Summary
- Federal judge finds the plaintiff had standing for a completed privacy injury involving exposed PII.
- The court rejected claims based on speculative future misuse, identity theft and fraud risks.
- The plaintiff could not seek prospective relief or damages tied to mitigation costs and diminished PII value.
A plaintiff can’t sue for future damages stemming from a ransomware attack, a federal district court judge has decided.
The plaintiff, a former employee of the defendant company, sued over a ransomware attack on the defendant’s computer system. The plaintiff alleged he provided the defendant with personally identifiable information (PII) which was accessed during the attack.
The defendant moved to dismiss, arguing the plaintiff lacked standing.
Judge Linda V. Parker held that while the plaintiff had standing to seek damages for a completed privacy injury, he could not to seek relief.
“The Court concludes that Plaintiff has standing to seek damages for a completed privacy injury, but lacks standing to seek prospective relief or relief based on speculative future misuse, mitigation costs, or diminished value of PII,” Parker wrote.
The 36-page decision is Malone v. Edw. C. Levy Co.; MiLW No. 02-111087.
Attorneys from Bloomfield Hills firm Fink Bressack represented the plaintiff. Attorneys from Bloomfield Hills firm McDonald Hopkins represented the defendant company.
Data breach leads to lawsuit
In November 2023, the defendant experienced a ransomware attack where employees’ personal information was accessed.
The plaintiff alleged that the breach resulted from inadequate cybersecurity practices and that the defendant failed to provide timely notice of the breach.
The company didn’t notify employees of the breach until January 2025 – more than 14 months after the attack.
In his initial complaint, the plaintiff claimed the following injuries: exposure of his PII; damages for and a diminution in value of his PII; time spent mitigating the impact of the breach; anxiety, stress and fear; continued risk of fraud and identity theft; and an increase in suspicious spam calls and emails.
In an amended complaint, the plaintiff asserted claims of negligence, negligence per se, breach of implied contract, unjust enrichment, invasion of privacy and breach of fiduciary duty.
The defendant filed a motion to dismiss under Rules 12(b)(1) and 12(b)(6). The company argued that the plaintiff lacked standing because he had not alleged a concrete or imminent injury. The company also argued that the plaintiff’s amended allegations concerning future harm were too speculative to establish standing, and that he failed to adequately plead the elements of his Michigan-law claims.
In response, the plaintiff argued that the defendant’s Rule 12(b)(1) challenge was facial and that the court therefore had to accept his allegations as true. He also argued that his allegations concerning the data breach were sufficient to establish standing and state viable claims.
Limits on plaintiff’s standing
Parker concluded that the plaintiff had standing based on the completed privacy injury caused by the exposure of his PII, but that his allegations of future harm were too speculative to support standing.
She also concluded that the plaintiff failed to adequately plead his Michigan-law claims.
“Plaintiff has standing to seek damages for the alleged completed privacy injury, but he lacks standing to seek prospective relief or to proceed based on speculative future misuse, mitigation efforts tied to that future risk, diminished value of PII, increased spam communications, or the employee-credential allegations,” she wrote.
Parker found that while the alleged unauthorized access to the plaintiff’s PII constituted a sufficiently concrete injury for purposes of Article III standing, he had not alleged that his information had actually been misused to open a fraudulent account, make an unauthorized charge, damage his credit or commit identity theft. The passage of time without any alleged misuse further weakened his claim that future harm was imminent.
The court likewise rejected standing based on the plaintiff’s mitigation efforts, the diminished value of his PII, increased spam calls and emails, and employee login credentials allegedly posted on the dark web.
Parker found those theories either depended on speculative future harm or lacked a sufficient connection to the plaintiff’s alleged injury. She also concluded that the plaintiff lacked standing to seek prospective relief because he had not established a real and immediate threat of future injury.
Parker emphasized that establishing Article III standing did not mean the plaintiff had adequately pleaded a state-law cause of action.
She found that his negligence claim failed because Michigan law requires an actual, present injury, and the plaintiff had not alleged a completed misuse of his PII or other concrete loss. His delayed-notice theory likewise rested on the possibility that earlier notice would have allowed him to mitigate a future risk.
Finally, the judge rejected the plaintiff’s claims for breach of implied contract, unjust enrichment, invasion of privacy and breach of fiduciary duty, finding that the allegations did not establish the required elements of those claims.
