¶¶ 155, 165, 177, 190, 203, 215, 226, 238. Seven of the eight named Plaintiffs have already spent time and effort monitoring their accounts and attempting to mitigate harm from the data breach. Id. ¶¶ 154, 164, 176, 186, 199, 224, 236. At various times in December, 2025 and January, 2026, five named Plaintiffs—Boyle, Wilkins, Malone, Ganesh, and Cai—received notice that the Personal Information that they provided to UA was posted on the dark web. Id. ¶¶ 153, 163, 187, 225, 237. In addition, four named Plaintiffs allege additional, individualized injuries: a. In January, 2026, Plaintiff Martin experienced fraudulent activity on her debit card when the card “was charged for a gas station transaction that she did not make.” Id. ¶ 175. She “called her bank to dispute and rescind the charge and was issued a replacement debit card by her bank.” Id. b. Plaintiff Malone has “received multiple emails from various lenders and loan companies stating that she owes them money, even though she has never applied for loans from those companies, and has no prior relationship with them,” and was “notified of a fraudulent attempt to access her direct express following the Data Breach.” Id. ¶ 188. c. An unauthorized individual fraudulently opened a bank account with Bank of America using Plaintiff Costar’s Personal Information without her knowledge or consent. Id. ¶ 200.
An individual also fraudulently applied for an apartment in Pennsylvania using Plaintiff Costar’s Personal Information, opened an Indigo credit card in her name, and “reported income that Plaintiff Costar supposedly earned in Pennsylvania although Plaintiff Costar has never earned any income or lived in Pennsylvania before.” Id. ¶ 201. As a result, Plaintiff Costar’s credit score has dropped significantly. Id. ¶ 202. d. Plaintiff Ganesh has received “a significant increase in unsolicited spam calls.” Id. ¶ 227. The Class Action The eight named Plaintiffs seek to represent a class of “[a]ll individuals residing in the United States whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Nationwide Class”). Id. ¶ 242. Plaintiff Malone, who resides
in Maryland, also seeks to represent a class of “[a]ll individuals residing in the State of Maryland whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Maryland Subclass”). Id. ¶ 242. The Nationwide Class asserts four claims: negligence and negligence per se (Count I), breach of express or implied contract (Count II), breach of fiduciary duty (Count III), and unjust enrichment (Count IV). The Maryland Subclass asserts one claim, a violation of the Maryland Consumer Protection Act (Count V). The classes seek injunctive relief and monetary damages. Id. at 61. II. LEGAL STANDARDS UA has now filed a Motion to Dismiss the CCAC under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). ECF 29. A. Rule 12(b)(1) Standard
Free access — add to your briefcase to read the full text and ask questions with AI
IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND
* IN RE UNDER ARMOUR, INC. * DATA INCIDENT LITIGATION * * * Civil Case No.: SAG-25-03857 * * * * * * * * * * * * * * MEMORANDUM OPINION
Four plaintiffs brought three separate actions against Under Armour, Inc. (“UA” or “Defendant”), individually and on behalf of those similarly situated, alleging injuries from a ransomware attack of UA’s computer system, which contained their personal information. ECF 7. The separate actions were consolidated into the instant case, in which eight individuals, bringing suit on behalf of themselves and all others similarly situated (“Plaintiffs”), filed the Consolidated Class Action Complaint (“CCAC”) on March 6, 2026. ECF 19. The CCAC alleges common law negligence and contract claims on behalf of all Plaintiffs, along with a violation of the Maryland Consumer Protection Act on behalf of Plaintiffs who reside in Maryland. Id. UA has filed a Motion to Dismiss the CCAC. ECF 29. Plaintiffs oppose the motion, ECF 32, and UA filed a reply, ECF 33. This Court has reviewed the filings and finds that no hearing is necessary. See Loc. R. 105.6 (D. Md. 2025). For the reasons explained below, the Motion will be granted in part and denied in part. I. BACKGROUND The following facts are derived from Plaintiffs’ CCAC, ECF 19, and are assumed to be true for the purpose of the motion to dismiss. UA is a Maryland-based corporation, and an “inventor, marketer, and distributor of branded athletic performance apparel, footwear, and accessories.” Id. ¶ 22. It “operates a global retail and e‑commerce business, with online stores, mobile apps, loyalty programs, and other digital services.” Id. ¶ 27. In the course of its business, UA “collects and stores vast quantities of Personal Information from customers and employees.” Id. This “Personal Information” includes “email addresses, phone numbers, gender, dates of birth,
passport information, zip codes, location data for cities and regions, deep‑link tracking entries, and identifiers tied to user accounts and transactions.” Id. ¶ 2. The Data Breach In November, 2025, Everest, a ransomware gang, “infiltrated Under Armour’s systems and stole approximately 343 GB of internal company data, including the personal data of over 72 million Under Armour consumers and employees.” Id. ¶ 1. Everest gave UA a seven-day window to meet a ransom demand for the data, id. ¶ 41, and when UA did not pay the ransom, Everest “leaked the unique records of 72 million individuals on the dark web.” Id. ¶ 43. Sources, “including TechCrunch, Have I Been Pwned, BankInfoSecurity, Hackread, SentryBay, and Bitedefender … confirm that a dataset containing information for approximately 72 million Under Armour
accounts has been posted on the dark web and tied to the Everest ransomware group.” Id. ¶ 3. “On information and belief,” Plaintiffs allege that Everest and other actors have: • Advertised Plaintiffs’ and Class Members’ Personal Information on dark‑web forums and marketplaces; • Bundled Plaintiffs’ and Class Members’ stolen Personal Information— including names, email addresses, phone numbers, dates of birth, passport information, location and store‑preference data, and detailed purchase and browsing histories—into saleable “profiles”; and • Sold and distributed those profiles to other criminal actors.
Id. ¶ 64. UA has not provided notice of the breach to any customers or employees whose Personal Information may have been affected. Id. ¶ 44. Plaintiffs’ Injuries Named Plaintiffs are eight former employees or customers of UA, or both. Plaintiffs allege that they suffered the following actual injuries and damages from UA’s data breach: (a) lost time and money related to monitoring [their] accounts and credit reports for fraudulent activity, (b) loss of privacy due to [their] Personal Information being accessed and stolen by cybercriminals; (c) loss of the benefit of the bargain because Under Armour did not adequately protect [their] Personal Information; (d) emotional distress because identity thieves now possess [their] Personal Information; (e) imminent and impending injury arising from the increased risk of fraud and identity theft now that [their] Personal Information has likely been stolen and published on the dark web; (f) diminution in the value of [their] Personal Information, a form of intangible property that Under Armour obtained from [Plaintiffs]; and (g) other economic and non-economic harm.
Id. ¶¶ 157, 167, 179, 192, 207, 217, 229, 240. Further, all named Plaintiffs anticipate “spending considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach.” Id. ¶¶ 155, 165, 177, 190, 203, 215, 226, 238. Seven of the eight named Plaintiffs have already spent time and effort monitoring their accounts and attempting to mitigate harm from the data breach. Id. ¶¶ 154, 164, 176, 186, 199, 224, 236. At various times in December, 2025 and January, 2026, five named Plaintiffs—Boyle, Wilkins, Malone, Ganesh, and Cai—received notice that the Personal Information that they provided to UA was posted on the dark web. Id. ¶¶ 153, 163, 187, 225, 237. In addition, four named Plaintiffs allege additional, individualized injuries: a. In January, 2026, Plaintiff Martin experienced fraudulent activity on her debit card when the card “was charged for a gas station transaction that she did not make.” Id. ¶ 175. She “called her bank to dispute and rescind the charge and was issued a replacement debit card by her bank.” Id. b. Plaintiff Malone has “received multiple emails from various lenders and loan companies stating that she owes them money, even though she has never applied for loans from those companies, and has no prior relationship with them,” and was “notified of a fraudulent attempt to access her direct express following the Data Breach.” Id. ¶ 188. c. An unauthorized individual fraudulently opened a bank account with Bank of America using Plaintiff Costar’s Personal Information without her knowledge or consent. Id. ¶ 200.
An individual also fraudulently applied for an apartment in Pennsylvania using Plaintiff Costar’s Personal Information, opened an Indigo credit card in her name, and “reported income that Plaintiff Costar supposedly earned in Pennsylvania although Plaintiff Costar has never earned any income or lived in Pennsylvania before.” Id. ¶ 201. As a result, Plaintiff Costar’s credit score has dropped significantly. Id. ¶ 202. d. Plaintiff Ganesh has received “a significant increase in unsolicited spam calls.” Id. ¶ 227. The Class Action The eight named Plaintiffs seek to represent a class of “[a]ll individuals residing in the United States whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Nationwide Class”). Id. ¶ 242. Plaintiff Malone, who resides
in Maryland, also seeks to represent a class of “[a]ll individuals residing in the State of Maryland whose Personal Information was accessed and/or acquired by an unauthorized party as a result of the Data Breach” (the “Maryland Subclass”). Id. ¶ 242. The Nationwide Class asserts four claims: negligence and negligence per se (Count I), breach of express or implied contract (Count II), breach of fiduciary duty (Count III), and unjust enrichment (Count IV). The Maryland Subclass asserts one claim, a violation of the Maryland Consumer Protection Act (Count V). The classes seek injunctive relief and monetary damages. Id. at 61. II. LEGAL STANDARDS UA has now filed a Motion to Dismiss the CCAC under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). ECF 29. A. Rule 12(b)(1) Standard
When a Rule 12(b)(1) motion contests the factual basis for subject matter jurisdiction, the burden of proving subject matter jurisdiction rests with the plaintiff. Richmond, Fredericksburg & Potomac R.R. Co. v. United States, 945 F.2d 765, 768 (4th Cir. 1991). A challenge to jurisdiction may be either facial, i.e., the complaint fails to allege facts upon which subject matter jurisdiction can be based, or factual, i.e., jurisdictional allegations of the complaint are not true. Adams v. Bain, 697 F.2d 1213, 1219 (4th Cir. 1982); see also Kerns v. United States, 585 F.3d 187, 192 (4th Cir. 2009) (same); Richmond, Fredericksburg & Potomac R.R. Co., 945 F.2d at 768 (same). In determining whether jurisdiction exists, the district court regards the pleadings’ allegations as mere evidence and may consider evidence outside the pleadings without converting the proceeding to one for summary judgment. Richmond, Fredericksburg & Potomac R.R. Co., 945 F.2d at 768.
Here, UA challenges Plaintiffs’ standing. Article III of the U.S. Constitution limits the jurisdiction of federal courts to “Cases” and “Controversies.” U.S. Const. art. III, § 2. “One element of the case-or-controversy requirement is that plaintiffs must establish that they have standing to sue.” Clapper v. Amnesty Int’l USA, 568 U.S. 398, 408 (2013) (internal citations and quotation marks omitted). To invoke federal jurisdiction, a plaintiff bears the burden of establishing the minimum requirements of Article III standing. Lujan v. Defs. of Wildlife, 504 U.S. 555, 561 (1992). “[T]he procedural posture of the case dictates the plaintiff’s burden as to standing.” Beck v. McDonald, 848 F.3d 262, 270 (4th Cir. 2017) (citing Lujan, 504 U.S. at 561). “At the pleading stage, general factual allegations of injury resulting from the defendant’s conduct may suffice, for on a motion to dismiss we presume that general allegations embrace those specific facts that are necessary to support the claim.” Id. (quoting Lujan, 504 U.S. at 561) (internal quotation marks omitted). In a class action, “[e]very class member must have Article III standing in order to recover
individual damages.” TransUnion LLC v. Ramirez, 594 U.S. 413, 431 (2021). The Court analyzes standing based on the allegations of personal injury made by the named plaintiffs. Beck, 848 F.3d at 269 (citing Doe v. Obama, 631 F.3d 157, 160 (4th Cir. 2011)). “Without a sufficient allegation of harm to the named plaintiff in particular, plaintiffs cannot meet their burden of establishing standing.” Id. at 270 (quoting Doe, 631 F.3d at 160) (internal quotation marks omitted). B. Rule 12(b)(6) Standard A defendant is permitted to test the legal sufficiency of a complaint by way of a motion to dismiss. See, e.g., In re Birmingham, 846 F.3d 88, 92 (4th Cir. 2017); Goines v. Valley Cmty. Servs. Bd., 822 F.3d 159, 165–66 (4th Cir. 2016). A Rule 12(b)(6) motion constitutes an assertion by a defendant that, even if the facts alleged by a plaintiff are true, the complaint fails as a matter of
law “to state a claim upon which relief can be granted.” Fed. R. Civ. P. 12(b)(6). Whether a complaint states a claim for relief is assessed by reference to the pleading requirements of Rule 8(a)(2), which provides that a complaint must contain a “short and plain statement of the claim showing that the pleader is entitled to relief.” The purpose of the rule is to provide the defendant with “fair notice” of the claims and the “grounds” for entitlement to relief. Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007). In reviewing a Rule 12(b)(6) motion, a court “must accept as true all of the factual allegations contained in the complaint” and must “draw all reasonable inferences [from those facts] in favor of the plaintiff.” E.I. du Pont de Nemours & Co. v. Kolon Indus., Inc., 637 F.3d 435, 440 (4th Cir. 2011) (citations omitted); Houck v. Substitute Tr. Servs., Inc., 791 F.3d 473, 484 (4th Cir. 2015). But if a complaint provides no more than “labels and conclusions” or “a formulaic recitation of the elements of a cause of action,” it is insufficient. Twombly, 550 U.S. at 555. III. DISCUSSION
A. Standing To invoke federal jurisdiction, Plaintiffs must establish the three “irreducible” minimum requirements of Article III standing: (1) injury in fact, (2) causation, and (3) redressability. Lujan, 504 U.S. at 560. At issue here are the first two elements, injury in fact and causation. “To establish injury in fact, a plaintiff must show that he or she suffered ‘an invasion of a legally protected interest’ that is ‘concrete and particularized’ and ‘actual or imminent, not conjectural or hypothetical.’” Spokeo, Inc. v. Robins, 578 U.S. 330, 339 (2016) (quoting Lujan, 504 U.S. at 560). A “‘threatened rather than actual injury can satisfy Article III standing requirements,’” but “not all threatened injuries constitute an injury-in-fact.” Beck, 848 F.3d at 271 (quoting Friends of the Earth, Inc. v. Gaston Copper Recycling Corp., 204 F.3d 149, 160 (4th Cir.
2000) (en banc)). “Although ‘imminence’ is concededly a somewhat elastic concept, it cannot be stretched beyond its purpose, which is to ensure that the alleged injury is not too speculative for Article III purposes.” Id. (quoting Lujan, 504 U.S. at 564–65 n.2) (internal quotation marks omitted). Ultimately, a “threatened injury must be certainly impending to constitute injury in fact.” Clapper, 568 U.S. at 409 (internal citations and quotation marks omitted) (emphasis in original). The causation prong of standing requires that a plaintiff’s alleged injury be “fairly ... traceable to the challenged action of the defendant, and not ... the result of the independent action of some third party not before the court.” Rouse v. Fader, 171 F.4th 272, 280 (4th Cir. 2026) (quoting Lujan, 504 U.S. at 560) (internal quotations omitted). However, causation “does not require that a defendant’s actions ‘be the sole or even immediate cause of [a plaintiff’s] injury.’” Sheppheard v. Morrisey, 143 F.4th 232, 243 (4th Cir. 2025) (quoting Sierra Club v. U.S. Dep’t of the Interior, 899 F.3d 260, 284 (4th Cir. 2018)). The Article III causation burden is “‘relatively modest,’ especially at the ‘motion-to-dismiss stage,’” Lowy v. Daniel Def., LLC, 167 F.4th 175,
195 (4th Cir. 2026) (quoting DiCocco v. Garland, 52 F.4th 588, 592 (4th Cir. 2022)), but a “highly attenuated chain of possibilities” will not support standing. Clapper, 568 U.S. at 410. The Fourth Circuit has specifically addressed standing requirements in data breach suits. It has held that “an alleged injury in an identity theft case is constitutionally sufficient under two recognized circumstances: (1) through actual injury of identity theft; or (2) a threatened injury based on substantial risk of future identity theft that is sufficiently imminent.” In re Marriott Int’l, Inc., Customer Data Sec. Breach Litig., No. 19-MD-2879, 2020 WL 6290670, at *4 (D. Md. Oct. 27, 2020) (citing Hutton v. Nat’l Bd. of Exam’rs in Optometry, Inc., 892 F.3d 613, 622 (4th Cir. 2018)); see also Beck, 848 F.3d at 274. An individual “being subjected to a data breach isn’t in and of itself sufficient to establish Article III standing without a nonspeculative, increased risk of
identity theft.” O’Leary v. TrustedID, Inc., 60 F.4th 240, 244 (4th Cir. 2023). Rather, standing in data breach cases is usually found in cases that include “allegations indicating that some of the stolen data had already been misused, that there was a clear intent to use the plaintiffs’ personal data for fraudulent purposes, or both.” Burger v. Healthcare Mgmt. Sols., LLC, No. CV 23-1215, 2024 WL 473735, at *5 (D. Md. Feb. 7, 2024) (quoting Khan v. Children’s Nat’l Health Sys., 188 F. Supp. 3d 524, 531 (D. Md. 2016) (internal quotations omitted)). Three Fourth Circuit cases illustrate this standard. In Beck v. McDonald, the court held that plaintiffs in two consolidated appeals whose personal information was compromised in data breaches had not shown an Article III injury based on an alleged “increased risk of future identity theft and the cost of measures to protect against it.” 848 F.3d at 267. In the first consolidated case, the defendant’s laptop containing plaintiffs’ private information was stolen by an unauthorized user, and in the second, the defendant’s record boxes containing plaintiffs’ health and private data were lost or stolen. Id. at 267‒268. The court found that the threat of identity theft and misuse of
the personal information was merely speculative because, “even after extensive discovery,” there was “no evidence” that the information had been “accessed or misused or that [the plaintiffs had] suffered identity theft.” Id. at 274. There was also no evidence that the thief even stole the laptop or record boxes with the intent to steal private information. Id. Even though the plaintiffs’ private information was stolen, the Fourth Circuit held that “the mere theft of these items, without more, cannot confer Article III standing.” Id. at 275. On the other hand, in Hutton v. National Board of Examiners in Optometry, Inc., the Fourth Circuit held that the plaintiffs had standing where they were “victims of identity theft traceable to the defendant’s data breach.” O’Leary, 60 F.4th at 244 (citing Hutton, 892 F.3d at 621‒22). There, the named plaintiffs had already suffered identity theft and credit card fraud such that there was
“no need to speculate on whether substantial harm will befall” them. Hutton, 892 F.3d at 622. Specifically, the named plaintiffs alleged that they: (1) “received an unsolicited Chase Amazon Visa credit card that was applied for using her social security number and her maiden name (the name that she had provided to the NBEO in 1998);” (2) “learned that someone had applied for a Chase credit card using her social security number and former married name;” and (3) “received an alert that her credit score had decreased eleven points due to a credit application that was fraudulently filed with Chase, using her address, social security number, and mother’s maiden name.” Id. In contrast to Beck, this information sufficed to allege that the plaintiffs’ “data ha[d] been stolen, accessed, and used in a fraudulent manner.” Id. In Hutton, the Fourth Circuit also found that the plaintiffs had satisfied the causation prong of standing because the complaint “contained sufficient allegations that the [defendant] was a plausible source of the [p]laintiffs’ personal information” that had been fraudulently used. Id. at 623. To reach this conclusion, the court looked to factual allegations that fraudulent credit cards
were applied for using the former surnames of two plaintiffs who had provided the defendant with those names years earlier; a plaintiff “was informed by a credit monitoring service of an effort to open a fraudulent credit card account in her name, using personal information she had previously provided to [the defendant]” years earlier; and “other national optometry organizations do not gather or store Social Security numbers, or have investigated and confirmed that their databases have not been breached.” Id. Thus, the court reasoned, the plaintiffs plausibly alleged that, “amongst the group of optometrists, the [defendant] is the only common source that collected and continued to store social security numbers that were required to open a credit card account, and also stored outdated personal information ... during the relevant time periods.” Id. Most recently, in Holmes v. Elephant Insurance Company, the Fourth Circuit again
addressed standing in data breach cases. 156 F.4th 413 (4th Cir. 2025). In Holmes, four individuals brought suit after hackers acquired their driver’s license numbers from the defendant’s online platform. Id. at 419. Two of the plaintiffs alleged that their driver’s license numbers were posted on the dark web and attributed the listings to the breach of the defendant’s online platform, while the other two plaintiffs alleged only that the unnamed hackers had access to their driver’s license numbers. Id. at 425. The Fourth Circuit held that the plaintiffs whose information had been published on the dark web did have standing because they suffered a concrete harm. Id. Applying TransUnion, the court found that “the public disclosure of private information tort makes concrete the intangible harm suffered when information that the plaintiff would justifiably prefer to tightly control is released into the open.” Id. On the other hand, the plaintiffs whose information was not posted on the dark web did not have standing because “the hackers’ private knowledge of their driver’s license number” did “not bear a close relationship to the harm addressed by the public- disclosure tort.” Id.
UA argues that Plaintiffs fail to establish standing because “‘being subjected to a data breach’ is not ‘in and of itself sufficient to establish Article III standing.’” ECF 29-1 at 6 (quoting O’Leary, 60 F.4th at 244). They contend that five of the eight named Plaintiffs—Boyle, Wilkins, Freifeld, Ganesh, and Cai—fail to allege any actual misuse of their data, id. at 8‒9, and the three named Plaintiffs who do allege misuse of their data—Martin, Costar, and Malone—do not allege an “injury-in-fact fairly traceable to the [data breach].” Id. at 9. 1. Actual Injuries Contrary to UA’s arguments, named Plaintiffs here allege more than the mere occurrence of a breach and the resulting heightened risk of identity theft and fraud. All but one of the eight named Plaintiffs allege sufficient facts to establish standing based on actual injuries traceable to
the breach. Specifically, five of the eight named Plaintiffs allege publication of their private information on the dark web. ECF 19 ¶¶ 153, 163, 187, 225, 237. In Holmes, the Fourth Circuit found this factual allegation sufficient to establish standing when “information that the plaintiff would justifiably prefer to tightly control is released into the open. Though the information need not be embarrassing or salacious, the plaintiff must have good reason to keep it close to the vest. And though the information need not be broadcast to the whole world, it must be accessible to many.” 156 F.4th at 425. The kind of information that Plaintiffs allege was published—“email addresses, phone numbers, gender, dates of birth, passport information, zip codes, location data for cities and regions, deep‑link tracking entries, and identifiers tied to user accounts and transactions,” ECF 19 ¶ 2—is the kind of sensitive private information that Plaintiffs “would justifiably prefer to tightly control,”1 making publication of it on the dark web sufficient to establish injury in fact. See Holmes, 156 F.4th at 425. Further, the Plaintiffs adequately established
causation because they allege facts that “attribute the listings to the ... breach.” Id. at 426. The named Plaintiffs who allege publication of their information on the dark web all allege that the information published was the personal information they shared with UA. As for the remaining three named Plaintiffs who did not allege receiving notice of the publication of their Personal Information on the dark web, two of them—Plaintiffs Martin and Costar—allege actual misuse of their data via fraud and identity theft attempts. “Actual misuse is the keystone of Article III injury in Fourth Circuit data breach case law.” Capiau v. Ascendum Mach., Inc., No. 24-CV-00142, 2024 WL 3747191, at *4 (W.D.N.C. Aug. 9, 2024) (collecting cases). “One way for a data breach plaintiff to establish actual misuse—and thus Article III injury—is to credibly plead ‘that their data [has] been used in a fraudulent manner’ as a
consequence of the breach.” Id. (quoting Stamat v. Grandizio Wilkins Little & Matthews, LLP, No. CV 22-00747, 2022 WL 3919685, at *5 (D. Md. Aug. 31, 2022)); see also Hutton, 892 F.3d at 622. Specifically, Plaintiff Martin experienced a fraudulent charge on her debit card, ECF 19 ¶ 175, and an individual fraudulently opened a bank account, opened a credit card, applied for an apartment, and reported income under Plaintiff Costar’s name. Id. ¶ 200‒202. These allegations of
1 Defendants argue that “the kind of basic demographic and contact information at issue here is non-sensitive and insufficient to support standing.” ECF 29-1 at 10 (emphasis in original). However, in the CCAC, Plaintiffs allege sensitive data, such as passport information, location data, and purchase information, was leaked in the data breach. ECF 19 ¶ 2. Particularly in combination, the data at issue goes beyond “basic demographic and contact information” and is more similar to the leaked driver’s license numbers in Holmes, which were sufficiently sensitive to establish standing when published on the dark web. attempted and actual identity theft plausibly demonstrate actual and fraudulent misuse of Plaintiffs’ data, satisfying injury in fact as to these named Plaintiffs at the pleading stage. Plaintiffs Martin and Costar must also establish causation and traceability. UA argues that Plaintiff Martin cannot do so because she does “not allege that the incident affected debit or
payment card information (or relevant passwords).” ECF 29-1 at 14. UA also argues that Plaintiff Costar cannot establish causation and traceability because she “does not allege she provided Under Armour with the type of personal information needed to open a bank account or credit card, submit an apartment application, or report income.” Id. at 15. However, in the CCAC, Plaintiffs allege that the data breach exposed their “email addresses, phone numbers, gender, dates of birth, passport information, zip codes, location data for cities and regions, deep‑link tracking entries, and identifiers tied to user accounts and transactions.” ECF 19 ¶ 2. Plaintiffs further allege that the “disclosed Personal Information is highly sensitive because it provides a high-resolution map of Plaintiffs’ and Class Members’ identity, contact points, movements, and commercial behavior, which can be (and is) exploited for
numerous identity-related crimes … even in the absence of governmental identification numbers or full payment-card data.” Id. ¶¶ 48‒49. Taking all of these allegations as true, as the Court must at the pleading stage, these named Plaintiffs have plausibly established that their identity theft and fraud was causally related to the UA breach as their sensitive personal information was leaked in the breach and later used for attempted fraud and identity theft. See DiCocco, 52 F.4th at 592 (“At the motion-to-dismiss stage, [the causation] burden is ‘relatively modest,’ ... and lower than the causation showing required to prevail in a tort suit.” (quoting Bennett v. Spear, 520 U.S. 154, 171 (1997))). Accordingly, seven of the eight named Plaintiffs have sufficiently established standing through their allegations of actual injury in fact which are plausibly traceable to UA’s breach. 2. Risk of Future Harms In addition to actual injuries, Plaintiffs can establish standing based on a “substantial risk”
that harm will occur in the future. Beck, 848 F.3d at 275. Plaintiffs allege two forms of imminent, future harms: increased risk of identity theft and fraud, and mitigation expenses they will incur to prevent identity theft and fraud. To establish standing based on these harms, Plaintiffs must allege information that “suffice[s] to push the threatened injury of future identity theft beyond the speculative to the sufficiently imminent.” Id. at 274. For example, a substantial risk exists if the plaintiff alleges that “the data thief intentionally targeted the personal information compromised in the data breaches” or “at least one named plaintiff alleged misuse or access of that personal information by the thief.” Id. (collecting cases). As discussed above, seven of the eight named Plaintiffs have established standing based on actual injury. The remaining named Plaintiff, Plaintiff Freifeld, alleges no actual injury based
on publication of his information on the dark web, fraudulent activity, or identity theft. However, he can establish that a substantial risk of harm will occur because Plaintiffs plausibly allege that “the data thief intentionally targeted the personal information compromised in the data breaches” and “at least one named plaintiff alleged misuse or access of that personal information by the thief.” Id.; see also In re Marriott Int’l, Inc., Customer Data Sec. Breach Litig., 440 F. Supp. 3d 447, 460 (D. Md. 2020) (“The allegations about the targeting of personal information in the cyberattack and the allegations of identity theft by other plaintiffs whose personal information was stolen makes the threatened injury sufficiently imminent. In other words, in these circumstances the remaining Bellwether Plaintiffs do not have to wait until they, too, suffer identity theft to bring their claims to this court.”) Further, while “incurring costs for mitigating measures to safeguard against future identity theft may not constitute an injury-in-fact when that injury is speculative, the Court has recognized
standing to sue on the basis of costs incurred to mitigate or avoid harm when a substantial risk of harm actually exists.” Hutton, 892 F.3d at 623 (first citing Beck, 848 F.3d at 276, then citing Clapper, 568 U.S. at 414 n.5). When an alleged injury is imminent and not speculative, “the costs of mitigating measures to safeguard against future identity theft support the other allegations and together readily show sufficient injury-in-fact to satisfy the first element of the standing to sue analysis.” Id. at 622. Here, because the alleged actual and threatened harm to the named Plaintiffs is sufficiently non-speculative to establish injury in fact, Plaintiffs have also established standing based on the alleged harm of the future time and money they will spend to mitigate the breach. B. Failure to State a Claim UA also seeks to dismiss Plaintiffs’ claims for failure to state a claim upon which relief
can be granted. As an initial matter, the parties disagree on which state law should govern this analysis. UA argues that the Court should apply the laws of the states in which the named Plaintiffs reside: “the laws of Maryland (Malone and Wilkins), Illinois (Freifeld), New Jersey (Cai), North Carolina (Martin), Ohio (Costar), Texas (Ganesh), and Washington D.C. (Boyle).” ECF 29-1 at 19. Plaintiffs contend that “a choice of law analysis is premature, and the Court need not reach it now, but any such analysis demands application of Maryland law.” ECF 32 at 19. This is a diversity action brought under the Class Action Fairness Act (“CAFA”). ECF 19 ¶ 23. “A federal court exercising diversity jurisdiction must apply the choice of law rules of the state in which it sits.” Perini/Tompkins Joint Venture v. Ace Am. Ins. Co., 738 F.3d 95, 100 (4th Cir. 2013). Accordingly, this court must apply Maryland choice of law rules to determine the substantive law that governs Plaintiffs’ claims. Maryland employs the principle of lex loci delicti to determine choice of law in tort actions, which provides that “where the events giving rise to a tort action occur in more than one State, we
apply the law of the State where the injury—the last event required to constitute the tort— occurred.” Erie Ins. Exch. v. Heffernan, 3925 A.2d 636, 648–49 (Md. 2007) (quoting Lab’y Corp. of Am. v. Hood, 911 A.2d 841, 845 (Md. 2006) (internal quotation omitted)). In regard to Plaintiffs’ contract claims, Maryland courts “apply the law of the jurisdiction where the contract was made. This is referred to as the principle of lex loci contractus.” Id. at 648 (quoting Allstate Ins. Co. v. Hart, 611 A.2d 100, 101 (Md. 1992) (internal quotations omitted)). In the context of data breaches, determining these locations for choice of law purposes can be fact-intensive and complex. “Courts have specifically recognized that ‘[t]he data breach context raises unique problems in choice-of-law analysis’ because it is not always clear where the breach occurred and where the harm from the breach can be said to have accrued.” Tjahjono v.
Westinghouse Air Brake Techs. Corp., No. 23-CV-531, 2024 WL 1287085, at *5 (W.D. Pa. Mar. 26, 2024) (quoting In re Mednax Servs., Inc., Customer Data Sec. Breach Litig., 603 F. Supp. 3d 1183, 1199 (S.D. Fla. 2022)). “Gone are the days when all data was stored on local servers or mainframes, whose physical location readily determined the location of the injury—i.e., the breach. Instead, today’s cases often involve data stored on the cloud—an interconnected and redundant storage mechanism distributed across datacenters whose locations may be unknown or even unknowable.” In re Mednax, 603 F. Supp. 3d at 1199. As such, many courts addressing this issue have held that it is inappropriate to decide which law applies at the motion to dismiss stage and before the parties have undertaken discovery. See M.D. Russell Constr., Inc. v. Consol. Staffing, Inc., No. 22-1420, 2023 WL 8798086, at *3 (4th Cir. Dec. 20, 2023) (“District courts in this Circuit thus regularly defer choice-of-law issues until after the parties have completed discovery.”); see also Banner Life Ins. Co. v. Bonney, 11-CV-198, 2011 WL 5027498, at *8 (E.D. Va. Oct. 21, 2011) (noting that many courts defer deciding choice-of-law issues until later in the
proceedings); Malinowski v. Lichter Grp., LLC, Civil No. 14-917, 2015 WL 1129522, at *4 (D. Md. Mar. 11, 2015) (declining to resolve choice-of-law issue at motion-to-dismiss stage because its “fact-intensive” and “context specific” inquiry made it appropriate to defer “until after the parties have engaged in discovery”). Based on the pleadings, the place of the wrong, the last act giving rise to Plaintiffs’ alleged injuries, and the place of contracting are not apparent. Plaintiffs contend that this location should be Maryland, where UA is headquartered and where “its data-security decisions, the systems holding Plaintiffs’ information, and its failure to safeguard that information all centered.” ECF 32 at 19. However, there are no allegations that Plaintiffs’ data was stored in Maryland, the data breach occurred in Maryland, Plaintiffs’ data was published to the dark web from Maryland,
Plaintiffs entered into contractual relationships with UA in Maryland, or that any of the identity theft and fraud occurred in Maryland. Cf. Capiau, 2024 WL 3747191, at *9 (applying North Carolina law under lex loci delicti because “the last act giving rise to Plaintiff’s alleged injuries occurred in North Carolina, where Ascendum is headquartered and where the data breach transpired.”). Further, considering the fact that UA operates a “global” business, ECF 19 ¶ 27, this Court does not have enough factual information at this time to determine that Maryland is the place of the wrong or of contracting with Plaintiffs. Therefore, the Court will apply Maryland law to resolve the pending motion and defer final determination of the choice of law issue until there exists a more fulsome record. See Malinowski, 2015 WL 1129522, at *4 (D. Md. Mar. 11, 2015) (deferring the choice of law issue and applying Maryland law for the purpose of the motion to dismiss). The parties remain free to reraise this issue as appropriate at later stages in this proceeding. a. Negligence and Negligence Per Se (Count I)
In Count I, Plaintiffs allege that UA was negligent when it breached its duty to use reasonable means to safeguard their Personal Information and data from theft and the risk of foreseeable criminal conduct of third parties. Further, Plaintiffs contend that they can establish negligence per se because UA breached its duty under the Federal Trade Commission Act (“FTC Act”), 15 U.S. § 45, “to provide fair and adequate computer systems and data security practices to safeguard Plaintiffs’ and Class Members’ Personal Information.” ECF 19 ¶ 257. UA argues that (1) Plaintiffs have failed to allege an applicable legal duty because there is no “special relationship” between UA and Plaintiffs, (2) a negligence per se action cannot lie for violations of the FTC Act because it contains no private right of action, (3) Plaintiffs do not allege any specific failures that led to the data breach, (4) Plaintiffs fail to allege cognizable damages caused by the data breach,
and (5) Plaintiffs’ claims are barred by the economic loss doctrine. See ECF 29-1 at 19‒26. To state a negligence claim under Maryland law, a plaintiff must prove the following four elements: “(1) that the defendant was under a duty to protect the plaintiff from injury, (2) that the defendant breached that duty, (3) that the plaintiff suffered actual injury or loss, and (4) that the loss or injury proximately resulted from the defendant’s breach of the duty.” Lloyd v. Gen. Motors Corp., 916 A.2d 257, 270–71 (Md. 2007) (citations omitted). i. Economic Loss Doctrine and Intimate Nexus As an initial matter, “Maryland courts do not allow plaintiffs to recover for economic loss under a theory of negligence if they did not suffer physical injury, and if they are not in contractual privity with the defendant, unless the plaintiff can establish the equivalent of a contractual relationship sufficient to establish an ‘intimate nexus’ with the defendant.” In re Marriott Int’l, 2020 WL 6290670, at *6 (first citing Chicago Title Ins. v. Allfirst Bank, 905 A.2d 366, 377–78 (Md. 2006), then citing Balfour Beatty Infrastructure, Inc. v. Rummel Klepper & Kahl, LLP, 155
A.3d 445, 454 (Md. 2017)). “[T]he economic loss doctrine serves as a boundary between contract law, the purpose of which is to enforce the expectations of the parties to an agreement, and tort law, the purpose of which is to protect people and property from foreseeable risks of harm by imposing upon others a duty of reasonable care.” Gordon v. Zeroed-In Tech., LLC, No. CV 23- 3284, 2025 WL 936415, at *10 (D. Md. Mar. 26, 2025) (quoting Cash & Carry Am., Inc. v. Roof Sols., Inc., 117 A.3d 52, 61 (Md. App. 2015) (internal quotation marks omitted)). The Court first addresses whether the economic loss doctrine bars Plaintiffs’ negligence claim. In Gordon, the court also analysed the application of the economic loss doctrine to a putative class’s negligence claim, and, in denying the defendant’s motion to dismiss, found: In the data breach context, courts, albeit outside the Fourth Circuit, have found that an individual’s loss of control over the use of their identity due to a data breach and the accompanying impairment to the value of their [personal information] constitutes non-economic harms. See Flores-Mendez v. Zoosk, Inc., No. 20-04929, 2021 WL 308543, at *3 (N.D. Cal. Jan. 30, 2021) (“Plaintiffs allege their loss of time, risk of embarrassment, and enlarged risk of identity theft as harms and so do not allege pure economic loss.”); Mehta v. Robinhood Fin. LLC, No. 21-CV-01013, 2021 WL 6882377, at *6 (N.D. Cal. May 6, 2021) (finding that the plaintiffs did not solely allege economic loss where they alleged harms derived from the “loss of control over the use of their identity” and right to privacy); Stasi v. Inmediata Health Grp. Corp., 501 F. Supp. 3d 898, 913 (S.D. Cal. 2020) (“[T]ime spent responding to a data breach is a non-economic injury, that when alleged to support a negligence claim, defeats an economic loss doctrine argument.”).
2025 WL 936415, at *11. Similarly, here, the economic loss doctrine does not bar Plaintiffs’ negligence claim because Plaintiffs allege both economic and non-economic harms from the data breach, such as “loss of privacy, loss of control over personal information, loss of time, and other harms.” ECF 32 at 23; see ECF 19 ¶ 12. However, even if the harms Plaintiffs suffered were purely economic, the economic loss doctrine will not bar Plaintiffs’ negligence claim if Plaintiffs sufficiently allege an “intimate
nexus” with UA. See Gordon, 2025 WL 936415, at *11. An “intimate nexus” can be established by allegations of privity between the plaintiffs and defendant, which “ensures that the plaintiff and defendant were sufficiently close to justify finding a tort duty running from the defendant to the plaintiff.” In re Marriott Int’l, 2020 WL 6290670, at *6 (citing Chicago Title Ins, 905 A.2d at 379). “The main consideration is whether there is linking conduct—‘enough to show the defendant knew or should have known of the plaintiff’s reliance.’” Id. at *6 (citing Balfour Beatty Infrastructure, Inc., 155 A.3d at 457). Here, Plaintiffs adequately allege “the most important factor for finding an intimate nexus—that the defendant knew or should have known of the specific plaintiff’s reliance.” Id. at *7. Plaintiffs, who were both employees and customers of UA, allege that they “entrusted Under
Armour with their Personal Information with the understanding that Under Armour would safeguard their information,” ECF 19 ¶ 256; “Under Armour had full knowledge of the sensitivity of the Personal Information and the types of harm that Plaintiffs and Class Members could and would suffer if the Personal Information were wrongfully disclosed,” id. ¶ 258; and “Under Armour knew or should have known of the inherent risks in collecting and storing the Personal Information of Plaintiffs and Class Members, the critical importance of providing adequate security of that Personal Information, and the necessity for encrypting Personal Information stored on Under Armour’s systems.” Id. ¶ 275. Further, in its Privacy Policy and public statements, UA represented that it employs “‘appropriate technical and organizational safeguards’ to protect personal data against unauthorized access, loss, or disclosure,” ECF 19 ¶ 28. Under these circumstances, the Court is satisfied that Plaintiffs have established the required nexus with UA for the purposes of a motion to dismiss. According to the aforementioned
allegations in the CCAC, which the Court accepts as true, UA acknowledged and appreciated the importance of protecting the Personal Information it gathered from its customers and employees in its Privacy Policy. Cf. Burger, 2025 WL 936415, at *7 (“Burger’s assertion that Defendants knew that Medicare beneficiaries relied on them to protect their Private Information finds no support in the alleged facts or analogous cases.”). “Accordingly, there were circumstances ‘that would allow the defendant to predict its liability exposure,’” and, therefore, an intimate nexus between the parties. Gordon, 2025 WL 936415, at *11 (quoting Walpert, Smullian & Blumenthal, P.A. v. Katz, 762 A. 2d 582, 606 (Md. 2000)); see also In re Marriott Int’l, 2020 WL 6290670, at *7 (finding an intimate nexus when the plaintiffs were “not simply members of the public at large, i.e., an indeterminate class of people, but rather a nationwide class of individuals whose personal
information [the defendant] explicitly assumed the responsibility of protecting”). ii. Duty of Care In Maryland, “regardless of any foreseeability, a duty does not exist to the general public, with respect to harm caused by a third party, absent the existence of a special relationship between the person sued and the injured party or the person sued and the third party.” Burger, 2024 WL 473735, at *8 (citing Warr v. JMGM Grp., LLC, 70 A.3d 347, 355 (Md. 2013)). “[A] ‘special duty’ to protect another from the acts of a third party may be established ‘(1) by statute or rule; (2) by contractual or other private relationship; or (3) indirectly or impliedly by virtue of the relationship between the tortfeasor and a third party.’” Remsburg v. Montgomery, 831 A.2d 18, 27 (Md. 2003) (quoting Bobo v. State, 697 A.2d 1371, 1376 (Md. 1997)). The “special relationship” exception to the general bar against liability is “narrowly construed.” Chang-Williams v. Dep’t of the Navy, 766 F. Supp. 2d 604, 620 (D. Md. 2011) (citing Patton v. US. of Am. Rugby Football, 851 A.2d 566, 574 (Md. 2004)).
UA argues that no duty of care exists because there is no “special relationship” between Plaintiffs and UA, and the FTC Act cannot supply a duty of care because it contains no private right of action. These arguments fail because an intimate nexus existed between Plaintiffs and UA. Maryland courts find that “if an intimate nexus was established, a duty of care was owed, and the defendant could be held liable to the plaintiff for pecuniary losses.” Balfour Beatty Infrastructure, Inc., 155 A.3d at 453 (citing Jacques v. First Nat’l Bank of Md., 515 A.2d 756 (Md. 1986)); see also Dwoskin v. Bank of Am., N.A., 850 F. Supp. 2d 557, 571 (D. Md. 2012) (“[A] plaintiff must prove the defendant owed a duty of care by demonstrating an intimate nexus between them.”). Further, despite UA’s arguments, courts in the Fourth Circuit have declined to dismiss negligence and negligence per se claims premised on the FTC Act, even if does not supply a private
right of action, and so Plaintiffs’ plausible allegations that UA violated the FTC Act can also supply the basis for a duty at this stage. See, e.g., Gordon, 2025 WL 936415, at *14 (“Plaintiffs have successfully pled that Defendant's alleged violation of Section 5 of the FTC Act is prima facie evidence of negligence. Accordingly, Plaintiffs have sufficiently pled the element of duty to support a negligence claim under Maryland law.”). iii. Breach Plaintiffs have also plausibly alleged that UA breached its duty of care by “failing to implement and maintain reasonable security measures, failing to detect and stop the intrusion, and failing to prevent exfiltration and public dissemination of Plaintiffs’ and Class Members’ Personal Information.” ECF 19 ¶ 270. Plaintiffs detail the security measures that UA “could and should have implemented” to prevent and detect cyber attacks. See id. ¶¶ 79‒82. These allegations, taken as true, do more than allow “this Court to infer that Under Armour’s security practices were inadequate from the unadorned fact that the incident occurred,” contrary to UA’s argument. See
ECF 29-1 at 24. Accordingly, they are sufficient at this stage to establish the element of breach. iv. Damages UA also argues that Plaintiffs “fail to allege cognizable damages,” and even if this Court is satisfied that Plaintiffs experienced an injury in fact under Article III standing doctrine, “a greater showing is required for pleading damages than for Article III standing.” Id. at 24‒25. At this stage in the proceedings, the Court finds that Plaintiffs’ allegations of damages meet the damages element of their negligence claim. Plaintiffs allege sufficient injuries, as described in detail above in this Court’s standing analysis, including “public disclosure of private information, loss of privacy and control, increased risk of identity‑related harm, mitigation costs and lost time, and emotional distress.” ECF 19 ¶ 273.
As Plaintiffs have adequately alleged all elements of their negligence and negligence per se claim, UA’s Motion to Dismiss is denied as to Count I. b. Breach of Express or Implied Contract (Count II) In Count II, Plaintiffs allege breach of an express2 or implied contract formed when “Plaintiffs and the Class entrusted their Personal Information to Under Armour in connection with
2 Despite styling their claim as a breach of express or implied contract, the CCAC makes no other references to an express contract between UA and Plaintiffs, and all of the allegations under Count II refer only to an implied contract. ECF 19 ¶¶ 277‒85. To the extent that Plaintiffs rely on UA’s Privacy Policy as creating an express contract as they argue in their response brief, ECF 32 at 25, this specific allegation is not present in the CCAC. However, Plaintiffs do reference the Privacy Policy and its assurances, so the Court will consider the Privacy Policy as part of the circumstances which will inform the implied contract analysis. the services Under Armour provides.” ECF 19 ¶ 278. “In so doing, Plaintiffs and the Class entered into implied contracts with Under Armour by which Under Armour agreed to safeguard and protect such information, to keep such information secure and confidential, and to timely and accurately notify Plaintiffs and the Class if their data had been breached and compromised or stolen.” Id. UA
argues that Plaintiffs fail to allege UA intended to be contractually bound or any definite contractual terms that UA agreed to; UA’s Privacy Policy cannot form the basis of a contract; and even if a contract existed, Plaintiffs fail to allege a breach. To allege the existence of an implied contract, as is the case with express contracts, Plaintiffs must demonstrate “mutual assent (offer and acceptance), an agreement definite in its terms, and sufficient consideration.” CTI/DC, Inc. v. Selective Ins. Co. of Am., 392 F.3d 114, 123 (4th Cir. 2004) (citing Peer v. First Fed. Sav. & Loan Ass’n of Cumberland, 331 A.2d 299, 301 (Md. 1975)). “In Maryland, courts infer mutuality of assent to an implied-in-fact contract from the parties’ actions or conduct and from ‘circumstances which, according to common understanding, show a mutual intention on the part of the parties to contract with each other.’” State Constr. Corp.
v. Slone Assocs., Inc., 385 F. Supp. 3d 449, 465 (D. Md. 2019) (quoting Mogavero v. Silverstein, 790 A.2d 43, 53 (Md. Ct. Spec. App. 2002)). “An implied-in-fact agreement is sufficiently ‘definite,’ when the meaning of such terms can be ‘ascertained to a reasonable degree of certainty.’” Innovations Surgery Ctr., P.C. v. United Healthcare Ins. Co., 722 F. Supp. 3d 582, 592 (D. Md. 2024) (quoting Mogavero, 790 A.2d at 50). Where “asserted terms are too vague or nonspecific such that the parties cannot know what they are ‘called upon by its terms to do,’” an implied contract has not been formed. Id. (quoting Mogavero, 790 A.2d at 50). In data breach cases, courts often find that plaintiffs have stated a claim for breach of implied contract based on an implicit agreement that the defendant would safeguard the plaintiffs’ personal information. For example, in Capiau, the court found that an implied contract to protect the plaintiffs’ personal data arose between the plaintiff and defendant where the plaintiffs were employees of the defendant and had shared their personal information as a condition of their employment.3 2024 WL 3747191, at *11. The court found that the “requirement that Plaintiff
provide Defendant his [personal information] vested in Defendant an implicit obligation to adequately safeguard Plaintiffs’ [personal information].” Id. Additionally, the court found that “[e]ven absent their employer-employee relationship, Plaintiff’s provision of [personal information] to Defendant arguably created an implicit obligation on behalf of Defendant to protect Plaintiff’s [personal information].” Id. (citing In re Marriott Int’l, 440 F. Supp. 3d at 463). Courts addressing this issue note that “it is difficult to imagine how, in our day and age of data and identity theft, the mandatory receipt of Social Security numbers or other sensitive personal information would not imply the recipient’s assent to protect the information sufficiently.” Castillo v. Seagate Tech., LLC, No. 16-CV-01958, 2016 WL 9280242, at *9 (N.D. Cal. Sept. 14, 2016) (citing In re Target Corp. Customer Data Sec. Breach Litig., 66 F. Supp. 3d 1154, 1176 (D. Minn. 2014)).
In the CCAC, Plaintiffs sufficiently allege that UA violated an obligation to safeguard Plaintiffs’ Personal Information. Plaintiffs allege that there was an implied agreement, based on UA’s Privacy Policy and the requirement that Plaintiffs provide their Personal Information to work for and make purchases from UA, that UA would take steps to safeguard Plaintiffs’ Personal Information and notify Plaintiffs of any breaches. ECF 19 ¶¶ 278, 282. Plaintiffs allege that UA did neither of those, which, Plaintiffs allege, breached their implied agreement. Id. ¶ 284. These
3 The court in Capiau applied North Carolina contract law. 2024 WL 3747191, at *9. In UA’s Motion to Dismiss, they acknowledge that North Carolina and Maryland courts apply substantively the same law with regard to breach of implied contract claims. ECF 29-1 at 27 n.19. allegations are sufficient at the pleading stage for Plaintiffs’ implied contract claim to survive. Therefore, UA’s Motion to Dismiss Count II is denied. c. Breach of Fiduciary Duty (Count III) In Count III, Plaintiffs allege that UA assumed a fiduciary duty to Plaintiffs and breached
that duty. UA argues that Plaintiffs have failed to allege a fiduciary relationship. To establish a claim of breach of fiduciary duty, a plaintiff must identify: (1) the existence of a fiduciary relationship between the parties, (2) a breach of the duty owed by the fiduciary to the beneficiary; and (3) harm to the beneficiary. Plank v. Cherneski, 231 A.3d 436, 466 (Md. Ct. Spec. App. 2020). Here, Plaintiffs’ claim fails at the first prong. A “cause of action for breach of fiduciary duty may proceed when a plaintiff identifies the appropriate fiduciary relationship, such as principal and agent or trustee and beneficiary.” Giddens v. CorePartners, Inc., Civ. No. 10-3357, 2011 WL 2934855, at *5 (D. Md. July 18, 2011) (citing Kann v. Kann, 690 A.2d 509, 521 (Md. 1997)). Courts addressing claims for breach of fiduciary duty in the data breach context routinely find that “this type of ‘guardian of personal information,’ without more, is ‘not the type of
relationship that historically has been considered fiduciary in character.’” Gordon, 2025 WL 936415, at *16 (quoting In re Premera Blue Cross Customer Data Security Breach Litig., 198 F. Supp. 3d 1183, 1203 (D. Or. 2016)); see also Capiau, 2024 WL 3747191, at *13 (dismissing breach of fiduciary duty under North Carolina law because the employer-employee relationship is “generally not a fiduciary relationship,” even if “Defendant made receipt of Plaintiff’s [personal information] a condition of his employment”). Accordingly, because Plaintiffs have not pleaded facts that establish a fiduciary relationship between themselves and UA, their claim for breach of fiduciary duty fails. Count III is dismissed without prejudice. d. Unjust Enrichment (Count IV) In Count IV, Plaintiffs bring an unjust enrichment claim, in which they allege that “Under Armour enriched itself by saving the costs it reasonably should have expended on data security measures to secure Plaintiffs’ and Class Members’ Personal Information.” ECF 19 ¶ 300. UA
argues that Plaintiffs’ claim fails because they did not adequately allege “that (1) they conferred a ‘benefit’ on Under Armour; (2) Under Armour knew or appreciated the alleged benefit; and (3) Under Armour’s alleged acceptance or retention of this benefit was inequitable.” ECF 29-1 at 34. To plead an unjust enrichment claim, Plaintiffs must adequately allege “(1) a ‘benefit conferred upon the defendant by the plaintiff’; (2) an ‘appreciation or knowledge by the defendant of the benefit’; and (3) the ‘acceptance or retention by the defendant of the benefit under circumstances as to make it inequitable for the defendant to retain the benefit without the payment of its value.’” Mason v. Mach. Zone, Inc., 140 F. Supp. 3d 457, 467 n.17 (D. Md. 2015), aff’d, 851 F.3d 315 (4th Cir. 2017) (quoting Hill v. Cross Country Settlements, LLC, 936 A.2d 343, 351 (Md. 2007)). “In the data breach context, courts have held that ‘an unjust enrichment claim can lie even
where the benefit conferred is not monetary’ and that a defendant ‘cannot be heard to argue that [d]efendant was indifferent to [p]laintiff’s provision of [personal information], since such provision was a condition of [p]laintiff’s employment.’” Midkiff v. Shoe Show, Inc., No. 24-CV- 858, 2026 WL 880210, at *13 (M.D.N.C. Mar. 30, 2026) (quoting Capiau, 2024 WL 3747191, at *12). Further, “[w]here a defendant accepts the benefits accompanying a plaintiff’s [personal information] without implementing safeguards adequate to protect that [personal information], the defendant accepts and retains that [personal information], and the benefit thereof, in inequitable circumstances.” Id. (first citing Capiau, 2024 WL 3747191, at *12, then citing Gordon, 2025 WL 936415, at *16). Plaintiffs have plausibly alleged that, in consideration for their employment and purchases with UA, they were required to provide their Personal Information to UA, which conferred a benefit on UA because “[w]ithout the required transfer of Personal Information, Under Armour could not perform the services it provides.” ECF 19 ¶ 36. UA’s argument that they did not know
or appreciate the benefit is unavailing because the “provision [of Personal Information] was a condition of Plaintiff’s employment.” Capiau, 2024 WL 3747191, at *12; see ECF 32 at 34 n.6. By not implementing adequate safeguards to protect Plaintiffs’ Personal Information, “Defendant thus retained Plaintiffs’ data, and the accompanying benefit, at Plaintiffs’ expense.” Gordon, 2025 WL 936415, at *16; see also In re Capital One Consumer Data Security Breach Litigation, 488 F. Supp. 3d 374, 413 (E.D. Va. 2020) (declining to dismiss an unjust enrichment claim because “[r]etaining the[ ] profits without adequately securing the data would be ‘unjust’”); Capiau, 2024 WL 3747191, at *12 (declining to dismiss an unjust enrichment class where “[d]efendant allegedly accepted the benefits accompanying [p]laintiff’s data without implementing adequate safeguards to protect [p]laintiff’s [data]”). Plaintiffs also allege that if they “had known that Under Armour
would not use adequate data security practices, procedures, and protocols to adequately monitor, supervise, and secure their Personal Information, they would not have entrusted their Personal Information to Under Armour.” ECF 19 ¶ 298. Accordingly, Plaintiffs have adequately pleaded an unjust enrichment claim, and UA’s Motion to Dismiss is denied as to Count IV. e. Violation of the Maryland Consumer Protection Act (Count V) In Count V, the Maryland Subclass asserts a claim for a violation of the Maryland Consumer Protection Act (“MCPA”), Md. Code Ann., Com. Law § 13-408(a). They allege that UA’s “representations regarding the security of personal data, while failing to implement reasonable security measures, constitute unfair or deceptive trade practices under Maryland’s consumer‑protection statutes.” ECF 19 ¶ 307. UA argues that Plaintiffs failed to plead their fraud claim with particularity as required by Fed. R. Civ. P. 9(b) and failed to adequately allege reliance. “To state a claim under the MCPA, a plaintiff must adequately plead that: ‘(1) the defendant engaged in an unfair or deceptive practice or misrepresentation, (2) the plaintiff relied upon the
misrepresentation, and (3) doing so caused the plaintiff actual injury.’” Barr v. Flagstar Bank, FSB, 303 F. Supp. 3d 400, 416 (D. Md. 2018) (citations omitted). Further, Rule 9(b) requires that claims sounding in fraud are plead “with particularity the circumstances constituting fraud.” Fed. R. Civ. P. 9(b); see Willis v. Bank of Am. Corp., No. 13-02615, 2014 WL 3829520, at *22 (D. Md. Aug. 1, 2014) (applying Rule 9(b) to MCPA claims). This “requires the Plaintiffs to allege ‘the time, place, and contents of the false representations, as well as the identity of the person making the misrepresentation and what he obtained thereby.’” In re Marriott Int’l, 440 F. Supp. 3d at 489 (quoting Harrison v. Westinghouse Savannah River Co., 176 F.3d 776, 784 (4th Cir. 1999)). Here, Plaintiffs have pleaded their claim with the requisite particularity and have adequately alleged reliance. Specifically, Plaintiffs allege that UA engaged in the following
“unfair, abusive, and deceptive trade practices”: (a) representing in its privacy policy that it employs “appropriate technical and organizational safeguards” to protect personal data against unauthorized access, loss, or disclosure, when in fact Under Armour failed to implement and maintain reasonable and adequate data security measures; (b) inducing consumers to provide their Personal Information based on the false premise that such information would be adequately secured and protected; and (c) Omitting and concealing material facts regarding the inadequacy of its data security practices, which facts would have been material to consumers in deciding whether to provide their Personal Information to Under Armour.
ECF 19 ¶ 308. Plaintiffs further allege that UA “knew or should have known that its data security practices were inadequate and that its representations regarding data security were misleading,” id. ¶ 312, especially because UA had been the target of a previous large data breach in 2018. Id. ¶ 6. As for reliance, Plaintiffs allege “they would not have provided their Personal Information to Under Armour, had they known the truth about Under Armour’s inadequate data security,” and they “reasonably relied on Under Armour’s representations and omissions regarding its data security practices when they provided their Personal Information to Under Armour.” Id. ¶ 309‒10.
These allegations establish that the Maryland Subclass Plaintiffs have met the particularity requirements of Rule 9(b) and sufficiently alleged reliance on UA’s representations, stating a claim under the MCPA. UA’s Motion to Dismiss as to Count V is denied. IV. CONCLUSION For the reasons stated above, UA’s Motion to Dismiss, ECF 29, is granted in part and denied in part. Count III will be dismissed without prejudice, but the remaining counts will proceed to discovery. A separate Order follows.
Dated: September 11, 2026 /s/ Stephanie A. Gallagher United States District Judge
In re Under Armour, Inc. Data Incident Litigation (In re Under Armour, Inc. Data Incident Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.