midpage
748 F.Supp.3d 262
E.D. Pa.
2024
Read the full case

Background

  • Plaintiffs are former customers of Bank of America and/or Pathward, whose personal information was provided to defendant NCB Management Services (a debt collection agency) for account servicing purposes.
  • In February 2023, NCB suffered a ransomware data breach compromising the personal data (PII) of over 1 million individuals.
  • Plaintiffs allege NCB failed to adequately safeguard their PII, causing identity theft risks and other damages.
  • Plaintiffs brought class action claims for negligence, breach of implied contract, unjust enrichment, and violations of federal and state consumer protection laws.
  • NCB moved to dismiss most claims for failure to state a claim and 8 out of 16 named plaintiffs for lack of standing (no concrete injury alleged).
  • Plaintiffs voluntarily dismissed the bank defendants and certain claims while the motion was pending.

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Standing (Concrete Injury) Time spent monitoring accounts and risk of future harm suffice for injury Monitoring alone, with no out-of-pocket loss or fraud, is insufficient No standing for 8 plaintiffs; claims dismissed
Breach of Implied Contract PII provided was consideration; NCB’s data security promises create contract No mutual assent/consideration; PII was given to banks, not NCB No implied contract; claim dismissed
Third-Party Beneficiary Plaintiffs are intended beneficiaries of data security agreements between banks and NCB Contracts expressly disclaim third-party beneficiary rights No rights for plaintiffs; claim dismissed
Unjust Enrichment NCB benefited from possessing PII without adequate safeguards Plaintiffs’ PII was not monetized or otherwise valuable to NCB No enrichment pled; claim dismissed
DPPA Liability Poor security was a knowing disclosure under DPPA Breach was theft, not voluntary disclosure No DPPA claim; dismissed
Negligence Per Se (FTC Act) FTC Act standard applies to NCB’s data practices FTC Act too vague for negligence per se No negligence per se; dismissed
Extraterritorial State Law Claims (CA, NY, MA, FL) Harm was felt in claimant's home state Liability-creating conduct was in PA, not plaintiff’s state State claims dismissed
California CCPA Status NCB qualifies as a ‘business’ under CCPA NCB is only a ‘service provider’; not liable to consumers NCB not a CCPA “business”; claim dismissed

Key Cases Cited

  • Clemens v. ExecuPharm Inc., 48 F.4th 146 (3d Cir. 2022) (data breach standing requires concrete, actual harm or mitigation expenses)
  • Meyer, Darragh, Buckler, Bebank & Eck, P.L.L.C. v. Law Firm of Malone Middleman, P.C., 137 A.3d 1247 (Pa. 2016) (essentials of contract formation under Pennsylvania law)
  • Scarpitti v. Weborg, 609 A.2d 147 (Pa. 1992) (third-party beneficiary rights under the Restatement)
  • Kuwaiti Danish Computer Co. v. Digital Equip. Corp., 781 N.E.2d 787 (Mass. 2003) (center of gravity test for Massachusetts consumer protection law)
  • Ashcroft v. Iqbal, 556 U.S. 662 (2009) (pleading standards for Rule 12(b)(6))
  • Bell Atl. Corp. v. Twombly, 550 U.S. 544 (2007) (plausibility standard for pleading)
Read the full case

Case Details

Case Name: LINDQUIST v. NCB MANAGEMENT SERVICES, INC.
Court Name: District Court, E.D. Pennsylvania
Date Published: Sep 11, 2024
Citations: 748 F.Supp.3d 262; 2:23-cv-01236
Docket Number: 2:23-cv-01236
Court Abbreviation: E.D. Pa.
Log In