In re MOVEit Customer Data Security Breach Litigation
- Reporters:
- , , , ,
TRANSFER ORDER
Before the Panel:* Plaintiff in the District of Minnesota Bailey action moves under
The parties differ significantly as to whether we should create an MDL, what defendants should be included in that MDL, and where any MDL should be centralized. Plaintiffs in 33 actions and potential tag-along actions support centralization. The following defendants also support centralization: Progress Software Corp. and Ipswitch, Inc. (collectively, Progress); Pension Benefits Information, LLC, and Berwyn Group (collectively, PBI);2 Athene Annuity and Life Company; F&G Annuities & Life, Inc.; Genworth Financial, Inc.; Milliman, Inc. and Milliman Solutions, LLC; and Union Bank and Trust Company. Fidelity Investments Institutional Operations Company LLC and FMR LLC do not oppose centralization.
Several parties oppose centralization, and others oppose transfer of their cases or, more broadly, cases brought against certain defendants. Plaintiffs in the Northern District of California Berry/Ng action oppose centralization and, alternatively, request exclusion of their putative statewide class action from the MDL. Plaintiffs in the Eastern District of Virginia Harding, Hale, and Smith and the District of New Jersey Weissman potential tag-along actions oppose centralization; at oral argument, certain of these plaintiffs suggested that we create a limited-purpose MDL for discovery of claims against only Progress. Plaintiffs in the Eastern District of
The parties variously, as their primary or alternative position, support centralization in one or more of the following districts: the Northern District of California, the Eastern District of Louisiana, the District of Massachusetts, the District of Minnesota, the District of Nebraska, and the Eastern District of Virginia. Certain parties ask that we create defendant-specific MDLs for their claims against Milliman entities, Maximus entities, Genworth Financial entities, and TD Ameritrade.
After considering the argument of counsel, we find that centralization of these actions in the District of Massachusetts will serve the convenience of the parties and witnesses and promote the just and efficient conduct of the litigation. All actions can be expected to share factual questions arising from allegations that a vulnerability in Progress Software Company‘s MOVEit Transfer and MOVEit Cloud file transfer services was exploited by a Russian cybergang in May 2023, which to date is estimated to have compromised the personally identifying information (PII)4 of over 55 million people. On May 31, 2023, Progress posted a notice on its website stating it had discovered an SQL injection vulnerability in its MOVEit file transfer services and a related breach in its network and systems. Plaintiffs are individuals whose PII was potentially compromised who bring largely overlapping putative nationwide or statewide class actions on behalf of persons impacted by the exploitation of the MOVEit software vulnerability. All actions can be expected
Plaintiffs opposing transfer argue that, instead of a singular breach, there have been numerous successive intrusions into different servers, which weighs against centralization because multiple entities responded differently to the alleged intrusions and at least one entity to which plaintiffs had given their PII prevented the intrusion from occurring. This argument does not change the fact that the MOVEit vulnerability is at the core of all cases. Even if the MOVEit vulnerability led to successive breaches, Progress, direct users of MOVEit software, and customer-facing companies (many of whom did not use MOVEit software but instead contracted or subcontracted with a company that did) are alleged to be responsible for the compromise of plaintiffs’ PII and are named in varying combinations among the overlapping putative class actions. Disentangling the allegations against Progress (and, in many cases, direct users of MOVEit software like PBI and IBM) from the allegations against other defendants in the same case5 seems impracticable, if not impossible, under
Plaintiffs opposing transfer and certain customer-facing defendants that seek exclusion of the claims against them argue that the Panel‘s decision denying centralization in In re Accellion, Inc., Customer Data Sec. Breach Litig., 543 F. Supp. 3d 1372, 1374 (J.P.M.L. 2021) should dictate the same result here. But Accellion is distinguishable. Accellion arose from a breach, over a period from mid-December 2020 into January 2021, of a “legacy” file transfer appliance that Accellion allegedly had encouraged its customers to discontinue using. Id. at 1374. Accellion also involved 26 cases – about a quarter of the 101 cases at issue here. Id. We denied centralization, in part, because most parties opposed centralization and the parties had largely self-organized, preferring to informally cooperate. Id. (“Most parties, including two defendants, oppose centralization, and have cooperated to organize all but two actions into three coordinated or consolidated proceedings...“). The parties here do not appear to be cooperating informally (which—with 101 total actions, numerous defendants, and 22 involved districts—may not be possible). While, as in Accellion, there may be allegations specific to each defendant‘s role in the breach of a particular plaintiff‘s data,7 this litigation—regardless of whether Progress is named as a defendant in a particular case—poses significant questions about Progress‘s role (and, in many cases, the role of direct users like PBI) in the ultimate exploitation of the MOVEit Transfer vulnerability. In contrast to the product in Accellion, the MOVEit Transfer software here is far from a “legacy” product—instead, the MOVEit technology appears to have been used by numerous companies across multiple sectors of the economy.
While we are sympathetic to the convenience-based arguments made by some plaintiffs who sue only the defendant to which they entrusted their data, in deciding the question of
At a certain stage of this litigation (e.g., perhaps after common discovery and motion practice concludes concerning Progress and other widely-named defendants such as PBI), the transferee judge may decide that some actions are ready for remand to their transferor courts ahead of other actions. If so,
We are persuaded that the District of Massachusetts is the appropriate transferee district for these cases. More cases are pending in this district than in any other district, and the owner of the MOVEit file transfer software, Progress Software Corp., is headquartered in Burlington, Massachusetts. Relevant employees likely are based in this district, where potentially relevant databases, documents, witnesses, and other evidence also may be found. We are confident that Judge Allison D. Burroughs will steer this litigation on a prudent course to resolution.
IT IS THEREFORE ORDERED that the actions listed on Schedule A and pending outside the District of Massachusetts are transferred to the District of Massachusetts and, with the consent of that court, assigned to the Honorable Allison D. Burroughs for coordinated or consolidated proceedings with the actions pending there and listed on Schedule A.
PANEL ON MULTIDISTRICT LITIGATION
Karen K. Caldwell
Chair
Nathaniel M. Gorton Matthew F. Kennelly
Dale A. Kimball Madeline C. Arleo
IN RE: MOVEIT CUSTOMER DATA SECURITY BREACH LITIGATION
MDL No. 3083
SCHEDULE A
Central District of California
ORTEGA, ET AL. v. PROGRESS SOFTWARE CORPORATION, ET AL., C.A. No. 5:23−01329
Northern District of California
BERRY v. PENSION BENEFIT INFORMATION, LLC, ET AL., C.A. No. 3:23−03297
Eastern District of Louisiana
BERRY v. PROGRESS SOFTWARE CORPORATION, C.A. No. 2:23−02089
MCADAM v. PROGRESS SOFTWARE CORPORATION, C.A. No. 2:23−02295
District of Massachusetts
DIGGS, ET AL. v. PROGRESS SOFTWARE CORPORATION, C.A. No. 1:23−11370
PIPES v. IPSWITCH, INC., ET AL., C.A. No. 1:23−11394
TENNER v. PROGRESS SOFTWARE CORPORATION, C.A. No. 1:23−11412
GUILLORY-CAILLIER, ET AL. v. PROGRESS SOFTWARE CORPORATION, C.A. No. 1:23−11417
ANASTASIO v. PROGRESS SOFTWARE CORPORATION, ET AL., C.A. No. 1:23−11442
District of Minnesota
BAILEY v. PROGRESS SOFTWARE CORPORATION, ET AL., C.A. No. 0:23−02028
Notes
In re Accellion, Inc., Customer Data Sec. Breach Litig., 543 F. Supp. 3d 1372, 1374 (J.P.M.L. 2021).any factual overlap among the actions as to Accellion‘s FTA product, its vulnerability to attack, and its alleged support of this “legacy” product may be eclipsed by factual issues specific to each client defendant. Opponents of centralization argue that, rather than a single data breach, there were numerous data breaches of each client defendant, occurring at different times and involving each client defendant‘s own servers. Moreover, each client defendant‘s knowledge of the FTA‘s alleged vulnerability to attack will be unique, as will Accellion‘s alleged efforts to urge each client to migrate to its newer file sharing product.