Malvitz v. Fincantieri Marine Group, LLC

District Court, District of Columbia·Decided June 12, 2025·No. Civil Action No. 2024-0238·Published

Opinion

UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA

CRYSTAL MALVITZ AND CHRISTOPHER FREDRICKSON,

Plaintiffs,

Civil Action No. 24-cv-238 (TSC)

v.

FINCANTIERI MARINE GROUP, LLC.

Defendant.

MEMORANDUM OPINION

Plaintiffs Crystal Malvitz and Christopher Fredrickson bring this class action, as individuals and on behalf of all others similarly situated, against Defendant Fincantieri Marine Group, LLC (“Defendant”), a company that builds and repairs maritime vessels. Plaintiffs assert claims for negligence, breach of implied contract, and unjust enrichment. Am. Compl., ECF No. 8. Defendant moves to dismiss for lack of subject matter jurisdiction under Federal Rule of Civil Procedure 12(b)(1) and failure to state a claim under Federal Rule of Civil Procedure 12(b)(6). Def.’s Mot. to Dismiss Am. Compl., ECF No. 9-1 (“MTD”). For the reasons set forth below, the court will GRANT in part and DENY in part Defendant’s motion.

I. BACKGROUND

A. Defendant’s Cybersecurity Practices and Data Breach Plaintiffs are Defendant’s former employees or benefit recipients. Am. Compl. ¶ 25. They provided personally identifiable information (“PII”) to Defendant as a condition of employment and/or employment-related benefits. Id. ¶ 2. Defendant allegedly made “promises and representations” that PII would be “kept safe, confidential, and that the privacy of that information would be maintained, and that Defendant would delete any sensitive information after it was no longer required to maintain it.” Id. ¶ 28. Defendant’s website stated that it stored PII “behind secured networks,” only provided access to “a limited number of persons,” and “encrypted” PII “via Secure Socket Layer (‘SSL’) technology.” Id. ¶ 29. Defendant also represented that it “use[d] regular Malware Scanning” to identify “security holes and known vulnerabilities.” Id.

On or about April 12, 2023, however, Defendant became “aware of a cyberattack” on its computer systems. Id. ¶ 36. It determined that “there was unauthorized access to certain systems . . . between April 6, 2023, and April 12, 2023,” resulting in “unauthorized acquisition” of more than sixteen thousand individuals’ PII. Id. ¶¶ 36, 46. The data stolen during the attack included Plaintiffs’ “name[s] . . . date[s] of birth, Social Security number[s], date[s] of service, [insurance] participant ID[s], and member number[s].” Id. ¶ 36. Defendant sent a “Notice of Security Incident letter” (the “Notice Letter”) to Plaintiffs on January 5, 2024, which offered “24 months of identity monitoring services.” Id. ¶¶ 36–37, 63, 139, 149.

Plaintiffs allege that, despite Defendant’s “promises and representations,” id. ¶ 28, it failed to implement “reasonable security procedures and practices” to prevent or promptly detect the cyberattack and stored data in unencrypted files, id. ¶¶ 37–40, 67. Plaintiffs contend that Defendant’s practices did not comply with the Federal Trade Commission’s (“FTC”) guidelines for protecting personal information, such as using “an intrusion detection system” to promptly identify a breach, monitoring suspicious activity or large data transmissions, developing a data- breach response plan, “properly dispos[ing] of [PII] that is no longer needed,” limiting “access to sensitive data[,]” using “industry-tested methods for security[,]” and verifying the security measures used by third-party service providers. Id. ¶¶ 81–83, 86. Plaintiffs also allege that Defendant “failed to follow [] industry best practices,” such as “strong passwords;” “firewalls, antivirus, and anti-malware software; encryption, making data unreadable without a key; multifactor authentication; backup data and limiting which employees can access sensitive data.” Id. ¶ 90. According to Plaintiffs, Defendant knew or should have known that their PII “would be targeted by cybercriminals” because data breaches are “widespread” and a dark web marketplace exists for PII, particularly social security numbers. Id. ¶¶ 41, 56–60, 69–73. Plaintiffs also challenge Defendant’s response to the cyberattack because the Notice Letter failed to disclose the “root cause” of the breach or “the remedial measures” taken to prevent another breach. Id. ¶¶ 37– 39. B. Plaintiffs’ Alleged Injuries Plaintiffs claim that, as a result of Defendant’s insufficient cybersecurity practices and the data breach, they suffered “actual injuries and damages.” Id. ¶ 94. Specifically, “(i) invasion of privacy; (ii) theft of their PII; (iii) lost or diminished value of PII; (iv) lost time and opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (v) lost opportunity costs associated with attempting to mitigate the actual consequences of the Data Breach; (vi) statutory damages; [and] (vii) nominal damages.” Id.

Malvitz and Fredrickson each identify their own harms. Malvitz receives benefits from Defendant because her spouse is a current employee. Id. ¶ 135. In general, she is “very careful about sharing her sensitive” information and “never knowingly” provides her unencrypted PII over the internet. Id. ¶ 137. Defendant obtained and retained her PII in connection with “employment- related benefits.” Id. ¶ 135. After receiving the Notice Letter, she experienced “an increase in spam calls, texts, and/or emails.” Id. ¶¶ 139, 142. She took steps to mitigate the harms from the data breach, such as monitoring her accounts and purchasing mitigation tools. Id. ¶¶ 139–40. She claims she has suffered “fear, anxiety, and stress . . .” from the increased exposure of her PII. Id. ¶ 142–44.

Fredrickson worked for Defendant intermittently from 2016 to 2023. Id. ¶ 147. He was very “cautious” and “careful about sharing his PII.” Id. ¶ 153. After he received the Notice Letter, he “suffered actual fraudulent misuse of his PII.” Id. ¶¶ 149–51. On or around April 18, 2024, “third party criminal actors” used his credit card for a “fraudulent purchase of $1,145.13 . . .” Id. ¶ 151. Fredrickson had to acquire “a new credit card” and “anticipates spending considerable time and money” to monitor his accounts and address any future harms. Id. ¶¶ 151–152, 158. Frederickson alleges that, as a result of the data breach, he “suffered injury from a loss of privacy” and “fear, anxiety, and stress.” Id. ¶¶ 155–159. C. Procedural History Malvitz filed the Complaint on January 26, 2024, and amended as of right on May 2, 2024.

ECF Nos. 2, 8. Fredrickson “voluntarily dismissed” a separate class action that he had filed against Defendant and joined as a named Plaintiff in the Amended Complaint. MTD at 3 (citing Fredrickson v. Fincantieri Marine Grp., LLC, Case No. 1:24-cv-0037-TSC (D.D.C. Feb. 7, 2024), ECF No. 1). Plaintiffs sue on behalf of themselves and a nationwide class of individuals, pursuant to Federal Rule of Civil Procedure 23. Am. Compl. ¶ 164. Plaintiffs proposed class definition is: “All individuals in the United States whose PII was impacted as a result of the Data Breach announced by Defendant in January 2024.” Id. Plaintiffs have not yet moved for class certification. Their Amended Complaint asserts claims for negligence, breach of implied contract, and unjust enrichment stemming from Defendant’s failure to protect Plaintiffs’ PII. Id. ¶¶ 176– 241. Defendant moves to dismiss under Federal Rule of Civil Procedure 12(b)(1) for lack of subject matter jurisdiction and Rule 12(b)(6) for failure to state a claim. MTD at 1.

II. LEGAL STANDARD

Free access — add to your briefcase to read the full text and ask questions with AI

Malvitz v. Fincantieri Marine Group, LLC, (D.D.C. 2025).

Malvitz v. Fincantieri Marine Group, LLC (Malvitz v. Fincantieri Marine Group, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Klaxon Co. v. Stentor Electric Manufacturing Co.
313 U.S. 487 (Supreme Court, 1941)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Kokkonen v. Guardian Life Insurance Co. of America
511 U.S. 375 (Supreme Court, 1994)
Raines v. Byrd
521 U.S. 811 (Supreme Court, 1997)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Thomas, Oscar v. Principi, Anthony
394 F.3d 970 (D.C. Circuit, 2005)
Novak v. Capital Management & Development Corp.
452 F.3d 902 (D.C. Circuit, 2006)
American Nat. Ins. Co. v. FDIC
642 F.3d 1137 (D.C. Circuit, 2011)
Henry S. Bloomgarden v. Charles B. Coyer
479 F.2d 201 (D.C. Circuit, 1973)
Richard Dominguez v. Ual Corporation
666 F.3d 1359 (D.C. Circuit, 2012)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
News World Communications, Inc. v. Thompsen
878 A.2d 1218 (District of Columbia Court of Appeals, 2005)
Board of Trustees of Univ. of DC v. DiSalvo
974 A.2d 868 (District of Columbia Court of Appeals, 2009)
Vassiliades v. Garfinckel's, Brooks Bros.
492 A.2d 580 (District of Columbia Court of Appeals, 1985)
Paul v. Howard University
754 A.2d 297 (District of Columbia Court of Appeals, 2000)