Leonard v. McMenamins Inc

District Court, W.D. Washington·Decided September 13, 2024·No. 2:22-cv-00094·Unknown

Opinion

1 2 3

4 5 UNITED STATES DISTRICT COURT 6 WESTERN DISTRICT OF WASHINGTON AT SEATTLE 7 ANDREW LEONARD et al., CASE NO. C22-0094-KKE 8

Plaintiffs, ORDER GRANTING DEFENDANT’S 9 v. MOTION FOR SUMMARY JUDGMENT

10 MCMENAMINS INC,

11 Defendant.

12 This is a data breach putative class action. Defendant McMenamins Inc. (“McMenamins”) 13 moves for summary judgment arguing Plaintiffs have failed to put forth evidence sufficient to raise 14 an issue of material fact on the required elements of their claims. The Court agrees. Plaintiffs fail 15 to identify evidence sufficient to raise a triable issue as to whether they have suffered any 16 actionable harms caused by the breach. Several of Plaintiffs’ claims fail for other reasons as well. 17 Defendant’s motion for summary judgment is therefore granted and Plaintiffs’ motion for 18 summary judgment is denied. The parties’ motions in limine and Plaintiffs’ motion for class 19 certification are denied as moot. 20 I. BACKGROUND 21 A. Undisputed Material Facts 22 McMenamins “owns and operates a collection of restaurants, brew pubs, hotels, and 23 entertainment venues throughout Oregon and Washington.” Dkt. No. 93-1 at 2. Plaintiffs are 24 1 former McMenamins employees who were required to provide certain personally identifiable 2 information (“PII”) to McMenamins in connection with their employment. Dkt. No. 87 at 32. 3 Around December 4, 2021, Conti, a cybercriminal hacker group, exploited a software

4 vulnerability in a tool used by McMenamins to unlawfully gain access to McMenamins’ systems. 5 Dkt. No. 110 at 11, Dkt. No. 92 at 7. On December 12, 2021, Conti launched a ransomware attack 6 that rendered nearly all of McMenamins’ technology unusable (“Breach”). Dkt. No. 93-1 at 2, 30. 7 A ransom note was left on most computer screens. Dkt. No. 87 at 8, Dkt. No. 93-1 at 111. In that 8 note, Conti stated, “We’ve downloaded a pack of your internal data and are ready to publish it on 9 out [sic] news website if you do not respond.” Dkt. No. 93-1 at 111. McMenamins received “a 10 list of the files that [Conti] claimed they stole[.]” Dkt. No. 87 at 26. McMenamins confirmed that 11 “the listing of files, the listing of directories, [] were correct files and correct directories” and that 12 some of the listed files “contained personal information, HR files, accounting files, things like

13 that.” Dkt. No. 87 at 17–18. 14 On December 30, 2021, McMenamins sent a notice to affected employees which stated, 15 “hackers stole certain business records, including human resources/payroll data files for previous 16 employees” and that the stolen files contained 17 the following categories of employee information: name, address, telephone number, email address, date of birth, race, ethnicity, gender, disability 18 status, medical notes, performance and disciplinary notes, Social Security number, health insurance plan election, income amount, and retirement 19 contribution amounts. It is possible that the hackers accessed or took records with direct-deposit bank account information, but we do not have any 20 indication that they did, in fact, do so.1 Dkt. No. 93-1 at 5, Dkt. No. 18 ¶ 29. McMenamins never paid the ransom to Conti. Dkt. No. 87 21 at 25. 22 23 1 McMenamins now states “[t]here is no indication that the hackers accessed direct-deposit bank account information.” Dkt. No. 86 at 3. But the deposition testimony they cite for this proposition does not discuss direct-deposit 24 information. Id. (citing Dkt. No. 87 at 28). 1 B. Disputed Material Facts 2 The parties present conflicting evidence via their experts on several aspects of the cause 3 and impact of the Breach. The parties dispute whether the security measures McMenamins had in

4 place to protect employees’ PII were reasonable. See generally Dkt. No. 110 at 8–12, Dkt. No. 5 93-1 at 57–60. They also dispute whether McMenamins could or should have taken certain steps 6 to prevent this intrusion or to identify and stop the intrusion sooner. See generally Dkt. No. 110 7 at 11–12, Dkt. No. 93-1 at 60. 8 McMenamins now also disputes whether Conti actually “exfiltrated” this information, 9 arguing that the evidence only shows Conti could have taken this information, not that they actually 10 did. Dkt. No. 86 at 3, Dkt. No. 105 at 2. Plaintiffs point to other testimony in the record to argue 11 the data was in fact taken by Conti. Dkt. No. 92 at 9 (citing Dkt. No. 93-1 at 5, 108). 12 The parties also dispute whether the PII, assuming Conti took it, was then made available

13 on the dark web. Dkt. No. 86 at 4, Dkt. No. 92 at 9. From December 28, 2021, to May 2024, 14 McMenamins’ data breach consultants “conducted threat intelligence monitoring and dark web 15 scans[.]” Dkt. No. 86 at 4, Dkt. No. 110 at 12, Dkt. No. 93-1 at 113–36 (reports from February 16 2022 to October 2022). The weekly scan reports in the record show the consultants “monitor[ed] 17 deep/dark web forums, marketplaces, paste sites, and threat actor chatrooms for 68 keywords 18 enumerated for McMenamins. Keywords include 31 domains, 33 IP addresses, three free text 19 strings, and one URL.” Dkt. No. 93-1 at 133. Plaintiffs point to two of these notices as evidence 20 that the PII from the Breach was on the dark web. Dkt. No. 92 at 9. Specifically, Plaintiffs rely 21 on the notices stating: 22 On September 25, 2022, an offer for McMenamins’ server information was posted on the online market “market_jmia” for $11 USD.…No sensitive 23 information related to McMenamins was found in the post. Dkt. No. 93-1 at 116. 24 1 On February 8, [2022,] the email generalinfo@mcmenamins[.]com was listed in a market for leaked databases via Telegram. The same email was 2 listed in a market of leaked databases via DB Leaks, a channel that provides compromised databases, on February 28. There were no associated 3 passwords present. Id. at 135. In contrast, McMenamins cites the same scans to argue that, despite more than three 4 years of monitoring, none of Plaintiffs’ PII was ever detected on the dark web. Dkt. No. 105 at 2. 5 Finally, the parties dispute whether Plaintiffs’ PII was ever actually misused in a manner 6 that resulted in cognizable harms. Plaintiffs allege that since the Breach, they each suffered the 7 following “actual misuse of their PII”: 8 9 • Plaintiff Leonard “suffered a $400 fraudulent credit card charge” 10 • Plaintiff Frazier “suffered a fraudulent address change with his automobile creditor, as well as an unauthorized attempt to access his email account” 11 • Plaintiff Frye “suffered a drop in his credit score, as well as an increase in robocalls and spam texts” 12 Dkt. No. 92 at 10 (internal quotations omitted). In a notice of supplemental facts filed on 13 September 6, 2024, Plaintiff Frazier submitted two emails purporting to show that “loan 14 applications had been submitted in his name, one of which was approved.” Dkt. No. 112 ¶ 2 (citing 15 Dkt. No. 113). Plaintiffs also allege the value of their PII has been diminished, they have had to 16 mitigate the risk of future harm, and that they have suffered emotional distress. Dkt. No. 92 at 18– 17 23. 18 C. Procedural History 19 On January 28, 2022, Plaintiffs sued McMenamins. Dkt. No. 1. On May 13, 2022, 20 Plaintiffs filed the operative amended class action complaint. Dkt. No. 18. Plaintiffs’ claims seek 21 two types of relief: “(1) retrospective damages resulting from the theft of their PII, and 22 23 24 1 (2) prospective injunctive relief requiring McMenamins to strengthen its data security systems and 2 procedures.”2 Dkt. No. 24 at 4. 3 McMenamins moved to dismiss under Federal Rule of Civil Procedure 12(b)(1) for lack of 4 subject matter jurisdiction, arguing that Plaintiffs lacked standing to assert their damages claims 5 because their alleged harms were too speculative. Dkt. No. 24 at 4.

Free access — add to your briefcase to read the full text and ask questions with AI

Leonard v. McMenamins Inc, (W.D. Wash. 2024).

Leonard v. McMenamins Inc (Leonard v. McMenamins Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Anderson v. Liberty Lobby, Inc.
477 U.S. 242 (Supreme Court, 1986)
Lujan v. National Wildlife Federation
497 U.S. 871 (Supreme Court, 1990)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
British Airways Board, 1 v. The Boeing Company
585 F.2d 946 (Ninth Circuit, 1978)
Johnson v. Nasi
309 P.2d 380 (Washington Supreme Court, 1957)
Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance
719 P.2d 531 (Washington Supreme Court, 1986)
Baughn v. Honda Motor Co.
727 P.2d 655 (Washington Supreme Court, 1986)
Miller v. U.S. Bank
865 P.2d 536 (Court of Appeals of Washington, 1994)
Gingrich v. Unigard Security Insurance
788 P.2d 1096 (Court of Appeals of Washington, 1990)
Michaels v. CH2M Hill, Inc.
257 P.3d 532 (Washington Supreme Court, 2011)
Nord v. Shoreline Savings Ass'n
805 P.2d 800 (Washington Supreme Court, 1991)
Young v. Young
191 P.3d 1258 (Washington Supreme Court, 2008)
TransUnion LLC v. Ramirez
594 U.S. 413 (Supreme Court, 2021)