Perry v. Bay & Bay Transportation Services, Inc.Perry v. Bay & Bay Transportation Services, Inc.
MEMORANDUM OPINION AND ORDER DENYING DEFENDANT‘S MOTION TO DISMISS
Jessica J. Nelson, Luke J. Wolf, Thomas W. Hayde, SPENCER FANE LLP, 100 South Fifth Street, Suite 2500, Minneapolis, MN 55402, for Defendant.
Plaintiff Billy Perry brings this action against Defendant Bay & Bay Transportation Services, Inc., alleging negligence, negligence per se, and breach of implied contract. Perry‘s claims stem from a ransomware attack in November 2021 on Bay & Bay‘s network that resulted in unauthorized access to their computer systems and customer and employee data. Perry brings claims individually and on behalf of a putative nationwide class of all employees and consumers affected by the data breach that resulted in the theft of their personal information, seeking damages, costs and attorney fees, and injunctive relief to require Bay & Bay to implement certain data security measures. Bay & Bay now moves to dismiss the action.
BACKGROUND1
Defendant Bay & Bay is a nationwide trucking and logistics company that delivers supply chain solutions to businesses. (Compl. ¶ 19, April 15, 2022, Docket No. 1.) Plaintiff Billy Perry, an individual citizen of the State of Minnesota, applied for employment with Bay & Bay and as a condition of employment, provided Bay & Bay with private information. (Id. ¶¶ 17, 28.) Perry alleges that Bay & Bay required customers and/or employees (prospective, current, and former) to provide sensitive personal and private information such as: full name, residential address, social security number, date of birth, driver‘s license, and direct deposit information (“Private Information” or “PI“).2 (Id. ¶ 21.)
Through the course of its business, Bay & Bay acquired and stored Perry and Class Members’ Private Information and prоmised to provide confidentiality and adequate security through their applicable privacy policy3 and through other disclosures. (Id. ¶¶ 22-25.)
On or about January 5, 2022, Bay & Bay discovered suspicious activity on its IT systems. (Id. ¶ 32.) Following this discovery, Bay & Bay launched an investigation and learned that in or around November 2021, unauthorized parties accessed files containing Private Information via a ransomware attack (“data breach“) and published Private Information on the dark web. (Id. ¶¶ 1, 33.)
On a data breach notice letter dated February 9, 2022, Perry was notified by Bay & Bay that his Private Information was compromised in a data breach. (Id. ¶ 17.)4 Perry alleges that some 7,500 individuals were victims of the data breach. (Id. ¶ 34). Perry alleges he and Class Members provided their Private Information to Bay & Bay with the reasonable expectation and mutual understanding that Bay & Bay would comply with its obligations to keep such information confidential and secure from unauthorized access,
and that data security obligations were particularly important given the substantial increase in cyberattacks and Bay & Bay‘s previous cyberattack in 2018. (Id. ¶¶ 35-41.)
As a result of the data breach, Bay & Bay directed Perry to take certain steps to protect his Private Information and otherwise mitigate his damages. (Id. ¶ 87.) Bay
Perry commenced the instant action on March 17, 2022. In his complaint, he seeks damages under three causes of action: (1) negligence, (2) negligence per se under the Federal Trade Commission Act, and (3) breach of implied contract. (Id. ¶¶ 124-149.) Perry also seeks injunctive and equitable relief to require Bay & Bay to implement certain data security measures. (Id. ¶ 134). Perry contends that Bay & Bay failed to comply with the Federal Trade Commission Act‘s established cyber-security guidelines for businesses and industry standards, and such neglect presents Perry and Class Members with a present and substantially increased risk of fraud and identity theft. (Id. ¶¶ 50-63).
Bay & Bay now moves to dismiss the action on two grounds. First, as a threshold issue, Bay & Bay argues that Perry lacks Article III standing under
DISCUSSION
I. RULE 12(B)(1) SUBJECT MATTER JURISDICTION
A. Standard Of Review
A
B. Article III Standing
Bay & Bay presents both a facial and factual attack on the Court‘s subject matter jurisdiction by asserting a deficiency in the pleadings and by presenting a declaration that provides evidence of Perry‘s employment application, its credit monitoring services, and
the data breach letter sent to Perry. Since these documents are necessarily embraced, as the contents of these documents are alleged in the Complaint and are undisputed by the parties, the Court may consider them.
To bring a claim in federal court, a plaintiff must have Article III standing. See Lujan v. Defenders of Wildlife, 504 U.S. 555, 559 (1992). This means that there must be an actual controversy between the parties. See Genesis Healthcare Corp. v. Symczyk, 569 U.S. 66, 71 (2013). To have Article III standing, the plaintiff “must havе (1) suffered an injury in fact, (2) that is fairly traceable to the challenged conduct of the defendant, and (3) that is likely to be redressed by a favorable judicial decision.” Spokeo, Inc. v. Robins, 578 U.S. 330, 338 (2016). When a defendant makes a facial attack on the plaintiff‘s Article III standing under
Bay & Bay‘s main arguments attacking Perry‘s Article III standing center on the requirements of injury in fact and traceability. To establish injury in fact, a plaintiff must show that he suffered an injury “that is ‘concrete and particularizеd’ and ‘actual or imminent, not conjectural or hypothetical.‘” Spokeo, 578 U.S. at 339 (quoting Lujan, 504 U.S. at 560). For an injury to be “particularized,” it “must affect the plaintiff in a personal and individual way.” Id. A future injury may constitute an injury in fact, but only if the plaintiff demonstrates that “the threatened injury is certainly impending, or there is a substantial risk that the harm will occur.” In re SuperValu, Inc., 870 F.3d 763, 769 (8th Cir. 2017) (internal quotations omitted).
1. Standing for Injunctive and Equitable Relief
Here, Perry seeks injunctive and equitable relief to require Bay & Bay to make improvements to its data security systems, to provide future annual audits, and to provide adequate credit monitoring services funded by Bay & Bay. To establish standing for this forward-looking relief, Perry must allege a “sufficiently imminent and substantial” risk of harm that would be avoided if the sоught-after relief was
An increased risk of identity theft is more likely to constitute an injury in fact where there is evidence that a third party has accessed PI and/or already fraudulently used the data. See Attias v. Carefirst, Inc., 865 F.3d 620, 628 (D.C. Cir. 2017) (“Here . . . an unauthorized party has already accessed personally identifying data on CareFirst‘s servers, and it is much less speculative—at the very least, it is plausible—to infer that this party has both the intent and the ability to use that data for ill.“); In re Horizon Healthcare Services Inc. Data Breach Litigation, 846 F.3d 625, 639 n.19 (3d Cir. 2017) (explaining, in dicta, that in accordance with the Seventh Circuit‘s decision in Remijas, a material risk of harm to all plaintiffs existed becаuse one plaintiff alleged that he had already been a victim of identity theft as a result of the breach). Perry alleges just that in this case, by alleging fraud or misuse of his PI through the publishing of such information on the dark web and through an alleged bank scam where cyberthieves used his PI disclosed in Bay & Bay‘s data breach to contact him and impersonate his bank and scam him out of $500. As such, Perry sufficiently alleges that his PI was misused, and such misuse strengthens the plausibility of a substantial risk of identity theft.
Bay & Bay points to SuperValu I to assert that “allegations that criminals are buying and selling information, and that data breaches facilitate identity theft are not sufficient to establish that the risk of plaintiffs suffering future identify theft is substantial.” (Def. Mem. Supp. Mot. Dismiss at 8, Apr. 28, 2022, Docket No. 12.) In that case, the Eighth Circuit found that plaintiffs failed to factually support their bare allegation that data breaches facilitate identity theft, having rested their claim solely on a 2007 GAO report.6 SuperValu I, 870 F.3d at 770. Bay & Bay likens SuperValu I to the instant case, asserting that Perry‘s allegation that data breaches create a substantial risk of identity theft is factually bare and only grounded in the GAO report, a general recounting of the types of fraud that could occur.
Supervalu I is, however, distinguishable. Importantly, the GAO report that plaintiffs relied on in SuperValu I concluded that compromised credit or debit card information, like the card information in that case, generally could not be used alone to
open unauthorized new accounts. SuperValu I, 870 F.3d at 770–71. As such, pursuant to the factual evidence relied on in the complaint, there was little to no risk that anyone would use the card information stolen to open unauthorized accounts in the plaintiffs’ names. Id. The court concluded that because the report found that data breaches are unlikely to result in account fraud, it does not support the allegation that defendants’ data breaches created a substantial risk that plaintiffs will suffer credit or debit card fraud. Id. at 771. Contrary to Bay & Bay‘s contention, here the compromised PI included information such as social security numbers, which could ostensibly result in opening unauthorized accounts. Because the SuperValu Court indicated that the type of information stolen can be important in determining standing in a data breach case, see id. at 770, it is significant that the information here could be and has allegedly already been used to perpetuate fraud. In such instance, Perry has alleged that he has already experienced harm from the data breach by way of the bank scam
In sum, Perry has demonstrated standing for his injunctive and equitable relief claims, thus Bay & Bay‘s motion to dismiss as to these claims must be denied.
2. Standing for Monetary Relief
Perry also seeks various monetary damages flowing from Bay & Bay‘s conduct. As the Spokeo Court explained, certain harms readily qualify as concrete injuries under Article III. The most obvious are traditional tangible harms, such as physical harms and monetary harms. See Spokeo, 578 U. S. at 340–341. If a defendant has caused physical or monetary injury to the plaintiff, the plaintiff has suffered a concrete injury in fact under Article III. TransUnion, 141 S. Ct. at 2204.
Bay & Bay contends that Perry‘s allegations of harm are conclusory and speculative and do not establish an impending threat of injury, especially considering that Bay & Bay has offered complimentary credit monitoring services for up to twelve months which fully redresses Perry‘s alleged injuries.7
Perry has sufficiently alleged сoncrete injuries stemming from the data breach which is allegedly the result of Bay & Bay‘s failure to protect his PI to avoid dismissal. First, Perry alleges that his PI has been disclosed to cybercriminals, such injury having a “close relationship” to a harm “traditionally recognized as providing a basis for lawsuits in American courts.” TransUnion, 141 S.Ct. at 2204 (establishing that traditional harms recognized as providing a basis for Article III standing include “reputational harms, disclosure of private information, and intrusion upon seclusion.“). Next, Perry has alleged and described how his PI has already been misused, having been published on the dark
web and used for the bank scam. Lastly, Perry alleges that he and Class Members have spent time monitoring the effects of the data breach, which qualifies as a concrete injury because he alleges a substantial and imminent risk of identity theft based on the misuse that has already occurred.8
Further, Perry has generally established that his injuries are fairly traceable to Bay & Bay‘s conduct. Perry has alleged at least one monetary harm: a $500 bank scam that resulted after cyberthieves
Bay & Bay failed to secure customer and prospective employees’ Private Information on their network, their network was subsequently hacked, Private Information was stolen by the hackers, and Perry became the victim of a bank scam after the data breaches. At this stage of the litigation, “we presum[e] that [these] general allegations embrace those specific facts that are necessary to support” a link between Perry‘s fraudulent charge and the data breaches. SuperValu, 870 F.3d at 772 (quoting
Bennett v. Spear, 520 U.S. 154, 168 (1997) (first alteration in the original) (quoting Lujan, 504 U.S. at 561)). Bay & Bay‘s argument that Perry did not provide his bank information is of no moment for establishing standing; Perry provided certain information to Bay & Bay that was stolen and thereafter misused. Therefore, Perry pleads an injury in fact that is fairly traceable to Bay & Bay‘s conduct, the alleged lack of adequate safeguards to protect his PI. Thus, the Court concludes that Perry has met his burden, “which is relatively modest at this stage of the litigation,” of alleging that bank scam is fairly traceable to Bay & Bay‘s data breach. SuperValu I, 870 F.3d at 772 (internal citation and quotation omitted). The Court will deny Bay & Bay‘s motion to dismiss for lack of standing.
II. RULE 12(B)(6) FAILURE TO STATE A CLAIM
A. Standard of Review
In the alternative, Bay & Bay moves to dismiss the complaint pursuant to
“A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. “Where a complaint pleads facts that are merely consistent with a defendant‘s liability, it stops short of thе line between possibility and plausibility,” and therefore must be dismissed. Id. (internal quotation marks omitted). Finally,
B. FTCA Section 5
Perry‘s negligence per se claim is grounded in Bay & Bay‘s alleged violation of Section 5 of the FTCA, which prohibits engaging in “unfair methods of competition” and “unfair or deceptive acts or practices” in or affecting commerce.
Contrary to Bay & Bay‘s contentions, the term “unfair or deceptive acts or practices” is not too vague to establish a fixed standard of care—the term encompasses acts or practices that cause or are likely to cause reasonably foreseeable injury within the United States or involve material conduct.
In fact, the FTCA has indicated that certain cybersecurity practices are “unfair” under the statute. See Consumer Data Protectiоn: Hearing Before the Subcomm. on Com., Mfg. & Trade of the H. Comm. on Energy & Com., 2011 WL 2358081 at *6 (June 15, 2011) (statement of Edith Ramirez, Comm‘r, FTC) (“[T]he Commission enforces the FTC Act‘s proscription against unfair or deceptive acts or practices in cases where a business [‘s] failure to employ reasonable security measures causes or is likely to cause substantial consumer injury.“); Data Theft Issues: Hearing Before the Subcomm. on Com., Mfg. & Trade of the H. Comm. on Energy & Com., 2011 WL 1971214 at *7 (May 4,
2011) (statement of David C. Vladeck, Director, FTC Bureau of Consumer Prot.) (same). Thus, Section 5 of the FTCA is not too amorphous and vague to establish a fixed standard of care.
Next, Bay & Bay argues that even if the FTCA did establish a fixed standard of care, Minnesota law does not recognize a negligence per se claim based on a civil statute that does not provide a private right of action. Bay & Bay‘s argument is unavailing.
Certainly, not all penal statutes establish a tort duty of care under all circumstances. Kronzer v. First Nat. Bank of Minneapolis, 235 N.W.2d 187, 193 (1975). In Minnesota, a violation of a statute or regulation gives rise to negligence per se if (1) the person harmed by that violation is among those the legislature sought to protect and (2) the harm suffered is of the type the statute or regulation was intended to prevent. Anderson v. State, Dep‘t of Nat. Res., 693 N.W.2d 181, 189–90 (Minn. 2005); Alderman‘s Inc. v. Shanks, 536 N.W.2d 4, 8 (Minn. 1995). If these standards are met, then the statute or regulation “imposes a fixed duty of care, so its breach constitutes conclusive еvidence of negligence.” Alderman‘s, 536 N.W.2d at 8 (quoting Pacific Indem. Co. v. Thompson-Yaeger, Inc., 260 N.W.2d 548, 558–59 (Minn. 1977). As such, Minnesota law permits negligence per se
Here, Perry‘s allegations that Bay & Bay was negligent in not protecting PI could reasonably fall under the harm contemplated by the statute and the class of persons the statute intended to protect. A company‘s failure tо protect PI—which may constitute an unfair act under the FTCA—plausibly is the type of injury the FTCA was designed to prevent. In fact, the Federal Trade Commission has previously used this authority to bring a number of enforcement actions against companies that have purportedly failed to protect consumer financial data against hackers. See FTC v. Wyndham Worldwide Corp., 799 F.3d 236, 240 (3d Cir. 2015). In other words, Bay & Bay‘s alleged failure to adequately protect PI and the resulting disclosure may very well constitute the type of harm intended to be protected by FTCA.
Bay & Bay cites SuperValu II and notes that the Eighth Circuit made clear that allowing a negligence per se claim based on Section 5 of the FTCA “would be inconsistent with Congress‘s anticipated enforcement scheme.” In re SuperValu (”SuperValu II“), 925 F.3d 955, 964 (8th Cir. 2019). However, the SuperValu II court was applying Illinois law and explicitly noted that whether a defendant has a legal duty is “a question of state law.” SuperValu II, 925 F.3d at 963-64. In this lens, the Court analyzed Illinois negligence requirements and found several of those conditions “absent” in the facts of that case, concluding that “Illinois is unlikely to recognize a legal duty enforceable through a negligence action arising from the FTCA.” Id. at 964. Thus, contrary to Bay & Bay‘s proposition, the Eighth Circuit in SuperValu II did not have the occasion to consider whether a negligence per se claim based on Section 5 is colorable under Minnesota law.
As of now, Perry has sufficiently alleged that Bay & Bay‘s violation of Section 5 constitutes negligеnce per se under Minnesota law. Because the Court so concludes, Bay & Bay‘s motion to dismiss in this respect is denied.
C. Negligence & Negligence Per Se
Bay & Bay contends that as to Perry‘s negligence and negligence per se claims, he fails to allege sufficient facts to support the element of damages and similarly fails to plead facts to establish causation. To state a valid cause of action for negligence under Minnesota law, a plaintiff must demonstrate “(1) the existence of a duty of care, (2) a breach of that duty, (3) an injury, and (4) that the breach of the duty of care was a proximate cause of the injury.” Domagala v. Rolland, 805 N.W.2d 14, 22 (Minn. 2011) (citing Funchess v. Cecil Newman Corp., 632 N.W.2d 666, 672 (Minn. 2001)); Lubbers v. Anderson, 539 N.W.2d 398, 401 (Minn. 1995).
Although negligence per se may be pleaded separately from negligence, the two causes of action are inseparably intertwined. Anderson, 693 N.W.2d at 189. While the standard for ordinary negligence is “the traditional standard of the reasonable man of ordinary prudence, negligence per se may exist when the reasonable person standard is supplanted by a standard of care established by the legislature.” Seim v. Garavalia, 306 N.W.2d 806, 810 (Minn. 1981) (internal quotations omitted).
Here, Perry has sufficiently pleaded injury and causation. Perry alleges that he and class members suffered some loss: compromised PI published on the dark web, lost time and resources mitigating the effects of the data breach and in at least one instance, misuse of PI materialized when cyberthieves used Perry‘s PI to contact him and commit the bank scam. This constitutes a cognizable injury.
Further, the Court construes all inferences at this stage in favor of the plaintiff. As such, Perry has plausibly alleged that Perry‘s sensitive PI would not have been disclosеd to cyberthieves had Bay & Bay‘s not failed to establish adequate data-security systems. Therefore, Perry has sufficiently alleged that Bay & Bay‘s alleged negligent conduct was the proximate cause of Perry‘s monetary loss because the cyberthieves used information from the breach to commit the bank scam.
It is true that Perry will need to later prove that Bay & Bay‘s alleged negligence is the proximate cause of his injury. In Minnesota, “a party‘s negligence is the proximate cause of an injury, if the act is one which the party ought, in the exercise of ordinary care, to have anticipated was likely to result in injury to others and the defendant‘s conduct was a substantiаl factor in bringing about the injury.” McDougall v. CRC Indus., Inc., 523 F. Supp. 3d 1061, 1072 (D. Minn. 2021) (quoting Lubbers v. Anderson, 539 N.W.2d 398, 401 (Minn. 1995)) (internal quotations omitted). Here, reasonable minds can arrive at multiple conclusions. First, there are arguably many alternative causes of the injury. For example, bank scams such as the one Perry fell victim to may happen in the ordinary course of life, even without data breaches. Information such as one‘s name, phone number, or even birthdate is readily accessible without an individual‘s information having been compromised by an entity that possesses it. Second, Perry does not state when the bank scam occurred. If the bank scam happened prior to the data breach, therе is no causation. See In re SuperValu, Inc., Customer Data Sec. Breach Litig., No. 14-MD-2586, 2018 WL 1189327, at *13 (D. Minn. Mar. 7, 2018), aff‘d sub nom. In re SuperValu, Inc., 925 F.3d 955 (8th Cir. 2019).
However, Perry has nevertheless sufficiently pleaded his claim to survive this Motion to Dismiss. Whether he can, in fact, prove that the Bay & Bay‘s conduct was the proximate cause is an issue to be resolved at a later stage, in which discovery will play a key role in developing this issue.
Ultimately, the Court concludes that Perry‘s negligence and negligence per se claims establish causation and damages. Bay & Bay‘s motion to dismiss for failure to state a claim upon which relief can be granted as to these claims is thus denied.
D. Implied Contract
Finally, Bay & Bay asserts that Perry does not allege any facts to establish that
Under Minnesota law, a breach of contract claim has four elements: “(1) formation of a contract; (2) performance by plaintiff of any conditions precedent; (3) a material breach of the contract by defendant; and (4) damages.” Gen. Mills Operations, LLC v. Five Star Custom Foods, Ltd., 703 F.3d 1104, 1107 (8th Cir. 2013). Under the common law of Minnesota, contracts of any sort can be implied in fact and can be oral or written. See McArdle v. Williams, 258 N.W. 818, 820–21 (Minn. 1935) (noting that contracts may be written, oral, implied from the actions of the parties, or some combination thereof). Equally uncontroversial in the law of contrаcts is that the formation of an implied contract is evaluated objectively. Holman Erection Co. v. Orville E. Madsen & Sons, 330 N.W.2d 693, 695 (Minn. 1983)). In other words, an intent to be contractually bound is determined by the objective manifestations of the parties’ words, conduct, and documents, and not by their subjective intent. See id.
While it is a close call, Perry sufficiently alleges factual circumstances to meet contractual elements of formation, performance of conditions precedent, breach, and damages, however slight. Perry was a prospective employee who was required to provide certain Private Information to Bay & Bay to be considered for employment. The contractual offer is the exchange of PI (Perry) for employment consideration (Bay & Bay). Upon Perry applying and providing this information, and Bay & Bay accepting and considering him for employment, the parties mutually assented to an implied contract.
Bay & Bay provided consideration by promising to consider Perry for employment, while Perry provided consideration by providing valuable property, his PI. By mandating this exchange of information, it is plausible that Bay & Bay made an implied promise to keep the PI secure. Bay & Bay breached this implied contract when it failed to keep this promise and a data breach occurred. Lastly, Perry can arguably establish damages because he allegedly suffered injuries that included loss of the benefit of the bargain, monetary loss, and diminution of value of the PI.
At this stage, Perry has alleged enough to move forward with his breach of implied contract claim and thus the Court will deny Bay & Bay‘s motion in this respect.
CONCLUSION
Because Perry has Article III standing and has alleged sufficient facts at this stage to support the negligence elements of damages and causation and that Bay & Bay entered into an implied contract, Bay & Bay‘s motion to dismiss is denied.
ORDER
Based on the foregoing, and all the files, records, and proceedings herein, IT IS HEREBY ORDERED that Defendant
DATED: January 12, 2023 at Minneapolis, Minnesota.
JOHN R. TUNHEIM
United States District Judge