Stamat v. Grandizio Wilkins Little & Matthews, LLP

District Court, D. Maryland·Decided August 31, 2022·No. 1:22-cv-00747·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND

* SPYRO STAMAT, individually and on * behalf of others similarly situated, * * Plaintiff, * * v. * Civil Case No.: SAG-22-00747 * GRANDIZIO WILKINS LITTLE & * MATTHEWS, LLP, * * Defendant. * * * * * * * * * * * * * * *

MEMORANDUM OPINION

Plaintiff Spyro Stamat, on behalf of himself and others similarly situated, filed this class action against Defendant Grandizio Wilkins Little & Matthews, LLP (“Grandizio”) seeking monetary, declaratory, and injunctive relief for the alleged negligent failure to protect Personal Identifying Information (“PII”) from unauthorized access, and for unjust enrichment. ECF 1. Defendant has filed a Motion to Dismiss the Complaint (“Motion”). ECF 16. The issues have been fully briefed, ECF 16-1, 18, 23, and no hearing is necessary. See Local Rule 105.6 (D. Md. 2021). For the following reasons, Defendant’s Motion will be granted. I. BACKGROUND The following facts are derived from the Complaint, ECF 1, and are taken as true for purposes of evaluating Defendant’s Motion. Plaintiff, Mr. Stamat, is a resident of Delaware. ECF 1 ¶ 9. Defendant Grandizio, a Maryland corporation, is an accounting firm that offers tax and business services. Id. ¶¶ 15–16. Grandizio acquires and stores PII of individuals in connection with its services. Id. ¶ 49. 1 A. The Data Breach On June 7, 2021, Grandizio discovered unauthorized access into one of its employee’s email accounts. ECF 1 ¶ 28. Grandizio commissioned an investigation with cybersecurity experts to determine whether any information had been compromised. Id. ¶ 29. The internal investigation

completed on December 17, 2021, but could not conclusively determine whether any data has been or will be misused by those who gained unauthorized access to the email account. Id. ¶¶ 35, 36. The following month, on or around January 14, 2022, Grandizio informed relevant States’ Attorney Generals about the breach of its email account. Id. ¶ 38. At the same time, Grandizio sent written notification to any individuals whose data may have been compromised. Id. ¶ 39. Thereafter, Mr. Stamat received a “Notice of Data Security Incident” from Grandizio, id. ¶ 9, informing him about the email account breach and noting that some of the company’s files “may have been accessed by the unauthorized individual” that “may have contained names, Social Security numbers, Medical Information, Drivers[’] License Information, Financial Account Information, or Payment Card Information,” id. ¶ 31. The letter further informed Mr. Stamat that

his personal information “may have been involved.” Id. The letter offered single bureau credit and identity monitoring services for 12 months, id. ¶ 82, and suggested Mr. Stamat take measures to protect against possible identity theft, id. ¶ 13. Mr. Stamat does not purport to have worked with Grandizio directly; he alleges that Grandizio acquired his PII through a third-party intermediary without his knowledge. Id. ¶ 21 (“Plaintiff and Class Members were persons who provided, or who third-parties provided on their behalf, their PII to Defendant in conjunction with utilizing [Grandizio’s] tax and business services.”); ECF 18 at 23 (“[T]his is a situation where Defendant, without Mr. Stamat’s knowledge, took control of Mr. Stamat’s valuable asset, his PII[.]”). Beyond the information

2 provided in the letter, Mr. Stamat is unaware to what extent his PII has been compromised (if at all), what type of his information may have been compromised, or how the unauthorized email access occurred. ECF 1 ¶ 30. Mr. Stamat believes the likely mechanism was an email phishing attack of one of Grandizio’s employees. Id. ¶ 57. Mr. Stamat “further believes his PII, and that

of Class Members, was subsequently sold on the dark web following the Data Breach, as that is the modus operandi of cybercriminals that commit cyber-attacks of this type.” Id. ¶ 41. B. Plaintiff’s Injury As a result of the potential exposure of his PII, Mr. Stamat spends “a considerable amount of time” monitoring his accounts and credit scores and researching how the unauthorized access of the email account may have impacted him. ECF 1 ¶ 105. Mr. Stamat further “anticipates spending considerable time and money on an ongoing basis” to mitigate and prevent potential misuses of his PII. Id. ¶ 110. Mr. Stamat has “sustained emotional distress,” id. ¶ 105, specifically, he has “suffered lost time, annoyance, interference, and inconvenience as a result of the Data Breach and has anxiety and increased concerns for the loss of his privacy,” id. ¶107.

Free access — add to your briefcase to read the full text and ask questions with AI

Stamat v. Grandizio Wilkins Little & Matthews, LLP, (D. Md. 2022).

Stamat v. Grandizio Wilkins Little & Matthews, LLP (Stamat v. Grandizio Wilkins Little & Matthews, LLP) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Doe v. Chao
540 U.S. 614 (Supreme Court, 2004)
Doe v. Obama
631 F.3d 157 (Fourth Circuit, 2011)
Adams v. Bain
697 F.2d 1213 (Fourth Circuit, 1982)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Kerns v. United States
585 F.3d 187 (Fourth Circuit, 2009)
Pisciotta v. Old National Bancorp
499 F.3d 629 (Seventh Circuit, 2007)
Hilary Remijas v. Neiman Marcus Group, LLC
794 F.3d 688 (Seventh Circuit, 2015)
Spokeo, Inc. v. Robins
578 U.S. 330 (Supreme Court, 2016)
Richard Beck v. Robert McDonald
848 F.3d 262 (Fourth Circuit, 2017)
Hutton v. Nat'l Bd. of Examiners in Optometry, Inc.
892 F.3d 613 (Fourth Circuit, 2018)
TransUnion LLC v. Ramirez
594 U.S. 413 (Supreme Court, 2021)
Galaria v. Nationwide Mutual Insurance Co.
663 F. App'x 384 (Sixth Circuit, 2016)