Hilary Remijas v. Neiman Marcus Group, LLC

794 F.3d 688 (7th Cir. 2015) · United States Court of Appeals for the Seventh Circuit · July 20, 2015 · No. No. 14-3122

Summary

The Seventh Circuit held that customers whose payment-card information was exposed in the Neiman Marcus data breach adequately alleged Article III standing. The court concluded that costs associated with resolving fraudulent charges, mitigation expenses, and the substantial risk of future fraudulent charges or identity theft could constitute concrete injuries, and that the injuries were plausibly traceable to the breach and redressable through judicial relief. The court reversed the district court’s dismissal and remanded for further proceedings.

Court
United States Court of Appeals for the Seventh Circuit
Writing for the Court
Chief Judge Diane P. Wood; Judge Michael S. Kanne; Judge John L. Tinder
Jurisdiction
Federal
Decision date
July 20, 2015
Docket number
No. 14-3122
Procedural posture
Plaintiffs appealed the dismissal of their putative class action under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). The district court dismissed the complaint without prejudice solely for lack of Article III standing.
Standard of review
De novo review of a dismissal for lack of Article III standing. On a Rule 12(b)(1) motion, material allegations are accepted as true and reasonable inferences are drawn in the plaintiff's favor unless standing is challenged factually.
Precedential value
published precedential opinion
Parties
Hilary Remijas, on behalf of herself and all others similarly situated, et al. v. Neiman Marcus Group, LLC
Disposition
reversed_and_remanded

Topics

standingsubject matter jurisdictionmotions to dismissappellate jurisdictioncivil procedure

Practice areas

constitutional lawcivil procedureconsumer protectiondata breach and privacyclass actionsappellate procedure

Questions Presented

  1. Whether the plaintiffs adequately alleged injury-in-fact, causation, and redressability sufficient to establish Article III standing at the pleading stage.
  2. Whether the district court's dismissal for lack of standing should be reversed.
  3. Whether the Seventh Circuit could address Neiman Marcus's alternative Rule 12(b)(6) argument when the district court had not reached that ground and Neiman Marcus had not filed a cross-appeal.

Holdings

  1. Customers who incurred fraudulent charges suffered concrete injuries from the time and effort required to resolve those charges, and customers whose payment-card information was stolen adequately alleged a substantial risk of future fraudulent charges or identity theft. Those allegations were sufficient to establish injury-in-fact at the pleading stage.
  2. Reasonable expenses incurred to protect against future identity theft or fraudulent charges may constitute a concrete injury when the risk of harm is sufficiently imminent; plaintiffs do not lose standing merely because the defendant offered credit monitoring or because some charges may be reimbursed.
  3. The plaintiffs plausibly alleged that their injuries were fairly traceable to the Neiman Marcus data breach and that a favorable judicial decision could redress mitigation expenses and any losses not fully reimbursed.
  4. The court would not decide whether the complaint stated a claim under Rule 12(b)(6) because the district court had not ruled on that ground and Neiman Marcus had not filed a cross-appeal seeking to enlarge or alter the judgment.

Key quotations

Like the Adobe plaintiffs, the Neiman Marcus customers should not have to wait until hackers commit identity theft or credit-card fraud in order to give the class standing, because there is an “objectively reasonable likelihood” that such an injury will occur. (794 F.3d at 697)
The injuries associated with resolving fraudulent charges and protecting oneself against future identity theft do. (794 F.3d at 703)

Factual background

Hackers infiltrated Neiman Marcus's computer systems between July 16 and October 30, 2013, and potentially exposed approximately 350,000 payment-card numbers. The company learned in December 2013 that some customers had incurred fraudulent charges, discovered malware on January 1, 2014, and publicly disclosed the breach on January 10, 2014. The named plaintiffs alleged fraudulent charges, time and expense resolving or protecting against fraud and identity theft, and other injuries arising from the breach.

Procedural history

After a data breach exposed approximately 350,000 payment cards and fraudulent charges appeared on approximately 9,200 cards, customers filed consolidated class-action complaints asserting negligence, contract, unjust-enrichment, consumer-protection, privacy, and state data-breach claims. The district court granted Neiman Marcus's motion to dismiss solely on standing grounds. The Seventh Circuit held that the plaintiffs adequately alleged Article III standing, reversed, and remanded for further proceedings.

Remand instructions

Remanded for further proceedings consistent with the opinion, including consideration of the remaining issues not reached by the district court.

Court Document

Open PDF
Loading document…