Judge Michelle Williams Court in the Central District of California dismissed claims involving a business owner whose accounts were compromised by a former employee. The business owner sought to hold financial institutions liable for losses stemming from internal fraud and alleged bank failures in fraud detection.
After the case was removed to federal court, the bank moved to dismiss all ten causes of action, which included negligence, fraud, aiding and abetting, breach of contract, conversion, unjust enrichment, and violations of the California Consumer Privacy Act (CCPA), Unfair Competition Law (UCL), and the Electronic Fund Transfer Act (EFTA).
Negligence
The court reaffirmed that, under California law, banks generally owe limited duties to customers beyond the contractual relationship. While a duty to investigate may arise when a bank is alerted to potential fraud, the plaintiff’s allegations lacked specificity regarding when the bank was notified and what actions followed. The court also found that the economic loss rule did not bar the claim, as the plaintiff alleged some non-economic damages, but dismissed the claim for insufficient factual detail, granting leave to amend.
Fraud and Aiding and Abetting
Fraud claims must meet a heightened pleading standard, requiring particularity as to the “who, what, when, where, and how” of the alleged misrepresentations. The court found that most of the plaintiff’s allegations were conclusory or lacked the necessary detail, except for one instance involving a $4,200 transaction. However, even this did not establish reliance or resulting harm. The aiding and abetting claim failed for similar reasons, as the complaint did not show intentional participation by the bank in the embezzlement scheme. Both claims were dismissed with leave to amend.
Breach of Contract
The plaintiff abandoned a written contract theory in favor of an implied-in-fact contract, based on alleged verbal assurances by the bank. The court held that such assurances did not constitute an enforceable contract, especially where an express user agreement governed the relationship. The breach of contract claim was dismissed.
Conversion and Unjust Enrichment
The court reiterated that, under California law, depositors do not retain ownership of funds once deposited in a bank, precluding conversion claims unless a specific, identifiable sum is wrongfully withheld. The plaintiff failed to identify such a sum or establish a right to possession. The unjust enrichment claim was also dismissed, as the existence of a user agreement and lack of a specific benefit retained by the bank defeated the claim.
Statutory Claims: CCPA, UCL, and EFTA
The court dismissed the CCPA claim, finding no allegations of a security breach or failure to implement reasonable security measures.
The CCPA provides a limited civil remedy for any “consumer whose nonencrypted and nonredacted personal information . . . is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’s violation of the duty to implement and maintain reasonable security practices.” Shah v. Cap. One Fin. Corp., 768 F. Supp. 3d 1033, 2025 WL 714252, at *8 (N.D. Cal. 2025) (quoting Cal. Civ. Code § 1798.150(a)(1)). Subdivision (c) of the same statute provides: “The cause of action established by this section shall apply only to violations as defined in subdivision (a) and shall not be based on violations of any other section of this title. Nothing in this title shall be interpreted to serve as the basis for a private right of action under any other law.” Cal. Civ. Code § 1798.150(c).
The FAC, like Plaintiff’s initial complaint, does not allege facts constituting a CCPA violation. MTD O. at 13-14. It avers that “Defendant unlawfully mishandled Plaintiff’s personal and financial information, violating [CCPA] and exposing Plaintiff to identity [*25] theft and permitting a third party, [Bronfeld], to exercise complete control over accounts while cutting off Plaintiff’s access, even after Plaintiff alerted Defendant of the unauthorized account access Bronfeld was exercising.” FAC ¶ 112. It also contends that Defendant’s internal controls were so deficient that Bronfeld altered credentials, redirected debit card functions, and issued bank statements that facilitated the fraudulent transfers. Id. ¶ 18. Those allegations do not support an actionable claim. See Danfer-Klaben v. JPMorgan Chase Bank, N.A., No. 2:12-cv-62, 2022 U.S. Dist. LEXIS 25553, 2022 WL 3012528, at *7 (C.D. Cal. Jan. 24, 2022) (dismissing CCPA claim where plaintiff failed to allege that defendant’s disclosures to third parties was the result of a failure “to implement and maintain reasonable security measures”). Simply put, there are no allegations of mishandling, let alone how Bronfeld pulled such information from Defendant. See McCoy v. Alphabet, Inc., No. 20-CV-05427-SVK, 2021 U.S. Dist. LEXIS 24180, 2021 WL 405816, at *8 (N.D. Cal. Feb. 2, 2021) (dismissing CCPA claim where “there are no allegations of a security breach”).
Accordingly, the Court GRANTS Defendant’s motion to dismiss Count No. 8.
The UCL claim, which was predicated on the CCPA violation, was also dismissed, as was the EFTA claim, due to lack of specificity regarding the transactions at issue and whether they involved consumer accounts. The court dismissed the UCL and EFTA claims with prejudice, barring further amendment.
