midpage
Projects
Sign in to see your projects.
638 F.Supp.3d 1175
D. Nev.
2022
Read the full case

Background

  • July 7, 2019 data breach of MGM network exposed PII of millions (reported ~10.6M); hackers posted the data on dark‑web marketplaces and MGM acknowledged a compromised cloud/account.
  • Stolen data included names, addresses, phone numbers, emails, dates of birth; some victims also lost driver’s license, passport, or military ID numbers.
  • MGM notified consumers nearly two months after the breach; plaintiffs allege MGM failed to encrypt data, retained PII too long, and deviated from FTC/NIST industry practices.
  • Plaintiffs (consolidated class) allege harms: spam/phishing, attempted fraud, time and money spent monitoring/resetting accounts, purchase of identity‑protection services, and diminution of PII value; they assert multiple state and common‑law claims.
  • Procedural posture: Plaintiffs filed a Consolidated Class Action Complaint; MGM moved to dismiss. Court granted in part and denied in part the motion.

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Whether the economic‑loss doctrine bars negligence claim Plaintiffs allege non‑economic harms (privacy loss, diminished PII value) so doctrine does not apply Economic losses should be remediable only in contract; negligence barred Doctrine does not bar negligence here because plaintiffs alleged non‑economic harms
Negligence — duty, breach, and cognizable damages (benefit‑of‑the‑bargain, diminution, risk of identity theft, lost time/expenditures) MGM deviated from industry standards, failed to encrypt/monitor, retained PII; damages include overpayment, diminished PII, risk, and mitigation costs Plaintiffs fail to plead breach or cognizable damages; lost time alone insufficient; some damage theories speculative Breach adequately alleged; benefit‑of‑the‑bargain, diminution, and increased risk of identity theft recognized as cognizable; lost time alone dismissed but plaintiffs who incurred out‑of‑pocket mitigation costs may proceed
Negligent misrepresentation (omission theory) Plaintiffs: entrusting PII creates a special/fiduciary‑like relationship and MGM had duty to disclose MGM: only arms‑length vendor relationship exists; no duty to disclose, so omission cannot support claim No special relationship; negligent misrepresentation by omission dismissed with prejudice
Breach of implied contract Plaintiffs: providing PII to reserve/stay implied MGM would protect it; paid consideration (rooms) MGM: Plaintiffs fail to plead nature/scope of any implied contract Implied contract claim adequately pleaded and survives
Unjust enrichment / equitable restitution Plaintiffs seek disgorgement because MGM was unjustly enriched by payments not accompanied by promised data security MGM: Sonner requires plaintiff to plead lack of adequate legal remedy; money damages available Unjust enrichment dismissed (leave to amend) because plaintiffs did not plead inadequacy of legal remedies under Sonner
Nevada Consumer Fraud Act (NRS §§41.600, 598.0923) — omission & Rule 9(b) Omission of material data‑security facts in sale of services; MGM knowingly failed to disclose vulnerabilities MGM: failure to plead fraud with particularity; no cognizable injury Claim pleaded with requisite particularity and survives
California statutory claims (UCL, CLRA, CRA) — injunctive relief and omissions California plaintiffs seek prospective injunctive relief and allege omission of material data‑security facts, violations of CRA and CLRA MGM: Sonner bars equitable remedies; no duty to disclose California plaintiffs pleaded inadequacy of legal remedy for prospective injunctive relief; UCL (fraud/unfair/unlawful), CLRA, and CRA claims survive at pleading stage
Ohio Deceptive Trade Practices Act (ODTPA) — standing Plaintiff asserts consumer injury from deceptive trade practices MGM: ODTPA does not afford consumer (non‑commercial) standing ODTPA claim dismissed with prejudice for lack of consumer standing
Oregon OUTPA / OCIPA — private right of action Plaintiff predicates OUTPA on OCIPA violations MGM: OCIPA provides no private cause of action OCIPA and any OUTPA claims based on OCIPA dismissed with prejudice

Key Cases Cited

  • Bell Atl. Corp. v. Twombly, 550 U.S. 544 (2007) (pleading must contain plausible factual allegations)
  • Ashcroft v. Iqbal, 556 U.S. 662 (2009) (facial plausibility standard for complaints)
  • Remijas v. Neiman Marcus Grp., LLC, 794 F.3d 688 (7th Cir. 2015) (reasonable inference that hackers steal consumer data to commit fraud)
  • In re Zappos.com, Inc., 888 F.3d 1020 (9th Cir. 2018) (data breach risk analysis and standing considerations)
  • Sonner v. Premier Nutrition Corp., 971 F.3d 834 (9th Cir. 2020) (equitable restitution requires showing inadequacy of legal remedies)
  • Kwikset Corp. v. Superior Court, 246 P.3d 877 (Cal. 2011) (UCL standing: economic injury and benefit‑of‑the‑bargain theory)
  • Pruchnicki v. Envision Healthcare Corp., 439 F. Supp. 3d 1226 (D. Nev. 2020) (diminution in value of personal information can be a viable damages theory)
  • In re Anthem, Inc. Data Breach Litig., 162 F. Supp. 3d 953 (N.D. Cal. 2016) (benefit‑of‑the‑bargain damages and UCL standing in breach litigation)
  • Bass v. Facebook, Inc., 394 F. Supp. 3d 1024 (N.D. Cal. 2019) (information need not be SSN or financial data to create credible risk of identity theft)
Read the full case

Case Details

Case Name: Smallman v. MGM Resorts International
Court Name: District Court, D. Nevada
Date Published: Nov 2, 2022
Citations: 638 F.Supp.3d 1175; 2:20-cv-00376
Docket Number: 2:20-cv-00376
Court Abbreviation: D. Nev.
Log In
    Smallman v. MGM Resorts International, 638 F.Supp.3d 1175