Leonard v. McMenamins Inc

District Court, W.D. Washington·Decided September 13, 2024·No. 2:22-cv-00094·Unknown

Opinion

UNITED STATES DISTRICT COURT AT SEATTLE ANDREW LEONARD et al., CASE NO. C22-0094-KKE

Plaintiffs, ORDER GRANTING DEFENDANT’S v. MOTION FOR SUMMARY JUDGMENT

MCMENAMINS INC,

Defendant.

This is a data breach putative class action. Defendant McMenamins Inc. (“McMenamins”) moves for summary judgment arguing Plaintiffs have failed to put forth evidence sufficient to raise an issue of material fact on the required elements of their claims. The Court agrees. Plaintiffs fail to identify evidence sufficient to raise a triable issue as to whether they have suffered any actionable harms caused by the breach. Several of Plaintiffs’ claims fail for other reasons as well. Defendant’s motion for summary judgment is therefore granted and Plaintiffs’ motion for summary judgment is denied. The parties’ motions in limine and Plaintiffs’ motion for class certification are denied as moot. I. BACKGROUND A. Undisputed Material Facts McMenamins “owns and operates a collection of restaurants, brew pubs, hotels, and entertainment venues throughout Oregon and Washington.” Dkt. No. 93-1 at 2. Plaintiffs are former McMenamins employees who were required to provide certain personally identifiable information (“PII”) to McMenamins in connection with their employment. Dkt. No. 87 at 32. Around December 4, 2021, Conti, a cybercriminal hacker group, exploited a software

vulnerability in a tool used by McMenamins to unlawfully gain access to McMenamins’ systems. Dkt. No. 110 at 11, Dkt. No. 92 at 7. On December 12, 2021, Conti launched a ransomware attack that rendered nearly all of McMenamins’ technology unusable (“Breach”). Dkt. No. 93-1 at 2, 30. A ransom note was left on most computer screens. Dkt. No. 87 at 8, Dkt. No. 93-1 at 111. In that note, Conti stated, “We’ve downloaded a pack of your internal data and are ready to publish it on out [sic] news website if you do not respond.” Dkt. No. 93-1 at 111. McMenamins received “a list of the files that [Conti] claimed they stole[.]” Dkt. No. 87 at 26. McMenamins confirmed that “the listing of files, the listing of directories, [] were correct files and correct directories” and that some of the listed files “contained personal information, HR files, accounting files, things like

that.” Dkt. No. 87 at 17–18. On December 30, 2021, McMenamins sent a notice to affected employees which stated, “hackers stole certain business records, including human resources/payroll data files for previous employees” and that the stolen files contained the following categories of employee information: name, address, telephone number, email address, date of birth, race, ethnicity, gender, disability status, medical notes, performance and disciplinary notes, Social Security number, health insurance plan election, income amount, and retirement contribution amounts. It is possible that the hackers accessed or took records with direct-deposit bank account information, but we do not have any indication that they did, in fact, do so.1 Dkt. No. 93-1 at 5, Dkt. No. 18 ¶ 29. McMenamins never paid the ransom to Conti. Dkt. No. 87 at 25. 1 McMenamins now states “[t]here is no indication that the hackers accessed direct-deposit bank account information.” Dkt. No. 86 at 3. But the deposition testimony they cite for this proposition does not discuss direct-deposit information. Id. (citing Dkt. No. 87 at 28). B. Disputed Material Facts The parties present conflicting evidence via their experts on several aspects of the cause and impact of the Breach. The parties dispute whether the security measures McMenamins had in

place to protect employees’ PII were reasonable. See generally Dkt. No. 110 at 8–12, Dkt. No. 93-1 at 57–60. They also dispute whether McMenamins could or should have taken certain steps to prevent this intrusion or to identify and stop the intrusion sooner. See generally Dkt. No. 110 at 11–12, Dkt. No. 93-1 at 60. McMenamins now also disputes whether Conti actually “exfiltrated” this information, arguing that the evidence only shows Conti could have taken this information, not that they actually did. Dkt. No. 86 at 3, Dkt. No. 105 at 2. Plaintiffs point to other testimony in the record to argue the data was in fact taken by Conti. Dkt. No. 92 at 9 (citing Dkt. No. 93-1 at 5, 108). The parties also dispute whether the PII, assuming Conti took it, was then made available

Free access — add to your briefcase to read the full text and ask questions with AI

Leonard v. McMenamins Inc, (W.D. Wash. 2024).

Leonard v. McMenamins Inc (Leonard v. McMenamins Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Anderson v. Liberty Lobby, Inc.
477 U.S. 242 (Supreme Court, 1986)
Lujan v. National Wildlife Federation
497 U.S. 871 (Supreme Court, 1990)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
British Airways Board, 1 v. The Boeing Company
585 F.2d 946 (Ninth Circuit, 1978)
Johnson v. Nasi
309 P.2d 380 (Washington Supreme Court, 1957)
Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance
719 P.2d 531 (Washington Supreme Court, 1986)
Baughn v. Honda Motor Co.
727 P.2d 655 (Washington Supreme Court, 1986)
Miller v. U.S. Bank
865 P.2d 536 (Court of Appeals of Washington, 1994)
Gingrich v. Unigard Security Insurance
788 P.2d 1096 (Court of Appeals of Washington, 1990)
Michaels v. CH2M Hill, Inc.
257 P.3d 532 (Washington Supreme Court, 2011)
Nord v. Shoreline Savings Ass'n
805 P.2d 800 (Washington Supreme Court, 1991)
Young v. Young
191 P.3d 1258 (Washington Supreme Court, 2008)
TransUnion LLC v. Ramirez
594 U.S. 413 (Supreme Court, 2021)