UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MICHIGAN SOUTHERN DIVISION
MICHAEL MALONE, on behalf of himself and all other similarly situated,
Plaintiff, Case No. 25-cv-11107 v. Honorable Linda V. Parker
EDW. C. LEVY CO.,
Defendant. ________________________________/
OPINION AND ORDER GRANTING DEFENDANT’S MOTION TO DISMISS
On April 16, 2025, Plaintiff Michael Malone, a former employee of Defendant Edw. C. Levy Co., filed this putative class action asserting claims related to a November 2023 ransomware attack on Defendant’s computer network. (See generally ECF Nos. 1, 12.) The data breach enabled hackers to obtain employee personally identifiable information (“PII”). (Id.) Plaintiff alleges that he provided Defendant with his name and Social Security number (“SSN”) as a condition of employment, and that the unauthorized actor(s) accessed employee PII during the attack due to Defendant’s inadequate cybersecurity practices. (ECF No. 12 at PageID.111, 119-20.) In an Amended Complaint, Plaintiff asserts six claims: (I) Negligence; (II) Negligence per se; (III) Breach of Implied Contract; (IV) Unjust Enrichment; (V) Invasion of Privacy; and (VI) Breach of Fiduciary Duty. (Id. at PageID.134-43.) Defendant moves to dismiss Plaintiff’s Amended Complaint under Federal
Rules of Civil Procedure 12(b)(1) and 12(b)(6), arguing that Plaintiff lacks Article III standing and, alternatively, that the Amended Complaint fails to state a claim. (ECF No. 13.) For the reasons below, the Court concludes that Plaintiff has
standing to seek damages for a completed privacy injury, but lacks standing to seek prospective relief or relief based on speculative future misuse, mitigation costs, or diminished value of PII. Plaintiff voluntarily dismisses his standalone negligence per se claim, and his remaining claims fail under Rule 12(b)(6). Accordingly,
Defendant’s motion is granted. Factual Background Plaintiff is Defendant’s former employee. (ECF No. 12 at PageID.106-07.)
As a condition of his employment, Plaintiff provided Defendant with his PII, including his name and SSN. (Id. at PageID.111.) Defendant collected and maintained this information as part of its employment, payroll, and administrative functions. (Id. at PageID.111-12.)
In November 2023, Defendant experienced a ransomware attack in which unauthorized actors accessed business files. (Id. at PageID.109-11, 119-20.) According to Plaintiff, the compromised information included employee names
and SSNs. (Id. at PageID.111, 119-21.) Plaintiff alleges that his name and SSN were among the PII maintained by Defendant and placed at risk by the breach. (Id.)
Plaintiff further alleges that the breach resulted from Defendant’s inadequate cybersecurity practices. (Id. at PageID.111-31.) He alleges that Defendant failed to implement and maintain reasonable data security measures to protect employee
PII, including adequate access controls, credential safeguards, monitoring and detection systems, encryption or other protective measures, employee training, and timely incident response procedures. (Id. at PageID.119-31.) Plaintiff asserts that Defendant failed to provide reasonably timely notice of the breach, which
prevented him from taking earlier steps to protect his information and increased the risk that employee PII could be misused before employees could take measures to protect their data. (Id. at PageID.119-21.)
Defendant in fact notified Plaintiff of the breach on January 16, 2025, more than 14 months after the alleged ransomware attack. (ECF No. 12-1.) The Notice informed Plaintiff that Defendant had experienced a data security incident, and through an investigation, “learned that certain files, kept in the normal course of
business, may have been subject to unauthorized access during the incident.” (Id. at PageID.149.) The notice did not state that Plaintiff’s PII was accessed during the data breach. Rather, Defendant stated that it was “notifying those individuals
known to date whose information may have been subject to unauthorized access[,]” and that the incident “may have involved [his first and last name and social security number].” (Id.; see also ECF No. 12 at PageID.107 ¶ 2.) Defendant shared that it
had hired a third-party forensic specialist to investigate the matter, but “[o]ut of an abundance of caution, . . . arranged for you to activate, at no cost to you, [credit monitoring] for twelve months . . ..” (ECF No. 12-1 at PageID.149.)
Plaintiff alleges two categories of information relevant to the data breach. First, Plaintiff alleges that he provided Defendant his PII, including his name and SSN, as a condition of employment, and that unauthorized actors accessed
employee PII during the ransomware attack. (ECF No. 12 at PageID.106-12, 119- 21.) Second, Plaintiff alleges that approximately 1,500 login credentials belonging to Defendant’s employees were published on the dark web and, on information and belief, were used to perpetrate the data breach. (Id. at PageID.112.) Plaintiff does
not allege, however, that his own login credentials were among those credentials. (Id. at PageID.112, 120-21.) In the Amended Complaint, Plaintiff claims the following injuries: (1)
“actual injury from the exposure of his PII,” which he says “violates his rights to privacy”; (2) “damages to and diminution in the value of his PII”; (3) time spent and “reasonable efforts to mitigate the impact of the [d]ata [b]reach,” including researching the breach, reviewing account statements, changing passwords, placing
credit freezes, and monitoring his credit; (4) “anxiety, sleep disruption, stress, fear, and frustration”; (5) a “present and continuing risk of fraud, identity theft, and misuse”; and (6) “a significant increase in suspicious spam calls and emails.” (Id.
at PageID.119-21.) Plaintiff also alleges that he and the proposed class “have suffered and will continue to suffer damages, including monetary losses, lost time, anxiety, and emotional distress.” (Id. at PageID.122.)
At the same time, Plaintiff does not contend that he has experienced completed identity theft, a fraudulent account opened in his name, an unauthorized charge, damage to his credit, or out-of-pocket financial loss resulting from the misuse of his PII. (See id. at PageID.119-21, 134-43.)
Procedural Background Plaintiff filed his original Complaint in this matter on April 16, 2025, asserting claims on behalf of himself and a putative class. (ECF No. 1.) Class
certification is not presently before this Court. Defendant filed its first motion to dismiss on July 11, 2025. (ECF No. 10.) Then, on July 30, 2025, Plaintiff filed the Amended Complaint, which is now the operative pleading. (ECF No. 12.) The Amended Complaint did not assert new claims, but added five factual paragraphs
to the original pleading, including the allegations concerning the publication of approximately 1,500 Defendant employee login credentials on the dark web. (Compare ECF No. 1 with ECF No. 12.) This Court thereafter denied Defendant’s
first motion to dismiss as moot. Defendant then filed the renewed motion to dismiss pursuant to Rules 12(b)(1) and (6), which is now pending. (ECF No. 13.) Defendant seeks dismissal
of the Amended Complaint with prejudice under Rules 12(b)(1) and 12(b)(6). (Id.) Defendant argues that Plaintiff lacks Article III standing because he has not alleged completed identity theft, fraud, financial loss, misuse of his PII, or any other
concrete and imminent injury. (Id.) Defendant further argues that Plaintiff’s alleged future risk injuries, mitigation efforts, diminished value theory, and request for prospective relief are too speculative to support standing. (Id.) Alternatively, Defendant argues that each claim fails under Michigan law because Plaintiff has
not pled a present, cognizable injury or the required elements of his claims. (Id.) Plaintiff filed a response opposing Defendant’s motion to dismiss. (ECF No. 14.) Plaintiff argues that Defendant’s Rule 12(b)(1) challenge is facial, so the
Court must accept the Amended Complaint’s well-pleaded factual allegations as true. (Id. at PageID.228.) Plaintiff further argues that the alleged unauthorized access to his PII, the sensitivity of the information involved, his mitigation efforts, emotional distress, loss of privacy, diminished value of PII, and increased spam
communications are sufficient to establish standing and state viable claims. (See generally ECF No. 14.) In the response, Plaintiff indicates that he is voluntarily dismissing his
standalone negligence per se claim (Count II), relying instead on the Federal Trade Commission (FTC) Act negligence per se theory to support his ordinary negligence claim. (ECF No. 14 at PageID.237 n.1.) Plaintiff also clarifies in the
response that his invasion of privacy claim (Count V) is based only on an intrusion-upon-seclusion theory, not the public disclosure of private information. (Id. at PageID.245.)
Defendant filed a reply. (ECF No. 15.) Defendant maintains that Plaintiff’s alleged injuries are based on fears of possible future misuse, which do not satisfy Article III’s concrete and imminent injury requirement. (Id. at PageID.253-56.) Defendant also argues that Plaintiff’s added allegations concerning approximately
1,500 login credentials belonging to Defendant’s employees do not cure the defects in the initial Complaint. (Id. at PageID.255-57.) According to Defendant, Plaintiff still does not allege that his own credentials were among those published, that any
compromised dataset has been misused, that any third party used his information to withdraw money, obtain credit, take out a loan, or assume his identity, or that he suffered any monetary loss. (Id.) As to Rule 12(b)(6), Defendant reiterates that Plaintiff has not pleaded an
actual, present injury under Michigan law; has not alleged a meeting of the minds or essential terms for an implied contract; has not shown that Defendant retained an independent benefit for unjust enrichment purposes; cannot maintain an
intrusion upon seclusion claim because he voluntarily provided his PII to Defendant; and has not pleaded a fiduciary relationship arising from his former employment. (Id. at PageID.256-59.)
In supplemental filings, the parties submitted recent decisions by judges in this District addressing similar data breach cases. Plaintiff submitted Rodriguez v. CRG Lynwood LLC, No. 24-11576, 2025 WL 2700614 (E.D. Mich. Sept. 22,
2025) (Michelson, J.). (ECF No. 16-1.) Defendant responded that Plaintiff misreads Rodriguez and that the decision in fact supports dismissal or, at minimum, limits Plaintiff’s standing theories and available damages. (ECF No. 17 at PageID.296-98.) Defendant later submitted Polkowski v. Jack Doheny Cos., No.
2:25-cv-10516, 2025 WL 3079358 (E.D. Mich. Nov. 4, 2025) (McMillion, J.). (ECF No. 19-1.) Plaintiff then moved to file another notice of supplemental authority. (ECF
No. 20-1.) In a text-only order, this Court granted that filing in part and denied it in part, taking notice of the authority, In re Manpower of Lansing, MI, Inc., Data Breach Litig., No. 25-cv-956, 2026 WL 1194822 (W.D. Mich. Mar. 19, 2026) (Maloney, J.), but not considering Plaintiff’s arguments as they pertain to the
authority. Standards of Review As indicated, Defendant moves to dismiss Plaintiff’s Amended Complaint
under Rules 12(b)(1) and 12(b)(6). (ECF No. 13.) Defendant’s standing argument arises under Rule 12(b)(1) because Article III standing is a threshold jurisdictional requirement. See Kanuszewski v. Mich. Dep’t of Health & Hum. Servs., 927 F.3d
396, 405 (6th Cir. 2019). A Rule 12(b)(1) motion may present either a facial or factual challenge to subject-matter jurisdiction. Gentek Bldg. Prods., Inc. v. Sherwin-Williams Co., 491 F.3d 320, 330 (6th Cir. 2007).
Defendant raises a facial challenge because it does not submit evidence to dispute the existence of subject-matter jurisdiction. See Harris v. Lexington- Fayette Urban Cty. Gov’t, 685 F. App’x 470, 472 (6th Cir. 2017). In resolving a facial challenge, the court accepts the complaint’s material factual allegations as
true and draws reasonable inferences in the plaintiff’s favor. Hile v. Michigan, 86 F.4th 269, 273 (6th Cir. 2023); Gentek, 491 F.3d at 330. Plaintiff bears the burden of establishing standing. Lujan v. Defs. of Wildlife, 504 U.S. 555, 561 (1992).
A Rule 12(b)(6) motion tests the legal sufficiency of the complaint. RMI Titanium Co. v. Westinghouse Elec. Corp., 78 F.3d 1125, 1134 (6th Cir. 1996). “To survive a motion to dismiss, a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim to relief that is plausible on its face.’”
Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)). In deciding whether the plaintiff has set forth a “plausible” claim, a court must accept the factual allegations in the complaint as
true. Erickson v. Pardus, 551 U.S. 89, 94 (2007). This presumption is not applicable to legal conclusions, however. Iqbal, 556 U.S. at 678-79. Therefore, “[t]hreadbare recitals of the elements of a cause of action, supported by mere
conclusory statements, do not suffice.” Id. (citing Twombly, 550 U.S. at 555). In evaluating Defendant’s motion, the Court considers the Amended Complaint, its attachments, and Plaintiff’s response to the extent it clarifies the
theories Plaintiff pursues. A plaintiff may use a response brief to clarify allegations whose meaning is unclear. Pegram v. Herdrich, 530 U.S. 211, 230 n.10 (2000) (citations omitted). But a plaintiff may not amend the complaint through an opposition brief or ask the Court to consider new factual allegations or
evidence not contained in the complaint. Bates v. Green Farms Condo. Ass’n, 958 F.3d 470, 483-84 (6th Cir. 2020) (citations omitted). Accordingly, the Court considers Plaintiff’s clarification that Count V
proceeds only as an intrusion upon seclusion claim and that Count II is not pursued as a standalone claim. (See ECF No. 14 at PageID.237 n.1, 245.) The Court does not, however, treat Plaintiff’s response as adding facts beyond those alleged in the Amended Complaint.
Analysis and Application Because federal courts are courts of limited jurisdiction, Plaintiff must establish that the Court has subject-matter jurisdiction before it may reach the
merits. See, e.g., Kokkonen v. Guardian Life Ins. Co. of Am., 511 U.S. 375, 377 (1994). Article III standing is a threshold component of that jurisdiction. Kanuszewski, 927 F.3d at 405. Plaintiff therefore must establish standing for each
asserted injury and each form of relief. See TransUnion LLC v. Ramirez, 594 U.S. 413, 423, 431 (2021). Thus, the Court addresses Defendant’s standing arguments before turning to its arguments challenging the merits of Plaintiff’s claims.
Article III Standing Defendant argues that Plaintiff has not established “a concrete and particularized injury in fact that is fairly traceable” to Defendant because Plaintiff’s claims are “based merely on fear of potential and speculative future harm.” (ECF
No. 13 at PageID.161.) Standing requires Plaintiff to show an injury in fact that is “fairly traceable” to Defendant’s challenged conduct and likely to be redressed by a favorable decision. Lujan, 504 U.S. at 560-61. The injury must be “concrete,
particularized, and actual or imminent.” TransUnion, 594 U.S. at 423. Concreteness requires that the injury “actually exist,” meaning it must be “real, and not abstract.” Spokeo, Inc. v. Robins, 578 U.S. 330, 340 (2016) (internal quotation marks omitted). An injury is particularized when it “affect[s] the
plaintiff in a personal and individual way.” Id. at 339 (quoting Lujan, 504 U.S. at 560 n.1). An injury is actual or imminent when a “plaintiff’s legal right has been frustrated or impeded, or where such an injury is certainly impending.” Rodriguez,
2025 WL 2700614, at *2 (quoting Lewis v. Casey, 518 U.S. 343, 353 (1996) and Clapper v. Amnesty Int’l USA, 568 U.S. 398, 401 (2013) (internal quotation marks omitted)).
At the pleading stage, Plaintiff need only allege facts that plausibly establish standing. Ass’n of Am. Physicians & Surgeons v. U.S. Food & Drug Admin., 13 F.4th 531, 543-44 (6th Cir. 2021). Nevertheless, because standing is not
“dispensed in gross,” it is the plaintiff’s burden to establish standing for each claim and form of relief sought. TransUnion, 594 U.S. at 431; Kanuszewski, 927 F.3d at 406. Because Defendant’s standing challenge is facial, the Court accepts Plaintiff’s
well-pleaded factual allegations as true and draws reasonable inferences in his favor. See Hile, 86 F.4th at 273; Gentek, 491 F.3d at 330. Applying that standard, the Court concludes that Plaintiff has standing to seek damages for an alleged
completed privacy injury, but lacks standing to seek prospective relief or relief based on speculative future misuse, mitigation costs, or diminished value of PII. Plaintiff has standing to seek damages for a completed privacy injury
Defendant argues that Plaintiff lacks standing because he does not allege completed identity theft, fraud, monetary loss, or misuse of his PII. But those arguments do not defeat standing for Plaintiff’s alleged completed privacy injury. The relevant injury is not that Plaintiff’s information may be misused in the future; it is that unauthorized actors allegedly accessed his private identifying information during the ransomware attack. See TransUnion, 594 U.S. at 424-25; Rodriguez, 2025 WL 2700614, at *3-4.
Plaintiff plausibly alleges that his completed privacy injury is both actual and particularized. The Breach Notice was addressed to Plaintiff and informed him that Defendant was writing about a cybersecurity incident that “may have
involved [his] information.” (ECF No. 1-1 at PageID.31.) Although the Notice uses cautious language, stating that certain files “may have been subject to unauthorized access,” Defendant sent the Notice only after reviewing the impacted files to determine “the type of information contained therein and to whom that
information related.” (Id.) As in Rodriguez, such language supports the reasonable inference at this early stage that Plaintiff’s information was among the information accessed. See
Rodriguez, 2025 WL 2700614, at *2-3. If Plaintiff’s information was not potentially involved, Defendant would have had no apparent reason to send him the Notice. Drawing that inference in Plaintiff’s favor, the alleged injury is actual because the unauthorized access already “frustrated” or “impeded” Plaintiff’s
privacy interest. See id. at *2-3. And it is particularized because the Notice concerned Plaintiff’s own information, affecting him “in a personal and individual way.” Spokeo, 578 U.S. at 339.
Plaintiff’s alleged privacy injury is also concrete. The standing inquiry for concreteness asks whether the injury is of a kind traditionally recognized as a harm, not whether the plaintiff has already proven a viable tort claim. See
TransUnion, 594 U.S. at 424; Dickson v. Direct Energy, LP, 69 F.4th 338, 348 (6th Cir. 2023). Plaintiff clarified that his invasion of privacy theory is limited to intrusion upon seclusion, making intrusion upon private affairs the relevant
historical analogue. (ECF No. 14 at PageID.245.) The alleged harm is “real, and not abstract,” Spokeo, 578 U.S. at 340, because Plaintiff does not rely only on a general fear that his information may be misused someday. As explained earlier, Defendant sent the Notice after reviewing the impacted
files and determining whose information may have been involved. (ECF No. 1-1 at PageID.31.) Together with Plaintiff’s allegation that the information involved included his name and SSN, those facts plausibly allege a present privacy invasion,
not an abstract risk of future harm. (ECF No. 12 at PageID.111, 119-21.) That harm is similar in kind to intrusion upon seclusion because it involves unauthorized access to Plaintiff’s private identifying information. See TransUnion, 594 U.S. at 425; Dickson, 69 F.4th at 345, 348; Salazar v. Paramount Glob., 133
F.4th 642, 647-48 (6th Cir. 2025); Rodriguez, 2025 WL 2700614, at *3-4. As in Rodriguez, Plaintiff need not show at the pleading stage that he can satisfy every element of Michigan’s intrusion upon seclusion tort; he need only allege a harm
bearing a close relationship to that traditional privacy injury. See Rodriguez, 2025 WL 2700614, at *3-4. Plaintiff also satisfies traceability at this stage. He alleges that the
unauthorized access occurred through Defendant’s systems and resulted from Defendant’s failure to implement reasonable data security safeguards. (ECF No. 12 at PageID.111-31.) In Galaria v. Nationwide Mut. Ins. Co., 663 F. App’x 384
(6th Cir. 2016), the Sixth Circuit held that, at the pleading stage, such allegations are sufficient as traceability does not require proof of tort causation. Id. at 390. The same is true here. Accepting Plaintiff’s allegations as true, the alleged privacy injury arose from the data breach itself and is fairly traceable to
Defendant’s challenged data security practices. The Court therefore rejects Defendant’s standing challenge to the extent Defendant argues that Plaintiff lacks standing to seek damages for a completed privacy injury.
Plaintiff’s other injury theories do not otherwise support standing
Although Plaintiff’s alleged privacy injury satisfies the injury-in-fact requirement, Plaintiff must establish standing for each claim and form of relief sought. See TransUnion, 594 U.S. at 431; DaimlerChrysler Corp. v. Cuno, 547 U.S. 332, 351-54 (2006); Kanuszewski, 927 F.3d at 406. Because the absence of any one standing element is fatal, the Court addresses only the dispositive defect for each injury theory. See Lujan, 504 U.S. at 560-61. First, Plaintiff’s future risk theory does not independently support standing. A future risk may satisfy Article III where the threatened harm is “certainly impending” or there is a “substantial” risk that the harm will occur. Clapper, 568
U.S. at 414 & n.5. In the data breach context, the risk of fraud is more likely to be substantial when the data was intentionally targeted by hackers, some compromised information has already been misused, and the exposed information
is the type that lends itself to fraud. See Rodriguez, 2025 WL 2700614, at *4-5; Bohnak v. Marsh & McLennan Cos., 79 F.4th 276, 288-89 (2d Cir. 2023); Galaria, 663 F. App’x at 388-89. Here, as in Rodriguez, some considerations favor Plaintiff. Plaintiff alleges
a malicious ransomware attack, not an accidental disclosure, and the information allegedly involved included names and SSNs, which can be used for identity theft. (ECF No. 12 at PageID.106-12, 119-21.) But those facts do not, by themselves,
make future misuse substantial or certainly impending. Plaintiff does not allege that his PII, or any compromised employee PII, has been used to open a fraudulent account, make an unauthorized charge, damage credit, obtain credit, or otherwise commit identity theft. (See generally id.)
The absence of misuse does not defeat standing for the completed privacy injury, which depends on unauthorized access itself. See TransUnion, 594 U.S. at 424-25; Dickson, 69 F.4th at 345, 348; Rodriguez, 2025 WL 2700614, at *3-4. It
does, however, weaken Plaintiff’s separate future fraud theory because Plaintiff asks the Court to infer future misuse from access to sensitive information alone. The passage of time makes that inference even weaker. The breach
allegedly occurred in November 2023, yet Plaintiff does not allege any fraud or identity theft attributable to the breach as of the filing of his Amended Complaint on July 30, 2025. In Rodriguez, Judge Michelson concluded that the plaintiff
could not demonstrate imminent harm where she failed to allege even one instance of fraud attributable to the breach three years earlier. 2025 WL 2700614, at *5 (citing Storm v. Paytime, Inc., 90 F. Supp. 3d 359, 366-67 (M.D. Pa. 2015)). Although less time has passed here between the data breach and Plaintiff’s
amended pleading, the court in Storm indicated that “a layperson with a common sense notion of ‘imminence’ would find [a one-year] lapse of time, without any identity theft, to undermine the notion that identity theft would happen in the near
future.” 90 F. Supp. 3d at 367; see also Duqum v. Scottrade, Inc., No. 4:15-cv- 1537, 2016 WL 3683001, at *4 (E.D. Mo. July 12, 2016), aff’d sub nom Kuhns v. Scottrade, Inc., 868 F.3d 711 (8th Cir. 2017) (finding no threat of injury where the plaintiffs did not allege that any stolen PII had been used to commit any identity
theft, fraud, or any other act harming them and more than two years had passed since the original breach). Thus, Plaintiff alleges a possible future injury, not a substantial or certainly
impending one. In a damages action, that “mere risk of future harm, standing alone,” is not a concrete injury unless the risk materializes or causes a separate concrete harm. TransUnion, 594 U.S. at 436-37.
Second, Plaintiff’s mitigation efforts do not cure that defect. Plaintiff alleges that he has spent time monitoring his accounts and information and has taken, or will need to take, steps such as credit monitoring, identity protection, and
password changes. (ECF No. 12 at PageID.119-21.) But those efforts respond to the same future misuse theory that is not substantial or certainly impending. Because a plaintiff cannot manufacture standing by spending time or money to guard against a non-imminent harm, those mitigation efforts do not
independently establish standing. See Clapper, 568 U.S. at 416; Rodriguez, 2025 WL 2700614, at *5; Greenstein v. Noblr Reciprocal Exch., No. 22-17023, 2024 WL 3886977, at *3 (9th Cir. Aug. 21, 2024). To the extent mitigation efforts are
tied to the alleged completed privacy injury, they may be relevant to damages if Plaintiff states a viable claim. But they do not create standing for a separate future risk injury. Third, Plaintiff’s diminished value theory is too abstract to establish
standing. Plaintiff alleges that his PII has lost value because PII can be bought and sold on the dark web. (ECF No. 12 at PageID.119-21.) But he does not allege that the breach diminished his own lawful use of the information, forced him to change
identifying information, prevented him from obtaining services or opening accounts, or caused any other concrete economic loss. Nor does he allege that he intended to sell his PII. As other courts have observed, the alleged black market
value of stolen information does not show an economic loss to a plaintiff because the court must assume the plaintiff will act lawfully. See Rodriguez, 2025 WL 2700614, at *5-6; Lochridge v. Quality Temp. Servs., Inc., No. 22-cv-12086, 2023
WL 4303577, at *4 n.2 (E.D. Mich. June 30, 2023) (finding no injury in fact where the plaintiff did not allege that he intended to sell his private information); cf. O’Shea v. Littleton, 414 U.S. 488, 497 (1974). Plaintiff therefore has not alleged a concrete diminished value injury.
Fourth, increased spam communications do not provide an independent basis for standing on the allegations pleaded. Plaintiff alleges that he began experiencing more suspicious spam calls and emails after the data breach and
asserts, on information and belief, that those communications resulted from the breach. (ECF No. 12 at PageID.120-21.) But Plaintiff does not allege that his phone number and email address were compromised in the breach. (See id. at PageID.106-12, 119-21.) Without that link, the alleged increase in spam
communications is not plausibly connected to this breach rather than to some other source. Unwanted communications may be concrete injuries in some circumstances, see Dickson, 69 F.4th at 345, 348, but Plaintiff must still allege
facts making the injury fairly traceable to Defendant’s challenged conduct. See Lujan, 504 U.S. at 560-61. He has not done so. Cf. Polkowski, 2025 WL 3079358, at *6-8.
Finally, Plaintiff’s dark web allegations do not expand standing beyond the completed privacy injury recognized above. To the extent Plaintiff alleges that his own PII was published or will imminently be published on the dark web, that
theory either overlaps with the completed privacy injury or depends on the same speculative future misuse theory already rejected.1 (ECF No. 12 at PageID.119- 21.) Plaintiff also alleges that approximately 1,500 login credentials belonging to Defendant’s employees were published on the dark web and were used to
perpetrate the breach.2 (Id. at PageID.112, 120-21.) But he does not allege that his own credentials were among them, that those credentials were tied to his financial accounts, or that the credentials were used to
misuse his PII. Those allegations may bear on Defendant’s alleged data security failures, but they do not identify a concrete and particularized injury to Plaintiff. See Lujan, 504 U.S. at 560 n.1; TransUnion, 594 U.S. at 423. And to the extent Plaintiff relies on those credentials to suggest future breaches or future misuse, that
1 Plaintiff simply speculates that his PII has already been published; he offers no concrete allegations that it was. (ECF No. 12 at PageID.119.)
2 Notably, Plaintiff’s allegations do not suggest that employee login credentials were obtained in the ransomware attack. Instead, Plaintiff alleges the presence of login credentials on the dark web enabled the hackers to commit the ransomware attack. threatened harm is certainly not impending. See Clapper, 568 U.S. at 414 & n.5. Nor do the supplemental authorities require a different conclusion.
Rodriguez supports standing for an alleged completed privacy injury, but it rejected standing based on future fraud risk, mitigation efforts tied to that risk, diminished value of private information, and prospective relief. 2025 WL
2700614, at *4-7. Polkowski is factually distinguishable. There, the plaintiff’s own PII appeared on the dark web within a few months of the data breach. 2025 WL 3079358, at *5-8. In summary, Plaintiff has standing to seek damages for the alleged
completed privacy injury, but not for the separate future risk, mitigation cost, diminished value, spam communication, or employee credential theories discussed above.
Plaintiff lacks standing to seek prospective relief
Plaintiff also seeks prospective relief, but standing to seek damages does not automatically confer standing to seek injunctive or declaratory relief. Friends of the Earth, Inc. v. Laidlaw Env’t Servs. (TOC), Inc., 528 U.S. 167, 185 (2000); Kanuszewski, 927 F.3d at 406. To seek prospective relief, Plaintiff must plausibly allege a real and immediate threat of future injury. See City of Los Angeles v. Lyons, 461 U.S. 95, 102 (1983); Clapper, 568 U.S. at 409, 414 n.5. Plaintiff has not done so for the reasons discussed above. His request for prospective relief depends on the same future risk theory that does not independently support standing. Plaintiff alleges a past ransomware attack,
continued concern about future misuse, Defendant’s continued possession of employee PII, and dark-web publication of employee login credentials. (ECF No. 12 at PageID.112, 119-21.) Those allegations show a possible risk of future
misuse or another breach, but they do not plausibly show a real and immediate threat of either. As in Rodriguez, one alleged breach and the possibility of future misuse do not establish standing to seek forward-looking data security relief. See Rodriguez,
2025 WL 2700614, at *6-7. Thus, Plaintiff lacks standing to seek injunctive or declaratory relief. Rule 12(b)(6)
The standing analysis decides only whether Plaintiff may be in federal court; it does not decide whether he plausibly alleges a claim under Michigan law. With that distinction in mind, the Court turns to Defendant’s Rule 12(b)(6) arguments. For each count, the question is whether the Amended Complaint pleads facts—not
labels, conclusions, or speculation—that plausibly satisfy the elements of the asserted claim. See Iqbal, 556 U.S. at 678-79; Twombly, 550 U.S. at 555, 570. In conducting that analysis, the Court accepts well-pleaded facts as true and draws
reasonable inferences in Plaintiff’s favor. See Thomas v. Montgomery, 140 F.4th 335, 339 (6th Cir. 2025). Plaintiff’s negligence-based theories fail because Michigan law requires more than exposure to risk. Defendant’s first merits argument is that Plaintiff’s negligence claim fails for lack of a cognizable injury. (ECF No. 13 at PageID.173-79.) Plaintiff answers
that this is not merely a future risk case because the breach allegedly involved sensitive employee PII, including names and SSNs, and because he has already suffered privacy loss, emotional distress, mitigation harms, diminished value of
PII, increased spam communications, and an increased risk of identity theft. (ECF No. 14 at PageID.237-40.) Both sides’ arguments have some force, but they answer different questions. Plaintiff is correct that a completed privacy injury may be sufficiently concrete to
confer standing. See TransUnion, 594 U.S. at 424-25; Rodriguez, 2025 WL 2700614, at *3-4. Defendant is correct, however, that Michigan negligence law requires more—that is, a legally cognizable injury, not merely a risk that the
exposed information might be misused later. See Henry v. Dow Chem. Co., 701 N.W.2d 684, 690-91 (Mich. 2005); Doe v. Henry Ford Health Sys., 865 N.W.2d 915, 921 (Mich. Ct. App. 2014).
Michigan negligence law requires duty, breach, causation, and damages. Hill v. Sears, Roebuck & Co., 822 N.W.2d 190, 195 (Mich. 2012). The damages element requires an “actual, present injury.” Doe, 865 N.W.2d at 921. Possible future injuries are not actual, present injuries. See In re A-Line Staffing Sols. Data Sec. Incident Litig., No. 24-cv-11917, 2026 WL 1480273, at *9 (E.D. Mich. May
27, 2026) (White, J.) (quoting In re Grede Holdings LLC Data Breach Litig., No. 25-10831, 2026 WL 396292, at *2 (E.D. Mich. Feb. 12, 2026)) (“Insofar as plaintiffs allege to have suffered injuries associated with the ‘risk’ or ‘imminent
threat’ of future harm, those damages are not cognizable under Michigan law because they ‘are wholly derivative of a possible, future injury rather than an actual, present injury.’”). More so, there must be a “present harm to person or property.” Henry, 701 N.W.2d at 690; see also Means v. U.S. Conf. of Cath.
Bishops, 836 F.3d 643, 653 (6th Cir. 2016) (stating that “[i]n Michigan, ‘personal physical injury’ is necessary to state a claim for negligence”) In Henry, the Michigan Supreme Court rejected a negligence theory based
on medical monitoring costs because the claimed expenses were incurred to guard against possible future disease, not to remedy a present injury. 701 N.W.2d at 690- 91. The Michigan Court of Appeals applied the same reasoning in the data breach context in Doe v. Henry Ford Health, 865 N.W.2d at 921-22 (holding that credit
monitoring costs were not recoverable following the exposure of the plaintiff’s personal health information on the internet), and Rakyta v. Munson Healthcare, No. 354831, 2021 WL 4808339, 2021 WL 4808339 (Oct. 14, 2021) (holding that
possible future misuse of the plaintiff’s private information, prophylactic measures, and emotional distress did not satisfy Michigan’s present injury requirement). These cases matter here because Plaintiff’s negligence damages, apart from the
completed privacy theory, rest on the same or similar anticipated future harm. As for the alleged privacy injury, as Judge Michelson reasoned in Rodriguez, injuries stemming from hackers viewing Plaintiff’s PII are not physical harms
sufficient to satisfy the damages element under Michigan law. 2025 WL 2700614, at *8; see also In re Manpower of Lansing, MI, Inc., Data Breach Litig., No. 1:25- cv-956, 2026 WL 1194822, at *5 (W.D. Mich. Mar. 19, 2026) (citing Rakyta, 2021 WL 4808339, at*7); Polkowski, 2025 WL 3079358, at *8 (“disclosure of stolen
information alone is not a present injury if no actual identity theft resulted from the disclosure”). The cases cited by Plaintiff do not change the result above. (See ECF No. 14
at PageID.237-38.) For example, in Kingen v. Warner Norcross + Judd LLP, No. 1:22-cv-01126, 2023 WL11965363 (W.D. Mich. Oct. 5, 2023), the court found the plaintiffs’ allegations sufficient to state a negligence claim under Michigan law because the plaintiffs seemed to allege that their injuries (e.g., actual identity theft)
“have occurred.” Id. at *5 (emphasis added). In Lochridge, the plaintiff alleged a sufficiently concrete injury based on the allegation “that his information was already used to fraudulently open an account and apply for a loan [in his name].”
2023 WL 4303577, at **2, 5-6; see also In re Flagstar Dec. 2021 Data Sec. Incident Litig., No. 22-cv-11385, 2024 WL 5659583, at *9-11 (E.D. Mich. Sept. 30, 2024) (finding an actual, present injury where the plaintiffs’ PII “was
exfiltrated, held for ransom by the cyber attackers, and ultimately ‘made available to other criminals on the dark web’”). The problem here is that, in comparison, no actual, present physical injury is
alleged. Plaintiff has alleged unauthorized access to sensitive information, but the Amended Complaint does not connect that access to any completed misuse or concrete loss recognized by Michigan negligence law. See Doe, 865 N.W.2d at 921-22; Nyman v. Thomson Reuters Holdings, Inc., 942 N.W.2d 696, 705 (Mich.
Ct. App. 2019); Rakyta, 2021 WL 4808339, at *5. His future risk, mitigation, diminished value, spam, and employee credential theories either fail for lack of standing or depend on misuse that has not occurred. See TransUnion, 594 U.S. at
436-37; Clapper, 568 U.S. at 416; Henry, 701 N.W.2d at 690-91. His completed privacy injury theory gets further, but Michigan courts have not treated unauthorized access alone as negligence damages without a present injury to credit, identity, person, or property. See Doe, 865 N.W.2d at 921-22;
Nyman, 942 N.W.2d at 705; Rakyta, 2021 WL 4808339, at *5; Polkowski, 2025 WL 3079358, at *8-9. This same reasoning defeats Plaintiff’s delayed notice argument. A delay in
notice may be relevant if the delay caused a “present injury.” See Craig ex rel. Craig v. Oakwood Hosp., 684 N.W.2d 296, 308-09 (Mich. 2004). But a delay does not itself satisfy the damages element where the pleaded harm remains an
increased risk of future misuse. See Lochridge, 2023 WL 4303577, at *6; Polkowski, 2025 WL 3079358, at *9. Plaintiff alleges that earlier notice would have allowed earlier protective measures, but that is still a mitigation theory tied to
possible future misuse. See Henry, 701 N.W.2d at 690-91; Doe, 865 N.W.2d at 921-22. Regarding Plaintiff’s negligence per se theory, Michigan does not recognize this claim as an independent cause of action. Abnet v. Coca-Cola Co., 786 F.
Supp. 2d 1341, 1345 (W.D. Mich. 2011). Rather, a statutory violation can provide evidence of negligence or create a rebuttable presumption within an ordinary negligence claim. See id. Recognizing this, Plaintiff indicates in his response that
he voluntarily dismisses Count II as a standalone claim and instead relies on alleged FTC Act violations as part of Count I. (ECF No. 14 at PageID.237 n.1.) Even assuming those allegations support duty or breach, they do not supply cognizable damages. See Hill, 822 N.W.2d at 195; Doe, 865 N.W.2d at 921-22.
Here, because the negligence claim fails, negligence per se also fails. Polkowski, 2025 WL 3079358, at *9. Accordingly, Plaintiff’s negligence and negligence per se claims (Counts I
and II) are dismissed. Plaintiff’s contract and quasi-contract theories fail because Plaintiff has not alleged a separate data security bargain or a direct benefit retained by Defendant Defendant next challenges Plaintiff’s breach of implied contract and unjust enrichment claims. Defendant argues that Plaintiff has not pleaded mutual assent, essential terms, consideration, or cognizable contract damages. (ECF No. 13 at
PageID.179-83; ECF No. 15 at PageID.257-58.) Defendant also argues that Plaintiff’s unjust enrichment claim is deficient because Plaintiff did not pay Defendant for data security and did not confer an independent benefit on
Defendant. (ECF No. 15 at PageID.258.) Plaintiff responds that an implied agreement arose when Defendant required him to provide sensitive PII as a condition of employment and represented that it would use reasonable efforts to safeguard personal data. (ECF No. 14 at
PageID.240-43.) Plaintiff further argues that Defendant retained the benefit of his valuable PII and saved money by failing to spend enough on cybersecurity. (Id. at PageID.243-44.)
To state a breach of contract claim under Michigan law, Plaintiff must allege that “(1) there was a contract, (2) the other party breached the contract, and (3) this breach resulted in damages to the party claiming breach.” Miller-Davis Co. v.
Ahrens Constr., Inc., 848 N.W.2d 95, 104 (Mich. 2014). Under Michigan law, a valid contract is not formed absent inter alia legal consideration (i.e., a “bargained- for exchange), mutuality of agreement (i.e., assent), and mutuality of obligation (i.e., consideration). Stackpole Int’l Engineered Prods. Ltd. v. Angstrom Auto. Grp., LLC, 52 F.4th 274, 279-80 (6th Cir. 2022) (citations omitted). An implied
contract may arise from the parties’ conduct, language, or other circumstances showing their intent to contract. Featherston v. Steinhoff, 575 N.W.2d 6, 9 (Mich. Ct. App. 1997). But an implied contract still requires mutual assent and
consideration. Mallory v. Detroit, 449 N.W.2d 115, 118 (Mich. Ct. App. 1989). Of these requirements, Plaintiff comes closest to plausibly alleging mutual assent. Several data-breach cases have found this element satisfied where the defendant-employer required employees to provide sensitive information and
allegedly failed to safeguard it. For example, in Hummel v. Teijin Auto. Techs., Inc., No. 23-cv-10341, 2023 WL 6149059 (E.D. Mich. Sept. 20, 2023), the court found it plausible that the mandatory receipt of employee PII implied an agreement
to protect that information. Id. at *10-11. Lochridge reached a similar conclusion where the plaintiff alleged that the defendant required sensitive information and failed to safeguard it. Lochridge, 2023 WL 4303577, at *7. And Rodriguez acknowledged that while the plaintiff
had not pleaded specific words or acts promising data security, the employee’s provision of sensitive information plausibly supported mutual assent at the pleading stage. Rodriguez, 2025 WL 2700614, at *9-10.
Those cases matter here because Plaintiff alleges the same general exchange. Defendant required employee PII, Defendant’s privacy policy stated that “it will use all reasonable efforts to safeguard that information,” and Plaintiff gave that
information in connection with employment. (ECF No. 12 at PageID.111, 118.) These cases undermine Defendant’s broad argument that an employee can never plead mutual assent to reasonable data security in this setting. See Hummel, 2023
WL 6149059, at *10-11; Lochridge, 2023 WL 4303577, at *7; Rodriguez, 2025 WL 2700614, at *9-10. They also explain why Plaintiff is not required to plead the precise technical details of the alleged data security obligation before discovery. See Rodriguez, 2025 WL 2700614, at *9-10.
However, mutual assent is not Defendant’s only challenge here. Even assuming Plaintiff plausibly alleges an implied understanding that Defendant would use reasonable efforts to protect employee PII, Plaintiff must still plead
consideration. Mallory, 449 N.W.2d at 118. That is where Polkowski matters. The defendant’s challenge in Rodriguez was limited to mutual assent, so finding this requirement plausibly alleged, Judge Michelson allowed the plaintiff’s implied-contract claim to proceed. 2025 WL 2700614, at *9-10. The defendant in
Polkowski, however, raised the lack of consideration in a similar employee data breach case. 2025 WL 3079358, at *10-11. The court dismissed the implied contract claim because the plaintiff provided PII as part of the employment
relationship, not as independent consideration for a separate data security agreement. Id. The same defect is present here, as Plaintiff claims that he provided his
name and SSN as a condition of employment. (ECF No. 12 at PageID.111, 118.) But that shows why Defendant had the information, not that Plaintiff gave something separate in exchange for data security services. See Higgins, 272
N.W.2d at 543; Polkowski, 2025 WL 3079358, at *10-11. Defendant’s alleged privacy policy statement may help define what Plaintiff expected Defendant to do with the information, but it does not itself supply the bargained-for exchange required to form a separate implied contract. See Mallory, 449 N.W.2d at 118;
Polkowski, 2025 WL 3079358, at *10-11. The facts pled therefore do not turn the employment relationship into a separate implied contract for data-security services. See Polkowski, 2025 WL
3079358, at *10-11. Because Plaintiff has not pled consideration for the alleged implied contract, Count III fails. See Mallory, 449 N.W.2d at 118; Higgins, 272 N.W.2d at 543. For a related reason, Plaintiff’s unjust enrichment claim also falls short. To
plead unjust enrichment, Plaintiff must allege “(1) the receipt of a benefit by the defendant from the plaintiff and (2) an inequity resulting to the plaintiff because of the retention of the benefit by the defendant.” Morris Pumps v. Centerline Piping,
Inc., 729 N.W.2d 898, 904 (Mich. Ct. App. 2006). Not every benefit is unjust; the key inquiry is whether the defendant unjustly received and retained an independent benefit. Landstar Express Am., Inc. v. Nexteer Auto. Corp., 900 N.W.2d 650, 657
(Mich. Ct. App. 2017). The benefit also must come from the plaintiff. Morris Pumps, 729 N.W.2d at 904. Plaintiff’s theory is that Defendant received valuable PII and saved money
by underinvesting in cybersecurity. (ECF No. 12 at PageID.139-40.) But Plaintiff gave his PII so Defendant could employ and pay him, not so Defendant could sell, monetize, or keep a separate benefit for itself. (Id. at PageID.111, 118.) The alleged cost savings are even further removed from Plaintiff. They describe money
Defendant allegedly failed to spend on its own systems, not a benefit Plaintiff transferred to Defendant. See Landstar, 900 N.W.2d at 657-58; Lochridge, 2023 WL 4303577, at *6-7; Polkowski, 2025 WL 3079358, at *11.
Plaintiff cites out-of-circuit authority for a broader unjust enrichment theory. (ECF No. 14 at PageID.243-44.) But Michigan law controls here, and it requires a benefit received from Plaintiff and unjustly retained by Defendant. Morris Pumps, 729 N.W.2d at 904; Landstar, 900 N.W.2d at 657-58. Lochridge and Polkowski
applied that rule and rejected unjust enrichment theories based on the use of PII and alleged cybersecurity cost savings. Lochridge, 2023 WL 4303577, at *6-7; Polkowski, 2025 WL 3079358, at *11.
Because Plaintiff has not pled consideration for the alleged implied contract or a direct, independent benefit unjustly retained by Defendant, Counts III and IV are dismissed.
Plaintiff’s privacy and fiduciary duty theories fail because Defendant’s possession of employee PII does not satisfy the special elements of either claim Plaintiff’s remaining claims are invasion of privacy and breach of fiduciary duty. Plaintiff clarifies that his invasion of privacy claim proceeds only as intrusion upon seclusion. (ECF No. 14 at PageID.245.) Michigan recognizes intrusion upon seclusion as one of the four common law invasion of privacy torts. Tobin v. Civ.
Serv. Comm’n, 331 N.W.2d 184, 189-90 (Mich. 1982); Lewis v. LeGrow, 670 N.W.2d 675, 688 (Mich. Ct. App. 2003). To state an intrusion upon seclusion claim, Plaintiff must allege that Defendant used an objectionable method to obtain information about a private matter Plaintiff had a right to keep private. Doe v.
Mills, 536 N.W.2d 824, 832-33 (Mich. Ct. App. 1995). The tort focuses on how information was obtained, not on the information’s later publication or disclosure. Id.; Tobin, 331 N.W.2d at 189-90.
Plaintiff’s theory is that Defendant may be liable for intrusion because its allegedly inadequate data security allowed unauthorized actors to access his PII. (ECF No. 14 at PageID.244-45.) But Michigan’s intrusion tort is narrower than
that. The objectionable acquisition must be the defendant’s intrusion, not merely a third party’s intrusion that the defendant allegedly failed to prevent. See Mills, 536 N.W.2d at 832-33; Meier v. Detroit Diesel Corp., No. 268009, 2006 WL 2089208, at *3 (Mich. Ct. App. July 27, 2006); Polkowski, 2025 WL 3079358, at *11. Both Mills and Meier illustrate the point. For example, in Mills, abortion
protesters publicly displayed private information about multiple patients that a nonparty had found in a clinic’s trash. Mills, 536 N.W.2d at 827-28. The Michigan Court of Appeals allowed the patients’ public-disclosure claim against
the protesters to proceed, but dismissed the intrusion claim because the protesters’ alleged wrongdoing was publication, not objectionable acquisition. Id. at 832-33; see, e.g., Meier, 2006 WL 2089208, at *3. Here, Plaintiff’s theory has the same missing link. Defendant had the information because Plaintiff willingly provided it
for employment, not because Defendant intruded into his private affairs. See Mills, 536 N.W.2d at 832-33; Polkowski, 2025 WL 3079358, at *11. Applying these principles, Plaintiff pleads a failure to prevent a third-party
intrusion, not an intrusion by Defendant. See Mills, 536 N.W.2d at 832-33; Meier, 2006 WL 2089208, at *3; Polkowski, 2025 WL 3079358, at *11. Thus, Count V is dismissed. Count VI fails for a different but equally narrow reason, which is that
Plaintiff pleads no fiduciary relationship. A breach of fiduciary duty claim requires a fiduciary duty, breach, and damages caused by the breach. Highfield Beach at Lake Mich. v. Sanderson, 954 N.W.2d 231, 247 (Mich. Ct. App. 2020). Whether
such a duty exists is a question of law. Calhoun Cnty. v. Blue Cross Blue Shield Mich., 824 N.W.2d 202, 209 (Mich. Ct. App. 2012). Michigan recognizes fiduciary duties where one party acts for another’s benefit in a relationship of trust,
confidence, superiority, control, advice, or traditional fiduciary status. In re Estate of Karmey, 658 N.W.2d 796, 799 n.2 (Mich. 2003); Highfield Beach, 954 N.W.2d at 247 n.13.
Plaintiff’s theory does not fit that rule because he only alleges that Defendant, his former employer, required his PII and controlled how it was stored. But an employer’s possession of employee information does not, without more, make the employer a fiduciary. See Delphi Auto. PLC v. Absmeier, 167 F. Supp.
3d 868, 884 (E.D. Mich. 2016); Polkowski, 2025 WL 3079358, at *10. At most, Plaintiff alleges reliance on Defendant to safeguard his PII. That may support an ordinary data security duty, but Michigan law requires something more before
imposing fiduciary status. See Calhoun Cnty., 824 N.W.2d at 209; Brooks Williamson & Assocs., Inc. v. Braun, No. 357170, 2022 WL 1508992, at *5-6 (Mich. Ct. App. May 12, 2022). Count VI is dismissed. Conclusion
For the reasons stated above, Plaintiff has standing to seek damages for the alleged completed privacy injury, but he lacks standing to seek prospective relief or to proceed based on speculative future misuse, mitigation efforts tied to that
future risk, diminished value of PII, increased spam communications, or the employee-credential allegations. On the merits, however, Plaintiff has not stated any claim under Michigan law. Accordingly, Defendant’s motion to dismiss is
granted, and all claims are dismissed. Accordingly, IT IS ORDERED that Defendant’s motion to dismiss (ECF No. 13) is
GRANTED.
s/ Linda V. Parker LINDA V. PARKER U.S. DISTRICT JUDGE Dated: August 20, 2026