Smallman v. MGM Resorts InternationalSmallman v. MGM Resorts International
Case Information
UNITED STATES DISTRICT COURT DISTRICT OF NEVADA
SMALLMAN et al ., )
) Plaintiffs, ) Case No.: 2:20-cv-00376-GMN-EJY
vs. ) ) ORDER MGM Resorts International, )
)
Defendant. )
)
Pending before the Court is Defendant MGM Resorts International’s (“Defendant MGM’s”) Motion to Dismiss, (ECF No. 103). Plaintiffs Ryan Bohlim, Duke Hwynn, Andrew Sedaghatpour, Gennady Simkin, Robert Taylor, Michael Fossett, Victor Wukovits, Kerri Shapiro, Julie Mutsko, John Dvorak, Larry Lawter, individually and on behalf of those similarly situated (collectively “Plaintiffs”) filed a Response, (ECF No. 109), and Defendant MGM filed a Reply, (ECF No. 117).
For the reasons discussed below, the Court GRANTS in part and DENIES in part Defendant MGM’s Motion to Dismiss.
I. BACKGROUND
This case arises from a July 7, 2019, data breach of Defendant MGM’s network in which hackers download the personally identifiable information (“PII”) of Defendant MGM guests worldwide (“Data Breach”). (Consolidated Class Action Complaint (“CAC”) ¶¶ 1, 29, ECF No. 101). Plaintiffs are a consolidated class action of consumers whose PII was stolen in the Data Breach. ( Id .). Specifically, hackers accessed Plaintiffs name, address, phone number, email address, and dates of birth ( Id . ¶¶ 2, 29). Furthermore, certain Plaintiffs also had their driver’s license number, passports number, and military identification number stolen. ( .). Plaintiffs allege that the stolen PII has been posted on the dark web for purchase on at least three separate occasions. ( Id . ¶ 46). Cybersecurity journalists have observed that the PII of at least 10.6 million MGM guests are available on a dark web hacking forum. ( Id ¶ 34). In a letter to the North Dakota Attorney General on September 7, 2019, Defendant MGM noted that the hacker “posted the data on a closed internet forum with the intent to sell the information for financial gain.” ( Id . ¶ 32). Plaintiffs posit that they now face a long-term heightened risk that their PII will be sold or disseminated on the dark web. ( Id . 47–65).
Defendant MGM has not disclosed how the hackers were able to obtain consumers PII. ( Id . ¶ 37). However, a Defendant MGM spokesperson revealed that the Data Breach may have been caused by “unauthorized access to a cloud server.” [1] ( Id .) Further, Defendant MGM disclosed to the North Dakota Attorney General that the hackers “exfiltrated data by exploiting a compromised account.” ( Id . ¶ 38). Despite the Data Breach occurring on July 7, 2019, Defendant MGM did not notify affected consumers until nearly two months later, on September 7, 2019. ( Id . ¶ 44). Plaintiffs allege that Defendant MGM’s delayed response exacerbated the risk of harm to Plaintiffs. ( Id . ¶ 45).
Plaintiffs contend that Defendant MGM failed to implement reasonable data security measures to protect their PII, maintain and monitor its server against intrusions, and retained Plaintiffs PII for longer than necessary. ( Id . ¶¶ 7, 77, 90–91). Additionally, Plaintiffs allege that Defendant MGM failed to encrypt the PII stored on its server. ( Id . ¶ 38). Furthermore, Plaintiffs allege that Defendant MGM failed to adopt reasonable safety measures despite knowing that the hotel industry is frequently targeted by cyber security attacks. ( Id . ¶ 77–88).
Following the Data Breach, all Plaintiffs have experienced an increase in spam and phishing phone calls, text messages, and emails. ( . ¶¶ 10–20). Similarly, all Plaintiffs allege that they have spent a greater amount of time monitoring their financial and other accounts. ( Id .). Additionally, all Plaintiffs contend that their PII is available on the dark web, and that they have been forced to expend a significant amount of time and energy resetting passwords and taking additional steps to protect their PII. ( Id .). Plaintiffs posit that the value of their PII has diminished due to its dissemination. ( Id . ¶¶ 5, 100). Plaintiffs further contend they have suffered “benefit of the bargain” damages because they paid MGM for services that were “intended to be accompanied by adequate data security[] but were not.” ( Id . ¶ 5, 111–12).
In addition to the alleged injuries set forth above, several Plaintiffs have asserted additional harms. Specifically, multiple Plaintiffs contend that criminals have attempted to make fraudulent purchases on their accounts. ( Id . ¶¶ 13–14, 16). Other Plaintiffs assert that criminals have perpetrated ransom attacks against them or attempted to sign into their personal accounts. ( Id . ¶ 11, 16, 19). Several Plaintiffs have taken the additional step of purchasing security services to protect their PII. ( . ¶¶ 12, 16, 20).
On April 4, 2021, Plaintiffs filed the present Consolidated Class Action Complaint asserting claims for: (1) negligence; (2) negligent misrepresentation; (3) breach of implied contract; (4) unjust enrichment; (5) violation of the Nevada Consumer Fraud Act, NRS § 41.600; (6) violation of the California Unfair Competition Law, Cal. Bus. & Prof. Code §§ 17200, et seq. ; (7) violation of the California Consumers Legal Remedies Act, Cal. Civ. Code §§ 1750, et seq. ; (8) violation of the California Customer Records Act, Cal. Civ. Code §§ 1798.80, et seq. ; (9) violation of the Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. § 42-110a, et seq .; (10) violation of the Georgia Deceptive Trade Practices Act, Ga. Code. Ann. §§ 10-1-370, et seq. ; (11) violation of New York General Business Law, N.Y. Gen. Bus. Law § 349; (12) violation of the Ohio Deceptive Trade Practices Act, Ohio Rev. Code §§ 4165.01, et seq .; (13) violation of the Oregon Unlawful Trade Practices Act, Or. Stat. §§ 646.605, et seq .; and (14) violation of the Oregon Consumer Information Protection Act, Or. Stat. §§ 646A.600, et seq . ( . ¶¶ 143–340). On June 1, 2021, Defendant MGM filed the present Motion to Dismiss. ( See generally MTD, ECF No. 103).
II. LEGAL STANDARD
Dismissal is appropriate under Rule 12(b)(6) where a pleader fails to state a claim upon
which relief can be granted. Fed. R. Civ. P. 12(b)(6);
Bell Atl. Corp. v. Twombly
,
“Generally, a district court may not consider any material beyond the pleadings in ruling
on a Rule 12(b)(6) motion.”
Hal Roach Studios, Inc. v. Richard Feiner & Co.
,
If the court grants a motion to dismiss for failure to state a claim, leave to amend should
be granted unless it is clear that the deficiencies of the complaint cannot be cured by
amendment.
DeSoto v. Yellow Freight Sys., Inc
.,
III. DISCUSSION
Defendant MGM moves to dismiss all of Plaintiffs’ common law [2] and statutory claims. The Court will first examine Plaintiffs negligence claim.
A. NEGLIGENCE
Defendant MGM argues that Plaintiffs negligence claim cannot survive the economic loss doctrine. (MTD 28:23–24). Alternatively, Defendant MGM contends that Plaintiffs have failed to allege that Defendant MGM breached a legal duty or suffered cognizable damages. ( Id . 29:10–17). In rebuttal, Plaintiffs assert that their negligence claim survives the economic loss doctrine because they allege both economic and non-economic losses. (Resp. 27:8–29:16, ECF No. 109). Additionally, Plaintiffs argue that they sufficiently alleged Defendant MGM’s deviation from industry standard data security procedure. ( . 30:16–19). The Court will first examine whether Plaintiffs negligence claim is barred by the economic loss doctrine. ///
///
///
1. Economic Loss Doctrine
Here, Plaintiffs assert the economic loss doctrine does not apply because they allege non-economic harms in the form diminished value to their PII and intangible damage to their privacy caused by the Data Breach. (Resp. 27:18–27).
The Nevada Supreme Court has “applied the economic loss doctrine in product liability
cases, as well as in negligence cases unrelated to product liability.”
Giles v. Gen. Motors
Acceptance Corp.
,
In the data breach context, courts within the Ninth Circuit have found that an
individual’s loss of control over the use of their identity due to a data breach and the
accompanying impairment in value of PII constitutes non-economic harms.
See Flores-Mendez
v. Zoosk, Inc.
, No. 20-04929,
2. Breach of Duty Defendant MGM also argues that Plaintiffs failed to allege that Defendant MGM breached their owed duty of care. (MTD 29:10–17). In response, Plaintiffs contend that have alleged specific deficient security practices employed by Defendant MGM that led to the breach. (Resp. 29:27–30:22).
Under Nevada law, “[t]o prevail on a negligence claim, a plaintiff must establish four
elements: (1) the existence of a duty of care, (2) breach of that duty, (3) legal causation, and (4)
damages.”
Sanchez ex rel. Sanchez v. Wal-Mart Stores, Inc.
,
3. Cognizable Harm Defendant MGM further argues that Plaintiffs failed to allege a cognizable harm. (MTD 29:10–17). In rebuttal, Plaintiffs argue they alleged cognizable damages in the form of: (1) diminished value of their PII; (2) benefit of the bargain damages; (3) increased risk of identity theft and fraud; (4) and lost time and expenditures mitigating the effects of the Data Breach. (Resp. 13:21–23). The Court will first examine whether Plaintiffs’ diminished value of PII constitutes a cognizable harm.
a. Benefit of the Bargain Damages Defendant MGM contends that Plaintiffs benefit of the bargain theory fails as a matter of law because Defendant MGM did not affirmatively represent that adequate data security was included in the cost of hotel rooms. (MTD 25:3– 10); (Reply 9:15–25, ECF No. 117). In rebuttal, Plaintiffs contend that at the motion to dismiss stage, they are not required to specifically allege what portion of their hotel payments were designated for data security. (Resp. 19:27– 20:7). Instead, Plaintiffs posit that it is sufficient for them to generally allege that part of the price they paid to Defendant MGM was intended to provide adequate data security, and that had they known Defendant MMG utilized deficient data security practices, they would have paid less for their rooms. ( . 18:25–19:26).
In data breach cases, courts are divided on the level of detailed factual allegation
required to show that data security was part of the bargain. Many district courts within this
Circuit have accepted more general allegations that data security was expected and was part of
the bargain.
See In re Yahoo! Inc. Customer Data Sec. Breach Litig.
,
Defendant MGM relies upon a line of cases which required more specific factual
allegations showing how data security was a part of the bargain or how much of the money
spent was for data security.
See Ables v. Brooks Bros. Grp.
, No. 17-4309,
Here, Plaintiffs pled that they “overpaid for hotel services that should have been—but were not—accompanied by reasonable data security.” (CAC ¶ 111). Plaintiffs contend that “part of the price consumers paid to [Defendant] MGM was intended to be used to provide adequate data security . . . .” ( Id . ¶ 113). Plaintiffs further allege that had Defendant MGM disclosed its deficient security policies, they would either have paid less for the room, or not purchased a room from Defendant MGM. ( . ¶¶ 10–20, 114, 118(b)). The Court finds that at this stage of the proceeding, Plaintiffs have sufficiently alleged benefit of the bargain damages.
b. Diminished Value of PII Defendant MGM contends that diminution in value of PII does not constitute a compensable harm. (MTD 11:3–6). Alternatively, Defendant MGM argues that Plaintiffs have not alleged that they have been impaired from selling their own PII. (Reply 9:3–10). In rebuttal, Plaintiffs allege that diminution in value of PII is a viable theory of damages, and that the Data Breach diminished the value of Plaintiffs PII. (Resp. 61:16–62:18).
“Diminution in value of personal information can be a viable theory of damages.”
Pruchnicki v. Envision Healthcare Corp.
,
Here, Plaintiffs sufficiently allege details about the existence of an economic market for
selling stolen PII, including the fact that PII can be bought and sold at identifiable prices on
established markets. (CAC ¶¶ 101–104). Moreover, Plaintiffs have shown that a market exists
for their PII because their information has already been posted for sale on “multiple dark web
sites.” ( . ¶¶ 47, 104). The “value of consumer [PII] is not derived solely (or even
realistically) by its worth in some imagined marketplace where the consumer actually seeks to
sell it to the highest bidder, but rather in the economic benefit the consumer derives from being
able to purchase goods and services remotely and without the need to pay in cash or a check.”
In re Marriott Int’l, Inc., Customer Data Sec. Breach Litig.
,
c. Increased Risk of Identity Theft and Fraud Defendant MGM contends that the dissemination of the PII at issue is not the type of particularly sensitive personal information that creates a credible threat of fraud or identity theft. (MTD 27:20–28:7). In rebuttal, Plaintiffs argue that an imminent risk of harm is evidenced by the fact that their PII has already been posted on the dark web for sale on several occasions. (Resp. 20:9–22:14).
The Court finds that the rightful determination is “not to look at the minutia of what
information has been taken — such as credit card information — or social security numbers —
but to specifically determine whether the data taken ‘gave hackers the means to commit fraud
or identity theft.’”
Bass v. Facebook, Inc
.,
Here, Plaintiffs have alleged that their PII has already been posted for sale on the dark
web. (
Id
. ¶ 46). Moreover, multiple Plaintiffs contend that criminals have attempted to make
fraudulent purchases on their accounts. (
Id
. ¶¶ 13–14, 16). Other Plaintiffs assert that criminals
have perpetrated ransom attacks against them or attempted to sign into their personal accounts.
( . ¶ 11, 16, 19). It is difficult to reconcile Defendant MGM’s argument that the PII at issue
does not provide hackers with the ability to commit fraud or identity theft when the PII has
already been posted for sale or used in attempt identity theft attacks. Instead, the Court finds it
is evident that the PII stolen here will “provide further ammo” for hackers to commit identity
fraud or threat in the future.
Bass
,
Furthermore, as the United States Court of Appeals for the Seventh Circuit
acknowledged, “[w]hy else would hackers break into a store's database and steal consumers'
private information? Presumably, the purpose of the hack is, sooner or later, to make
fraudulent charges or assume those consumers’ identities.”
Remijas v. Neiman Marcus Grp.,
LLC
,
d. Lost Time & Expenditures Defendant MGM contend that Plaintiffs lost time monitoring their accounts does not constitute cognizable damages. (MTD 27:7–10). Moreover, Defendant MGM posits that the Plaintiffs who did purchase identity protection services cannot allege damages because these prophylactic measures were not reasonable and necessary. (MTD 26:9–27:6). In response, Plaintiffs argue that lost time and out-of-pocket expenses both constitute viable theory of damages. (Resp. 22:16–23:22).
In
Pruchnicki v. Envision Healthcare Corp.
, this Court held that “tangible, out-of-pocket
expenses are required in order for lost time spent monitoring credit to be cognizable as
damages.”
Here, all Plaintiffs assert they have all lost time monitoring their personal accounts and
sifting through phishing messages. (CAC. ¶¶ 10–20). Lost time alone does not establish
compensable damages.
See Pruchnicki
, 845 Fed. App’x at 614;
Stasi
,
B. NEGLIGENT MISREPRESENTATION
Defendant MGM contends that Plaintiffs’ negligent misrepresentation claim is barred by
the economic loss doctrine because there is no “special relationship” between Defendant MGM
and Plaintiffs. (MTD 30:2–18). Defendant MGM further argues that Plaintiffs’ claim fails
because a cognizable negligent misrepresentation claim under Nevada law requires an
affirmative false statement, whereas Defendant MGM is guilty, at most, of an omission. (
Id
.
30:19–30:28). In rebuttal, Plaintiffs argue that a fiduciary-like relationship existed between
Defendant MGM and Plaintiffs because Plaintiffs entrusted Defendant MGM with their
confidential PII. (Resp. 31:3–31:21). Additionally, Plaintiffs argue that contrary to Defendant
MGM’s assertion, an omission can constitute negligent misrepresentation under Nevada law.
( . 31:22–32:18). However, before an omission can constitute negligent misrepresentation, a
special relationship must exist between the parties such that the defendant had a duty to speak.
See Copper Sands Homeowners Ass’n v. Copper Sands Realty, LLC
, No. 2:10-cv-00510, 2012
WL 934294, at *4 (D. Nev. Mar. 20, 2012) (“Nevada also recognizes negligent
misrepresentation by nondisclosure when the defendant had a duty to speak. However, such a
duty generally only exists when there is a special relationship between the parties.”) (citing
In
re Agribiotech, Inc.
,
a. Special Relationship
“The Nevada Supreme Court has held that a special relationship may exist where ‘one
party interposes confidence in the other because of that person’s position and the other party
knows of this confidence.’”
Bond Mfg. Co., Inc. v. Ashley Furniture Indus., Inc.
, No. 2:17-cv-
1522,
Here, “[Defendant MGM] collected names, addresses, phone numbers, email addresses,
dates of birth, and for some class members their driver’s license numbers, passport numbers, or
military ID numbers[.]” (Resp. 31:11–21). The Court recognizes that the transmittal of the PII
at issue is not typical of many standard ordinary daily transactions. However, the Court
declines to conclude that the transmittal of PII alone necessarily transforms an arms-length
business relationship into a special or fiduciary-like relationship.
See In re Ambry Genetics
Data Breach Litig.
,
Compared to the categories of special relationships approved by the Nevada Supreme
Court, the nature of the relationship here is not what has historically been considered special in
character.
See Peri & Sons Farms, Inc.
,
C. BREACH OF IMPLIED CONTRACT
Defendant MGM asserts that Plaintiffs’ claim for breach of implied contract fails because Plaintiffs “cannot plead the nature and scope of any implied contract.” (MTD 31:10– 11). Specifically, Defendant MGM argues that Plaintiffs’ conclusory allegations that Defendant MGM agreed to protect Plaintiffs PII when they purchased a hotel room neither constitutes the formation of an implied contract, nor shows it was breached if one is found. ( Id . 31:12–32:15). In rebuttal, Plaintiffs contend that the formation of an implied contract is a question of fact that the Court should decline to address on a Rule 12(b)(6) motion. (Resp. 32:20–33:2). Alternatively, Plaintiffs posit that the parties entered into an implied contract during the “reservation and/or hotel check-in process” when Plaintiffs provided Defendant MGM with their PII and Defendant MGM impliedly promised to protect that information. ( . 33:4–35:20).
Nevada law requires the plaintiff in a breach of contract action to show: (1) the existence
of a valid contract; (2) a breach by the defendant; and (3) damage as a result of the breach.
Mizrahi v. Wells Fargo Home Mortg.
,
The Court finds that Plaintiffs have adequately stated a claim for breach of implied
contract. Specifically, Plaintiffs allege that they “were required to” provide their PII to
Defendant MGM as a condition of staying at its hotels. (CAC ¶¶ 8, 93). Thus, Plaintiffs
provided their PII to Defendant MGM for lodging, with the understanding that Defendant
MGM, while it held the information, would take adequate measures to protect it. ( . ¶¶ 185 –
86). In terms of consideration, it is undisputed that Plaintiffs paid for their hotel rooms. These
alleged actions plausibly demonstrate that Plaintiffs manifested their assent to Defendant
MGM’s privacy statements.
See In re Marriot
,
D. UNJUST ENRICHMENT
Defendant MGM argues that Plaintiffs’ unjust enrichment claim fails for two reasons. First, Defendant MGM contends that Plaintiffs’ claim is “barred by virtue of Plaintiffs’ inability to plead a lack of legal remedies.” (MTD 32:25). Second, Defendant posits that “Plaintiffs fail to plead facts sufficient to state an unjust enrichment claim.” ( Id. 33:12). In rebuttal, Plaintiffs argue that Defendant MGM has been unjustly enriched because Plaintiffs paid for a hotel room and adequate PII protection. (Resp. 37:16–24). Plaintiffs contend they only received the hotel room. ( .)
In Nevada, the elements of an unjust enrichment claim are: “(1) a benefit conferred on
the defendant by the plaintiff; (2) appreciation of the benefit by the defendant; and (3)
acceptance and retention of the benefit by the defendant; (4) in circumstances where it would
be inequitable to retain the benefit without payment.”
Ames v. Caesars Ent. Corp.
, No. 2:17-cv-
02910,
It is undisputed that unjust enrichment and disgorgement are equitable remedies.
See
Small v. Univ. Med. Ctr. of S. Nevada
, No. 2:13-cv-00298,
Plaintiffs argue that Sonner is inapplicable to the instant action for three reasons. First, Plaintiffs posit that Sonner only applies later in proceedings. (Resp. 36:22–37:12). Second, Plaintiffs contend that the scope of Sonner is limited to claims arising from California’s UCL and CLRA. ( . 36:26–37:5). Lastly, Plaintiffs argue that under Fed. R. Civ. P 8(d)(2), they can plead their unjust enrichment claim in the alternative to their implied contract claim. (Resp. 36:13–21). The Court will first address Plaintiffs argument that Sonner does not apply at the motion to dismiss stage.
The Court agrees with Plaintiffs that the circumstances examined in
Sonner
arose late in
the case on the eve of trial; the Court disagrees, however, that
Sonner’s
language suggests it
reasoning applies only late in a case’s life cycle and not at the pleading stage.
[5]
Indeed, district
court’s relying on
Sonner
have not made this distinction in applying
Sonner
’s reasoning at the
pleading stage.
See Forrett v. Gourmet Nut, Inc.
, No. 22-cv-02405,
Plaintiffs further argue that the Ninth Circuit’s decision in
Sonner
is limited to equitable
restitution under California’s UCL and CLRA and thereby does not apply to Plaintiffs’ unjust
enrichment claim under Nevada law. (Resp. 35:26–36:5). However, the
Sonner
court explicitly
held “that state law cannot circumscribe a federal court’s equitable powers even when state law
affords the rule of decision.”
Sonner
,
Plaintiffs additionally argue that pursuant to Fed. R. Civ. P. 8(d)(2), they may plead their
unjust enrichment claim in the alternative to their legal claims. (Resp. 36:13–21). Specifically,
Plaintiffs contend that their unjust enrichment claim may be brought as an alternative claim to
their claim for breach of implied contract. Under Fed. R. Civ. P. 8(d)(2), “[a] party may set out
reasoning suggested that its holding was limited to cases in which a party had voluntarily dismissed a damages
claim to avoid a jury trial.”
Guzman v. Polaris
,
two or more statements of a claim or defense alternatively or hypothetically, either in a single
count or defense or in separate ones. If a party makes alternative statements, the pleading is
sufficient if any one of them is sufficient.” Plaintiffs are correct that under this rule, they may
plead unjust enrichment in the alternative to legal claims. However, “[t]he issue is not whether
a pleading may seek distinct forms of relief in the alternative, but rather whether a prayer for
equitable relief states a claim if the pleading does not demonstrate the inadequacy of a legal
remedy. On that point,
Sonner
holds that it does not.”
Sharma v. Volkswagen AG
, 524 F. Supp.
3d 891, 907 (N.D. Cal. 2021) (citing
Sonner
,
As stated, Defendant MGM argues that Plaintiffs unjust enrichment claim fails because they cannot show a lack of legal remedies. (MTD 32:25–33:11). In rebuttal, Plaintiffs argue they do not have an adequate remedy at law because Defendant MGM “continues to retain [Plaintiffs’] PII while exposing the PII to a risk of future data breaches while in [Defendant] MGM’s possession.” ( . ¶ 203). Plaintiffs further contend that Defendant MGM should not be permitted to retain the monetary benefits it accrued from its transactions with Plaintiffs, and that Defendant MGM should be forced to disgorge any profits it received from Plaintiffs. ( Id. ¶¶ 200, 205). As to the former, the Court recognizes that Defendant MGM’s continued retention of Plaintiffs’ PII poses a risk of prospective harm. The issue, however, is that the remedy ultimately sought by Plaintiffs is money damages. Plaintiffs seek retrospective 1 damages for the past harm derived by Plaintiffs overpayment for hotel rooms and prospective damages for the continued profit Defendant MGM derives from their use of Plaintiffs PII. [6] The Court is unable to conclude that Plaintiffs’ alleged injuries cannot be remedied by money damages when that is the precise remedy requested. (CAC ¶¶ 203–05). Plaintiffs have not alleged, even in the alternative, that they do not have adequate legal remedies. Therefore, Plaintiffs’ unjust enrichment claims are dismissed, with leave to amend.
E. NEVADA CONSUMER FRAUD ACT
Defendant MGM asserts that Plaintiffs’ Nevada Consumer Fraud Act (“NCFA”) claim fails because they have not alleged a cognizable injury caused by the Data Breach. [7] (MTD 34: 24–25). Alternatively, Defendant MGM argues that Plaintiffs failed to plead their claims with sufficient particularity under the heightened standard of Fed. R. Civ. P. 9(b). ( Id . 34:26–35:1). As an initial matter, Plaintiffs argue that the heightened standard of Fed. R. Civ. Pro 9(b) is inapplicable because they only allege negligence-based conduct rather than intentional fraud. (Resp. 37:25–38:10). Even if Rule 9(b) is applicable, however, Plaintiffs assert that their allegations satisfy the heightened pleading standard by describing the “specific data security practices [Defendant] MGM neglected, explains what [Defendant] MGM should have done, describes how [Defendant] MGM knew it was a prime target for hackers, and explains that [Defendant] MGM should have disclosed its deficient practices when it collected Plaintiffs’ information at booking and check-in.” ( . 38:18–25).
“Fraud claims must meet a heightened pleading standard under [Fed. R. Civ. P. 9(b)],
which requires a party to “state with particularity the circumstances constituting fraud.”
Brandstorm
,
NRS § 41.600 provides that “[a]n action may be brought by any person who is a victim of consumer fraud.” Id . “Consumer fraud’ is defined as “a deceptive trade practice as defined in NRS § 598.0915 to 598.025, inclusive.” Id . § (2)(e). A claim under NRS § 41.600 “requires a ‘victim of consumer fraud to prove that (1) an act of consumer fraud by the defendant (2) caused (3) damage to the plaintiff.’” Whittum v. Acceptance Now , No. 2:18-cv-01574, 2019 WL 4781846, at *3 (D. Nev. Sept. 30, 2019) (quoting Sattari v. Wash. Mut ., 475 Fed. App’x 648, 648 (9th Cir. 2011).
NRS § 598.0923(1)(b) in turn provides that, “a person engages in a ‘deceptive trade
practice’ when in the course of his or her business or occupation he or she knowingly . . . [f]ails
to disclose a material fact in connection with the sale or lease of goods or services.” The Court
of Appeals of Nevada has explained that a “knowing[]’ act or omission . . . does not require that
the defendant intend to deceive with the act or omission, or even know of the prohibition
against the act or commission, but simply that the defendant is aware that the facts exist that
constitute the act or omission.”
Poole v. Nevada Auto Dealership Invs., LLC
,
As a preliminary matter, Defendant MGM relies on
Soffer v. Five Mile Capital Partners,
LLC
, for the proposition that fraud by omission requires an affirmative duty to disclose to
constitute a violation of NRS § 598.0923(1)(b). No. 12-cv-1407,
Here, Plaintiffs’ allegations meet the requirements of Fed. R. Civ. P. 9(b). Plaintiffs
allege that Defendant MGM knew its data security practices were deficient and that the hotel
industry is a frequent target of sophisticated cyberattacks, (CAC ¶¶ 78, 208). Despite this
knowledge, Plaintiffs allege that Defendant MGM declined to disclose any facts regarding its
cybersecurity when it sold hotel rooms to Plaintiffs. The Court finds that Defendant MGM’s
data security, or lack thereof, is a material fact connected to the sale of hotel rooms. At this
stage in the pleading, Plaintiffs sufficiently allege that Defendant MGM’s failure to disclose its
data security deficiency or vulnerability to Plaintiffs constitutes a “knowing” omission.
Poole
,
Additionally, Plaintiffs allege that Defendant MGM failed to implement reasonable security measures to protect its servers, including encrypting consumer’s PII, ( Id . ¶¶ 7, 38, 40, 66–77), retained Plaintiffs PII for longer than necessary, ( Id . ¶¶ 90–94), and that Plaintiffs were damaged as a result of the Data Breach. ( Id . ¶¶ 95–125). These damages include loss of the benefit-of-the bargain, money spent mitigating harms, diminished value of PII, and identity theft in the form of unauthorized charges and accounts. [10] ( .). Accordingly, the Court finds that Plaintiffs have adequately pled a claim under NRS §§ 41.600 and 598.0923(b)(1).
Furthermore, pursuant to NRS § 598.0923(1)(c), a person also engages in a “deceptive trade practice” when he or she knowingly “[v]iolates a state or federal statute or regulation relating to the sale or lease of goods or services.” Because Plaintiffs have adequately pled violations of NRS §§ 41.600 and 598.0923(b)(1), the Court declines to dismiss Plaintiffs NCFA claims.
F. CALIFORNIA STATUTORY LAW CLAIMS
Plaintiffs Ryan Bohlim, Duke Hwynn, Andrew Sedaghatpour, and Gennady Simkin (collectively “California Plaintiffs”) seek injunctive relief, in addition to damages, pursuant to their California statutory law claims. (CAC ¶¶ 10–13, 233–34, 250, 266). Because the California Plaintiffs seek injunctive relief, Defendant MGM contends that pursuant to Sonner , the Court should dismiss the California Plaintiffs’ California statutory law claims. [11]
Here, the California Plaintiffs sufficiently plead an inadequate remedy at law with
respect to Defendant MGM’s alleged continuing unlawful conduct. The California Plaintiffs
remedy at law, money damages, is retrospective. An injunction is prospective. While damages
would compensate the California Plaintiffs for past harms, an injunction would ensure that the
California Plaintiffs and other consumers can rely on Defendant MGM’s representations in the
future.
See Brooks v. Thomson Reuters Corp.
, No. 21-cv-01418,
The Court will first examine whether the California Plaintiffs have sufficiently pled a claim under the UCL.
a. Unfair Competition Law
The California UCL prohibits “unfair competition” and defines the term as a “business
act or practice” that is (1) “fraudulent,” (2) “unlawful,” or (3) “unfair.” Bus. & Prof. Code §
17200. Each prong of the UCL provides “a separate and distinct theory of liability[.]”
Kearns
v. Ford Motor Co.
,
///
///
///
/// a. Standing
To establish standing under the UCL, “[a] plaintiff must show he personally lost
money or property because of his own actual and reasonable reliance on the allegedly unlawful
business practice.”
In re iPhone Application Litig
.,
In
In re Anthem,
the court found that the plaintiffs’ allegations that they lost the benefit
of their bargain was sufficient to satisfy the economic injury requirement for standing under the
UCL, explaining that this type of loss “mirrors the California Supreme Court's determination in
Kwikset
that a plaintiff who has ‘surrender[ed] in a transaction more, or acquire[d] in a
transaction less, than he or she otherwise would have’ may bring a UCL claim.” 162 F. Supp.
3d 953, 985 (N.D. Cal. 2016) (quoting
Kwikset
,
Here, the California Plaintiffs’ loss of money or property is in the form of the allegedly
overinflated cost of the hotel rooms they purchased as a result of Defendant MGM’s omissions
regarding the adequacy of data security policies. (Resp. 43:21–27). The California Plaintiffs
allege that had Defendant MGM disclosed its deficient security policies, they would either have
paid less for the room, or not purchased a room from Defendant MGM. (CAC ¶¶ 10–20, 114,
118(b));
see, e.g., Kwikset Corp
.,
b. Fraud Prong Defendant MGM contends that its alleged omission cannot constitute fraudulent conduct under the UCL because they were not obligated to disclose their security practices to Plaintiffs. (MTD 38:8–24). In response, the California Plaintiffs claim that Defendant MGM was obligated to disclose its security practices because it had exclusive knowledge of the fact that its security practices were beneath industry standards, and that this fact was material. (CAC ¶¶ 169–170, 235, 244(a), 243–245).
Claims stated under the fraud prong of the UCL are subject to the particularity
requirements of Fed. R. Civ. P. 9(b).
See Kearns
,
The California Plaintiffs have adequately pled a duty to disclose based upon Defendant’s
exclusive knowledge of the alleged inadequacy of its security measures.
See In re Solara
, 202
WL 2214152, at *10 (finding that the plaintiffs adequately alleged a fraudulent omission UCL
claim where they pled “a duty to disclose based upon [d]efendant’s exclusive knowledge of the
alleged inadequacy of its security measures);
In re Carrier IQ, Inc.
,
c. Unfair Prong Defendant MGM argues that the California Plaintiffs’ conclusory assertion that it failed to implement and maintain reasonable data security measures is insufficient to satisfy the unfair prong of the UCL. (MTD 38:1–3).
The unfair prong of the UCL creates a cause of action for a business practice that is ///
unfair even if not proscribed by some other law.
See In re Yahoo! Inc. Customer Data Sec.
Breach Litig.
,
Some California courts apply a balancing approach, which requires courts to “weigh the
utility of the defendant’s conduct against the gravity of the harm to the alleged victim.”
Davis
,
The California Plaintiffs “may proceed with a UCL claim under the balancing test by
either alleging immoral, unethical, oppressive, unscrupulous or substantially injurious conduct
by Defendant[] [MGM] or by demonstrating that Defendant [MGM’s] conduct violated an
established public policy.”
In re Anthem
,
d. Unlawful Prong
“The unlawful prong of the UCL prohibits anything that can properly be called a
business practice and that at the same time is forbidden by law
.” In re iPhone Application
Litig.
,
The Court has already considered the adequacy of the California Plaintiffs’ allegations under the fraud and unfair prongs of the UCL. Accordingly, the Court finds that the California Plaintiffs have sufficiently pled “unlawful” conduct in violation of the UCL. [12]
G. CALIFORNIA CONSUMER LEGAL REMEDIES ACT As with the California Plaintiffs claim for fraud by omission under the UCL, Defendant MGM again asserts that the California Plaintiffs California Consumers Legal Remedies Act (“CLRA”) fails because they failed to plead that Defendant MGM had a duty to disclose. (MTD 38:25–39:6).
The CLRA prohibits “unfair methods of competition and unfair or deceptive acts or
practices.” Cal. Civ. Code § 1770. To state a claim under CLRA §§ 1770(a)(5) and (7), a
plaintiff must allege: “(1) a misrepresentation; (2) reliance on that misrepresentation; and (3)
damages caused by that misrepresentation.”
In re Sony PS3 Other OS Litig.
,
The CLRA applies the same standard as the UCL for determining whether a defendant
engaged in fraud by omission.
See Barrett v. Apple Inc.
,
The Court has already considered the adequacy of the California Plaintiffs’ fraudulent omission UCL claim. Accordingly, the Court declines to dismiss Plaintiffs’ fraudulent omission CLRA claim for the reasons set forth above.
H. CALIFORNIA CUSTOMER RECORDS ACT
Defendant MGM contends that the California Plaintiffs California Customer Records Act (“CRA”) claim fails because their allegations do no explain how Defendant MGM took insufficient measures to protect customer’s PII. (MTD 39:7–17); (Reply 23:11–18). In response, the California Plaintiffs contend they asserted detailed allegations of how Defendant MGM failed to maintain reasonable security practices, including a failure to encrypt PII. (Resp. 46:3–47:2).
The CRA “regulates businesses with regard to treatment and notification procedures
relating to their customers’ personal information.”
Corona
,
The Court finds that the California Plaintiffs adequately alleged that Defendant MGM
failed to maintain reasonable cybersecurity practices as required by the CRA. Specifically, the
California Plaintiffs allege that Defendant MGM failed to encrypt the PII stored on its server in
violation of industry practice. (CAC ¶ 38);
see In re Mednax Servs., Inc., Customer Data Sec.
Breach Litig.
, No. 21-02994,
///
///
///
I. CONNETICUIT UNFAIR TRADE PRACTICES ACT Defendant MGM alleges that Plaintiff Robert Taylor’s (“Connecticut Plaintiff’s) claim under Connecticut’s Unfair Trade Practices Act (“CUPTA”) fails because the Connecticut Plaintiff have not alleged an unfair or deceptive practice. (MTD 39:19–40:3). The Connecticut Plaintiff, in response, contend that the “unfair or deceptive practice at issue” is Defendant MGM’s failure to implement adequate safeguards and notify the Connecticut class representative of its inadequate security.
The CUPTA provides: “No person shall engage in unfair methods of competition or deceptive acts or practices in the conduct of any trade or commerce.” Conn. Gen. St. § 42-110b(a). “Any person who suffers any ascertainable loss of money or property, real or personal, as a result of the use or employment of a method, act or practice prohibited by section 42-110b, may bring an action” to recover actual damages, punitive damages, and equitable relief. Conn. Gen. St. 42-110g(a).
Here, the Connecticut Plaintiff sufficiently alleged that Defendant MGM knew or should have known about its allegedly inadequate data security practices and the risk of a data breach. The Connecticut Plaintiff alleges that Defendant MGM (1) knew it was a target for hackers, (2) was aware that its data security practices were inadequate, and (3) failed to disclose to the Connecticut Plaintiff when he purchased a hotel room that they did not employ reasonable safeguards to protect Plaintiffs’ PII. (CAC ¶¶ 38–41, 66–77, 78–87, 162–177, 270(a)–(e)). The Connecticut Plaintiff alleges he relied on these omissions and “would not have stayed at MGM properties or would have paid less than he did for his rooms” had he known of Defendant MGM’s allegedly inadequate security practices. ( . ¶ 14). Therefore, the Court declines to dismiss the Connecticut Plaintiffs CUPTA claim. [14]
J. GEORGIA DECEPTIVE TRADE PRACTICES ACT Defendant MGM contends that Plaintiff Michael Fossett’s (“Georgia Plaintiff’s) claim under Georgia’s Uniform Deceptive Trade Practices Act (“GUDTPA”) fails pursuant to Sonner because GUDTPA only provides equitable remedies, and the Georgia Plaintiff cannot show a lack of legal remedies. (MTD 40:4–10); (Reply 24:1–7). In rebuttal, the Georgia Plaintiff contend that Sonner does not bar his claim because injunctive relief is necessary to prospectively protect against future data breaches. (Resp. 48:2–22).
For the reasons set forth above, the Georgia Plaintiff has plausibly alleged the inadequacy of remedies at law with respect to their claims for injunctive relief. The Georgia Plaintiff sufficiently alleged that monetary damages for past harm are an inadequate remedy for the future harm an injunction is designed to prevent. Accordingly, the Court declines to dismiss the Georgia Plaintiff’s GUDTPA claim.
K. NEW YORK GENERAL BUSINESS LAW
Plaintiff Kerri Shapiro (“New York Plaintiff”) alleges claims under the New York
General Business Law (“GBL”), N.Y. Gen. Bus. §§ 349,
et seq
. Section § 349(a) of the GBL
prohibits “[d]eceptive acts or practices in the conduct of any business, trade or commerce or in
the furnishing of any service.” N.Y. Gen. Bus. § 349(a). To state a § GBL claim, the New
York Plaintiff must allege (1) that defendant’s “act or practice was consumer-oriented,” (2) that
the act or practice “was misleading in a material way,” and (3) that plaintiff “suffered injury as
a result of the deceptive act.”
Stutman v. Chem Bank
,
To begin with, the parties dispute whether Rule 9(b)’s pleading requirements apply to
the GBL claim. (MTD 34:3–17). Several federal courts have held that Rule 9(b)’s pleading
requirements do not apply to GBL claims.
See, e.g., Pelman ex rel. Pelman v. McDonald’s
Corp
.,
Foremost, the New York Plaintiff alleges that she is a “resident of New York.” (CAC ¶ 17). The New York Plaintiff further alleges that she transacted with Defendant MGM by “making hotel reservations from New York and paying any necessary room deposits form New York.” ( Id . ¶ 296). The New York Plaintiff asserts that Defendant MGM’s deceptive acts or practices including failing to implement reasonable security and privacy measures, failing to identify and remediate foreseeable privacy risks, misrepresenting that it would protect the Plaintiffs’ PII, and failing to comply with statutory duties regarding the security and privacy of Plaintiffs’ personal information, including duties imposed by the FTC Act, 15 U.S.C. § 45. ( Id . ¶¶ 295–96). The New York Plaintiff claims that these acts affected the public interest and consumers at large, and that the New York class representative suffered damages as a result of Defendant MGM’s alleged practices. ( . ¶¶ 300–05). Based on the foregoing, the New York Plaintiff has adequately pled that the alleged deception took place in New York, that Defendant MGM misrepresented their security and privacy measures, and that she suffered an injury as result of this deception. Therefore, the Court declines to dismiss the New York Plaintiff’s GBL claim.
///
///
///
/// L. OHIO DECEPTIVE TRADE PRACTICES ACT
Defendant MGM argues that the Ohio Trade Practices Act. (“ODTPA”) does not provide a cause of action for consumers like Plaintiff Julie Mutsko (“Ohio Plaintiff”). (MTD 40:25–41:4). In rebuttal, the Ohio Plaintiff contend that there a split of authority on the issue of whether individual consumers have standing to assert a claim under the ODTPA, and that this Court should find that individual consumers have standing. (Resp. 49:23–50:24).
The ODTPA gives standing to bring a civil action to a “person who is likely to be damaged by a person who commits a deceptive trade practice” or a “person who is injured by a person who commits a deceptive trade practice.” Ohio Rev. Code § 4165.03(A)(1)-(2). ODTPA defines a “person” as “an individual, corporation, government, governmental subdivision or agency, business trust, estate, trust, partnership, unincorporated association, limited liability company, two or more of any of the foregoing having a joint or common interest, or any other legal or commercial entity.” Ohio Rev. Code § 4165.01(D).
Here, the Court adopts the reasoning of the United States District Court for the Northern District of Ohio in Hamilton v. Ulta Beauty and finds that Plaintiffs do not have standing to pursue a claim under ODTPA. See Hamilton v. Ulta Beauty , No. 5:18-cv-754, 2018 WL 3093527, at *3 (N.D. Ohio June 21, 2018) (“A broad majority of the courts to directly address this issue have held that the ODTPA does not give consumers standing.”). The Hamilton court explained that there are three reasons why ODTPA does not provide for consumer standing. First, “Ohio courts look to the federal Lanham Act when interpreting the ODTPA, and the Lanham Act does not give a consumer right of action.” Id . at *3. Second, the definition of “person” in the ODTPA qualifies the list of individuals and entities with the phrase “or any other legal or commercial entity,” thereby implying that an individual “may not bring suit as a non-commercial consumer.” . Third, the Hamilton court recognized that the Ohio Consumer Sales Practice Act (“OSCPA”) already “provides for consumer standing and prohibits virtually the same practices as the ODTPA.” . The court thereby reasoned that OSCPA would be 1 rendered superfluous if ODTPA also provided consumer standing. Id.
This Court sides with the majority of courts that have found that consumers do not have standing under ODTPA, as the OCSPA would be rendered superfluous if consumers could sue under ODTPA. [15] Accordingly, the Court dismisses the Ohio Plaintiff’s ODTPA claim with prejudice.
M. OREGON UNLAWFUL TRADE PRACTICES ACT Defendant MGM moves to dismiss Plaintiff John Dvorak’s (“Oregon Plaintiff’s) Oregon Unlawful Trade Practices Act (“OUTPA”) claim, arguing that he has not alleged an “unlawful” trade practice or have pled fraud with the requisite particularity required under Rule 9(b). (MTD 41:6–12).
Several courts have applied Rule 9(b)’s heightened pleading to OUTPA.
See Martell v.
General Motors LLC
,
Under the first element, the Oregon Plaintiff alleges that Defendant MGM knew or should have known about its allegedly inadequate data security practices and the risk of a data breach and that its alleged failures and omissions were material and relied upon by consumers. (CAC ¶¶ 38–41, 66–77, 78–87, 162–177, 270(a)–(e)). At this stage in the pleadings, the Court finds that this satisfies the first element. Pursuant to the second element, the Oregon Plaintiff posits he suffered damages in the form of include loss of the benefit-of-the bargain, money spent mitigating harms, diminished value of PII, and attempted identity theft. ( Id . ¶¶ 19, 95– 125). Turning to the third element, the Oregon Plaintiff contends he would not have stayed at Defendant MGM’s property or would have paid less for the room had he known about Defendant MGM’s deficient data security. ( . ¶ 19).
Additionally, Defendant MGM argues that dismissal of the OUTPA is warranted because a portion of the Oregon Plaintiff’s claim is based on violation of Oregon’s Consumer Information Act (“OCIPA”), which Defendant MGM contends does not provide a private right of action. (MTD 41:13–22). The Oregon Plaintiff, in rebuttal, contends that a private right of action can be inferred. (Resp. 52:8–53:12).
The Oregon Court of Appeals has found that under OCIPA, “only the state can prosecute
trade practices declared unlawful by ORS 646.607.”
Horton v. Nelson
,
N. OREGON CONSUMER INFORMATION PROTECTION ACT For the reasons set forth above, the Court finds that OCIPA does not provide the Oregon Plaintiff with a private cause of action. Accordingly, the Court dismisses the Oregon Plaintiff’s OCIPA claim with prejudice.
The Ninth Circuit “ha[s] held that in dismissing for failure to state a claim under Rule
12(b)(6) ‘a district court should grant leave to amend even if no request to amend the pleading
was made, unless it determines that the pleading could not possibly be cured by the allegation
of other facts.’”
Lopez v. Smith
,
Here, the Court finds that Plaintiffs’ negligence claim to the extent it alleges damages based solely on lost time, negligent misrepresentation, ODPTA, and OCIPA claims cannot be cured by the inclusion of other facts. Accordingly, the Court dismisses these claims without leave to amend. Plaintiffs’ unjust enrichment is dismissed with leave to amend.
IV. CONCLUSION
IT IS HEREBY ORDERED that Defendant MGM’s Motion to Dismiss, (ECF No. ECF No. 103), is GRANTED in part and DENIED in part .
DATED this _____ day of November, 2022.
___________________________________ Gloria M. Navarro, District Judge UNITED STATES DISTRICT COURT
Notes
[1] See Details of 10.6 Million MGM Hotel Guests Posted on a Hacking Forum , ZDNet, Feb. 19, 2020, available at https://www.zdnet.com/article/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking- forum/ (quoting unnamed “MGM spokesperson”) (last visited Oct. 26, 2022).
[2] The parties do not dispute that Nevada substantive law controls the common law tort and contract-based in this action. (CAC ¶ 127); (MTD 21:23–22:3).
[3] Because Plaintiffs have sufficiently pled non-economic losses, the Court need not consider Plaintiffs remaining arguments regarding the economic loss doctrine.
[4] The Court additionally finds that Plaintiffs have adequately pled damages and breach for the reasons set forth above.
[5] Plaintiffs also argue
Sonner
is distinguishable because the plaintiff in
Sonner
attempted to avoid a jury trial by
voluntarily dismissing her CLRA damages claim. In contrast, Plaintiffs have not engaged in legal
gamesmanship.
Sonner
,
[6] In contrast, a claim for injunctive relief to prevent future harm would seek a remedy qualitatively different from money damages: an order requiring Defendant MGM to timely delete and cease to use or share Plaintiffs’ PII or 24 implement reasonable data security requirements to prevent any future data breaches.
[7] For the reasons set forth above, the Court finds that Plaintiffs have alleged a cognizable injury.
[8] “Both courts within the District of Nevada and the Nevada Supreme Court have applied Rule 9(b)’s heightened
pleading standard to consumer fraud/deceptive trade practices under Nevada law.”
Urban Outfitters, Inc. v.
Dermody Operating Co., LLC
, No. 3:21-cv-00109,
[9] Defendant MGM also relies on
Taddeo v. Taddeo
, No. 2:08-cv-01463,
[10] The Court finds that these damages equally apply to all of Plaintiffs statutory claims.
[11] For the reasons set forth above, the Court finds that Sonner applies to the instant action.
[12] As addressed below, the Court finds that the California Plaintiffs additionally alleged cognizable claims under the California Consumers Legal Remedies Act, Cal. Civ. Code § 1770, and California Customer Records Act, Cal. Civ. Code §§ 1798.90. Therefore, the unlawful prong is alternatively satisfied based on violations of these statutes.
[13] Defendant MGM also argues in a single sentence that the California Plaintiffs failed to plead the requisite damages needed to sustain a CRA claim. (Reply 23:16–18). However, for the reasons set forth above, the Court finds that the California Plaintiffs’ alleged cognizable damages.
[14] The Court finds that Plaintiffs have adequately alleged unfair or deceptive acts that adequately satisfy Rule 9(b).
[15] In contrast, Plaintiffs cite two cases finding that consumers have standing under the ODTPA.
See Schumacher
v. State Auto. Mut. Ins. Co.
,