McGlenn v. Driveline Retail Merchandising Inc

District Court, C.D. Illinois·Decided September 21, 2021·No. 2:18-cv-02097·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE CENTRAL DISTRICT OF ILLINOIS SPRINGFIELD DIVISION

LYNN MCGLENN, ) ) Plaintiff, ) Case No. 18-cv-2097 ) v. ) ) DRIVELINE RETAIL ) MERCHANDISING, INC., ) ) Defendant. )

ORDER AND OPINION

SUE E. MYERSCOUGH, U.S. District Judge: This cause is before the Court on Defendant Driveline Retail Merchandising, Inc.’s (“Driveline”) Motion for Summary Judgment (d/e 84). For the reasons stated below, the Court GRANTS Defendant’s Motion for Summary Judgment (d/e 84). I. FACTS The Court draws the following facts from the parties’ statements of undisputed facts and from the evidence submitted by the parties. Any facts not disputed, or disputed without evidentiary documentation of the basis for the dispute, have been deemed admitted. See CDIL-LR 7.1(D)(2)(b)(2). On January 25, 2017, Driveline and thousands of its employees became the victims of a criminal phishing attack. An

unknown individual (the “perpetrator”), disguised as the Chief Financial Officer (“CFO”) of Driveline, sent an e-mail to a Driveline employee who worked in the payroll department. The perpetrator

asked the employee to send all of Driveline’s employees’ 2016 W-2s. The employee responded to the email and sent the 2016 W-2s of 15,878 employees to the perpetrator. These 15,878 W-2s contained

social security numbers, names, home addresses, and wage information for employees who worked at and received wages from Driveline during the time period of January 1 2016 to December 31,

2016. Driveline admits that this information is irretrievably lost, to be used against its employees forever. When Driveline realized that the email had been a phishing

attack, it notified the Federal Bureau of Investigation (“FBI”). Driveline also provided the IRS with the names and Social Security numbers (“SSNs”) of the affected employees so the IRS could impose appropriate controls to prevent the filing of fraudulent returns.1

1 McGlenn states that she objects to the temporal characterization of the FBI and IRS notifications being “immediately” or “within hours of the breach.” At least with regards to the IRS notification, email documentation confirms that Driveline notified the appropriate governmental authorities of all fifty states, Guam, and Puerto Rico of the Disclosure.

Effective January 31, 2017, Driveline retained the services of AllClear ID, a credit and identity theft prevention monitoring service, to protect the employees whose personal identifying

information (“PII”) was involved in the Disclosure. All affected employees were automatically enrolled in the base protection, called “AllClear ID Identity Repair.” Any employee suspecting identity

theft could file a claim, and AllClear ID would provide identity and credit remediation services. Additionally, employees were given the opportunity to enroll for free for one year of enhanced services,

called “AllClear Credit Monitoring.” To obtain the enhanced services, the employees had to contact AllClear ID and set up their individual accounts.

Driveline waited to notify employees of the Disclosure until the FBI gave Driveline the “green light.” On February 14, 2017, after

this information was sent to the IRS roughly two days after the phishing email was sent. See January 27, 2017 Email Communications from S. Hasenfratz to A. Douglas, attached as Exhibit 3 to Defendant’s Motion, d/e 84-3. The Court finds that the dispute on temporal terminology, however, is not material to this motion. the FBI notified Driveline that issuing notice would not hinder the FBI’s investigation, AllClear ID mailed a letter and supporting

materials on behalf of Driveline to all the employees involved in the Disclosure. McGlenn’s PII was part of the Disclosure. She received the

Disclosure notification letter, but McGlenn did not enroll in the free enhanced credit monitoring offered by Driveline through AllClear ID. Some Driveline employees involved in the Disclosure received

letters from the IRS requiring them to present to an IRS office in person before filing their 2016 taxes, but McGlenn did not receive such a letter. McGlenn does not claim that anyone attempted to file

a fraudulent tax return using her PII. McGlenn, however, did experience some fraudulent activity on her financial accounts after the Disclosure. Six months after the

Disclosure, someone tried to activate a Capital One credit card on an account opened in her name. Capital One received a credit card application that included McGlenn’s former married name (Lynn Watts), her telephone number, her date of birth, address, and SSN

on or about July 20, 2017. A man attempted to activate the Capital One account via telephone by providing McGlenn’s former name, her telephone number, and her date of birth. McGlenn’s W-2 does not contain her date of birth. Nor did the Disclosure reveal her

telephone number or former last names. Driveline never even knew McGlenn’s former married name (Watts) because when she applied for a job with Driveline, she was already married to Mr. McGlenn.

In December 2017, eleven months after the Disclosure, someone used McGlenn’s Charlotte Metro Credit Union debit card to incur a $252.79 charge. McGlenn confirmed that the

information at issue in the debit card charge, which included her credit union account number, credit union name, credit card numbers, and debit card numbers, were not part of the Driveline

Disclosure. McGlenn also acknowledged that her data was stolen during the Equifax data breach. As clarified in McGlenn’s response,

Equifax provided notice of the breach in September 2017, but the breach itself occurred between May 2017 and July 2017. See d/e 86 at p. 3 (citing In re Equifax, Inc., Customer Data Sec. Breach Litig., 362 F. Supp. 3d 1295, 1308 (N.D. Ga. 2019) (“On September

7, 2017, the Defendant Equifax Inc. announced that it was the subject of one of the largest data breaches in history. From mid- May through the end of July 2017, hackers stole the personal and financial information of nearly 150 million Americans.”)). McGlenn

assumes that the Equifax data breach disclosed her SSN, her past and present address, her date of birth, other names she has used in the past, and the identities of her banks, lending institutions, and

past and present credit card issuers. Equifax, like Driveline, offered free credit monitoring. McGlenn declined both offers because she was already using Credit Karma.

McGlenn also highlights reports by the IRS and FBI warning about certain frauds prior to the Disclosure. Driveline does not dispute the facts surrounding these reports, but Driveline argues

that they are immaterial because there is no evidence that Driveline had received, was aware of, or should have been aware of these reports. First, on August 27, 2015, the FBI issued a report warning

of the increasingly common scam, known as Business Email Compromise, in which companies had fallen victim to phishing emails. The report called attention to the significant spike in scams, also referred to as “spoofing,” in which emails that appear to

have been initiated from the CEO or other top-level executives request employee W-2 or other personal information. Second, on March 1, 2016, the IRS issued an alert to payroll and human resources professionals warning of a scheme whereby

false emails, purportedly from one of the company’s chief officers, were sent to individuals in the human resources or accounting department asking for copies of W-2 data for all employees. The

alert stated: The Internal Revenue Service today issued an alert to payroll and human resources professionals to beware of an emerging phishing email scheme that purports to be from company executives and requests personal information on employees.

Free access — add to your briefcase to read the full text and ask questions with AI

McGlenn v. Driveline Retail Merchandising Inc, (C.D. Ill. 2021).

McGlenn v. Driveline Retail Merchandising Inc (McGlenn v. Driveline Retail Merchandising Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Harvey v. Town of Merrillville
649 F.3d 526 (Seventh Circuit, 2011)
David Blood v. Vh-1 Music First
668 F.3d 543 (Seventh Circuit, 2012)
Standard Fire Insurance Co. v. Knowles
133 S. Ct. 1345 (Supreme Court, 2013)
Cunningham Charter Corp. v. Learjet, Inc.
592 F.3d 805 (Seventh Circuit, 2010)
Majetich v. P.T. Ferro Construction Co.
906 N.E.2d 713 (Appellate Court of Illinois, 2009)
Moorman Manufacturing Co. v. National Tank Co.
435 N.E.2d 443 (Illinois Supreme Court, 1982)
Young v. Bryco Arms
821 N.E.2d 1078 (Illinois Supreme Court, 2004)
Neade v. Portes
739 N.E.2d 496 (Illinois Supreme Court, 2000)
Williams v. Manchester
888 N.E.2d 1 (Illinois Supreme Court, 2008)
First Springfield Bank & Trust v. Galman
720 N.E.2d 1068 (Illinois Supreme Court, 1999)
Nolan v. Weil-McLain
910 N.E.2d 549 (Illinois Supreme Court, 2009)
Dahlin v. Evangelical Child & Family Agency
252 F. Supp. 2d 666 (N.D. Illinois, 2002)
Hilary Remijas v. Neiman Marcus Group, LLC
794 F.3d 688 (Seventh Circuit, 2015)
Cooney v. Chicago Public Schools
943 N.E.2d 23 (Appellate Court of Illinois, 2010)
Tummelson v. White
2015 IL App (4th) 150151 (Appellate Court of Illinois, 2015)
John Lewert v. P.F. Chang's China Bistro, Inc
819 F.3d 963 (Seventh Circuit, 2016)
Ronald Ward v. Soo Line Railroad Company
901 F.3d 868 (Seventh Circuit, 2018)
Matthew King v. Hendricks County Commissioner
954 F.3d 981 (Seventh Circuit, 2020)