Michael Malone, on behalf of himself and all other similarly situated v. Edw. C. Levy Co.

District Court, E.D. Michigan·Decided August 20, 2026·No. 2:25-cv-11107·Unknown

Opinion

UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MICHIGAN SOUTHERN DIVISION

MICHAEL MALONE, on behalf of himself and all other similarly situated,

Plaintiff, Case No. 25-cv-11107 v. Honorable Linda V. Parker

EDW. C. LEVY CO.,

Defendant. ________________________________/

OPINION AND ORDER GRANTING DEFENDANT’S MOTION TO DISMISS

On April 16, 2025, Plaintiff Michael Malone, a former employee of Defendant Edw. C. Levy Co., filed this putative class action asserting claims related to a November 2023 ransomware attack on Defendant’s computer network. (See generally ECF Nos. 1, 12.) The data breach enabled hackers to obtain employee personally identifiable information (“PII”). (Id.) Plaintiff alleges that he provided Defendant with his name and Social Security number (“SSN”) as a condition of employment, and that the unauthorized actor(s) accessed employee PII during the attack due to Defendant’s inadequate cybersecurity practices. (ECF No. 12 at PageID.111, 119-20.) In an Amended Complaint, Plaintiff asserts six claims: (I) Negligence; (II) Negligence per se; (III) Breach of Implied Contract; (IV) Unjust Enrichment; (V) Invasion of Privacy; and (VI) Breach of Fiduciary Duty. (Id. at PageID.134-43.) Defendant moves to dismiss Plaintiff’s Amended Complaint under Federal

Rules of Civil Procedure 12(b)(1) and 12(b)(6), arguing that Plaintiff lacks Article III standing and, alternatively, that the Amended Complaint fails to state a claim. (ECF No. 13.) For the reasons below, the Court concludes that Plaintiff has

standing to seek damages for a completed privacy injury, but lacks standing to seek prospective relief or relief based on speculative future misuse, mitigation costs, or diminished value of PII. Plaintiff voluntarily dismisses his standalone negligence per se claim, and his remaining claims fail under Rule 12(b)(6). Accordingly,

Defendant’s motion is granted. Factual Background Plaintiff is Defendant’s former employee. (ECF No. 12 at PageID.106-07.)

As a condition of his employment, Plaintiff provided Defendant with his PII, including his name and SSN. (Id. at PageID.111.) Defendant collected and maintained this information as part of its employment, payroll, and administrative functions. (Id. at PageID.111-12.)

In November 2023, Defendant experienced a ransomware attack in which unauthorized actors accessed business files. (Id. at PageID.109-11, 119-20.) According to Plaintiff, the compromised information included employee names

and SSNs. (Id. at PageID.111, 119-21.) Plaintiff alleges that his name and SSN were among the PII maintained by Defendant and placed at risk by the breach. (Id.)

Plaintiff further alleges that the breach resulted from Defendant’s inadequate cybersecurity practices. (Id. at PageID.111-31.) He alleges that Defendant failed to implement and maintain reasonable data security measures to protect employee

PII, including adequate access controls, credential safeguards, monitoring and detection systems, encryption or other protective measures, employee training, and timely incident response procedures. (Id. at PageID.119-31.) Plaintiff asserts that Defendant failed to provide reasonably timely notice of the breach, which

prevented him from taking earlier steps to protect his information and increased the risk that employee PII could be misused before employees could take measures to protect their data. (Id. at PageID.119-21.)

Defendant in fact notified Plaintiff of the breach on January 16, 2025, more than 14 months after the alleged ransomware attack. (ECF No. 12-1.) The Notice informed Plaintiff that Defendant had experienced a data security incident, and through an investigation, “learned that certain files, kept in the normal course of

business, may have been subject to unauthorized access during the incident.” (Id. at PageID.149.) The notice did not state that Plaintiff’s PII was accessed during the data breach. Rather, Defendant stated that it was “notifying those individuals

known to date whose information may have been subject to unauthorized access[,]” and that the incident “may have involved [his first and last name and social security number].” (Id.; see also ECF No. 12 at PageID.107 ¶ 2.) Defendant shared that it

had hired a third-party forensic specialist to investigate the matter, but “[o]ut of an abundance of caution, . . . arranged for you to activate, at no cost to you, [credit monitoring] for twelve months . . ..” (ECF No. 12-1 at PageID.149.)

Plaintiff alleges two categories of information relevant to the data breach. First, Plaintiff alleges that he provided Defendant his PII, including his name and SSN, as a condition of employment, and that unauthorized actors accessed

employee PII during the ransomware attack. (ECF No. 12 at PageID.106-12, 119- 21.) Second, Plaintiff alleges that approximately 1,500 login credentials belonging to Defendant’s employees were published on the dark web and, on information and belief, were used to perpetrate the data breach. (Id. at PageID.112.) Plaintiff does

not allege, however, that his own login credentials were among those credentials. (Id. at PageID.112, 120-21.) In the Amended Complaint, Plaintiff claims the following injuries: (1)

“actual injury from the exposure of his PII,” which he says “violates his rights to privacy”; (2) “damages to and diminution in the value of his PII”; (3) time spent and “reasonable efforts to mitigate the impact of the [d]ata [b]reach,” including researching the breach, reviewing account statements, changing passwords, placing

credit freezes, and monitoring his credit; (4) “anxiety, sleep disruption, stress, fear, and frustration”; (5) a “present and continuing risk of fraud, identity theft, and misuse”; and (6) “a significant increase in suspicious spam calls and emails.” (Id.

at PageID.119-21.) Plaintiff also alleges that he and the proposed class “have suffered and will continue to suffer damages, including monetary losses, lost time, anxiety, and emotional distress.” (Id. at PageID.122.)

At the same time, Plaintiff does not contend that he has experienced completed identity theft, a fraudulent account opened in his name, an unauthorized charge, damage to his credit, or out-of-pocket financial loss resulting from the misuse of his PII. (See id. at PageID.119-21, 134-43.)

Procedural Background Plaintiff filed his original Complaint in this matter on April 16, 2025, asserting claims on behalf of himself and a putative class. (ECF No. 1.) Class

certification is not presently before this Court. Defendant filed its first motion to dismiss on July 11, 2025. (ECF No. 10.) Then, on July 30, 2025, Plaintiff filed the Amended Complaint, which is now the operative pleading. (ECF No. 12.) The Amended Complaint did not assert new claims, but added five factual paragraphs

to the original pleading, including the allegations concerning the publication of approximately 1,500 Defendant employee login credentials on the dark web. (Compare ECF No. 1 with ECF No. 12.) This Court thereafter denied Defendant’s

first motion to dismiss as moot. Defendant then filed the renewed motion to dismiss pursuant to Rules 12(b)(1) and (6), which is now pending. (ECF No. 13.) Defendant seeks dismissal

of the Amended Complaint with prejudice under Rules 12(b)(1) and 12(b)(6). (Id.) Defendant argues that Plaintiff lacks Article III standing because he has not alleged completed identity theft, fraud, financial loss, misuse of his PII, or any other

Free access — add to your briefcase to read the full text and ask questions with AI

Michael Malone, on behalf of himself and all other similarly situated v. Edw. C. Levy Co., (E.D. Mich. 2026).

Michael Malone, on behalf of himself and all other similarly situated v. Edw. C. Levy Co. (Michael Malone, on behalf of himself and all other similarly situated v. Edw. C. Levy Co.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

O'Shea v. Littleton
414 U.S. 488 (Supreme Court, 1974)
City of Los Angeles v. Lyons
461 U.S. 95 (Supreme Court, 1983)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Kokkonen v. Guardian Life Insurance Co. of America
511 U.S. 375 (Supreme Court, 1994)
Lewis v. Casey
518 U.S. 343 (Supreme Court, 1996)
Pegram v. Herdrich
530 U.S. 211 (Supreme Court, 2000)
DaimlerChrysler Corp. v. Cuno
547 U.S. 332 (Supreme Court, 2006)
Erickson v. Pardus
551 U.S. 89 (Supreme Court, 2007)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Henry v. Dow Chemical Company
701 N.W.2d 684 (Michigan Supreme Court, 2005)
In Re KARMEY ESTATE
658 N.W.2d 796 (Michigan Supreme Court, 2003)
Lewis v. LeGrow
670 N.W.2d 675 (Michigan Court of Appeals, 2003)
Tobin v. Civil Service Commission
331 N.W.2d 184 (Michigan Supreme Court, 1982)
Featherston v. Steinhoff
575 N.W.2d 6 (Michigan Court of Appeals, 1998)
Morris Pumps v. Centerline Piping, Inc.
729 N.W.2d 898 (Michigan Court of Appeals, 2007)