748 F.Supp.3d 262
E.D. Pa.2024Background
- Plaintiffs are former customers of Bank of America and/or Pathward, whose personal information was provided to defendant NCB Management Services (a debt collection agency) for account servicing purposes.
- In February 2023, NCB suffered a ransomware data breach compromising the personal data (PII) of over 1 million individuals.
- Plaintiffs allege NCB failed to adequately safeguard their PII, causing identity theft risks and other damages.
- Plaintiffs brought class action claims for negligence, breach of implied contract, unjust enrichment, and violations of federal and state consumer protection laws.
- NCB moved to dismiss most claims for failure to state a claim and 8 out of 16 named plaintiffs for lack of standing (no concrete injury alleged).
- Plaintiffs voluntarily dismissed the bank defendants and certain claims while the motion was pending.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Standing (Concrete Injury) | Time spent monitoring accounts and risk of future harm suffice for injury | Monitoring alone, with no out-of-pocket loss or fraud, is insufficient | No standing for 8 plaintiffs; claims dismissed |
| Breach of Implied Contract | PII provided was consideration; NCB’s data security promises create contract | No mutual assent/consideration; PII was given to banks, not NCB | No implied contract; claim dismissed |
| Third-Party Beneficiary | Plaintiffs are intended beneficiaries of data security agreements between banks and NCB | Contracts expressly disclaim third-party beneficiary rights | No rights for plaintiffs; claim dismissed |
| Unjust Enrichment | NCB benefited from possessing PII without adequate safeguards | Plaintiffs’ PII was not monetized or otherwise valuable to NCB | No enrichment pled; claim dismissed |
| DPPA Liability | Poor security was a knowing disclosure under DPPA | Breach was theft, not voluntary disclosure | No DPPA claim; dismissed |
| Negligence Per Se (FTC Act) | FTC Act standard applies to NCB’s data practices | FTC Act too vague for negligence per se | No negligence per se; dismissed |
| Extraterritorial State Law Claims (CA, NY, MA, FL) | Harm was felt in claimant's home state | Liability-creating conduct was in PA, not plaintiff’s state | State claims dismissed |
| California CCPA Status | NCB qualifies as a ‘business’ under CCPA | NCB is only a ‘service provider’; not liable to consumers | NCB not a CCPA “business”; claim dismissed |
Key Cases Cited
- Clemens v. ExecuPharm Inc., 48 F.4th 146 (3d Cir. 2022) (data breach standing requires concrete, actual harm or mitigation expenses)
- Meyer, Darragh, Buckler, Bebank & Eck, P.L.L.C. v. Law Firm of Malone Middleman, P.C., 137 A.3d 1247 (Pa. 2016) (essentials of contract formation under Pennsylvania law)
- Scarpitti v. Weborg, 609 A.2d 147 (Pa. 1992) (third-party beneficiary rights under the Restatement)
- Kuwaiti Danish Computer Co. v. Digital Equip. Corp., 781 N.E.2d 787 (Mass. 2003) (center of gravity test for Massachusetts consumer protection law)
- Ashcroft v. Iqbal, 556 U.S. 662 (2009) (pleading standards for Rule 12(b)(6))
- Bell Atl. Corp. v. Twombly, 550 U.S. 544 (2007) (plausibility standard for pleading)