Smallman v. MGM Resorts International

District Court, D. Nevada·Decided November 2, 2022·No. 2:20-cv-00376·Unknown

Opinion

SMALLMAN et al., ) ) Plaintiffs, ) Case No.: 2:20-cv-00376-GMN-EJY vs. ) ) ORDER MGM Resorts International, ) ) Defendant. ) )

Pending before the Court is Defendant MGM Resorts International’s (“Defendant MGM’s”) Motion to Dismiss, (ECF No. 103). Plaintiffs Ryan Bohlim, Duke Hwynn, Andrew Sedaghatpour, Gennady Simkin, Robert Taylor, Michael Fossett, Victor Wukovits, Kerri Shapiro, Julie Mutsko, John Dvorak, Larry Lawter, individually and on behalf of those similarly situated (collectively “Plaintiffs”) filed a Response, (ECF No. 109), and Defendant MGM filed a Reply, (ECF No. 117). For the reasons discussed below, the Court GRANTS in part and DENIES in part Defendant MGM’s Motion to Dismiss. This case arises from a July 7, 2019, data breach of Defendant MGM’s network in which hackers download the personally identifiable information (“PII”) of Defendant MGM guests worldwide (“Data Breach”). (Consolidated Class Action Complaint (“CAC”) ¶¶ 1, 29, ECF No. 101). Plaintiffs are a consolidated class action of consumers whose PII was stolen in the Data Breach. (Id.). Specifically, hackers accessed Plaintiffs name, address, phone number, email address, and dates of birth (Id. ¶¶ 2, 29). Furthermore, certain Plaintiffs also had their driver’s license number, passports number, and military identification number stolen. (Id.). Plaintiffs allege that the stolen PII has been posted on the dark web for purchase on at least three separate occasions. (Id. ¶ 46). Cybersecurity journalists have observed that the PII of at least 10.6 million MGM guests are available on a dark web hacking forum. (Id ¶ 34). In a letter to the North Dakota Attorney General on September 7, 2019, Defendant MGM noted that the hacker “posted the data on a closed internet forum with the intent to sell the information for financial gain.” (Id. ¶ 32). Plaintiffs posit that they now face a long-term heightened risk that their PII will be sold or disseminated on the dark web. (Id. 47–65). Defendant MGM has not disclosed how the hackers were able to obtain consumers PII. (Id. ¶ 37). However, a Defendant MGM spokesperson revealed that the Data Breach may have been caused by “unauthorized access to a cloud server.”1 (Id.) Further, Defendant MGM disclosed to the North Dakota Attorney General that the hackers “exfiltrated data by exploiting a compromised account.” (Id. ¶ 38). Despite the Data Breach occurring on July 7, 2019, Defendant MGM did not notify affected consumers until nearly two months later, on September 7, 2019. (Id. ¶ 44). Plaintiffs allege that Defendant MGM’s delayed response exacerbated the risk of harm to Plaintiffs. (Id. ¶ 45). Plaintiffs contend that Defendant MGM failed to implement reasonable data security measures to protect their PII, maintain and monitor its server against intrusions, and retained Plaintiffs PII for longer than necessary. (Id. ¶¶ 7, 77, 90–91). Additionally, Plaintiffs allege that Defendant MGM failed to encrypt the PII stored on its server. (Id. ¶ 38). Furthermore, Plaintiffs allege that Defendant MGM failed to adopt reasonable safety measures despite

knowing that the hotel industry is frequently targeted by cyber security attacks. (Id. ¶ 77–88). Following the Data Breach, all Plaintiffs have experienced an increase in spam and phishing phone calls, text messages, and emails. (Id. ¶¶ 10–20). Similarly, all Plaintiffs allege 1 See Details of 10.6 Million MGM Hotel Guests Posted on a Hacking Forum, ZDNet, Feb. 19, 2020, available at https://www.zdnet.com/article/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking- forum/ (quoting unnamed “MGM spokesperson”) (last visited Oct. 26, 2022). that they have spent a greater amount of time monitoring their financial and other accounts. (Id.). Additionally, all Plaintiffs contend that their PII is available on the dark web, and that they have been forced to expend a significant amount of time and energy resetting passwords and taking additional steps to protect their PII. (Id.). Plaintiffs posit that the value of their PII has diminished due to its dissemination. (Id. ¶¶ 5, 100). Plaintiffs further contend they have suffered “benefit of the bargain” damages because they paid MGM for services that were “intended to be accompanied by adequate data security[] but were not.” (Id. ¶ 5, 111–12). In addition to the alleged injuries set forth above, several Plaintiffs have asserted additional harms. Specifically, multiple Plaintiffs contend that criminals have attempted to make fraudulent purchases on their accounts. (Id. ¶¶ 13–14, 16). Other Plaintiffs assert that criminals have perpetrated ransom attacks against them or attempted to sign into their personal accounts. (Id. ¶ 11, 16, 19). Several Plaintiffs have taken the additional step of purchasing security services to protect their PII. (Id. ¶¶ 12, 16, 20). On April 4, 2021, Plaintiffs filed the present Consolidated Class Action Complaint asserting claims for: (1) negligence; (2) negligent misrepresentation; (3) breach of implied contract; (4) unjust enrichment; (5) violation of the Nevada Consumer Fraud Act, NRS § 41.600; (6) violation of the California Unfair Competition Law, Cal. Bus. & Prof. Code §§ 17200, et seq.; (7) violation of the California Consumers Legal Remedies Act, Cal. Civ. Code §§ 1750, et seq.; (8) violation of the California Customer Records Act, Cal. Civ. Code §§ 1798.80, et seq.; (9) violation of the Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. §

Free access — add to your briefcase to read the full text and ask questions with AI

Smallman v. MGM Resorts International, (D. Nev. 2022).

Smallman v. MGM Resorts International (Smallman v. MGM Resorts International) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Foman v. Davis
371 U.S. 178 (Supreme Court, 1962)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
John Desoto v. Yellow Freight Systems, Inc.
957 F.2d 655 (Ninth Circuit, 1992)
MacKintosh v. Jack Matthews and Co.
855 P.2d 549 (Nevada Supreme Court, 1993)
Calloway v. City of Reno
993 P.2d 1259 (Nevada Supreme Court, 2000)
Kearns v. Ford Motor Co.
567 F.3d 1120 (Ninth Circuit, 2009)
Williams v. Gerber Products Co.
552 F.3d 934 (Ninth Circuit, 2008)
Giles v. General Motors Acceptance Corp.
494 F.3d 865 (Ninth Circuit, 2007)
Lozano v. AT & T Wireless Services, Inc.
504 F.3d 718 (Ninth Circuit, 2007)
Leasepartners Corp. v. Robert L. Brooks Trust
942 P.2d 182 (Nevada Supreme Court, 1997)
Bower v. International Business MacHines, Inc.
495 F. Supp. 2d 837 (S.D. Ohio, 2007)
Goshen v. Mutual Life Insurance
774 N.E.2d 1190 (New York Court of Appeals, 2002)
In Re Autocue Sales & Distributing Corp.
162 F. Supp. 17 (S.D. New York, 1958)
Stutman v. Chemical Bank
731 N.E.2d 608 (New York Court of Appeals, 2000)
Berryman v. Merit Property Management, Inc.
62 Cal. Rptr. 3d 177 (California Court of Appeal, 2007)