In re: Salesforce, Inc., Customer Data Security Breach Litigation; In re: Trans Union, LLC, Customer Data Security Breach Litigation

In re Salesforce/Trans Union MDLs · United States Judicial Panel on Multidistrict Litigation · January 16, 2026 · No. MDL Nos. 3164 and 3170; 25cv10320

Summary

The United States Judicial Panel on Multidistrict Litigation denied centralization of the proposed Salesforce customer data-breach litigation in MDL No. 3164. The Panel granted centralization of TransUnion-related actions in MDL No. 3170, transferring actions pending outside the Northern District of Illinois to that district for coordinated or consolidated pretrial proceedings. Judge Robert W. Gettleman was selected as the transferee judge.

Court
United States Judicial Panel on Multidistrict Litigation
Writing for the Court
Karen K. Caldwell; Nathaniel M. Gorton; Matthew F. Kennelly; David C. Norton; Roger T. Benitez; Dale A. Kimball
Jurisdiction
United States Judicial Panel on Multidistrict Litigation
Decision date
January 16, 2026
Docket number
MDL Nos. 3164 and 3170; 25cv10320
Procedural posture
The Judicial Panel on Multidistrict Litigation considered competing motions under 28 U.S.C. § 1407 to centralize actions arising from Salesforce-customer data breaches and a separate group of actions arising from a TransUnion data breach.
Standard of review
Under 28 U.S.C. § 1407(a), centralization is appropriate when actions share common questions of fact and transfer will promote the convenience of the parties and witnesses and the just and efficient conduct of the litigation.
Precedential value
Panel transfer order; precedential status not specified in the source.
Parties
Movants in MDL No. 3164, Movants in MDL No. 3170 v. Responding parties in the Salesforce and TransUnion actions
Disposition
other

Topics

civil procedureclass actionsdiscovery disputecommercial litigationconsumer protection

Practice areas

civil proceduremultidistrict litigationdata security and privacyclass actionscommercial litigation

Questions Presented

  1. Whether the Salesforce-customer data-breach actions should be centralized in a single multi-defendant MDL under 28 U.S.C. § 1407.
  2. Whether the TransUnion data-breach actions should be centralized in a separate MDL under 28 U.S.C. § 1407.
  3. Whether claims against non-TransUnion defendants in multi-defendant actions should be separated and remanded at the time of transfer.
  4. Which district and transferee judge should receive the TransUnion MDL.

Holdings

  1. Centralization of the Salesforce-customer actions in MDL No. 3164 was not necessary because the actions presented few common questions of fact and a large multi-defendant MDL would hinder rather than promote the just and efficient conduct of the litigation.
  2. The TransUnion actions listed on Schedule B should be centralized in MDL No. 3170 because they involved common questions of fact arising from the same TransUnion data breach, and centralization would eliminate duplicative discovery, reduce inconsistent pretrial rulings, and conserve judicial and party resources.
  3. The Panel declined to separate and remand claims against non-TransUnion defendants at that time, leaving the transferee judge to determine, based on the pleadings and case-management considerations, whether separation and remand would be appropriate.

Key quotations

In contrast to the expansive request for a multi-defendant Salesforce MDL, we are persuaded that a TransUnion MDL is appropriate. (at 4)
Whether Section 1407(a) remand is available turns on a highly specific inquiry about how each complaint is pled. (at 5)
As with any other litigation, the transferee judge retains wide discretion as to how the MDL should be defined, and if, after close scrutiny, the transferee judge determines that remand of any claims . . . is appropriate, procedures are available whereby this may be accomplished with a minimum of delay. (at 5)

Factual background

The actions arose from social-engineering attacks in 2025 that allegedly enabled threat actors to access databases maintained by Salesforce customers, including Allianz, Farmers Insurance, Louis Vuitton, and TransUnion. The Salesforce-related actions involved separate breaches affecting different customers, with potentially different methods of attack, employee conduct, security procedures, responses, and types of compromised personally identifiable information. The TransUnion actions all arose from the same breach affecting TransUnion customers and presented common factual questions concerning TransUnion's duties, the execution of the attack, preventative procedures, and the response to the breach.

Procedural history

Plaintiffs in five actions moved to centralize 41 Salesforce-customer data-breach actions in MDL No. 3164. TransUnion later moved to centralize 53 actions arising from the TransUnion breach in MDL No. 3170. After briefing, the movants in MDL No. 3164 sought to withdraw their motion, but the Panel denied that request because other plaintiffs had responded in support. The Panel denied centralization of the Salesforce actions and ordered transfer of the TransUnion actions pending outside the Northern District of Illinois to that district for coordinated or consolidated pretrial proceedings.

Remand instructions

The actions listed on Schedule B and pending outside the Northern District of Illinois were transferred to the Northern District of Illinois and, with that court's consent, assigned to Judge Robert W. Gettleman for coordinated or consolidated pretrial proceedings in MDL No. 3170. The Panel did not order immediate separation or remand of claims against non-TransUnion defendants; Judge Gettleman may later determine whether such relief is appropriate.

Court Document

Open PDF
Loading document…