638 F.Supp.3d 1175
D. Nev.2022Background
- July 7, 2019 data breach of MGM network exposed PII of millions (reported ~10.6M); hackers posted the data on dark‑web marketplaces and MGM acknowledged a compromised cloud/account.
- Stolen data included names, addresses, phone numbers, emails, dates of birth; some victims also lost driver’s license, passport, or military ID numbers.
- MGM notified consumers nearly two months after the breach; plaintiffs allege MGM failed to encrypt data, retained PII too long, and deviated from FTC/NIST industry practices.
- Plaintiffs (consolidated class) allege harms: spam/phishing, attempted fraud, time and money spent monitoring/resetting accounts, purchase of identity‑protection services, and diminution of PII value; they assert multiple state and common‑law claims.
- Procedural posture: Plaintiffs filed a Consolidated Class Action Complaint; MGM moved to dismiss. Court granted in part and denied in part the motion.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Whether the economic‑loss doctrine bars negligence claim | Plaintiffs allege non‑economic harms (privacy loss, diminished PII value) so doctrine does not apply | Economic losses should be remediable only in contract; negligence barred | Doctrine does not bar negligence here because plaintiffs alleged non‑economic harms |
| Negligence — duty, breach, and cognizable damages (benefit‑of‑the‑bargain, diminution, risk of identity theft, lost time/expenditures) | MGM deviated from industry standards, failed to encrypt/monitor, retained PII; damages include overpayment, diminished PII, risk, and mitigation costs | Plaintiffs fail to plead breach or cognizable damages; lost time alone insufficient; some damage theories speculative | Breach adequately alleged; benefit‑of‑the‑bargain, diminution, and increased risk of identity theft recognized as cognizable; lost time alone dismissed but plaintiffs who incurred out‑of‑pocket mitigation costs may proceed |
| Negligent misrepresentation (omission theory) | Plaintiffs: entrusting PII creates a special/fiduciary‑like relationship and MGM had duty to disclose | MGM: only arms‑length vendor relationship exists; no duty to disclose, so omission cannot support claim | No special relationship; negligent misrepresentation by omission dismissed with prejudice |
| Breach of implied contract | Plaintiffs: providing PII to reserve/stay implied MGM would protect it; paid consideration (rooms) | MGM: Plaintiffs fail to plead nature/scope of any implied contract | Implied contract claim adequately pleaded and survives |
| Unjust enrichment / equitable restitution | Plaintiffs seek disgorgement because MGM was unjustly enriched by payments not accompanied by promised data security | MGM: Sonner requires plaintiff to plead lack of adequate legal remedy; money damages available | Unjust enrichment dismissed (leave to amend) because plaintiffs did not plead inadequacy of legal remedies under Sonner |
| Nevada Consumer Fraud Act (NRS §§41.600, 598.0923) — omission & Rule 9(b) | Omission of material data‑security facts in sale of services; MGM knowingly failed to disclose vulnerabilities | MGM: failure to plead fraud with particularity; no cognizable injury | Claim pleaded with requisite particularity and survives |
| California statutory claims (UCL, CLRA, CRA) — injunctive relief and omissions | California plaintiffs seek prospective injunctive relief and allege omission of material data‑security facts, violations of CRA and CLRA | MGM: Sonner bars equitable remedies; no duty to disclose | California plaintiffs pleaded inadequacy of legal remedy for prospective injunctive relief; UCL (fraud/unfair/unlawful), CLRA, and CRA claims survive at pleading stage |
| Ohio Deceptive Trade Practices Act (ODTPA) — standing | Plaintiff asserts consumer injury from deceptive trade practices | MGM: ODTPA does not afford consumer (non‑commercial) standing | ODTPA claim dismissed with prejudice for lack of consumer standing |
| Oregon OUTPA / OCIPA — private right of action | Plaintiff predicates OUTPA on OCIPA violations | MGM: OCIPA provides no private cause of action | OCIPA and any OUTPA claims based on OCIPA dismissed with prejudice |
Key Cases Cited
- Bell Atl. Corp. v. Twombly, 550 U.S. 544 (2007) (pleading must contain plausible factual allegations)
- Ashcroft v. Iqbal, 556 U.S. 662 (2009) (facial plausibility standard for complaints)
- Remijas v. Neiman Marcus Grp., LLC, 794 F.3d 688 (7th Cir. 2015) (reasonable inference that hackers steal consumer data to commit fraud)
- In re Zappos.com, Inc., 888 F.3d 1020 (9th Cir. 2018) (data breach risk analysis and standing considerations)
- Sonner v. Premier Nutrition Corp., 971 F.3d 834 (9th Cir. 2020) (equitable restitution requires showing inadequacy of legal remedies)
- Kwikset Corp. v. Superior Court, 246 P.3d 877 (Cal. 2011) (UCL standing: economic injury and benefit‑of‑the‑bargain theory)
- Pruchnicki v. Envision Healthcare Corp., 439 F. Supp. 3d 1226 (D. Nev. 2020) (diminution in value of personal information can be a viable damages theory)
- In re Anthem, Inc. Data Breach Litig., 162 F. Supp. 3d 953 (N.D. Cal. 2016) (benefit‑of‑the‑bargain damages and UCL standing in breach litigation)
- Bass v. Facebook, Inc., 394 F. Supp. 3d 1024 (N.D. Cal. 2019) (information need not be SSN or financial data to create credible risk of identity theft)
