Schmitt v. SN Servicing Corporation, an Alaska Corporation

District Court, N.D. California·Decided November 12, 2021·No. 3:21-cv-03355·Unknown

Opinion

DESIREE SCHMITT, et al., Case No. 21-cv-03355-WHO

Plaintiffs, ORDER GRANTING IN PART AND v. DENYING IN PART MOTION TO DISMISS ALASKA CORPORATION, Re: Dkt. No. 35 Defendant.

Plaintiff Desiree Schmitt brings this lawsuit against defendant SN Servicing Corporation (“SNSC”) on behalf of a nationwide class of impacted borrowers for claims arising out of a data breach incident that occurred on SNSC’s system in late 2020, of which SNSC did not notify its customers for three months. SNSC has filed a motion to dismiss Schmitt’s First Amended Complaint (“FAC”), which is GRANTED in part and DENIED in part, with leave to amend. The motion is GRANTED with prejudice on Schmitt’s invasion of privacy claim because she has not adequately alleged egregious conduct by SNSC. The motion is also GRANTED on the claim brought under the “unlawful” prong of the UCL, with leave to amend. Although the Ninth Circuit permits the Federal Trade Commission (“FTC”) Act and Guides to serve as predicates for unlawful UCL claims, Schmitt has not pleaded these violations with enough specificity. The motion is DENIED on Schmitt’s claim brought under the “unfair” prong of the UCL as well as her negligence claim, as she has sufficiently pleaded elements of both. Schmitt was a customer of SNSC, a financial services corporation that specializes in servicing residential, small balance commercial, consumer, and unsecured loans. FAC [Dkt. No. (the “Unauthorized Party”) deployed ransomware into SNSC’s system and successfully acquired a number of digital files maintained by SNSC (known hereinafter as the “data breach”). Id. at ¶ 15. She states that the personal and financial information of at least 170,426 people were stolen and held for ransom. Id. at ¶ 18. She also alleges that despite learning of the data breach and alerting the Federal Bureau of Investigation “almost immediately,” SNSC did not notify Schmitt or class members of the breach until January 14, 2021. Id. at ¶ 19. SNSC’s Notice of Data Breach (“Notice”) informed recipients that personal information was acquired through a “ransomware” attack that “may include, but is potentially not limited to: your name, address, loan numbers, balance information and billing information such as charges assessed, owed and/or paid.” Id. at ¶ 20 (citing Ex. B). The letter also stated that SNSC was “still in the process of conducting a comprehensive investigation of this incident” and that recipients “will be notified in the event we discover that any additional nonpublic personal information (‘NPI’) or personally identifiable information (‘PII’) pertaining to you was exposed.” Id. at ¶ 21 (citing Ex. B). The Notice encouraged recipients, “[o]ut of an abundance of caution,” to “remain vigilant . . . review your account statements and immediately report any suspicious activity.” See id. at ¶ 67; Ex. B. It also recommended that recipients “obtain credit reports from each nationwide credit reporting agency.” Id. Schmitt claims that she did just that, purchasing credit monitoring at an annual cost of more than $200, along with a password manager (costing $3 per month) and password protection (costing more than $90). FAC at ¶ 68. She also contends that she has spent and will continue to spend “time and energy protecting and monitoring her identity and credit,” including at least four hours reviewing bank accounts and statements and at least 10 hours changing “hundreds of passwords related to her business and personal accounts.” Id. at ¶ 69. This vigilance was warranted, Schmitt contends. She alleges that on or around July 16, 2021, SNSC provided a supplemental disclosure to some class members stating that names, contact information, birthdates, Social Security numbers, and “loan/borrower information” had also been stolen in the data breach. Id. at ¶ 30 (citing Ex. C). Schmitt concedes that she did not Id. at ¶ 66. Schmitt further argues that she had “no reason to doubt, and every reason to assume,” that her Social Security number, birthdate, and “loan/borrower information” was “also stolen and in the hands of criminals.” Id. Schmitt asserts that she and other class members “provided their lenders, servicers, and SNSC with significant personal, income, and financial information that SNSC was able to acquire and to supplement by obtaining credit reports and banking information from third parties.” Id. at ¶ 63. This information, she contends, includes: full names, mailing addresses, phone numbers, email addresses, loan identification numbers, tax information, and Social Security numbers. See id. Schmitt contends that personal and financial information is “such a valuable commodity to identity thieves that once information has been compromised, criminals often trade the information on the ‘cyber black-market’ for years.” Id. at ¶ 53. As such, she argues, “there is a strong probability that entire batches of stolen information have been dumped on the black market, or are yet to be dumped on the black market,” placing her and other class members “at an increased risk of fraud and identity theft for many years into the future.” Id. at ¶ 54. She also alleges that after the data breach, she has experienced an “increase in spam, phishing attempts, and social engineering,” including repeated robotexts to her cell phone. Id. at ¶ 70. Schmitt blames SNSC for the data breach, arguing that its “failure to adhere to reasonable and necessary industry standards . . . resulted in the Data Breach and exacerbated its scope and impact.” Id. at ¶ 32. She claims that SNSC undertook “basic steps recognized in the industry” to protect her and other class members’ personal and financial information only after the breach. Id. at ¶ 35. According to Schmitt, these steps included “replacing email filtering tools, malware software, and Internet monitoring tools with more robust solutions that utilize artificial intelligence (AI) to detect and block known and newly introduced malware,” and blocking all Internet traffic with foreign countries. See id. (citing Ex. B). Schmitt also alleges that SNSC failed to comply with FTC cybersecurity standards. See id. at ¶¶ 37-43. Schmitt argues that had SNSC properly maintained its systems and protected Schmitt and other class members’ information, it could have prevented the breach. See id. at ¶ 44. She also contends that SNSC Schmitt filed this lawsuit in San Francisco County Superior Court on March 12, 2021, bringing three claims on behalf of a nationwide class of borrowers impacted by the data breach: (1) negligence; (2) invasion of privacy; (3) the “unlawful” and “unfair” prongs of California’s Unfair Competition Law (“UCL”).1 On May 5, 2021, SNSC removed the action to federal court and subsequently filed a motion to dismiss for failure to state a claim. Dkt. Nos. 1, 14. Although I found that Schmitt could assert California law claims as an Ohio resident, she failed to plausibly plead elements of those claims. See Mot. to Dismiss Order (“First MTD Order”) [Dkt. No. 27] 1. As such, I denied the motion in part and granted in part with leave to amend. Id. Schmitt filed her FAC on August 30, 2021, which prompted a second motion to dismiss by SNSC. Dkt. Nos. 34, 35. I now consider that motion. Under Federal Rule of Civil Procedure 12(b)(6), a district court must dismiss a complaint if it fails to state a claim upon which relief can be granted. To survive a Rule 12(b)(6) motion to dismiss, the plaintiff must allege “enough facts to state a claim to relief that is plausible on its face.” See Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007). A claim is facially plausible when the plaintiff pleads facts that allow the court to “draw the reasonable inference that the defendant is liable for the misconduct alleged.” See Ashcroft v. Iqbal,

Schmitt v. SN Servicing Corporation, an Alaska Corporation, (N.D. Cal. 2021).

Schmitt v. SN Servicing Corporation, an Alaska Corporation (Schmitt v. SN Servicing Corporation, an Alaska Corporation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Gary Davis v. Hsbc Bank Nevada, N.A.
691 F.3d 1152 (Ninth Circuit, 2012)
Rose v. Bank of America
304 P.3d 181 (California Supreme Court, 2013)
In Re Gilead Sciences Securities Litigation
536 F.3d 1049 (Ninth Circuit, 2008)
People v. Garcia
980 P.2d 829 (California Supreme Court, 1999)
Lozano v. AT & T Wireless Services, Inc.
504 F.3d 718 (Ninth Circuit, 2007)
Conroy v. Regents of University of California
203 P.3d 1127 (California Supreme Court, 2009)
Linda Rubenstein v. Neiman Marcus Group
687 F. App'x 564 (Ninth Circuit, 2017)
The Regents of the University of California v. Superior Court
413 P.3d 656 (California Supreme Court, 2018)
Sakai v. Massco Invs., LLC
229 Cal. Rptr. 3d 775 (California Court of Appeals, 5th District, 2018)
Lopez v. Smith
203 F.3d 1122 (Ninth Circuit, 2000)
In re Adobe Systems, Inc. Privacy Litigation
66 F. Supp. 3d 1197 (N.D. California, 2014)
Golden v. Sound Inpatient Physicians Medical Group, Inc.
93 F. Supp. 3d 1171 (E.D. California, 2015)
In re Anthem, Inc. Data Breach Litigation
162 F. Supp. 3d 953 (N.D. California, 2016)
In re iPhone Application Litig.
844 F. Supp. 2d 1040 (N.D. California, 2012)
Low v. Linkedin Corp.
900 F. Supp. 2d 1010 (N.D. California, 2012)