Quinalty v. FocusIT LLC

District Court, D. Arizona·Decided December 26, 2024·No. 2:23-cv-00207·Unknown

Opinion

WO

Joshua Quinalty and Alene Motta, on behalf No. CV-23-00207-PHX-KML of himself and all others similarly situated, Plaintiff, v. FocusIT LLC, Defendant.

Defendant FocusIT, LLC, a software vendor, possessed the personal data of plaintiffs Joshua Quinalty and Alene Motta when its computer systems were compromised. Quinalty and Motta had provided their data to non-parties (like banks and mortgage lenders) when applying for mortgage and loan services and the non-parties in turn provided it to FocusIT. When FocusIT’s data systems were compromised on June 1, 2022, Quinalty and Motta’s personal data was exposed. They filed an amended putative class action complaint against FocusIT on behalf of themselves and class members alleging FocusIT (1) negligently managed their data; and (2) was unjustly enriched as a result. FocusIT moved to dismiss Quinalty and Motta’s complaint and strike their class allegations. FocusIT’s motion to dismiss is granted and its motion to strike is denied as moot. I. Background FocusIT provides software for banks and financial institutions to “process financial transactions, such as loan applications.” (Doc. 36 at 2.) As a condition of providing this software, FocusIT requires these banks and financial institutions to provide personal identifying information (“PII”) of its customers. (Doc. 36 at 5.) These banks in turn require their customers to submit their PII to the banks to receive certain financial services. (Doc. 36 at 15.) The banks and financial institutions then “entrust” their customers’ PII to FocusIT. (Doc. 36 at 2.) On June 1, 2022, unknown actors “compromised a system” in FocusIT’s “environment,” exposing to cybercriminals the names, birth dates, addresses, and social security numbers of 147,799 people. (Doc. 36 at 11.) Two months later, the Texas Financial Crimes Intelligence Center (“TFCIC”) notified FocusIT it had detected the breach. (Doc. 36 at 11.) FocusIT was not aware of the breach before the TFCIC’s warning. (Doc. 36 at 11.) Governmental authorities reported that the breach resulted from a phishing attack. (Doc. 36 at 11.) Nearly two months later on September 28, 2022, FocusIT began to notify victims of the data breach. (Doc. 36 at 12.) FocusIT offered free credit monitoring services for a year to those impacted by the breach. (Doc. 36 at 3.) Quinalty alleges his PII was included in the data breach and as a result he purchased additional credit monitoring services, experienced an increase in spam phone calls, messages, and targeted advertisements, spent approximately twelve hours responding to the breach, and is subject to “the present and continuing risk of fraud, identity theft, and misuse resulting from his PII . . . being placed in the hands of unauthorized third parties/criminals.” (Doc. 36 at 16–17.) To his knowledge, he had never been the victim of a data breach before. (Doc. 36 at 15.) But while the breach was occurring, he alleges two iPhones were purchased under “his Verizon account using a fake ID that contained his PII.” (Doc. 36 at 16.) Motta also alleges that her data was included in the breach and a result she experienced an increase in spam emails, text messages, and phone calls, including “‘vishing’ phone calls from unknown callers engaging in attempted scams”; spent approximately three hours responding to the breach; and discovered her PII was detected on the “dark web” where “[h]ackers can access and then offer for sale” unencrypted PII. (Doc. 38 at 12, 18–19.) As a result, she alleges she has experienced anxiety and emotional distress, including sleep disruption, stomach issues, and trouble focusing. (Doc. 36 at 18.) Quinalty and Motta filed claims of negligence, unjust enrichment, and violations of the Arizona Consumer Fraud Act (“ACFA”) against FocusIT on behalf of themselves and a putative nationwide class consisting of all United States residents whose PII was compromised in the data breach. (Doc. 26 at 28–38.) FocusIT moved to dismiss the claims, arguing Quinalty and Motta lacked standing and failed to state a claim. (Doc. 27.) The court granted the motion to dismiss in part, finding Quinalty and Motta failed to state a claim for negligence, unjust enrichment, or a violation of the ACFA. (Doc. 34 at 11.) Quinalty and Motta filed an amended complaint realleging only their claims of negligence and unjust enrichment. (Doc. 36 at 30, 38–39.) FocusIT moved to dismiss again, arguing Quinalty and Motta lacked standing and failed to state a claim. FocusIT also moved to strike their class allegations. (Doc. 40 at 2.) FocusIT’s motion to dismiss is granted because plaintiffs have failed to state a claim and its motion to strike is denied as moot. II. Failure to Allege Jurisdiction FocusIT moves to dismiss Quinalty and Motta’s claims under Rule 12(b)(1) for lack of standing. Facial challenges under Rule 12(b)(1) “are adjudicated under the familiar Rule 12(b)(6) standard.” Bowen v. Energizer Holdings, Inc., 118 F.4th 1134, 1142 n.7 (9th Cir. 2024). Under a facial challenge, as here, the moving party accepts the truth of plaintiff’s allegations but asserts they are “insufficient on their face to invoke federal jurisdiction.” Jones v. L.A. Cent. Plaza LLC, 74 F.4th 1053, 1056 n.1 (9th Cir. 2023) (quoting Leite v. Crane Co., 749 F.3d 1117, 1121 (9th Cir. 2014)). “‘[A]t the pleading stage, plaintiffs must clearly allege facts demonstrating each element’ of Article III standing and that the Iqbal pleading standards therefore apply in assessing the facial adequacy of allegations of standing.” Id. at 1056 (quoting Winsor v. Sequoia Benefits & Ins. Servs., LLC, 62 F.4th 517, 523–25 (9th Cir. 2023)). Standing is “an essential and unchanging part of the case-or-controversy requirement of Article III” of the United States Constitution. Lujan v. Defs. of Wildlife, 504 U.S. 555, 560 (1992). A plaintiff must show “(1) an injury in fact that is (a) concrete and particularized and (b) actual or imminent; (2) the injury is fairly traceable to the challenged action of the defendant; and (3) it is likely, not merely speculative, that the injury will be redressed by a favorable decision.” Maya v. Centex Corp., 658 F.3d 1060, 1067 (9th Cir. 2011) (quoting Friends of the Eart, Inc. v. Laidlaw Envtl. Servs., Inc., 528 U.S. 167, 180-81 (2000)). The court previously rejected FocusIT’s standing argument. (Doc. 34 at 5.) FocusIT resurrects that argument now, sometimes adding a slight twist. Because Quinalty, Motta, and the class plaintiffs all have standing, these arguments are rejected again. First as to Quinalty, FocusIT argues he has not shown a fairly-traceable injury because it is unclear (1) whether the fraudulent charges were caused by the FocusIT data breach or a different breach; (2) Quinalty himself had to pay for the fraudulent charges; and (3) the credit monitoring services provided by FocusIT were inadequate. (Doc. 40 at 5– 6.) FocusIT also argues Quinalty’s injury is too speculative because he purchased credit reporting services based on a future risk that has not materialized. (Doc. 40 at 5–6.) “[A] plaintiff meets the injury-in-fact requirement by alleging an increased risk of identity theft due to the theft of his or her PII even without alleging that any actual identity theft has occurred.” In re Banner Health Data Breach Litig., No. CV-16-02696-PHX-SRB, 2017 WL 6763548, at *2 (D. Ariz. Dec. 20, 2017) (citing Krottner v. Starbucks Corp., 328 F

Free access — add to your briefcase to read the full text and ask questions with AI

Quinalty v. FocusIT LLC, (D. Ariz. 2024).

Quinalty v. FocusIT LLC (Quinalty v. FocusIT LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Robey v. Shapiro, Marianos & Cejda, L.L.C.
434 F.3d 1208 (Tenth Circuit, 2006)
Cervantes v. Countrywide Home Loans, Inc.
656 F.3d 1034 (Ninth Circuit, 2011)
Maya v. Centex Corp.
658 F.3d 1060 (Ninth Circuit, 2011)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Gipson v. Kasey
150 P.3d 228 (Arizona Supreme Court, 2007)
Johnson v. American National Insurance
613 P.2d 1275 (Court of Appeals of Arizona, 1980)
CDT, Inc. v. Addison, Roberts & Ludwig, C.P.A., P.C.
7 P.3d 979 (Court of Appeals of Arizona, 2000)
Loiselle v. COSAS MANAGEMENT GROUP, LLC
228 P.3d 943 (Court of Appeals of Arizona, 2010)
Douglas Leite v. Crane Company
749 F.3d 1117 (Ninth Circuit, 2014)
Mike Robertson v. Facebook, Inc.
572 F. App'x 494 (Ninth Circuit, 2014)
April Abigail Guerra v. State of Arizona
348 P.3d 423 (Arizona Supreme Court, 2015)
Hilary Remijas v. Neiman Marcus Group, LLC
794 F.3d 688 (Seventh Circuit, 2015)
Ernest Quiroz Et Ux v. Alcoa Inc
416 P.3d 824 (Arizona Supreme Court, 2018)
Span v. Maricopa
437 P.3d 881 (Court of Appeals of Arizona, 2019)
Rachael Winsor v. Sequoia Benefits & Insurance
62 F.4th 517 (Ninth Circuit, 2023)
George Jones v. L.A. Central Plaza, LLC
74 F.4th 1053 (Ninth Circuit, 2023)