Schmitt v. SN Servicing Corporation, an Alaska Corporation

District Court, N.D. California·Decided November 12, 2021·No. 3:21-cv-03355·Unknown

Opinion

1 2 3 6 7 DESIREE SCHMITT, et al., Case No. 21-cv-03355-WHO

8 Plaintiffs, ORDER GRANTING IN PART AND 9 v. DENYING IN PART MOTION TO DISMISS ALASKA CORPORATION, Re: Dkt. No. 35 11 Defendant.

12 13 Plaintiff Desiree Schmitt brings this lawsuit against defendant SN Servicing Corporation 14 (“SNSC”) on behalf of a nationwide class of impacted borrowers for claims arising out of a data 15 breach incident that occurred on SNSC’s system in late 2020, of which SNSC did not notify its 16 customers for three months. SNSC has filed a motion to dismiss Schmitt’s First Amended 17 Complaint (“FAC”), which is GRANTED in part and DENIED in part, with leave to amend. The 18 motion is GRANTED with prejudice on Schmitt’s invasion of privacy claim because she has not 19 adequately alleged egregious conduct by SNSC. The motion is also GRANTED on the claim 20 brought under the “unlawful” prong of the UCL, with leave to amend. Although the Ninth Circuit 21 permits the Federal Trade Commission (“FTC”) Act and Guides to serve as predicates for 22 unlawful UCL claims, Schmitt has not pleaded these violations with enough specificity. The 23 motion is DENIED on Schmitt’s claim brought under the “unfair” prong of the UCL as well as her 24 negligence claim, as she has sufficiently pleaded elements of both. 26 Schmitt was a customer of SNSC, a financial services corporation that specializes in 27 servicing residential, small balance commercial, consumer, and unsecured loans. FAC [Dkt. No. 1 (the “Unauthorized Party”) deployed ransomware into SNSC’s system and successfully acquired a 2 number of digital files maintained by SNSC (known hereinafter as the “data breach”). Id. at ¶ 15. 3 She states that the personal and financial information of at least 170,426 people were stolen and 4 held for ransom. Id. at ¶ 18. She also alleges that despite learning of the data breach and alerting 5 the Federal Bureau of Investigation “almost immediately,” SNSC did not notify Schmitt or class 6 members of the breach until January 14, 2021. Id. at ¶ 19. 7 SNSC’s Notice of Data Breach (“Notice”) informed recipients that personal information 8 was acquired through a “ransomware” attack that “may include, but is potentially not limited to: 9 your name, address, loan numbers, balance information and billing information such as charges 10 assessed, owed and/or paid.” Id. at ¶ 20 (citing Ex. B). The letter also stated that SNSC was “still 11 in the process of conducting a comprehensive investigation of this incident” and that recipients 12 “will be notified in the event we discover that any additional nonpublic personal information 13 (‘NPI’) or personally identifiable information (‘PII’) pertaining to you was exposed.” Id. at ¶ 21 14 (citing Ex. B). The Notice encouraged recipients, “[o]ut of an abundance of caution,” to “remain 15 vigilant . . . review your account statements and immediately report any suspicious activity.” See 16 id. at ¶ 67; Ex. B. It also recommended that recipients “obtain credit reports from each nationwide 17 credit reporting agency.” Id. 18 Schmitt claims that she did just that, purchasing credit monitoring at an annual cost of 19 more than $200, along with a password manager (costing $3 per month) and password protection 20 (costing more than $90). FAC at ¶ 68. She also contends that she has spent and will continue to 21 spend “time and energy protecting and monitoring her identity and credit,” including at least four 22 hours reviewing bank accounts and statements and at least 10 hours changing “hundreds of 23 passwords related to her business and personal accounts.” Id. at ¶ 69. 24 This vigilance was warranted, Schmitt contends. She alleges that on or around July 16, 25 2021, SNSC provided a supplemental disclosure to some class members stating that names, 26 contact information, birthdates, Social Security numbers, and “loan/borrower information” had 27 also been stolen in the data breach. Id. at ¶ 30 (citing Ex. C). Schmitt concedes that she did not 1 Id. at ¶ 66. Schmitt further argues that she had “no reason to doubt, and every reason to assume,” 2 that her Social Security number, birthdate, and “loan/borrower information” was “also stolen and 3 in the hands of criminals.” Id. Schmitt asserts that she and other class members “provided their 4 lenders, servicers, and SNSC with significant personal, income, and financial information that 5 SNSC was able to acquire and to supplement by obtaining credit reports and banking information 6 from third parties.” Id. at ¶ 63. This information, she contends, includes: full names, mailing 7 addresses, phone numbers, email addresses, loan identification numbers, tax information, and 8 Social Security numbers. See id. 9 Schmitt contends that personal and financial information is “such a valuable commodity to 10 identity thieves that once information has been compromised, criminals often trade the 11 information on the ‘cyber black-market’ for years.” Id. at ¶ 53. As such, she argues, “there is a 12 strong probability that entire batches of stolen information have been dumped on the black market, 13 or are yet to be dumped on the black market,” placing her and other class members “at an 14 increased risk of fraud and identity theft for many years into the future.” Id. at ¶ 54. She also 15 alleges that after the data breach, she has experienced an “increase in spam, phishing attempts, and 16 social engineering,” including repeated robotexts to her cell phone. Id. at ¶ 70. 17 Schmitt blames SNSC for the data breach, arguing that its “failure to adhere to reasonable 18 and necessary industry standards . . . resulted in the Data Breach and exacerbated its scope and 19 impact.” Id. at ¶ 32. She claims that SNSC undertook “basic steps recognized in the industry” to 20 protect her and other class members’ personal and financial information only after the breach. Id. 21 at ¶ 35. According to Schmitt, these steps included “replacing email filtering tools, malware 22 software, and Internet monitoring tools with more robust solutions that utilize artificial 23 intelligence (AI) to detect and block known and newly introduced malware,” and blocking all 24 Internet traffic with foreign countries. See id. (citing Ex. B). Schmitt also alleges that SNSC 25 failed to comply with FTC cybersecurity standards. See id. at ¶¶ 37-43. Schmitt argues that had 26 SNSC properly maintained its systems and protected Schmitt and other class members’ 27 information, it could have prevented the breach. See id. at ¶ 44. She also contends that SNSC 1 Schmitt filed this lawsuit in San Francisco County Superior Court on March 12, 2021, 2 bringing three claims on behalf of a nationwide class of borrowers impacted by the data breach: 3 (1) negligence; (2) invasion of privacy; (3) the “unlawful” and “unfair” prongs of California’s 4 Unfair Competition Law (“UCL”).1 On May 5, 2021, SNSC removed the action to federal court 5 and subsequently filed a motion to dismiss for failure to state a claim. Dkt. Nos. 1, 14. Although I 6 found that Schmitt could assert California law claims as an Ohio resident, she failed to plausibly 7 plead elements of those claims. See Mot. to Dismiss Order (“First MTD Order”) [Dkt. No. 27] 1. 8 As such, I denied the motion in part and granted in part with leave to amend. Id. Schmitt filed her 9 FAC on August 30, 2021, which prompted a second motion to dismiss by SNSC. Dkt. Nos. 34, 10 35. I now consider that motion. 12 Under Federal Rule of Civil Procedure 12(b)(6), a district court must dismiss a complaint 13 if it fails to state a claim upon which relief can be granted. To survive a Rule 12(b)(6) motion to 14 dismiss, the plaintiff must allege “enough facts to state a claim to relief that is plausible on its 15 face.” See Bell Atl. Corp. v. Twombly,

Schmitt v. SN Servicing Corporation, an Alaska Corporation, (N.D. Cal. 2021).

Schmitt v. SN Servicing Corporation, an Alaska Corporation (Schmitt v. SN Servicing Corporation, an Alaska Corporation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Gary Davis v. Hsbc Bank Nevada, N.A.
691 F.3d 1152 (Ninth Circuit, 2012)
Rose v. Bank of America
304 P.3d 181 (California Supreme Court, 2013)
In Re Gilead Sciences Securities Litigation
536 F.3d 1049 (Ninth Circuit, 2008)
People v. Garcia
980 P.2d 829 (California Supreme Court, 1999)
Lozano v. AT & T Wireless Services, Inc.
504 F.3d 718 (Ninth Circuit, 2007)
Conroy v. Regents of University of California
203 P.3d 1127 (California Supreme Court, 2009)
Linda Rubenstein v. Neiman Marcus Group
687 F. App'x 564 (Ninth Circuit, 2017)
The Regents of the University of California v. Superior Court
413 P.3d 656 (California Supreme Court, 2018)
Sakai v. Massco Invs., LLC
229 Cal. Rptr. 3d 775 (California Court of Appeals, 5th District, 2018)
Lopez v. Smith
203 F.3d 1122 (Ninth Circuit, 2000)
In re Adobe Systems, Inc. Privacy Litigation
66 F. Supp. 3d 1197 (N.D. California, 2014)
Golden v. Sound Inpatient Physicians Medical Group, Inc.
93 F. Supp. 3d 1171 (E.D. California, 2015)
In re Anthem, Inc. Data Breach Litigation
162 F. Supp. 3d 953 (N.D. California, 2016)
In re iPhone Application Litig.
844 F. Supp. 2d 1040 (N.D. California, 2012)
Low v. Linkedin Corp.
900 F. Supp. 2d 1010 (N.D. California, 2012)