Jimenez Jr. v. OE Federal Credit Union

District Court, N.D. California·Decided August 19, 2025·No. 4:24-cv-02746·Unknown

Opinion

DANIEL JIMENEZ JR., et al., Case No. 24-cv-02746-JST

Plaintiffs, ORDER GRANTING IN PART AND v. DENYING IN PART MOTION TO DISMISS Re: ECF No. 29 Defendant.

Before the Court is Defendant OE Federal Credit Union’s (“OEFCU”) motion to dismiss. ECF No. 29. The Court will grant the motion in part and deny it in part. I. BACKGROUND1 This case involves an alleged ransomware attack on and data breach of OEFCU’s network that resulted in unauthorized access to the personally identifiable information (“PII”) and protected health information (“PHI”) of Plaintiffs Daniel Jimenez Jr., Mark Hendren, Erica Jaramillo, and the class members they seek to represent. ECF No. 16 ¶¶ 1–2. OEFCU is “the country’s largest labor based credit union.” See id. ¶ 24 (internal quotation marks omitted). It maintains the PII/PHI of current and former customers, including: full names; Social Security numbers; dates of birth; bank and/or financial account information; Taxpayer Identification Numbers; driver’s license numbers; usernames and passwords; passport numbers; medical procedure information; clinical or treatment information; medical provider names; and health insurance information. Id. ¶ 25. Plaintiffs “directly or indirectly entrusted” OEFCU with

1 For the purposes of deciding this motion, the Court accepts as true the following factual their PII/PHI. Id. ¶ 26. Between approximately August 19, 2023 and October 29, 2023, OEFCU suffered a targeted data breach impacting at least the above categories of PII/PHI. See id. ¶¶ 33, 44. OEFCU sent impacted individuals of the data breach a notice letter on April 30, 2024, informing them of the breach. Id. ¶ 33. Third-party reports have confirmed that the perpetrators of the cyber-attack were from the cybercriminal group “No Escape.” Id. ¶ 47. Following the breach, OEFCU offered impacted individuals with access to a complimentary 12-month membership with a fraud and identity-monitoring service. Id. ¶¶ 11, 96. Plaintiffs allege that OEFCU failed to comply with the minimum standards of the following frameworks: “the NIST Cybersecurity Framework Version 1.1 (including without limitation PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-5, PR.AC-6, PR.AC-7, PR.AT-1, PR.DS-1, PR.DS-5, PR.PT-1, PR.PT-3, DE.CM-1, DE.CM-4, DE.CM-7, DE.CM-8, and RS.CO-2), and the Center for Internet Security’s Critical Security Controls (CIS CSC), which are all established standards in reasonable cybersecurity readiness,” and that this failure allowed the data breach to occur. Id. ¶ 70. Plaintiffs further allege that OEFCU failed to engage in other security measures, including failing to: “maintain an adequate data security system to reduce the risk of data breaches and cyber-attacks; . . . properly monitor their own data security systems for existing intrusions; . . . ensure that their vendors with access to their computer systems and data employed reasonable security procedures; [and] . . . protect against reasonably anticipated threats or hazards to the security or integrity of electronic PII/PHI.” Id. ¶ 72. Because of the data breach, Plaintiffs “anticipate[] spending considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach. This includes changing passwords, cancelling credit and debit cards, and monitoring their accounts for fraudulent activity.” Id. ¶ 100. Plaintiffs allege that they have been “placed at a present, imminent, immediate, and continuing increased risk of harm from fraud and identity theft” and that they “may also incur out-of-pocket costs for protective measures such as credit monitoring fees, credit report fees, credit freeze fees, and similar costs directly or indirectly related to the Data will continue to suffer from anxiety and emotional distress. Id. ¶ 113. Hendren and Jaramillo additionally allege that they have received an increased number of spam and scamming calls, texts, and/or emails as a result of the data breach. Id. ¶¶ 130, 145. Plaintiffs assert the following causes of action on behalf of themselves and a class of “[a]ll persons identified by Defendant (or its agents or affiliates) as being among those individuals impacted by the Data Breach, including all who were sent a notice of the Data Breach,” id. ¶ 154: negligence; breach of implied contract; invasion of privacy; unjust enrichment; violation of the California Unfair Competition Law (“UCL”), Cal. Bus. & Prof. Code § 17200, et seq.; violation of the California Consumer Privacy Act (“CCPA”), Cal. Civ. Code § 1798.150; violation of the California Customer Records Act (“CCRA”), Cal. Civ. Code § 1798.90, et seq.; and declaratory relief under the Declaratory Judgment Act, 28 U.S.C. §§ 2201, et seq. See id. at 51–75.2 This Court has jurisdiction under 28 U.S.C. § 1332(d)(2). “Dismissal under Rule 12(b)(6) is appropriate only where the complaint lacks a cognizable legal theory or sufficient facts to support a cognizable legal theory.” Mendiondo v. Centinela Hosp. Med. Ctr., 521 F.3d 1097, 1104 (9th Cir. 2008). To survive a motion to dismiss, “a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim to relief that is plausible on its face.’” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Bell Atlantic Corp. v. Twombly, 550 U.S. 544, 570 (2007)). “A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. In determining whether a plaintiff has met the plausibility requirement, a court must “construe the pleadings in the light most favorable to the nonmoving party.” Knievel, 393 F.3d at 1072. A. Negligence “In order to establish negligence under California law, a plaintiff must establish four required elements: (1) duty; (2); breach; (3) causation; and (4) damages.” Ileto v. Glock Inc., 349 F.3d 1191, 1203 (9th Cir. 2003). The parties here dispute the elements of duty, breach, and damages. 1. Duty “The general rule in California is that everyone is responsible for an injury occasioned to another by his or her want of ordinary care or skill in the management of his or her property or person. In other words, each person has a duty to use ordinary care and is liable for injuries caused by his failure to exercise reasonable care in the circumstances.” Cabral v. Ralphs Grocery Co., 51 Cal. 4th 764, 771 (2011) (simplified); see also Cal. Civ. Code § 1714 (“Everyone is responsible, not only for the result of his or her willful acts, but also for an injury occasioned to another by his or her want of ordinary care or skill in the management of his or her property or person.”). Plaintiffs contend that OEFCU stored their PII/PHI without implementing reasonable safeguards against foreseeable risks of unauthorized access and that this led to the data breach that injured them. District courts have routinely found comparable allegations sufficient to establish a duty at the motion to dismiss stage for negligence claims. See, e.g., In re Facebook, Inc., Consumer Priv. User Profile Litig., 402 F. Supp.

Free access — add to your briefcase to read the full text and ask questions with AI

Jimenez Jr. v. OE Federal Credit Union, (N.D. Cal. 2025).

Jimenez Jr. v. OE Federal Credit Union (Jimenez Jr. v. OE Federal Credit Union) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
McCaffrey v. Cronin
295 P.2d 587 (California Court of Appeal, 1956)
Reichert v. General Insurance of America
442 P.2d 377 (California Supreme Court, 1968)
Hill v. National Collegiate Athletic Assn.
865 P.2d 633 (California Supreme Court, 1994)
Mendiondo v. Centinela Hospital Medical Center
521 F.3d 1097 (Ninth Circuit, 2008)
Hernandez v. Hillsides, Inc.
211 P.3d 1063 (California Supreme Court, 2009)
Gonzales v. State of California
68 Cal. App. 3d 621 (California Court of Appeal, 1977)
In Re Facebook Privacy Litigation
791 F. Supp. 2d 705 (N.D. California, 2011)
California Medical Ass'n v. Aetna U.S. Healthcare of California, Inc.
114 Cal. Rptr. 2d 109 (California Court of Appeal, 2001)
Mike Robertson v. Facebook, Inc.
572 F. App'x 494 (Ninth Circuit, 2014)
Skye Astiana v. the Hain Celestial Group
783 F.3d 753 (Ninth Circuit, 2015)
Esg Capital Partners v. Venable LLP
828 F.3d 1023 (Ninth Circuit, 2016)
Kwikset Corp. v. Superior Court
246 P.3d 877 (California Supreme Court, 2011)
Doe v. Beard
63 F. Supp. 3d 1159 (C.D. California, 2014)
T'Bear v. Forman
359 F. Supp. 3d 882 (N.D. California, 2019)