Reidinger v. Zendesk, Inc.

District Court, N.D. California·Decided March 2, 2021·No. 3:19-cv-06968·Unknown

Opinion

CHARLES REIDINGER, Case No. 19-cv-06968-CRB

Plaintiff, ORDER GRANTING MOTION TO v. DISMISS WITH LEAVE TO AMEND

ZENDESK, INC., et al., Defendants.

A class of Zendesk, Inc. stock purchasers led by Local 353, I.B.E.W. Pension Fund (“the Pension Fund”) is suing Zendesk and two Zendesk officers (collectively, “Zendesk”) for securities fraud under §§ 10(b) and 20(a) of the Securities Exchange Act of 1934 and Securities and Exchange Commission (SEC) Rule 10b-5. The Court previously dismissed the Pension Fund’s First Amended Complaint under Rule 12(b)(6) of the Federal Rules of Civil Procedure for failure to state a claim for which relief may be granted. The Court gave the Pension Fund leave to amend. In its Second Amended Complaint, the Pension Fund alleges that Zendesk made false and misleading statements relating to Zendesk’s data security, resulting in harm to investors after the public learned that Zendesk had suffered a data breach that went undetected for nearly three years. Zendesk has moved to dismiss the Pension Fund’s Second Amended Complaint for failure to state a claim for which relief may be granted. The Court has determined that oral argument is unnecessary and vacates the hearing previously scheduled for March 5, 2021. The Court grants Zendesk’s motion to dismiss because the Pension Fund has not adequately pleaded a material misstatement or omission, and the Pension Fund’s scienter, i.e., fraudulent intent. The Court grants the Pension Fund leave to amend to cure these deficiencies. A. Procedural History On January 24, 2020, the Court consolidated two putative securities class action lawsuits against Zendesk and appointed the Pension Fund as lead plaintiff. See Order Consolidating Cases (dkt. 42). The Pension Fund then filed an Amended Class Action Complaint on behalf of all purchasers of Zendesk common stock between February 6, 2019 and October 1, 2019, inclusive (the Class Period). See FAC (dkt. 51) at 1. The First Amended Complaint alleged that Zendesk and three officers—Chief Executive Officer Mikkel Svane, Chief Financial Officer Elena Gomez, and Senior Vice President of Worldwide Sales Norman Gennaro—committed securities fraud in violation of § 10(b) of the Securities Exchange and SEC Rule 10b-5. See id. ¶¶ 34–36, 124–127. The Pension Fund also alleged that the individual defendants violated § 20(a) of the Securities Exchange Act as control persons liable for any fraud committed by Zendesk and its employees. See id. ¶¶ 128–131. The Pension Fund’s original claims centered on Zendesk’s public statements during the class period in relation to two events: (1) subpar performance in the Europe, Middle East, and Africa (EMEA) and Asia-Pacific (APAC) regions during Q2 2019; and (2) the September 24, 2019 discovery and subsequent disclosure of a data breach that had been ongoing for three years. See Order Dismissing FAC (dkt. 63) at 2. The Court dismissed the Pension Fund’s claims with respect to subpar regional performance because the Pension Fund had not adequately pleaded any false or misleading statement, or facts supporting a strong inference of scienter—that is, Zendesk’s intent to deceive, manipulate, or defraud. Id. at 13–18. The Court dismissed the Pension Fund’s claim with respect to the data breach because Zendesk’s failure to disclose the breach was the only potentially material misstatement or omission that the Pension Fund alleged, and deceive investors about the breach. Id. at 21–22. The Court granted the Pension Fund leave to amend. Id. at 22.1 On January 8, 2021, the Pension Fund filed a Second Amended Complaint. See SAC (dkt. 64). The Pension Fund noted that it had “not renewed its allegations concerning” Zendesk’s regional performance or its claims against Zendesk Senior Vice President of Worldwide Sales Norman Gennaro. Id. at 2 n.2. Instead, the Pension Fund supplemented its allegations regarding the data breach. B. Zendesk and the Data Breach Zendesk sells customer service software to companies. See id. ¶¶ 5–7. In doing so, Zendesk collects, stores, and transmits sensitive customer, agent, and end-user data, including personal identifiable information (PII). Id. ¶ 9. The Pension Fund alleges that Zendesk began hosting its data through Amazon Web Services (AWS)’s cloud computing platform in 2016 and completed its transition to hosting data there in 2019. Id. ¶ 8. But according to the Pension Fund, in 2016 Zendesk “did not follow basic precautions to secure data hosted by AWS.” Id. ¶ 19(a). Before Zendesk had experienced the data breach at issue, AWS had published a list of “best practices.” Id. ¶ 27. The list warned customers to “never share” their “AWS . . . access keys with anyone.” Id. AWS also instructed customers to “enable multifactor authentication for . . . users who are 1 One aspect of the Court’s Order dismissing the First Amended Complaint warrants clarification, if not revision. See Fed. R. Civ. P. 54(b). The Court stated that the Pension Fund’s First Amended Complaint had not alleged “any material misstatement or omission.” See Order Dismissing FAC at 1. But the Court also said that the Pension Fund “alleged a material omission” to the extent that the data breach “would have been viewed by the reasonable investor as significant,” though no allegations supported the inference that Zendesk had acted with scienter in relation to the data breach. See id. at 21 (citation omitted). The Court should have made its seemingly contradictory reasoning clearer, and does so now. The Court recognizes that significance to a reasonable investor is necessary, but not sufficient, to establish a materially misleading omission. See infra part II.B; In re Yahoo! Inc. Sec. Litig., 2012 WL 3282819, at *7 (N.D. Cal. Aug. 10, 2012) (“Silence, absent a duty to disclose, is not misleading under Rule 10b- 5.”) (quoting Basic, Inc. v. Levinson, 485 U.S. 224, 239 n.17 (1988)). The Court’s conclusion that reasonable investors would have viewed the data breach as significant was thus insufficient to establish the further conclusion that Zendesk had materially omitted information about the breach. In effect, the Court assumed that the Pension Fund had plausibly alleged a material omission and relied on the Pension Fund’s more obvious failure to allege facts giving rise to the required allowed access to sensitive resources.” Id. AWS further explained that customers could “use logging features in AWS” to detect nefarious activity by determining “the actions users have taken . . . and the resources that were used.” Id. The Pension Fund alleges that despite these “clear directions,” which were consistent (if not identical) with Zendesk’s own avowed security best practices,2 Zendesk “shared AWS keys” with “a third party vendor.” Id. ¶¶ 19(a), 25. A “small number” of those keys “were compromised,” which allowed “hackers to access customer service data.” Id. Zendesk also implemented multifactor authentication only “after it had provided AWS keys to others and . . . had been breached as a result.” Id. ¶ 19(b). And Zendesk “failed to properly use logging features” that could have enabled Zendesk to detect the breach. Id. As a result, Zendesk suffered a data breach in November 2016 and discovered the breach only after nearly three years had passed. Id. ¶ 51. The Pension Fund alleges that after the breach was discovered and revealed, Zendesk’s stock price fell. Id. ¶¶ 22, 24.3 After the data breach, Zendesk made various public statements regarding the breach’s nature and scale. On October 2, 2019, Zendesk published an “Important Notice regarding 2016 Security Incident” (the Notice) on its website. Id. ¶ 25. The Complaint incorporates relevant parts of the Notice:

Free access — add to your briefcase to read the full text and ask questions with AI

Reidinger v. Zendesk, Inc., (N.D. Cal. 2021).

Reidinger v. Zendesk, Inc. (Reidinger v. Zendesk, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Adams v. Woods
6 U.S. 336 (Supreme Court, 1805)
Ernst & Ernst v. Hochfelder
425 U.S. 185 (Supreme Court, 1976)
TSC Industries, Inc. v. Northway, Inc.
426 U.S. 438 (Supreme Court, 1976)
Santa Fe Industries, Inc. v. Green
430 U.S. 462 (Supreme Court, 1977)
Chiarella v. United States
445 U.S. 222 (Supreme Court, 1980)
Basic Inc. v. Levinson
485 U.S. 224 (Supreme Court, 1988)
Tellabs, Inc. v. Makor Issues & Rights, Ltd.
551 U.S. 308 (Supreme Court, 2007)
Matrixx Initiatives, Inc. v. Siracusano
131 S. Ct. 1309 (Supreme Court, 2011)
Gebhart v. Securities & Exchange Commission
595 F.3d 1034 (Ninth Circuit, 2010)
Glazer Capital Management, LP v. Magistri
549 F.3d 736 (Ninth Circuit, 2008)
Leadsinger, Inc. v. BMG Music Publishing
512 F.3d 522 (Ninth Circuit, 2008)
Carl Schwartz v. Arena Pharmaceuticals, Inc.
840 F.3d 698 (Ninth Circuit, 2016)
Karim Khoja v. Orexigen Therapeutics, Inc.
899 F.3d 988 (Ninth Circuit, 2018)
Nordstrom, Inc. v. Chubb & Son, Inc.
54 F.3d 1424 (Ninth Circuit, 1995)