IN RE: MOVEit Customer Data Security Breach Litigation
I. Background
a. Key Facts
The following facts reflect the well-pleaded allegations set forth in the Bellwether Complaint. See Ocasio-Hernández v. Fortuño-Burset, 640 F.3d 1, 5 (1st Cir. 2011).
i. MOVEit Transfer and the Data Breach
MOVEit Transfer is an encrypted file-transfer software offered by Progress Software Corporation, based in Burlington, Massachusetts. [CAC ¶¶ 6, 966]. The software applies encryption protocols to secure users’ data both while it is both being transferred and stored. [Id. ¶ 969]. These protocols are claimed to be “virtually unbreakable with existing technology,” [id. ¶¶ 970–71], meaning that under ordinary circumstances, files encrypted by MOVEit “can only be read if the user has the appropriate encryption keys, even if the files are stolen,” [id. ¶ 969].
The software “is licensed to customers on a subscription basis and installed by customers on their own servers.” [CAC ¶ 967]. Then, “users—such as the customer’s employees—access the software through a MOVEit Transfer software client installed on a computer, phone, or website accessible over the Internet that connects to the customer’s MOVEit Transfer server.”1 [Id. ¶ 973]. Progress provides security and software support, including “bug fixes, patches, upgrades, enhancements, new releases [and] technical support,” to MOVEit Transfer customers. [Id. ¶ 972].
On May 27, 2023, a Russian ransomware group called Cl0p “deploy[ed] malware to public-facing MOVEit Transfer web portals” that allowed the hackers to decrypt and download data stored in the MOVEit software. [CAC ¶ 14]. This enabled Cl0p to exfiltrate personally identifiable information (“PII”) and, in some cases, protected health information (“PHI”) from more than 2,600 entities, affecting more than 93 million individual records as of January 2024 (the “Data Breach”). [Id. ¶¶ 19, 1164, 1175].
ii. Progress
Progress, as described above, is a public corporation based in Massachusetts and incorporated in Delaware. [CAC ¶ 918]. Plaintiffs allege that the company knew and intended that MOVEit Transfer would be used to move and store highly sensitive information, [id. ¶¶ 990–92, 1325–46], and understood that secure file transfer software was a likely target of hacking efforts, [id. ¶¶ 1347–55]. For example, in online marketing materials targeting the banking and financial clients, Progress explained that “[d]ata in motion is data at risk and particular attention must be paid to the security and compliance of . . . external file transfer process[es].” [Id. ¶ 1347 (first alteration in original)]. Progress published on its website that it
Plaintiffs further contend that once Cl0p infiltrated the MOVEit Transfer environments, Progress moved too slowly in patching the vulnerabilities that had allowed the breach and in notifying Plaintiffs concerning the breach, and that such delays led to additional injuries. [Id. ¶¶ 1373–85.
b. Procedural History
After extensive negotiation among the parties, the Court ordered bellwether proceedings in this case, and permitted the Plaintiffs to consolidate and amend their allegations in the CAC. Plaintiffs filed an initial Bellwether Complaint on December 6, 2024, see [ECF No. 1297], which they corrected on January 9, 2025, with Defendants’ stipulated consent, see [ECF No. 1331 (stipulation)]; [ECF No. 1332 (CAC)].2 The CAC names Progress, as well as the PBI Bellwether Defendants, Delta Dental, Maximus, and the Welltok Defendants (together, the “non-Progress Defendants”).
Progress moved to dismiss on February 4, 2025, [ECF No. 1367], Plaintiffs opposed on April 7, 2025, [Opp.], and Progress replied on April 28, 2025, [Reply]. The non-Progress Defendants moved for dismissal on the same timeline, and their motions are the subject of MDL Order No. 22, filed contemporaneously with this order. The Court held oral argument on May 12, 2025.
II. Legal Standard
a. Rule 12(b)(6) Motion to Dismiss
“Dismissal of a complaint pursuant to
To apply these standards, the Court “employ[s] a two-pronged approach.” Ocasio-Hernández, 640 F.3d at 12. To begin, it must “identify[] and disregard[] statements in the complaint that merely offer “legal conclusions[s] couched as . . . fact[]” or “[t]hreadbare recitals of the elements of a cause of action.” Id. (first and second alterations added) (quoting Iqbal, 556 U.S. at 678). “Non-conclusory factual allegations in the complaint must then be treated as true, even if seemingly incredible.” Id. (quoting Iqbal, 556 U.S. at 681). “If that factual content, so taken, ‘allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged,’ the claim has facial plausibility.” Id. (quoting Iqbal, 556 U.S. at 678). The
b. Rule 9(b) Heightened Pleading
For claims sounding in fraud, and, as relevant here, claims alleging fraudulent misrepresentation,
III. Common Law Claims
In order to consider the sufficiency of the pleadings in this case, the Court must consider the elements of the various claims that are alleged. That, in turn, requires the Court to consider which jurisdiction’s law applies, at least when there are material differences in legal standards between various jurisdictions. Hence, we must begin with a choice of law analysis. The Court
a. Conflict of Laws
Federal courts sitting in diversity apply the choice of law rules of the forum state to determine which state’s law determines liability for common law claims. Cheng v. Neumann, 106 F.4th 19, 25 (1st Cir. 2024) (“[F]ederal courts sitting in diversity apply the substantive law of the forum state, . . . including its conflict of laws rules.” (quoting Smith v. Prudential Ins. Co. of Am., 88 F.4th 40, 49 (1st Cir. 2023))). Due “to the complexities of MDL litigation,”3 however, transferee courts in multidistrict litigation usually apply the conflict-of-law rules of the transferor court, rather than the MDL forum, to determine what law applies to common-law claims. In re Volkswagen & Audi Warranty Extension Litig., 692 F.3d 4, 14 (1st Cir. 2012) (citing cases). But see id. at 17 n.16 (noting that the First Circuit assumed but did not decide that the transferor court’s law would determine conflict of law questions). “This approach is consistent with the Supreme Court’s holding that ‘where a case is transferred pursuant to
i. True Conflicts
The First Circuit has long recognized that federal courts may “avoid a conflicts question if there is no reason to believe the contending states’ laws differ in any relevant respect.” Smith v. Prudential Ins. Co. of Am., 88 F.4th 40, 49 (1st Cir. 2023) (cleaned up) (quoting In re Pioneer Ford Sales, Inc., 729 F.2d 27, 31 (1st Cir. 1984) (Breyer, J.)). Though the Bellwether Parties dispute a variety of issues related to conflict of laws, they largely elide this “threshold step,” Cheng, 106 F.4th at 25 (1st Cir. 2024), even though it is well embedded within the Erie doctrine and the applicable states’ conflict of law rules, e.g., Chen v. L.A. Truck Ctrs., LLC, 444 P.3d 727, 730 (Cal. 2019) (explaining that at the “[f]irst” step of California’s interest-weighing analysis, “the court [must] determine[] whether the relevant law of each of the potentially affected jurisdictions with regard to the particular issue in question is the same or different”). Instead, the parties jump to the question of whether transferor courts’ conflict-of-law rules require the Court to apply the plaintiffs’ home-state law or the law of the location of the defendants’ headquarters, without examining whether those laws differ in material respects. Nonetheless, the briefing on the merits largely takes the position that the disposition of this case would be the same no matter which states’ laws apply, suggesting there might not be any meaningful conflict. See Phillips Petroleum Co. v. Shutts, 472 U.S. 797, 839 n.20 (1985) (Stevens. J., concurring) (“If the laws of both states relevant to the set of facts are the same, or would produce the same decision in the lawsuit, there is no real conflict between them.”).
Upon questioning at oral argument, the parties acknowledged that there are few “true” conflicts between the relevant aspects of plaintiffs’ and defendants’ home state laws, with the
ii. Ripeness
The parties dispute whether the conflict of law issues in this case are ripe for adjudication on the pleadings. Progress urges the Court to rule on the conflicts issues expeditiously, based on the pleadings, while Plaintiffs urge the Court to await further factual development and defer the issue until summary judgment.
There is no blanket rule for deciding when a conflict of law question is ripe for decision. “[T]he optimal timing for a choice-of-law determination is case-specific.” Foisie v. Worcester Polytechnic Inst., 967 F.3d 27, 42 (1st Cir. 2020). After all, “choice-of-law determinations are fact-intensive inquiries,” Bristol-Myers Squibb Co. v. Matrix Lab’ys Ltd., 655 F. App’x 9, 13 (2d Cir. 2016) (cited favorably in Foisie). Thus, if “the allegations in the plaintiff’s complaint are insufficient to evaluate adequately the choice of law issues raised by the defendant’s motion,” the issues should be deferred for “‘resolution on motions for summary judgment,’ after an opportunity for discovery.” Jones v. Lattimer, 29 F. Supp. 3d 5, 10 n.3 (D.D.C. 2014) (citation omitted).
The parties mainly argue over whether the current record is sufficient to permit the Court to apply the “most significant relationship test” (which governs claims originally filed in Illinois, Massachusetts, Minnesota, Nebraska, Texas, and Washington) and the lex loci delicti test (which governs claims originally filed in Virginia).
This analysis can be undertaken now, as the necessary information can be harvested from the thousand-page CAC. For example, Plaintiffs have pleaded their states of residence, and the parties seem to agree that the Plaintiffs suffered their injuries in their states of residence. E.g., [Opp. at 60 (“[T]he California Plaintiffs clearly allege their injuries occurred in California.”)]; [Mem. at 37]. In addition, Plaintiffs plead that Progress is headquartered in Massachusetts and registered in Delaware, which also does not seem to be disputed. And as the parties’ merits briefing makes clear, because Plaintiffs and Progress shared only an indirect relationship, the fourth factor warrants little weight here.
It bears noting, moreover, that when determining whether factual holes in the pleadings require that a choice of law analysis be deferred, what matters is whether the gaps in the record are material to the particular type of claim and dispute at issue. E.g., Foisie, 967 F.3d at 42 (explaining that, in fraudulent conveyance cases, conflict-determinative facts “include the character and site of the conveyed assets, the state (or states) from which the assets were
Plaintiffs further contend that the Court cannot apply lex loci delicti principles to the claims governed by Virginia choice-of-law rules without knowing the location of the affected servers. See [Opp. at 11 n.25 (suggesting, based on a case applying North Carolina conflict rules, that lex loci delicti principles point to the law of state where breached “servers were located” and the “situs of Defendant’s headquarters and principal place of business” (quoting Lamie v. LendingTree, LLC, No. 22-cv-00307, 2023 WL 1868198, at *3 (W.D.N.C. Feb. 9, 2023)))]. But, as explained further below, the dispositive contact under Virginia’s lex loci delicti test for tort claims is “the site of the injury,” Hazelwood v. Law. Garage, LLC, 904 S.E.2d 322, 328 (Va. Ct. App. 2024), and as noted above, the parties agree that the CAC supplies that information.
Finally, Plaintiffs suggest that the weight of authority shows that MDLs routinely defer choice of law determinations for further factual development in data breach cases. But nearly every case Plaintiffs cite involved a failure of the parties to “fully brief” the issues, rather than deficient factual allegations in the CAC. In re Am. Med. Collection Agency Customer Data Sec. Breach Litig. (In re Am. Med I), No. 19-md-2904, 2021 WL 5937742, at *13–14 (D.N.J. Dec. 16, 2021); In re Progressive Leasing Breach Litig., No. 23-cv-00783, 2025 WL 213744, at *18–19 (D. Utah Jan. 16, 2025) (deferring because parties “ha[d] not made any serious attempt to brief [the conflicts] issue); In re 21st Century Oncology Customer Data Sec. Breach Litig., 380 F. Supp. 3d 1243, 1259–60 (M.D. Fla. 2019) (same, where parties addressed conflicts issue only “in a passing footnote”); In re Brinker Data Incident Litig., No. 18-cv-00686, 2020 WL 691848, at *3 (M.D. Fla. Jan. 27, 2020) (“[T]he parties briefing on the motion to dismiss did not address
iii. Applicable Law
The transferor or direct-file designation forums in this case are located in California, Illinois, Massachusetts, Michigan, Minnesota, Nebraska, New York, Texas, Virginia, and Washington, which apply the following conflict-of-law tests.
1. Most Significant Relationship Test (Illinois, Massachusetts, Minnesota Nebraska, Texas, and Washington-Filed Tort Claims)
Illinois, Massachusetts, Minnesota, Nebraska, Texas, and Washington apply the “most significant relationship” test to tort claims.5 Progress contends this means that the Plaintiffs’ home states’ law should apply, because their domiciles and the places where they were injured are the key considerations under the “most significant relationship” analysis in the relevant states. [Mem. at 33 (“Under the significant relationship test, ‘the law of the place of injury controls unless some other jurisdiction has a more significant relationship with the occurrence
Plaintiffs’ position is better aligned with the general policy concerns that drive conflict of laws considerations under section 6 of the Restatement. Massachusetts’s interest in having Progress comply with its own tort principles governing cybersecurity is greater than the interest of each Plaintiff’s home state in seeing their residents compensated for injuries allegedly caused by a foreign corporation’s misconduct. Premera, 2013 WL 440702, at *15; see also Cosme v. Whitin Mach. Works, Inc., 632 N.E.2d 832, 836 (Mass. 1994) (discussing section 6 factors). This is particularly so when the alternative would be to fragment the liability analysis among dozens of competing jurisdictions. The Court concludes that the “most significant relationship” test points to application of Massachusetts law for the common-law claims raised by: Jose Soto,
2. Virginia-filed tort claims
For the tort claims governed by Virginia choice of law rules, Virginia’s lex loci delicti test applies. See Hazelwood v. Law. Garage, LLC, 904 S.E.2d 322, 328 (Va. Ct. App. 2024). In Virginia, “the law of the place of the wrong determines the substantive rights of the parties,” id. at 329 (internal quotation marks omitted) (quoting McMillan v. McMillan, 253 S.E.2d 662, 663 (Va. 1979)), and the “wrongful act” is the “injury,” id. at 328 (quoting Tingler v. Graystone Homes, Inc., 834 S.E.2d 244, 254 (Va. 2019)). Thus “when determining the place of the wrong in a tort matter, we must consider the site of the injury as the location where the tort is completed.” Id. Here, the parties agree that the location in question is the Plaintiff’s home state. Thus, the tort claims originally filed in Virginia (or the direct-filed claims that would have been filed in Virginia) shall be governed by the laws of the place of injury and the relevant Plaintiffs’ respective home states. Those states are:
- California (Shellie McCaskell);
- Florida (Plaintiffs Patrice Hauser, Keith Bailey, Aunali Khaku, and Gregory Bloch);
- Illinois (Rob Plotke);
- Indiana (Alexys Taylor);
- New York (Plaintiffs Gilbert and Lynda Hale);
- North Carolina (Ben Dieck);
- Ohio (Elaine McCoy);
- Pennsylvania (Victor DiLuigi); and
- Texas (Jvanne Rhodes and Aldreamer Smith).
3. Michigan-filed tort claims
In tort claims, “Michigan courts recognize a presumption in favor of lex fori and apply Michigan law ‘unless a “rational reason” to do otherwise exists.’” Standard Fire Ins. Co. v. Ford Motor Co., 723 F.3d 690, 693 (6th Cir. 2013) (quoting Sutherland v. Kennington Truck Serv., Ltd., 562 N.W.2d 466, 471 (Mich. 1997)). Michigan applies a two-part test for “determining whether such a rational reason exists.” Id. First, a Court must decide whether “any foreign state has an interest in having its law applied,” and if not, then “the presumption that Michigan law will apply cannot be overcome.” Id. (quoting Sutherland, 562 N.W.2d at 471). “If a foreign state does have an interest in having its law applied,” the Court proceeds to examine whether “Michigan’s interests mandate that Michigan law be applied, despite the foreign interests.”
Parties have given the Court no convincing reason to overcome the presumption in favor of Michigan law. Progress offers no argument at all concerning Michigan choice of law rules for tort claims, see [Mem. at 34–36], and has identified no state that could purportedly overcome the lex fori presumption. Plaintiffs, by contrast, contend that in this case, Michigan’s rules favor application of the breached defendant’s state law, here Massachusetts, see [Opp. at 34–35 & n.29], and proffer two data breach cases in support, see Hummel v. Teijin Auto. Techs., Inc., No. 23-CV-10341, 2023 WL 6149059, at *4 (E.D. Mich. Sept. 20, 2023); Kingen v. Warner Norcross & Judd LLP, No. 22-cv-01126, 2023 WL 11960672, at *6 (W.D. Mich. Oct. 5, 2023). In both cases, however, the defendant’s domicile was Michigan, so the defendant’s home state reinforced the lex fori presumption. See Hummel, 2023 WL 6149059, at *4 (“Defendant’s principal place of business is in Michigan and the leaked PII was collected and stored in Michigan,” so “Michigan law govern[ed] th[e] action.”); Kingen, 2023 WL 1195363, at *6 (“The data breach occurred in Michigan, and the Defendant linking the entire proposed class of plaintiffs is in Michigan. The Court will apply Michigan law.”). Here, Plaintiffs invite the court to override the
4. New York-filed claims
New York applies an “interest analysis” to choice of law analyses involving tort claims. See Toretto v. Donnelley Fin. Sols., Inc., 583 F. Supp. 3d 570, 589 (S.D.N.Y. 2022); Innovative BioDefense, Inc. v. VSP Techs., Inc., No. 12-cv-03710, 2013 WL 3389008, at *6 (S.D.N.Y. July 3, 2013). The nature of the analysis depends on the particular tort claim asserted.6 For conduct-regulating causes of action, New York law applies the law of “the place of the allegedly wrongful conduct.” Toretto, 583 F. Supp. 3d at 589; see also id. (explaining that such location “has the greatest interest in regulating behavior within its borders” and a “superior interest[] in protecting the reasonable expectations of the parties who relied on the laws of that place to govern their primary conduct and in the admonitory effect that applying its law will have on similar conduct in the future”). Here, such considerations point to Massachusetts, Progress’s principal place of business. See id. (applying Illinois law based on the inference that alleged negligent cybersecurity practices occurred in the state where defendant was “headquartered”). Accordingly, Massachusetts law governs the common-law tort claims asserted by Steven Checchia and Patricia Marshall.
5. California-filed claims
Like Michigan, California courts apply a presumption in favor of applying its law to California-filed claims. California’s “governmental interest” test has three parts. “First, the court determines whether the relevant law of each of the potentially affected jurisdictions with regard to the particular issue in question is the same or different.” Chen, 444 P.3d at 730. “Second, if there is a difference, the court examines each jurisdiction’s interest in the application of its own law under the circumstances of the particular case to determine whether a true conflict exists.” Chen, 444 P.3d at 730–31. Third, “if the court finds that there is a true conflict, it carefully evaluates and compares the nature and strength of the interest of each jurisdiction in the application of its own law to determine which state’s interest would be more impaired if its policy were subordinated to the policy of the other state, and then ultimately applies the law of the state whose interest would be the more impaired if its law were not applied.” Id. at 731.
As the Ninth Circuit has explained, and as Plaintiffs note in their separately filed opposition to Delta Dental, if objectors to the application of California law “fail to meet their burden at any step in the analysis, the district court may properly find California law applicable without proceeding to the rest of the analysis.” In re Hyundai & Kia Fuel Econ. Litig., 926 F.3d 539, 562 (9th Cir. 2019); [ECF No. 1440 at 20]. Here, both sides object to the application of California law, at least as to certain of the claims. Plaintiffs urge that Massachusetts law, not California law, should apply to all California-filed tort claims, but they support their position only with a citation to a single case involving the separate question of extraterritorial invocation of California consumer protection statutes for non-resident Plaintiffs. See Schmitt v. SN Servicing Corp., No. 21-cv-03355, 2021 WL 3493754, at *3 (N.D. Cal. Aug. 9, 2021). That is not enough to carry Plaintiffs’ burden.
Progress, by contrast, asserts that California law should not apply to the claims raised against it by non-California defendants because the Complaint does not allege that Progress engaged in conduct in California.7 [Mem. at 13 (citing Cassirer v. Thyssen-Bornemisza Collection Found., 89 F.4th 1226, 1239–42 (9th Cir. 2024)), vacated and remanded 145 S.Ct. 1331 (2025)]. Yet this bare assertion gives short shrift to the “comparative impairment” analysis required under California law, which asks whether the relevant conduct occurred in California, but also asks “in light of the question at issue and the relevant state interests at stake[,] which jurisdiction should be allocated the predominating lawmaking power under the circumstances of the present case.” Cassirer, 89 F.4th at 1237 (quoting McCann v. Foster Wheeler LLC, 225 P.3d 516, 534 (Cal. 2010)). That inquiry involves a multifactor balancing that Progress largely ignores and which the Court declines to perform on its behalf.
In sum, because neither party has carried its burden under California conflict of law rules, In re Hyundai, 926 F.3d at 562, the Court will apply California law to the claims asserted by Denise Meyer, Amanda Copans, Ricardo Moralez, Manuel Mendoza, Terrill Mendler, Michelle Gonsalves, Marvin Dovberg, Deanna Duarte, Taneisha Robertson, Doris Cadet, Margaret Kavanagh, Diamond Roberts, Karen Boginski, John Meeks, Yvette Tillman, and Hannah Polikowsky.
b. Count 1: Negligence
Progress contends that Plaintiffs (1) fail to plead a recognized common law duty, (2) plead purely economic losses, and (3) have not alleged cognizable damages. On this basis, Progress asks the Court to dismiss Plaintiffs’ common-law negligence claims.
i. Duty
Plaintiffs allege that Progress owed a duty to implement reasonable safeguards “to protect [them] from theft and misuse by unauthorized third parties.” [Opp. at 39]. Progress responds that it owed “no general duty of care . . . to prevent injury caused by a third-party tortfeasor” like Cl0p. [Mem. at 53 & n.44].
As Plaintiffs correctly observe, when it comes to liability for injuries involving a third-party tort-feasor, black-letter law paints a more nuanced picture than Progress‘s broad-brush disclaimer of liability. To begin with, a person “who undertakes to render services in the practice of a profession or trade is required to exercise the skill and knowledge normally possessed by members of that profession or trade in good standing in similar communities.” Restatement (Second) of Torts § 299A (A.L.I. 1965). In this context, a defendant may be liable for negligence when the defendant‘s act or omission creates “an unreasonable risk of harm to another” by the foreseeable conduct of a third party, even if the third party‘s conduct is, as here, “criminal.” Id. § 302(b). Third-party conduct is foreseeable if the “actor at the time of his negligent conduct realized or should have realized the likelihood that such a situation might be created, and that a third person might avail himself of the opportunity to commit such a . . . crime.” Id. § 448.
Here, Plaintiffs allege that Progress touted the quality and security of the code in the MOVEit Software, [CAC ¶ 972], “kn[ew] and intend[ed] that its customers use MOVEit software to transfer highly sensitive personally identifiable and protected health information”
The state laws applicable here have recognized an array of duties consistent with Plaintiffs’ allegations against Progress. Several jurisdictions recognize that a software provider may assume a duty to prevent foreseeable software vulnerabilities. See Weekes v. Cohen Cleary P.C., 723 F. Supp. 3d 97, 103 (D. Mass. 2024); In re Sony Gaming Networks and Customer Data Sec. Breach Litig., 996 F. Supp. 2d 942, 966 (S.D. Cal. 2014) (California law); In re Mednax Servs., Inc., v. Customer Data Sec. Breach Litig., 603 F. Supp. 3d 1183, 1222 (S.D. Fla. 2022) (under Florida Law, “by handing over their personal information, Plaintiffs placed their data in a foreseeable zone of risk that Defendants had a duty to mitigate“); Hummel v. Teijin Auto. Techs., Inc., No. 23-cv-10341, 2023 WL 6149059, at *7 (E.D. Mich. Sept. 20, 2023) (finding that under Michigan law, “specific factual allegation” that defendant failed to encrypt data adequately stated negligence claim). Other states recognize a duty to adhere to industry standards for cybersecurity. Webb v. Injured Workers Pharmacy, LLC, No. 23-cv-10341, 2023 WL 5938606, at *2 (D. Mass. Sept. 12, 2023) (Massachusetts law); Fischer v. CentralSquare Techs., LLC, No. 21-cv-60856, 2021 WL 10558134, at *1 (S.D. Fla. Sept. 16, 2021) (Florida law); Koeller v. Numrich Gun Pts. Corp., 675 F. Supp. 3d 260, 269–70 (N.D.N.Y. 2023) (New York law).
Progress argues that in Illinois, Indiana, and Michigan, “there is no duty to safeguard personal information” at all.8 [Mem. at 54 & n.45].
Plaintiffs have no answer to Progress‘s argument or citations concerning Indiana law. See Aspen Am. Ins. Co. v. Blackbaud, Inc., No. 22-cv-00044, 2023 WL 3737050, at *5 (N.D. Ind. May 31, 2023) (“[T]he Court predicts that the Indiana Supreme Court would hold there is no common law duty to safeguard the public from the risk of data exposure.“).
With regard to Michigan, Progress points to a Michigan case where the court found the absence of a duty “to act, install safeguards, and protect Plaintiff and its data from a third-party ransomware attack.” Grifo & Co. v. Cloud X Partners Holdings, 485 F. Supp. 3d 885, 895 (E.D. Mich. 2020) (alteration and citation omitted) (applying Michigan law). That case, however, as well as the cases it cites, see, e.g., Hart v. Ludwig, 79 N.W.2d 895, 897 (Mich. 1956), are about actions brought between vendors and their customers, where the conduct at issue is contemplated by the contract. Grifo, 485 F. Supp. 3d at 896. It is therefore not applicable to Plaintiffs’ claims. See Fultz v. Union Com. Assocs., 683 N.W.2d 587, 466 (Mich. 2004) (“We have held that a tort action will not lie when based solely on the nonperformance of a contractual duty.” (emphasis added)); see also Grifo, 485 F. Supp. 3d at 895 (citing Fultz).
Progress also suggests that, in certain jurisdictions, it must share a “special relationship” to Plaintiffs before it can be held liable for a failure to protect Plaintiffs from Cl0p‘s criminal activities. [Mem. at 54]. At this stage of the case, the allegations in the CAC sufficiently meet that standard. Read broadly, the CAC adequately alleges that Progress was the critical actor tasked with securing MOVEit Transfer on behalf of its clients as well as on behalf of those whose data would be entrusted to those clients, and further alleges that Progress reaped pecuniary benefits from doing so. [CAC ¶ 972]. In this light, the CAC adequately alleges that Progress was uniquely well-situated to prevent the harm allegedly visited upon Plaintiffs through the Data Breach. See In re Accellion, Inc. Data Breach Litig., 713 F. Supp. 3d 623, 632–33 (N.D. Cal. 2024) (California law); Portier v. NEO Tech. Sols., No. 17-cv-30111, 2019 WL 7946103, at *11 (D. Mass. Dec. 31, 2019) (Massachusetts law); In re Rutter‘s Inc. Data Sec. Breach Litig., 511 F. Supp. 3d 529–30 (M.D. Pa. 2021) (Pennsylvania law). In short, the fact that “third-party cybercriminals caused the [Plaintiffs‘] harm” does not relieve Progress of liability for “play[ing] a central role in permitting that harm to occur.” In re: Netgain Tech., LLC, No. 21-cv-1210, 2022 WL 1810606, at *11 (D. Minn. June 2, 2022).
ii. Economic loss
Progress contends that the economic-loss doctrine should bar Plaintiffs’ negligence claims arising under the laws of Massachusetts, California, Indiana, North Carolina, Ohio, Pennsylvania, and Texas.
The economic loss doctrine is a complex and esoteric common law principle of relatively recent vintage, which purports to limit remedies for tort claims that “seek[]to recover for a commercial loss rather than damage to person, property, or reputation.” See generally Miller v. U.S. Steel Corp., 902 F.2d 573, 574 (7th Cir. 1990). Despite the doctrine‘s complexity, the parties spill very little ink on the issue; indeed, the considerable variations in how particular states apply the doctrine are addressed only in string citations contained in footnotes. [Mem. at 57 n.49–50]; [Opp. at 42 n.42]. The takeaway is this: Plaintiffs point to data breach cases (i) applying the laws of each jurisdiction Progress invokes, (ii) in which courts have held that the economic-loss doctrine did not bar claims for damages either identical to or otherwise encompassing those alleged here. Progress offers no real response. See [Opp. at 42 n.42]; [Reply at 19].
The current state of the record does not really equip the Court to venture an Erie guess as to how the relevant states would apply their various iterations of the economic-loss doctrine in
iii. Cognizable damages
Finally, Progress contends that the negligence claims must fail because Plaintiffs have not alleged cognizable harm. These arguments are also not well developed,9 but in any case, the Court concludes that Plaintiffs have alleged sufficient damages against Progress to survive dismissal at the pleading stage. First, several Plaintiffs allege that they have already experienced identity theft or other forms of misuse, which are obviously cognizable (and Progress does not contend otherwise). See, e.g., Weekes, 723 F. Supp. 3d at 103; In re Accellion, 713 F. Supp. 3d at 637; Bohnak v. Marsh & McLennan Cos., 79 F.4th 276, 289–90 (2d Cir. 2023). Second, Plaintiffs allege an increased risk of future misuse. Although Progress dismisses this theory as “speculative,” see [Mem. at 58 & n.51], the cases it cites in support are distinguishable as the operative complaints in those cases involved no “allegations of actual misuse or other concrete harm,” Bonewit v. New-Indy Containerboard, LLC, No. 24-cv-11338, 2024 WL 4932186, at *4 (D. Mass. Dec. 2, 2024), unlike the allegations in the CAC. Third, many Plaintiffs allege that they have spent either time, money, or both addressing the fallout from the Data Breach. Such allegations are non-speculative in light of the Plaintiffs’ properly pled allegations of a risk of future harm. See, e.g., Bohnak, 79 F.4th at 290; Webb, 2023 WL 5938606, at *2. Fourth, Progress‘s argument that the CAC suffers from an “absence of any factual allegation . . . specify[ing] genuine injury” related to emotional distress, is inaccurate. At this stage, many Plaintiffs have adequately pleaded specific manifestations of their emotional distress to survive a
Finally, the parties address the question of loss of privacy only briefly, with each side offering no more than one citation in support of their respective positions. Although the Court is skeptical that loss of privacy constitutes a cognizable harm in a negligence action separate from the “impairment of value of [Plaintiffs‘] PII,” [Opp. at 44 (quoting Smallman v. MGM Resorts Int‘l, 638 F. Supp. 3d 1175, 1188 (D. Nev. 2022))], the Court reserves on that question for now. Plaintiffs have alleged several facially adequate types of harm and there is no reason to expect that deciding the issue on an under-developed record will meaningfully streamline the litigation of the next phases of this case.
The motion to dismiss Count 1 is GRANTED as to the Indiana law claims and otherwise DENIED.
c. Count 2: Negligence Per Se
Plaintiffs allege that Progress is liable for negligence per se because it violated several statutes or regulations that establish duties of care, in particular, the Federal Trade Commission Act (“FTC Act“), the Health Insurance Portability and Accountability Act (“HIPAA“), the HIPAA Privacy Rule and Security Rule, and the Health Information Technology for Economic
As to the first point, Plaintiffs do not contest that negligence per se is not a standalone cause of action in the states Progress identifies. Tolen v. Honeywell Int‘l, Inc., No. 05-cv-04220, 2006 WL 3333754, at *4 (S.D. Ill. Nov. 16, 2006) (holding, under Illinois law, that “negligence per se is not a cause of action in itself.“); Jones v. Awad, 252 Cal. Rptr. 3d 596, 605 (Cal. Ct. App. 2019) (same under California law); Juliano v. Simpson, 962 N.E.2d 175, 179–180 (Mass. 2012) (same under Massachusetts law); Abnet v. Coca-Cola Co., 786 F. Supp. 2d 1341, 1345 (W.D. Mich. 2011) (same under Michigan law); Merritt v. BASF Corp., No. 21-cv-00067, 2023 WL 3230983, at *6 (S.D. Ohio May 3, 2023) (same under Ohio law); In re Wawa, Inc. Data Sec. Litig., No. 19-cv-06019, 2021 WL 1818494, at *7 (E.D. Pa. May 6, 2021) (same under Pennsylvania law); Johnson v. Enriquez, 460 S.W.3d 669, 673 (Tex. App. 2015) (same under Texas law). As other courts have recognized, Count 2 is therefore “subject to dismissal as a
Plaintiffs request leave to amend their primary negligence claims to incorporate negligence per se theories as to the foregoing states, which Progress does not oppose. That request is GRANTED.
d. Count 3: Breach of Contract/Third-Party Beneficiary
Progress asks the Court to dismiss Count 3, which alleges a breach of contractual duties owed to Plaintiffs as intended third-party beneficiaries of Progress‘s agreements with PBI, Delta Dental, Maximus, and Welltok.12 Progress argues dismissal is appropriate because (1) Plaintiffs have not identified specific contracts of which they are intended third-party beneficiaries, and (2) Progress‘s End-User License Agreement (“EULA“) disclaims any intent to create third-party beneficiaries.
First, Progress argues that because the CAC does not specifically identify the contracts of which Plaintiffs are allegedly intended to be third-party beneficiaries, the CAC does not satisfy the requirements of notice pleading. [Mem. at 41]. Plaintiffs, though they acknowledge that some of the relevant contracts have been produced in discovery, respond that more discovery is needed, and argue that it is enough that they allege on information and belief that they are intended third-party beneficiaries of Progress‘s MOVEit-related contracts with the Bellwether Defendants. [Opp. at 51 & n.49].
Given Plaintiffs’ allegations that Progress was responsible for maintaining secure code for the MOVEit Transfer software on behalf of its customers—and particularly given that
It bears noting that the caselaw on which Plaintiffs rely appears to rest on a presupposition that the defendant(s) in question had exclusive access to the relevant agreements. In this light it would seem unfair—at the pleading stage—to require Plaintiffs to allege facts known only to the defendants in order to make out a third-party beneficiary claim. See, e.g., Stasi v. Inmediata Health Grp. Corp., 501 F. Supp. 3d 898, 906 (S.D. Cal. 2020) (“[W]ithout discovery, it is not clear what more Plaintiffs could plead, or what more [the defendant] would need to be able to defend against Plaintiffs’ claims that they are third party beneficiaries of [the defendant‘s] contracts . . . .“); Carr, 699 F. Supp. 3d at 1250. But see Kroeck v. UKG, Inc., No. 22-cv-00066, 2022 WL 4367348, at *5 (W.D. Pa. Sept. 21, 2022) (declining to dismiss a third-party beneficiary contract claim where “the contract between Defendants and the hospital is not yet part of the record,” without explaining whether contract was in the defendants’ exclusive possession).
It is not clear whether such access-to-information considerations fully apply in this case. Plaintiffs acknowledge that they have obtained some (but seemingly not all) of the relevant contracts through discovery. Given that the Court nevertheless concludes Plaintiffs have plead
Second, Progress offers a copy of the EULA in effect as of February 1, 2025, which disclaims any intent to recognize unnamed third-party beneficiaries, and argues that this agreement requires dismissal. See [ECF No. 1367-3]. Progress, however, offers little factual basis, even in the declaration accompanying the exhibit, from which the Court can conclude that this EULA is the agreement that Progress actually entered into with PBI, Welltok, Delta Dental, and Maximus. See [ECF No. 1367-2 (“Torrey Decl.“)].13 In fact, the contents of the EULA suggest otherwise. The last line of the agreement contains version information which reads “TMPLT26MAY2023MOVEit-WS_FTP1NOV2023.” [Ex. 1 at 16]. Drawing reasonable inferences in Plaintiff‘s’ favor, this suggests that the agreement was revised, at the earliest, in late-May 2023, the precise timeframe of the Data Breach. Although it may be the case that the specific agreements that Progress and the other Bellwether Defendants entered contain similar language, the Court declines to dismiss Count 3 on the basis of a purported exemplar contract, especially where, on its face, the proffered agreement appears to post-date the Data Breach.
The motion to dismiss Count 3 is DENIED.
e. Count 4: Unjust Enrichment
Progress argues that Plaintiffs’ unjust enrichment claim must be dismissed for a variety of reasons, and the Court agrees. In California, Illinois, and Texas, unjust enrichment does not
The Court disagrees. Plaintiffs allege that Progress was in the business of designing software for the very purpose of protecting sensitive information, including PII, and thus their business depended on the receipt of such information. In other words, drawing reasonable inferences for the Plaintiffs, they allege the design and ongoing maintenance of MOVEit was the commodification of their PII. See In re Ambry Genetics Data Breach Litig., 567 F. Supp. 3d 1130, 1145 (C.D. Cal. 2021) (allowing unjust enrichment claim where “a defendant has accepted the benefits accompanying plaintiff‘s data, but does so at the plaintiff‘s expense by not implementing adequate safeguards, thus making it inequitable and unconscionable to permit defendant to retain funds that it saved by shirking data-security and leaving the plaintiff to suffer the consequences.“); cf. Brooks, 732 F. Supp. 3d at 782 (“Plaintiffs fail to plausibly allege that
Consequently, the motion to dismiss Count 4 is GRANTED IN PART as to the California, Illinois, Texas, Florida, New York, Massachusetts, and North Carolina law claims and DENIED IN PART as to the Michigan, Ohio, and Pennsylvania law claims.
f. Count 5: Bailment
Because Plaintiffs have abandoned their bailment claim, see [Opp. at 36 n.32], the motion to dismiss Count 5 is GRANTED.
g. Counts 6 and 7: Invasion of Privacy
i. Count 6: Intrusion Upon Seclusion
Generally, to prevail on an intrusion-upon-seclusion claim, “a plaintiff must show ‘(1) an intentional intrusion by the defendant, (2) into a matter the plaintiff has a right to keep private, (3) which is highly offensive to a reasonable person.‘” Savidge v. Pharm-Save, Inc., No. 17-cv-186, 2023 WL 2755305, at *9 (W.D. Ky. Mar. 31, 2023) (quoting Wells v. Craig & Landreth Cars, Inc., No. 10-cv-376, 2012 WL 6487392, at *5 (W.D. Ky. Dec. 13, 2012)); Restatement (Second) of Torts § 652B cmts. a–d (A.L.I. 1977) (laying out the requirements for an intrusion-upon-seclusion claim). Progress contends that the Plaintiffs allegations falter for failure to (1) plead intent, (2) allege that the information was wrongfully obtained, and (3) allege an actual physical intrusion by Progress. The Court agrees that the claim should be dismissed on the first ground and declines to reach the latter.
ii. Count 7: Public Disclosure of Private Facts
For the tort of public disclosure of private facts, plaintiffs must allege “(1) public disclosure, (2) of a private fact, (3) which would be offensive and objectionable to the reasonable person, and (4) which is not of legitimate public concern.” E.g., Opperman v. Path, Inc., 87 F. Supp. 3d 1018, 1061–62 (N.D. Cal. 2014) (quoting Taus v. Loftus, 151 P.3d 1185, 1207 (Cal. 2007)).
Progress contends that the theft of Plaintiffs’ information from within the MOVEit Transfer software is not a “public disclosure” within the meaning of the tort, as required by the first element under the applicable states’ laws. Public disclosure “means that the matter is made public, by communicating it to the public at large, or to so many persons that the matter must be regarded as substantially certain to become one of public knowledge.” Opperman, 87 F. Supp. 3d at 1062 (quoting Restatement (Second) of Torts § 652D cmt. a (A.L.I. 1977)). Assuming for the sake of argument that Cl0p‘s theft constituted a communication, Progress maintains that because the communication was to Cl0p, not to the public, Progress cannot be held liable under this theory of the law of any relevant jurisdiction.
Plaintiffs offer several responses. First, they maintain that this contention “merely repackages the same substantive argument regarding the intentionality” that Progress offered to support dismissal of its intrusion-upon seclusion argument “and should accordingly be rejected for the same reasons.” [Opp. at 55]. But as explained above, Plaintiffs’ arguments on that point are unavailing. Plaintiffs also argue, with little elaboration, that the “allegations that CL0P posted stolen data on the clear and dark web” should alter the analysis. [Opp. at 55]. Those allegations, however, fit better with Progress‘s contention that it was Cl0p (not Progress) that disclosed Plaintiffs’ data to the public.15 Finally, Plaintiffs also briefly cite case law to the effect that the publicity element can be “satisfied by disclosure to a limited number of people if those people have a special relationship with the plaintiff that makes the disclosure as devastating as
IV. Statutory Claims
a. Count 8: Massachusetts General Laws Chapter 93A
Plaintiffs allege that Progress‘s failure to protect its data, which resulted in the Data Breach, constitutes a violation of the Massachusetts consumer protection law. [CAC ¶¶ 1495–1509]. In Massachusetts, “[u]nfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce” are forbidden,
Progress raises two arguments in reply. First, Progress contends that “the center of gravity of Plaintiffs’ claims is not Massachusetts.” [Mem. at 84]. It is true, as this Court has held in other cases, that Chapter 93A § 11 requires that the “center of gravity” of “the unfair and
Second, Progress disputes that the alleged conduct satisfies the meaning that the SJC and First Circuit have assigned to the word “unfair” under Chapter 93A, [Mem. at 85]. “[A]n act or practice is unfair if it falls ‘within at least the penumbra of some common-law, statutory, or other established concept of unfairness‘; ‘is immoral, unethical, oppressive or unscrupulous‘; and ‘causes substantial injury to consumers.‘” Tomasella v. Nestlé USA, Inc., 962 F.3d 60, 70 (1st Cir. 2020) (quoting PMP Assocs. v. Globe Newspaper Co., 321 N.E.2d 915, 917 (Mass. 1975)). “‘[M]ere negligence,’ standing alone, is not sufficient for a violation of ch. 93A“; rather, a plaintiff must allege “‘extreme or egregious’ negligence.” Baker v. Goldman, Sachs & Co., 771 F.3d 37, 51 (1st Cir. 2014) (first quoting Klairmont v. Gainsboro Rest., Inc., 987 N.E.2d 1247, 1257 (Mass. 2013), and then quoting Marram v. Kobrick Offshore Fund, Ltd., 809 N.E.2d 1017, 1032 (Mass. 2004)). Progress contends that Plaintiffs’ allegations “boil down to [Progress‘s] alleged ‘fail[ure] to maintain adequate systems and processes for keeping Plaintiffs’ . . . Private
Progress‘s high-level characterization glosses over concrete allegations in the CAC—which the Court must accept as fact at this stage—that plausibly allege at least some actions that fit within the state-law meaning of “egregious.” See Tomasella, 962 F.3d at 71 (deciding Chapter 93A liability is a “fact-specific . . . inquiry” (quoting Arthur D. Little, 174 F.3d at 55)). Specifically, Plaintiffs allege that Cl0p was able to steal their data because MOVEit Transfer was rife with specific cybersecurity defects that should have been obvious to Progress and timely resolved. To pluck perhaps the clearest example from the CAC, Plaintiffs allege that Progress allowed SQL injection vulnerabilities to go undiscovered and unresolved—in some cases, for several years. See, e.g., [CAC ¶¶ 1113, 1136–46]. Plaintiffs allege SQL injection vulnerabilities are “low-hanging fruit,” [CAC ¶ 1024(b)], and have “been documented, understood, and easy to prevent since 1998,” [id. ¶ 1023]. See also In re Yahoo!, 2017 WL 3727318, at *2 (“[T]he Federal Trade Commission found as early as 2003 that ‘SQL injection attacks’ were a known and preventable data security threat.“). It is well understood that leaving consumers’ data vulnerable to theft due to “unreasonably weak internal and external cybersecurity protocols” constitutes an unfair practice under Chapter 93A, In re LastPass, 742 F. Supp. 3d at 131, and Plaintiffs plausibly allege that Progress did that here. The motion to dismiss Count 8 is DENIED.
b. Count 9: California Consumer Privacy Act (“CCPA“)
The CCPA provides a limited civil cause of action for “[a]ny consumer whose nonencrypted and nonredacted personal information . . . is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of [a] business‘s violation of the duty to implement and
The Court agrees that the CAC does not allege that Progress collected PII. Accordingly, the Court need not reach the question of whether Progress could be said to have determined how such data would be processed. To be sure, the CCPA “adopts a broad understanding of ‘collects,‘” In re Accellion, 713 F. Supp. 3d at 641, but Plaintiffs have not alleged that Progress “collect[s]” data even within that broad scope. Rather, Progress‘s customers “transfer and receive highly sensitive Private Information” using MOVEit Transfer, [CAC ¶ 1325], and MOVEit Transfer gives those customers “complete control over . . . file transfers by consolidating them in one system on [the customers‘] own premises,” [id. ¶ 968]. Plaintiffs’ passing analogy to Accellion is inapposite. The Accellion breach affected cloud-based file-transfer software, and the plaintiffs alleged that consumers’ data was “transferred by Accellion.” In re Accellion, 713 F. Supp. 3d at 629. On those facts, plaintiffs could plausibly (though “barely“) allege that Accellion had “receiv[ed]” consumer data within the meaning of the CCPA, id. at 640–41, whereas here, Plaintiffs concede that the PII “at issue here was not taken from MOVEit Cloud,” [Opp. at 58].16 Progress‘s motion to dismiss Count 9 is GRANTED.
c. Count 10: California Consumer Legal Remedies Act
Plaintiffs allege a violation of the California Consumer Legal Remedies Act (“CLRA”), which prohibits “unfair methods of competition and unfair or deceptive acts or practices . . . undertaken by any person in a transaction intended to result or that results in the sale or lease of goods or services to any consumer.”
- “Progress violated California Civil Code section 1770(a)(5), by the use of untrue or misleading statements and omissions and representing that its MOVEit software had characteristics or benefits that it knew to be untrue,” [CAC ¶ 1527];
- “Progress violated California Civil Code section 1770(a)(14), by representing to its clients and the public at large that its MOVEit software employed the highest level of data security and would protect and safeguard Private Information from
unauthorized [access], knowing and intending that its clients would pass these representations along to the Progress California Plaintiffs and California Class Members, when in fact Progress knew such benefits were not conferred,” [id. ¶ 1528]; and - “Progress knew, or should have known, that its representations and advertisements about the nature of its data security and its promise to maintain and update the ability of its MOVEit software to securely store and transfer Private Information were false or misleading and were likely to deceive a reasonable consumer. No reasonable consumer would use Progress’s services if they knew that Progress was not taking reasonable measures to safeguard their Private Information,” [id. ¶ 1529].
As such, Plaintiffs have alleged “a unified course of fraudulent conduct and rely entirely on that course of conduct as the basis of [their CLRA] claim,” making the claim subject to Rule 9(b). Kearns, 567 F.3d at 1125; see also In re LastPass, 742 F. Supp. 3d at 131.
Apart from contesting the adequacy of pleading, Progress advances five separate arguments for dismissal of which the last (the absence of adequate allegations of reliance) is persuasive.
First, the parties bicker about pre-suit notice. The CLRA requires plaintiffs to give “at least 30 days’ notice to the alleged wrongdoer prior to filing an action for damages,” Allen v. Similasan Corp., No. 12-cv-0376, 2013 WL 5436648, at *2 (S.D. Cal. Sept. 27, 2013) (citing
Second, Progress contends that its alleged misconduct is immune from CLRA liability because such conduct did not occur in California. This argument is perplexing as the parties agree that the Plaintiffs’ injuries did in fact occur in California, [Mem. at 33 (“[T]he injuries each Plaintiff alleges occurred in their home states . . . .”)]; [Opp. at 60 (“[T]he California Plaintiffs clearly allege their injuries occurred in California.”)], which is enough to let a litigant
Third, Progress says that Plaintiffs do not allege that Progress transacted in goods or services with the California Plaintiffs, but as its own case citation acknowledges, a “consumer transaction” may be “indirect” and still be subject to CLRA liability without direct privity between the Plaintiff and Defendant. [Mem. at 69 (quoting In re NCB, 748 F. Supp. 3d at 286)]; see also In re Am. Med. II, 2023 WL 8540911, at *9 (finding that allegations that “Plaintiffs received services in exchange for the promise to pay for those services” was sufficient to sustain a CLRA claim).
Fourth, Progress says “the CLRA also does not apply to the MOVEit Transfer software,” which is an “intangible good[].” [Mem. at 69 (quoting Woulfe v. Universal City Studios LLC, No. 22-cv-00459, 2022 WL 18216089, at *15 (C.D. Cal. Dec. 20, 2022))]. As Plaintiffs correctly point out, however, the question of whether software qualifies as a good or service under the CLRA is fact-intensive, see In re Yahoo! Inc. Customer Data Sec. Breach Litig., 313 F. Supp. 3d 1113, 1141–42 (N.D. Cal. 2018), and Progress offers no more than a conclusory assertion that MOVEit Transfer software falls outside the CLRA’s scope.
Fifth, Progress says that Plaintiffs have not pleaded reliance, because they have not “allege[d] any direct interaction” between Progress and the Plaintiffs, [Mem. at 69 (quoting Miller v. NextGen Healthcare, Inc., No. 23-cv-02043, 2024 WL 3543433, at *10 (N.D. Georgia July 25, 2024))], and have not alleged that Plaintiffs “were even aware of Progress’s alleged
In reply, Progress convincingly argues that any rebuttable presumption of reliance is overcome by the fact that Plaintiffs do not allege that they ever interacted with Progress, or even knew Progress existed, [Reply at 28], such that they could have relied on any misrepresentation by the company, Miller, 742 F. Supp. 3d at 1324–26. “[P]laintiffs asserting CLRA claims sounding in fraud must establish that they actually relied on the relevant representations or omissions,” id. at 1326, and cannot plausibly allege they did so where they “do[] not allege any direct interaction between [themselves]” and Progress. Id. at 1324.
The motion is therefore GRANTED as to Count 10.
d. Claim 11: California Confidentiality of Medical Information Act (“CMIA”)
The California Plaintiffs also allege that Progress has violated the CMIA, a healthcare privacy statute prohibiting any “provider of health care, health care service plan, pharmaceutical company, or contractor” from negligently releasing an individual’s medical information except as specifically allowed.
On this Court’s own review of § 56.06 and its surrounding sections Progress has the better of this argument. Plaintiffs’ reading does not take full account of § 56.06’s “context,” “statutory purpose,” and other “statutory sections relating to the same subject.” Dyna-Med, Inc. v. Fair Emp. & Hous. Comm’n, 743 P.3d 1323, 1326 (Cal. 1987). First, the purpose of § 56.06, as disclosed in its title and reflected in its contents, is to identify “[b]usinesses deemed to be provider[s] of health care,” and the ordinary recipients of health care are individual persons, not corporations.20 Moreover, this purpose is borne out by the use of the word “consumer” synonymously with “individual” throughout the statute. For example, just two subsections
Progress’s motion to dismiss Count 11 is GRANTED.
e. Counts 12, 17, 20, 26, 31: State Data-Breach Notification Statutes
Plaintiffs assert that Progress failed to comply with state data-breach notification statutes in California, Illinois, Michigan, North Carolina, and Washington state. See [CAC Counts 12, 17, 20, 26 and 31]. Progress summarily contends it is not covered by those statutes because the notification requirements extend only to entities that “own[],” “license[],” or “maintain[]” their data, and Plaintiffs have not pleaded that Progress does any of these things. See
Progress also argues that Plaintiffs are not “customers” under the California Consumer Records Act. “Any customer injured by a violation of [the CCRA] may institute a civil action to recover damages,”
Plaintiffs do not dispute this characterization of the Bellwether Complaint. Instead, they argue that a recent California Appeals Court ruling provides a better analogy. See J.M. v. Illuminate Educ., Inc., 323 Cal. Rptr. 3d 605, 613 (Cal. Ct. App. 2024) cert granted sub nom., M. v. Illuminate Educ., 557 P.3d 735 (Cal. 2024). In J.M., a middle-school student sued Illuminate, “an education consulting business” that had contracted with his school to “evaluate his educational progress,” including by receiving from the school J.M.’s personal and medical information, which was later accessed by hackers. Id. at 608. The Court held that although “Illuminate had a contract with the school district,” J.M “was an intended beneficiary under the CRA” and fell within the definition of “customer,” which the Court “interpreted broadly.” Id. at 613. The California Supreme Court has acknowledged, however, that J.M. creates a split of authority on the proper scope of the CCRA and has granted review in that case, which remains pending as of the issuance of this order, M., 557 P.3d 735. In the meantime, this Court may “choose between sides of any such conflict.” Id. The Court concludes that J.M.’s interpretation of “customer” strays unpersuasively from the statutory definition. Accordingly, the motion to dismiss Count 12 is GRANTED.
f. Count 13: California Unfair Competition Law (“UCL”)
Progress urges dismissal of Count 13 on the grounds that (1) California Plaintiffs have “fail[ed] to allege a lack of an adequate remedy at law,” (2) “no relevant conduct by Progress is
Progress cites cases indicating that federal common law supplies the equitable rules for awarding restitution under the UCL, see Sonner v. Premier Nutrition Corp., 971 F.3d 834, 841 (9th Cir. 2020), and include a requirement that Plaintiffs “must establish that [they] lack[] an adequate remedy at law before securing equitable restitution for past harm under the UCL,” id. at 844. A complaint seeking equitable relief should be dismissed if it fails to plead “the basic requisites of the issuance of equitable relief,” including the “inadequacy of remedies at law.” Id. (quoting O’Shea v. Littleton, 414 U.S. 488, 502 (1974)). Here, Plaintiffs “seek restitution and an injunction” requiring Progress to modify its security practices, [CAC ¶ 1579], and Progress offers no explanation for why this proposed injunctive relief would be supplanted by a legal remedy.
As for Plaintiffs’ demand for restitution, they plead that their request is “in the alternative to any adequate remedy at law they may have.” [CAC ¶ 1580]. This comports with the decisions of California Courts applying Sonner, which have “allow[ed] the pursuit of alternative remedies at the pleadings stage.” Collyer v. Catalina Snacks Inc., 712 F. Supp. 3d 1276, 1289 (N.D. Cal. 2024) (collecting cases). Unlike in Sonner, the record here discloses no grounds on which the Court could conclude, at this stage, that Plaintiffs seek “the same sum in equitable restitution . . . as [they] request[] in damages to compensate [them] for the same past harm.” Id. (quoting Sonner, 971 F.3d at 844). Dismissal on this ground would be premature.
Nor does Progress’s extraterritoriality argument carry the day. California’s extraterritoriality test asks whether a statute discloses “that it was designed or intended to regulate claims of non-residents arising from conduct occurring entirely outside of California.”
Finally, Progress contends that Plaintiffs have not alleged “lost money or property” as required for UCL standing. [Mem. at 66]. The California Supreme Court has explained that a plaintiff can show “economic injury from unfair competition” in “innumerable ways,” and although California Proposition 64 sought to bar non-economic injuries from giving rise to UCL standing, “[n]either the text of [the] Proposition . . . nor the ballot arguments in support of it purported to define or limit the concept of ‘lost money or property.’” Kwikset Corp. v. Superior Ct., 246 P.3d 877, 885–86 (Cal. 2011). Here, Plaintiffs have alleged that they suffered concrete monetary and property losses from, for example, the loss of the benefit of their bargain,
g. Count 14: California Constitution’s Right to Privacy
The California Plaintiffs’ privacy claim under the California Constitution fails for the same reasons as their common law privacy claims, which are “functionally identical” under California law. Prutsman v. Nonstop Admin. & Ins. Servs., Inc., No. 23-cv-01131, 2023 WL 5257696, at *1 (N.D. Cal. Aug. 16, 2023) (dismissing claim); see also In re Accellion, 713 F. Supp. 3d at 623, 645–47 (considering claims under intrusion upon seclusion and the California Constitution’s right to privacy together). Because Plaintiffs fail to plead an intentional intrusion-upon-seclusion claim (Count 6), the motion to dismiss Count 14 is GRANTED.
h. Count 15: Connecticut Unfair Trade Practices Act (“CUPTA”)
Plaintiff Karen Boginski alleges that Progress violated the CUTPA by failing to adequately protect her PII, and that of other Connecticut Plaintiffs, thereby causing damages. Progress does not dispute that these allegations satisfy the elements of CUTPA. Hernandez v. Apple Auto Wholesalers of Waterbury, 460 F. Supp. 3d 164, 182 (D. Conn. 2020) (requiring
The problem with Progress’s argument on this score is that the broad wording of the statute cannot fairly be read to require the sort of privity suggested by Progress. It does not follow that requiring Boginski to “have some sort of business relationship” with Progress requires a direct business or consumer relationship. Aviles, 49 F. Supp. 3d at 232 (quoting Gersich, 1995 WL 904917 at *5). Indeed, the Connecticut Supreme Court has long recognized, and has “stated in no uncertain terms,” that statutory standing under CUTPA “imposes no requirement of a consumer relationship.” Larsen Chelsey Realty Co. v. Larsen, 656 A.2d 1009, 1019 (Conn. 1995). In a careful analysis of the applicable state cases, the late Judge Meyer explained that although “CUTPA’s reach is not ‘limitless,’” it has been “the Connecticut Supreme Court’s consistent view that CUTPA should be broadly construed to protect against unfair business practices in many shapes and forms.” Flynn v. DIRECTV, LLC, No. 15-cv-1053, 2016 WL 4467885, at *4 (D. Conn. 2016) (quoting Ganim v. Smith and Wesson Corp., 780 A.2d 98, 133 (Conn. 2001)); see id. at *4–5 (citing cases and rejecting argument that CUTPA
Attempting to salvage the point, Progress suggests in its Reply that Boginski’s allegations effectively convey that there is “no relationship” between Boginski and Progress. [Reply at 32 (emphasis added)]. But this slices it too thin. Drawing all reasonable inferences in Boginski’s favor, as the Court must, the allegations describe a relationship, albeit an indirect one,22 between Boginski and Progress that flows through Delta Dental. That is enough for the Court to conclude that the “any business relationship” requirement for a CUTPA claim has been adequately alleged. Id. The motion to dismiss Count 15 is DENIED.
i. Count 16: Georgia Uniform Deceptive Trade Practices Act (“GUDPTA”)
Progress contends that Plaintiffs Doris Cadet and Taneisha Robertson (the “Georgia Plaintiffs”) fail to state a claim under the GUDPTA because they (1) “fail to plead reliance” and (2) “are not entitled to injunctive relief.” [Mem. at 74]. On reliance, Progress cites to
The passage that Progress cites reads in full:
A plaintiff who demonstrates past harm, but does not allege ongoing or future harm, has not shown that he is likely to be damaged within the meaning of section 10-1-373(a). Plaintiffs have not pled that they read, relied upon and, thus, were harmed by Defendant’s “representations” and, even if they could replead such facts, Plaintiffs could, at most, demonstrate only past harm which is not a basis for injunctive relief under the [G]UDTPA.
Willingham, 2013 WL 440702, at *16. Taken literally, this reading of the GUDPTA poses something of a Catch-22: by alleging reliance a plaintiff necessarily points to a past harm, which precludes injunctive relief for ongoing or future harms.
Plaintiffs urge the Court to join more recent Georgia decisions finding Willingham unpersuasive. See, e.g., Miller v. NexGen Healthcare, 742 F. Supp. 3d 1304, 1320–21 (N.D. Ga. 2024) (noting that Willingham should not be read as “requiring all GUDTPA plaintiffs to plausibly allege reliance”). The Court agrees. Because forward-looking “[i]njunctive relief is the sole remedy under the [G]UDTPA,” Willingham, 2013 WL 440702, at *16; accord Moore-Davis Motors, Inc., 556 S.E.2d 137, 140 (Ga. Ct. App. 2001), it makes little sense to require the Georgia Plaintiffs to plead “past reliance,” as opposed to a reasonable likelihood they will “be damaged by a deceptive trade practice in the future.” Miller, 742 F. Supp. 3d at 1321.
Even without following Willingham, Plaintiffs’ claims hang by a thin thread. The CAC is scant on allegations that Plaintiffs face a “likelihood of future harm” due to “a deceptive trade practice.” Id. at 1319 (quoting
Although the path is narrow and factual development may be challenging, the allegation of ongoing risk is sufficiently well-pled in light of the extensive allegations concerning Progress’s past security deficiencies, to support a finding that Plaintiffs may be entitled to injunctive relief. The motion to dismiss Count 16 is DENIED.
j. Count 18: Illinois Consumer Fraud and Deceptive Business Practices Act (“ICFA”)
Progress urges dismissal of the ICFA claims brought by Rob Plotke, Christopher Rehm, and Katherine Uhrich (the “Illinois Plaintiffs”). Progress advances four reasons for dismissal. Three of these are unpersuasive, at least at the pleading stage. The last argument, however, warrants dismissal of Rehm’s and Uhrich’s claims, but not Ploke’s.
First, Progress argues that the Illinois Plaintiffs lack an adequate nexus to Illinois, such that application of the ICFA here would violate Illinois extraterritoriality rules. [Mem. at 71]. The ICFA does not “apply to fraudulent transactions which take place outside Illinois,” but in a modern economy, “it can be difficult to identify the situs of a consumer transaction when . . . the transaction is made up of components that occur in more than one state.” Avery v. State Farm Mut. Auto. Ins. Co., 835 N.E.2d 801, 853 (Ill. 2005). In such circumstances, a transaction falls within the territorial reach of the ICFA “if the circumstances relating to the transaction occur primarily and substantially within [Illinois].” Id.
Here, the first and third factors weigh in favor of allowing the ICFA claim to proceed. Plaintiffs’ residences are in Illinois and the parties, as discussed in the choice-of-law analysis, agree that their injuries occurred there. On the other hand, even drawing factual inferences in favor of Plaintiffs, relevant aspects of the alleged deceptive conduct likely occurred out of state, given the domiciles of Progress and the non-Progress Defendants, so the second factor weighs against the ICFA claim. There is no allegation that the Illinois Plaintiffs communicated with Progress in Illinois, but they do allege that their data ended up in the MOVEit environment based on transactions with Progress’s customers or downstream contracting parties that occurred in Illinois. Cf. Sweet v. BJC Health Sys., No. 20-cv-00947, 2021 WL 2661569, at *6 (S.D. Ill. June 29, 2021) (“Plaintiff Taylor represents that his contact with Defendants was through medical treatment that occurred wholly within Illinois.”).
These facts bear a close resemblance to Sweet, where “in-state plaintiffs” sued an “out of state defendant” over a data breach that “occurred in Missouri” and for which “decisions relevant to Defendants’ internal data security occurred” outside of Illinois. Sweet, 2021 WL 2661569, at *6. The court in Sweet concluded that “the bulk of the ‘transaction’ as it relates to [the Illinois
Although it is a close call, for present purposes, the allegations suffice to establish an adequate nexus to Illinois for the ICFA. The same is true for Progress’s nexus challenge to Plaintiffs’ Illinois Uniform Deceptive Trade Practices Act (“IUDTPA”) claim (Count 19.) Perdue, 455 F. Supp. 3d at 774 (ICFA and IUDTPA share the same nexus requirement).
Second, Progress challenges whether Plaintiffs have pled reliance, but the ICFA only requires allegations of materiality at the pleading stage and “does not require actual reliance,” Ash v. PSP Distrib., LLC, 226 N.E.3d 748, 754 (Ill. App. Ct. 2023), and the Illinois Plaintiffs’ allegations suffice, at this stage, to show that “a reasonable consumer would have acted differently had the consumer known the omitted fact,” id. (citation omitted); see [CAC ¶¶ 1648–54].
Third, Progress contends that Plaintiffs have failed to allege a misleading representation made by the company and directed toward the Plaintiffs. According to Progress, “[a] plaintiff cannot maintain an action under the ICFA for a deceptive practice sans a communication from the defendant containing either a deceptive misrepresentation or omission.” [Mem. at 71 (quoting Schwebe v. AGC Flat Glass N. Am., Inc., No. 12-c-9871, 2013 WL 2151551, at *2 (N.D. Ill. May 16, 2013))]. Because Progress’s relationship with the Illinois Plaintiffs was mediated by third parties, there was no direct communication. See [id. (“If there has been no communication with the plaintiff, there have been no statements and no omissions.”) (quoting De Bouse v. Bayer, 922 N.E.2d 309, 316 (Ill. 2009))].
Plaintiffs’ respond to this argument by pointing to language in DeBouse that appears to contemplate circumstances in which a Plaintiff may receive information through “indirect
Plaintiffs allege that Progress made misrepresentations to intermediaries, like TIAA, that stood between Plaintiffs and Progress. See, e.g., [CAC ¶ 1330 (“Progress markets, advertises, guarantees, and warrants to all its customers that the MOVEit Transfer software will keep Private Information safe and secure from unauthorized access.”)]. To the extent Rule 9(b) applies, they also identify specific statements Progress made targeting the healthcare and financial services industries, presumably including customers like TIAA and OSF Healthcare. See [CAC ¶ 1341 & n.430 (“Progress promises its customers in the financial industry that MOVEit will ‘help[] your organization meet cybersecurity compliance standards such as PCI-DSS, HIPAA, GDPR, SOC2 and more.’” (alteration in original))]; [id. ¶ 1344 & n.433 (“Progress likewise promises its clients in the healthcare industry that ‘MOVEit provides the features and deployment flexibility required to help healthcare agencies comply with HIPAA, PCI-DSS, GDPR and other leading cybersecurity standards.’”)]; In re Porsche Cars N. Am., 880 F. Supp. 2d 801, 847 (S.D. Ohio 2012) (“[C]laims for ‘deceptive practices’ must meet the heightened pleading standard of Rule 9(b).”). The CAC’s allegations suffice to state an ICFA claim against Progress based on a theory of indirect misrepresentation.
Here, all three Illinois Plaintiffs allege an increase in spam, a risk of future identity theft, lost time spent monitoring accounts or otherwise seeking to avoid identity fraud, and emotional distress. [CAC ¶¶ 161–67, 316–21, 910–16]. Plotke allegedly incurred out-of-pocket costs for postage to dispute fraudulent charges incurred as a result of the Data Breach. [Id. ¶ 161]. The latter injury is “a ‘real and measurable’ out-of-pocket loss,” albeit a modest one, while the other alleged injuries are not. In re Supervalu, 925 F.3d at 964; see also id. (“The time Holmes spent protecting himself against the threat of future identity theft does not amount to an out-of-pocket loss.”). Rehm and Ulrich attempt to bootstrap their risk of future pecuniary injury to Plotke’s present pecuniary injury, [Opp. at 74–75], by invoking the logic of Webb v. Injured Workers Pharmacy, LLC, where the First Circuit held that “actual misuse of a portion of . . . stolen information increases the risk that other information will be misused in the future,” such that a plaintiff who only faced a risk of future harm could still invoke Article III standing based on the
k. Count 19: Illinois Unfair and Deceptive Trade Practices Act (“IUDTPA“)
The IUDTPA permits a “person likely to be damaged by a deceptive trade practice” to obtain “injunctive relief” against the offender.
Progress says Plotke‘s, Rehm‘s, and Uhrich‘s claims for injunctive relief under the IUDPTA must be dismissed for the same reasons discussed in this Court‘s decision on standing, namely, that the injunctive relief requested at that stage would not have redressed the risk of future harm caused by the data breach. [ECF No. 1304 at 6 n.3]. But there‘s a disconnect. As the Court explained at the time, the focus then was on the inadequacy of injunctive relief against
l. Count 21: Michigan Consumer Protection Act (“MCPA“)
Plaintiffs allege that Progress violated the MCPA, which prohibits “[u]nfair, unconscionable, or deceptive methods, acts, or practices in the conduct of trade or commerce.”
Progress argues that MOVEit was “purchased primarily for business or commercial rather than personal purposes” and “therefore outside the MCPA‘s scope.” [Mem. at 75–76 (quoting Dusseau Farms LLC v. Wilbur-Ellis Co., No. 12-cv-12581, 2013 WL 3895829, at *6 (E.D. Mich. July 29, 2013))]. Plaintiffs respond that their transactions for healthcare services from Corewell Health (a Welltok VCE) were purchases for personal use. [Opp. at 76]. But the relevant statutory language asks whether the claim implicates “the conduct of a business providing goods, property, or service primarily for personal, family, or household purposes.”
Because the Court finds this claim falls outside the scope of the MCPA, there is no need to reach Progress‘s asserted second ground for dismissal, i.e., whether the Plaintiffs sufficiently allege that any misrepresentations or omissions were directed at them. The motion to dismiss is GRANTED as to Count 21.
m. Count 22: Nebraska Consumer Protection Act (“NCPA“)
Plaintiff Laquesha George, on behalf of the Progress Nebraska Class (together, “the Nebraska Plaintiffs“), alleges that through the Data Breach, Progress violated the NCPA. Progress contends that the NCPA claim must be dismissed because the Nebraska Plaintiffs have failed to allege “actual damages.” [Mem. at 83]. The parties’ briefing of this issue is sparse, relies entirely on cases addressing very different scenarios, and fails to identify relevant legal standards for determining the adequacy of George‘s damages allegations. Progress cites cases involving the NCPA‘s antitrust provisions to suggest that George‘s damages are too “derivative and remote” to state a claim. Kanne v. Visa U.S.A. Inc., 723 N.W.2d 293, 302 (Neb. 2006). As a cursory review of the case relied upon by Progress reveals, the NCPA‘s antitrust provisions specifically incorporate federal antitrust law, id. at 301–02 (quoting
For her part, rather than engage with Kanne, George cites a similarly inapposite case involving an appeal challenging a directed verdict and damages instructions given to a jury in a non-NCPA case. Lesiak v. Cent. Valley Ag Coop., Inc., 808 N.W.2d 67, 76 (Neb. 2012). Although this does not advance George‘s position, the fact remains that Progress has not given the Court a valid ground for dismissal.
In any case, George‘s alleged damages appear to pass muster under Nebraska case law. Although it does not appear that George has suffered a direct financial loss, the NCPA‘s damages provision does not seem to require a measurable pecuniary injury. To the contrary, the statute allows “actual damages sustained” or an award of damages “not susceptible of measurement by ordinary pecuniary standards” up to $1,000.
n. Count 23: Nebraska Uniform Deceptive Trade Practices Act (“NUDTPA“)
Progress contends that the Nebraska Plaintiffs’ claim falls outside the scope of the Nebraska Uniform Deceptive Trade Practices Act. The NUDTPA applies to “deceptive trade practices” even if the practices are “conducted outside of Nebraska against residents” of
o. Count 24: New Jersey Consumer Fraud Act (“NJCFA“)
Progress argues that Plaintiff Margaret Phelan‘s claim under the NJCFA on behalf of the Progress New Jersey Class (together, the “New Jersey Plaintiffs“), must be dismissed because Phelan is not a “consumer” within the meaning of the statute. [Mem. at 76]. To state a claim under the NJCFA, “a ‘consumer’ must allege sufficient facts to demonstrate (1) unlawful conduct by the defendant that violates the NJCFA; (2) an ascertainable loss by the plaintiff; and (3) a causal relationship between the unlawful conduct and the ascertainable loss.” In re Forta, 749 F. Supp. 3d at 1276 (quoting Gonzalez v. Wilshire Credit Corp., 25 A.3d 1103, 1115 (N.J. 2011)). “The NJCFA is intended to protect consumers who purchase goods or services generally sold to the public at large.” Id. at 1277 (cleaned up) (quoting Arc Networks Inc. v. Gold Phone Card Co., 756 A.2d 636, 637–38 (N.J. Super. Ct. Law Div. 2000)). A “plaintiff does not qualify as a consumer if they do not purchase a product for consumption.” Id. (quoting In re Blackbaud, 2021 WL 3568394, at *11 (citing Arc Networks, 756 A.2d at 637–38)). A plaintiff “must be a consumer vis-à-vis the defendants.” Id. (quoting Speciality Ins. Agency v. Walter Kaye Assocs., Inc., No. 89-cv-01708, 1989 WL 120752, at *5 (D.N.J. Oct. 2, 1989)).
Phelan‘s argument overstates the reach of the principle on which she relies. In each of the cited privity cases, the plaintiff was a downstream purchaser of a product or service, whereas here, Phelan does not allege that Progress is a “remote supplier” of the financial services Phelan obtained from TIAA, nor do her allegations naturally support such an inference. In any case, Phelan, as the inheritor of an insurance policy, is not a “consumer vis a vis” Progress. Accordingly, the motion to dismiss is GRANTED as to Count 24.
p. Count 25: New York General Business Law (“GBL“)
Progress urges dismissal of Gilbert and Lynda Hale‘s New York General Business Law claim on three grounds. First, the GBL requires a “sufficient nexus” to New York, which Progress says is absent from the Plaintiffs’ allegations. MacNaughton v. Young Living Essential Oils, LC, 67 F.4th 89, 99 (2d Cir. 2023).
A claim “falls within the territorial reach” of the GBL when the plaintiff alleges “a sufficient nexus between [the plaintiff‘s] transactions with [the defendant] and New York.” In re NCB, 748 F. Supp. 3d at 289 (quoting MacNaughton, 67 F.4th at 99). An allegation that the Plaintiff purchased a product from the defendant will typically suffice to satisfy the nexus requirement. MacNaughton, 67 F.4th at 99. Here, however, Plaintiffs concede they did not purchase anything from Progress, and, as in In re NCB, they do “not allege that [they] had any direct interaction with [Progress], or [were] even aware of [Progress]‘s existence before the data breach.” In re NCB, 748 F. Supp. 3d at 290.
Progress has the better of the argument on this point; the claims here lack a sufficient nexus to New York. The motion to dismiss Count 25 is therefore GRANTED.
q. Count 27: North Carolina Unfair and Deceptive Trade Practices Act (“NCUDTPA“)
Progress argues that Plaintiff Ben Dieck, suing on behalf of the Progress North Carolina Class, fails to state a claim under the NCUDTPA “because []he does not adequately allege unfair or deceptive conduct by Progress or actual damages.” [Mem. at 86].
To state an NCUDTPA claim, a plaintiff must allege (1) a prohibited unfair or deceptive act, (2) “in or affecting commerce,” that (3) “proximately cause[s] an injury to the plaintiff.” See Darne, 2015 WL 9259455, at *11 (quoting Bumpers v. Cmty. Bank of N. Virginia, 747 S.E.2d 220, 226 (N.C. 2013)). Showing proximate cause on a deceptiveness claim usually involves pleading reliance on the Defendant‘s misrepresentation. City of High Point v. Suez Treatment Sols. Inc., 485 F. Supp. 3d 608, 633 (M.D.N.C. 2020).
Progress convincingly argues that Dieck has not alleged any facts that would support an inference of reliance. [Mem. at 86]. Not only did Dieck lack a direct relationship with Progress, but he also concedes that he “ha[d] no known relationship” with Maximus or the Colorado Department of Human Services, the government entity through which Maximus obtained Dieck‘s information. [CAC ¶ 61]. Because Dieck acknowledges that he has no idea as to how
The motion to dismiss Count 27 is GRANTED.
r. Count 28: Ohio Consumer Sales Practices Act (“OCSPA“)
Progress contends that Plaintiff Elaine McCoy, suing on behalf of the Progress Ohio Class, fails to state a claim under the OCSPA because she does not allege a “consumer transaction” within the meaning of the statute. [Mem. at 79–80].
The OCSPA prohibits “supplier[s]” from engaging in “unfair or deceptive act[s] or practice[s] in connection with a consumer transaction.”
Progress contends that McCoy has failed to allege (1) a transaction with Progress or (2) that MOVEit Transfer is used primarily for “personal, family, or household purposes.” [Mem. at 80]. McCoy convincingly rebuts Progress‘s first contention, since the statute provides that a “supplier” under the statute need not “deal[] directly with the consumer.”
s. Count 29: Pennsylvania Unfair Trade Practices and Consumer Protection Law (“PUTPCPL“)
Progress contends that Plaintiffs Steven Checchia, Marvin Dovberg, and Victor Diluigi, suing on behalf of the Progress Pennsylvania Class, have failed to state a claim under the Pennsylvania PUTPCPL for failure to plead an “ascertainable loss” and or to allege reliance. In re Rutter‘s, 511 F. Supp. 3d at 541. Progress‘s argument is persuasive to the extent that Dovberg‘s and Diluigi‘s claims fail to surmount the “ascertainable loss” threshold, while Checchia‘s claim flounders for lack of reliance.
“To allege an ascertainable loss, the plaintiff ‘must be able to point to money or property that he would have had but for the defendant‘s fraudulent actions.‘” Id. (quoting Riviello v. Chase Bank USA, N.A., No. 19-cv-00510, 2020 WL 1129956, at *3 (M.D. Pa. Mar. 4, 2020)). “These damages must be identifiable and ‘cannot be speculative.‘” Id. (quoting Jarzyna v. Home Props., L.P., 185 F. Supp. 3d 612, 626 (E.D. Pa. 2016) aff‘d 783 Fed. Appx. 223 (3d Cir. 2019)). Dovberg claims he “expended time and effort checking his credit and financial accounts,” has “suffered lost time, annoyance, interference, and inconvenience,” and “anticipates spending considerable time and money on an ongoing basis to try to mitigate and address the harms caused by the Data Breach.” [CAC ¶¶ 439, 441–42]. Plaintiff DiLuigi also alleges that he incurred various fraudulent charges, but he admits that he was reimbursed for those costs. [CAC ¶ 88]; In re Rutter‘s, 511 F. Supp. 3d at 541 (holding injuries based on expenses that “were ultimately reimbursed by their banks” not cognizable). Plaintiffs Dovberg and DiLuigi both fall short of alleging ascertainable damages or a “tangible loss of money,” as required to show a cognizable injury. Id.
Checchia nonetheless fails to plead justifiable reliance on any omission or misrepresentation. To state a claim under the PUTPCPL, “a plaintiff must [allege] that he justifiably relied on the defendant‘s wrongful conduct or representation and that he suffered harm as a result of that reliance.” Yocca v. Pittsburgh Steelers Sports, Inc., 854 A.2d 425, 438 (Pa. 2004). Here, the Court cannot reasonably infer that Checchia even “knew that [Progress] existed,” let alone that he would not have transacted with TIAA but for Progress‘s alleged misrepresentations and omissions. In re Blackbaud, 2021 WL 3568394, at *14. Justifiable reliance cannot be presumed. Hunt v. U.S. Tobacco Co., 538 F.3d 217, 227 (3d Cir. 2008). Thus, the motion to dismiss Count 29 is GRANTED.
t. Count 30: Vermont Consumer Protection Act (“VCPA“)
Progress also contends Plaintiff Patricia Marshall, on behalf of the Progress Vermont Class (collectively, the “Vermont Plaintiffs“), has failed to state a claim under the VCPA because she does not allege that she is a “consumer” within the meaning of the statute. [Mem. at 82]. The VCPA defines “consumer” as “a person who purchases . . . goods or services . . . for the person‘s use or benefit or the use or benefit of a member of the person‘s household.”
The VCPA has been “liberally construed” to “include direct and indirect purchasers with no privity requirement.” Mongeon v. KPH Healthcare Servs., Inc., No. 21-cv-00195, 2022 WL 1978674, at *3 (D. Vt. June 6, 2022) (internal quotation marks omitted) (quoting Elkins v. Microsoft Corp., 817 A.2d 9, 13 (Vt. 2002)); see also Madowitz v. Woods at Killington Owners’ Ass‘n, 93 A.3d 571, 581 (Vt. 2014) (explaining that broad reading of VCPA effectuates statutory purpose of “allow[ing] the consumer to reach the person who committed the consumer fraud“). Although Vermont law only requires “some relationship,” and not “strict privity,’ Bellwether Cmty. Credit Union v. Chipotle Mexican Grill, Inc., 353 F. Supp. 3d 1070, 1097 (D. Colo. 2018)), the relationship must still be “akin to that of buyer and seller,” Maurise v. Fed. Ins. Co., No. 08-cv-00013, 2009 WL 10679101, at *3 (D. Vt. Jan. 23, 2009). Here, Marshall cannot plausibly be construed as an indirect buyer of Progress‘s services where he bought insurance from TIAA, which contracted with PBI for auditing services, which in turn contracted with MOVEit. Progress‘s motion to dismiss Count 30 is GRANTED.
u. Count 32: Washington Consumer Protection Act (“WCPA“)
Progress alleges that Plaintiff Megan McClendon, on behalf of the Progress Washington Class (collectively, the “Washington Plaintiffs“), fails to adequately allege a deceptive or unfair act under the WCPA, arguing McClendon has not alleged reliance or privity. [Mem. at 87]. With regards to reliance, Progress cites no state law and the Washington Supreme Court has, in fact,
v. Count 33: Declaratory Judgment
Progress argues for dismissal of Plaintiffs’ request for declaratory relief primarily on the ground that it is duplicative of their negligence and contract claims. [Mem. at 87–88]. Plaintiff‘s tort and contract claims, however, seek only retrospective relief. Their request for declaratory judgment, by contrast, is premised on allegations that the “security measures on [the] MOVEit software remain inadequate,” and that, as a result, “the risk remains that further compromises of [Plaintiffs‘] Private information will occur in the future.” [CAC ¶¶ 1813–14]. An allegation of “continued inadequacy of [a] Defendant[‘s] security measures” substantiates a claim for declaratory judgment in a data breach case. In re Unite Here Data Sec. Incident Litig., 740 F. Supp. 3d 364, 388 (S.D.N.Y. 2024) (quoting In re Cap. One Consumer Data Sec. Breach Litig., 488 F. Supp. 3d 374, 414–15 (E.D. Va. 2020)).24 Accordingly, the motion to dismiss Count 33 is DENIED.
V. CONCLUSION
For the foregoing reasons, the Motion is GRANTED on Counts 2, 5–7, 9–12, 14, 21, 24, 25, 27–30, GRANTED IN PART and DENIED IN PART on Counts 1, 4, and 18, and otherwise DENIED.
July 31, 2025
/s/ Allison D. Burroughs
ALLISON D. BURROUGHS
U.S. DISTRICT JUDGE