Judge Jon S. Tigar, in the Northern District of California, addressed a motion to dismiss in a class action lawsuit arising from a significant data breach at a large labor-based credit union. The breach, caused by a ransomware attack, exposed sensitive personal and health information of current and former customers.
Between August and October 2023, the credit union suffered a targeted cyberattack by the “No Escape” group, resulting in unauthorized access to a broad array of personally identifiable information (PII) and protected health information (PHI). Impacted individuals were notified in April 2024. Plaintiffs allege the credit union failed to implement reasonable cybersecurity measures, referencing noncompliance with the NIST Cybersecurity Framework and other industry standards. As a result, plaintiffs claim they face ongoing risks of identity theft, have incurred costs and emotional distress, and have experienced increased spam and scam communications.
Negligence
The court allowed the negligence claim to proceed, finding that the credit union owed a duty to safeguard customer PII/PHI and that plaintiffs sufficiently alleged breach and damages. The court recognized that time and money spent on credit monitoring, as well as emotional distress and increased scam contacts, constitute plausible damages in the data breach context.
Breach of Implied Contract
The court found that plaintiffs who were required to provide PII/PHI as a condition of receiving services adequately alleged consideration for an implied contract to safeguard that information. However, the claim was dismissed with leave to amend for a plaintiff who did not allege customer status.
Invasion of Privacy
The court declined to dismiss the invasion of privacy claim at the pleading stage, noting that the exposure of medical information in a data breach could constitute an “egregious breach of social norms” under California law.
Unjust Enrichment
The court allowed the unjust enrichment claim to proceed alongside the implied contract claim, distinguishing this case from those involving express contracts.
California Unfair Competition Law (UCL)
The UCL claim was dismissed with leave to amend. The court held that plaintiffs failed to allege actual economic injury, as lost time and general allegations of diminished value of PII/PHI were insufficient to confer statutory standing.
California Consumer Privacy Act (CCPA)
The court found that plaintiffs plausibly alleged the credit union was a “business” under the CCPA and allowed the claim to proceed, rejecting the argument that the credit union was merely a “service provider.”
Plaintiffs can only state a claim against OEFCU if it is a “business” and not a “service provider.”
OEFCU provides no explanation as to how it fits the definition of a “service provider” other than pointing to Plaintiffs’ passing description of OEFCU as a “financial services provider” in a different context in the first amended complaint. See ECF No. 29 at 19–20. It otherwise primarily relies on In re Accellion, Inc. Data Breach Litig., 713 F. Supp. 3d 623 (N.D. Cal. 2024), to argue that Plaintiffs fail to allege that OEFCU meets the definition of a business under the statute. In that case, the plaintiffs alleged that “Accellion was hired by various companies to ‘securely transfer’ and to ‘facilitate secure, encrypted file sharing that exceeded limits imposed on the size of email attachments.’ ” Id. at 641. The court thus found that it was actually Accellion’s customers—not Accellion itself—who made the decisions as to why and how any personal information was transferred. Id.
Here, however, Plaintiffs specifically allege that OEFCU collected Plaintiffs’ PII and PHI as a condition of providing its services. ECF No. 16 ¶¶ 28, 114, 124, 136, 244. OEFCU thus determined the “purpose” of collecting Plaintiffs’ PII—to enable OEFCU to maintain the information needed to provide financial services to its “current and former customers.” See id. ¶ 25. And Plaintiffs further alleged that OEFCU determined the “means” of processing their PII/PHI by choosing to store that information and the method of storing that information. See id. ¶ 3 (alleging that OEFCU “stored that PII/PHI, unencrypted, in an Internet-accessible environment on Defendant’s network”). Plaintiffs thus plausibly allege that OEFCU is a business under the CCPA. See Karter v. Epiq Sys., Inc., No. SACV 20-01385-CJC (KESX), 2021 WL 4353274, at *2 (C.D. Cal. July 16, 2021) (finding that when an entity collects consumers’ personal information from consumers “in order to perform its services,” that “is an activity for a business” under the CCPA).
*8 Accordingly, the Court declines to dismiss Plaintiffs’ CCPA claim.
California Customer Records Act (CCRA)
The court permitted CCRA claims to proceed for plaintiffs who alleged they were customers and that delayed notification of the breach caused incremental harm. The claim was dismissed with leave to amend for a plaintiff who did not allege customer status.
Declaratory Relief
The court dismissed the declaratory relief claim with prejudice, finding it duplicative of the negligence claim and not a standalone cause of action.
Jimenez v. OE Fed. Credit Union, No. 24-CV-02746-JST, 2025 WL 2402137 (N.D. Cal. Aug. 19, 2025).
