Full text
Gill v. Caesars Entertainment, Inc.
— 1 —
2 UNITED STATES DISTRICT COURT
3 DISTRICT OF NEVADA
— 4 —
Case No. 2:23-cv-01447-ART-BNW
— 5 —
In re: DATA BREACH SECURITY ORDER DENYING DEFENDANT’S 6 LITIGATION AGAINST CAESARS
MOTION TO DISMISS
ENTERTAINMENT, INC.
7 (ECF No. 91)
— 8 —
9 This is a consolidated class action against Defendant Caesars 10 Entertainment, Inc. (“Caesars”) relating to a data breach. In August 2023, 11 Caesars’ Rewards member database was hacked, and Plaintiffs’ personal 12 identifying information (“PII”) was accessed by hackers. Plaintiffs were members 13 of Caesars’ rewards program and/or customers of Caesars’ gaming and 14 entertainment services at the time. Plaintiffs bring a putative class action seeking 15 redress for the harms they allegedly suffered from the data breach. (See ECF No. 16 81 (“Consolidated Class Action Complaint”).) 17 Before the Court is Defendant’s motion to dismiss for lack of standing and 18 failure to state a claim. (ECF No. 91.) For the following reasons, the Court finds 19 that Plaintiffs have standing, and that Plaintiffs have plausibly pled each of their 20 claims. Accordingly, Defendant’s motion to dismiss is denied. 21 I. BACKGROUND 22 A. Summary of Allegations 23 On or around August 18, 2023, members of the cybercriminal group 24 Scattered Spider gained access to Caesars’ loyalty program database through a 25 social engineering attack on Caesars’ IT support company.1 (ECF No. 81 at ¶¶ 2,
— 26 —
— 27 —
28 1 Plaintiffs’ lawsuit against that company, Coforge, Ltd. (“Coforge”), has since 1 224, 225.) The database contained sensitive PII, including names, drivers’ license 2 numbers, and social security numbers of a “significant number” of Caesars’ 3 loyalty program’s 65 million members. (ECF No. 81 at ¶ 1.) Caesars identified the 4 suspicious activity on that day, yet Scattered Spider downloaded the PII five days 5 later. (Id. at ¶ 225.) 6 On September 7, 2023, Caesars’ interval investigation confirmed that 7 Scattered Spider had acquired, among other data, a copy of its loyalty program 8 database including names, driver’s license numbers, and social security numbers 9 for “a significant number of Caesars Rewards’ tens of millions of members.” (Id. 10 at ¶ 227.) On or around September 14, 2023, Caesars filed a Form 8-K with the 11 SEC to alert investors and shareholders that the data breach had occurred. (Id. 12 at ¶ 228.) Caesars also put up a website about the breach, which acknowledged 13 that at a minimum the driver’s license numbers and social security numbers of 14 Caesars Rewards members had been accessed and copied. (Id. at ¶ 228.) 15 B. Caesars’ Rewards Program 16 Caesars is one of the world’s largest lodging and gaming companies and 17 considers itself a global leader in gaming and hospitality. (Id. at ¶ 3.) Its loyalty 18 program, Caesars Rewards, allows members to earn credits by gambling or 19 staying at Caesars’ properties. (Id. at ¶¶ 3–4, 210.) Caesars requires that its 20 members provide highly sensitive PII such as their full legal name, full address, 21 date of birth, drivers’ license number, and social security number. (Id. at ¶ 212.) 22 Caesars’ 2023 Privacy Policy promises to “maintain physical, electronic and 23 organizational safeguards that reasonably and appropriately protect against the 24 loss, misuse, and alteration of the information under [their] control.” (Id. at ¶¶ 25 215, 239.)
— 26 —
— 27 —
been consolidated with this case, but the present motion concerns only Caesars. 28 (ECF No. 130.) 1 Caesars was aware that it faced a significant risk of cyberattacks well 2 before the August 2023 attack. (Id. at ¶¶ 250, 251.) Caesars told investors in 3 2022 that: “Compromises of our information systems or unauthorized access to 4 confidential information or our customers’ personal information could materially 5 harm our reputation and business.” (Id. at ¶ 250.) Plaintiffs allege that despite 6 knowing those risks, Caesars failed to adopt reasonable safeguards to protect 7 their PII. (Id. at ¶ 251.) 8 C. Plaintiffs’ Harm 9 Plaintiffs allege that as a result of the data breach, they have experienced 10 “actual and attempted fraud and/or have been exposed to an increased risk of 11 fraud, identity theft, and other misuse of their PII.” (Id. at ¶ 10.) They now closely 12 monitor their financial and other accounts to guard against fraud, which is 13 burdensome and time-consuming. (Id.) Plaintiffs also have already or will 14 purchase credit monitoring and other identity protection services, purchase 15 credit reports, place credit freezes and fraud alerts on their credit reports and 16 spend time investigating and disputing fraudulent or suspicious activity on their 17 accounts. (Id.) One Plaintiff has already spent $400 for a one-year subscription 18 for identity protection services. (Id. at 16.) Although Caesars offered to provide 19 credit monitoring to its loyalty program members, it has only agreed to provide 20 that service for 24 months. (Id. at ¶ 294.) 21 Several Plaintiffs have discovered that their PII was for sale on the dark 22 web following the data breach. (Id. at ¶¶ 6, 20, 41, 51, 61, 82, 92, 118, 140, 170, 23 191, 273.) Plaintiffs allege that this stolen PII can be used on its own or in 24 combination with personal information from other sources to create a package of 25 information capable of being used to commit further identity theft. (Id. at ¶ 11.) 26 Plaintiffs also allege that, had they known that the purchases at Caesars did not 27 include adequate data security, they would have paid less or not stayed at
— 28 —
1 Caesars hotels. (Id. at ¶ 290.) Plaintiffs also allege that the value of their PII has 2 diminished as a result of the data breach. (Id. at ¶¶ 276–85.) 3 D. Class Plaintiffs 4 There are nine proposed classes in this case: Nationwide Class; California 5 Subclass; Illinois Subclass; Indiana Subclass; Minnesota Subclass; New York 6 Subclass; Pennsylvania Subclass; Texas Subclass; and Virginia Subclass. (Id. at 7 ¶¶ 308, 312.) The Nationwide Class asserts claims against Caesars for negligence 8 (Count I), breach of implied contract (Count II), unjust enrichment (Count III), 9 and violation of the Nevada Consumer Fraud Act, Nev. Rev. Stat. § 41.600 (Count 10 IV). (Id. at ¶ 309.) The statewide subclasses assert statutory claims for violations 11 of various state data breach notification and consumer protection statutes. 12 (Counts V–XVIII). 13 E. Procedural History 14 Plaintiffs filed the initial class action complaint in this case in September 15 2023. (ECF No. 1.) Other lawsuits relating to the same data breach were 16 subsequently consolidated into this case. (ECF Nos. 21, 46, 55.) In July 2024, 17 Plaintiffs filed the Consolidated Class Action Complaint. (ECF No. 81.) Caesars 18 moves to dismiss all claims in that complaint. (ECF No. 91.) Also before the Court 19 is Plaintiffs’ motion for leave to file supplemental authorities in support of its 20 opposition to the motion to dismiss (ECF No. 114), which the Court grants and 21 considers in this order. 22 II. LEGAL STANDARD 23 A. Article III Standing 24 Under Rule 12(b)(1), a party may move to dismiss for lack of subject matter 25 jurisdiction. “[L]ack of Article III standing requires dismissal for lack of subject 26 matter jurisdiction under [Rule] 12(b)(1).” Maya v. Centex Corp., 658 F.3d 1060 , 27 1067 (9th Cir. 2011). The “irreducible constitutional minimum” of standing
— 28 —
1 requires that a “plaintiff must have (1) suffered an injury in fact, (2) that is fairly 2 traceable to the challenged conduct of the defendant, and (3) that is likely to be 3 redressed by a favorable judicial decision.” Spokeo, Inc. v. Robins, 578 U.S. 330 4 (2016). Injury in fact requires “an invasion of a legally protected interest which is 5 (a) concrete and particularized,” and “(b) ‘actual or imminent, not conjectural or 6 hypothetical.’” Lujan v. Defenders of Wildlife, 504 U.S. 555, 560-61 (1992) 7 (citations omitted). “The party invoking federal jurisdiction bears the burden of 8 establishing these elements . . . with the manner and degree of evidence required 9 at the successive stages of litigation.” Id. at 561 . At the pleading stage, “[g]eneral 10 allegations” of injury may suffice. Id.
11 B. 12 (b)(6) 12 An initial pleading must contain “a short and plain statement of the claim 13 showing that the pleader is entitled to relief.” Fed. R. Civ. P. 8(a). The court may 14 dismiss a complaint for “failure to state a claim upon which relief can be granted.” 15 Fed. R. Civ. P. 12(b)(6). In ruling on a motion to dismiss, “[a]ll well-pleaded 16 allegations of material fact in the complaint are accepted as true and are 17 construed in the light most favorable to the non-moving party.” Faulkner v. ADT 18 Sec. Servs., Inc., 706 F.3d 1017, 1019 (9th Cir. 2013) (citations omitted). 19 To survive a motion to dismiss, a complaint need not contain “detailed 20 factual allegations,” but it must do more than assert “labels and conclusions” or 21 “a formulaic recitation of the elements of a cause of action . . . .” Ashcroft v. Iqbal,
— 22 —
556 U.S. 662, 678 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544 , 555 23 (2007)). In other words, a claim will not be dismissed if it contains “sufficient 24 factual matter, accepted as true, to state a claim to relief that is plausible on its 25 face,” meaning that the court can reasonably infer “that the defendant is liable 26 for the misconduct alleged.” Id. (internal quotation and citation omitted). The 27 Ninth Circuit, in elaborating on the pleading standard described in Twombly and
— 28 —
1 Iqbal, has held that for a complaint to survive dismissal, the plaintiff must allege 2 non-conclusory facts that, together with reasonable inferences from those facts, 3 are “plausibly suggestive of a claim entitling the plaintiff to relief.” Moss v. U.S. 4 Secret Serv., 572 F.3d 962, 969 (9th Cir. 2009). 5 III. DISCUSSION 6 A. Article III Standing 7 Caesars contends that Plaintiffs lack Article III standing because Plaintiffs 8 cannot establish “injury in fact” and because Plaintiffs cannot establish that their 9 injury is “fairly traceable” to Caesars’ actions. (ECF No. 91 at 19–26.) The Court 10 addresses each argument in turn. 11 1. Injury In Fact 12 Plaintiffs allege that they have suffered several types of injuries, including 13 imminent risk of identity theft, actual or attempted fraud, loss of value of PII, 14 benefit of the bargain damages, and mitigation efforts. Caesars primarily 15 challenges Plaintiffs’ first theory of injury: risk of identity theft. Caesars argues 16 that this does not confer Article III standing because Plaintiffs allege only risk of 17 future harm, pointing to TransUnion LLC v. Ramirez, 594 U.S. 413, 436 (2021). 18 (ECF No. 91 at 19.) Plaintiffs argue that allegations of a credible threat of real and 19 immediate harm stemming from the theft of their personal information are 20 sufficient to establish injury in fact under In re Zappos.com, Inc., 888 F.3d 1020 , 21 1027 (9th Cir. 2018) and Krottner v. Starbucks Corp., 628 F.3d 1139 (9th Cir. 22 2010). (ECF No. 96 at 15–19.) Caesars contends that those cases “are no longer 23 good law” after TransUnion. (ECF No. 102 at 8–9.) 24 In TransUnion, the Court addressed whether a group of consumers who 25 had misleading alerts in their credit reports had standing to sue. 594 U.S. at 417 . 26 The Court distinguished between plaintiffs whose credit reports were 27 disseminated to third parties and plaintiffs whose credit reports were maintained
— 28 —
1 internally. Id. The Court held that the plaintiffs whose credit reports were 2 disseminated to third parties suffered a concrete injury in fact under Article III.
— 3 —
Id. at 433 . The plaintiffs whose credit reports were not disseminated lacked 4 standing because “[t]he mere presence of an inaccuracy in an internal credit file, 5 if it is not disclosed to a third party, causes no concrete harm.” Id.
6 i. Imminent Risk of Identity Theft 7 Following TransUnion, “courts across the country have recognized that 8 harms that result as a consequence of a plaintiff’s knowledge of a substantial risk 9 of identity theft, including time and money spent responding to a data breach or 10 emotion[al] distress can satisfy concreteness.” Medoff v. Minka Lighting, LLC, No. 11 2:22-CV-08885-SVW-PVC, 2023 WL 4291973 , at *4 (C.D. Cal. May 8, 2023) 12 (collecting cases). These additional harms “can only qualify as concrete injuries 13 in fact when they are based on a risk of harm that is either ‘certainly impending’ 14 or ‘substantial.’” Id. (quoting I.C. v. Zynga, Inc. 600 F. Supp. 3d 1034 , 1052 (N.D.
15 Cal. 2022 ). 16 TransUnion appears consistent with prior case law in this Circuit holding 17 that theft of personal identifying information is sufficient to establish injury in 18 fact. Abdulaziz v. Twitter, Inc., No. 21-16195, 2024 WL 4688893 , at *1 (9th Cir. 19 Nov. 6, 2024) (citing Zappos, 888 F.3d at 1027 ; Krottner, 628 F.3d at 1140, 1143 ). 20 In Krottner, Starbucks employees brought a putative class action against 21 Starbucks after a laptop containing “the unencrypted names, addresses, and 22 social security numbers of approximately 97,000 Starbucks employees” was 23 stolen. 628 F.3d at 1140 . The Ninth Circuit held that plaintiffs had “alleged a 24 credible threat of real and immediate harm stemming from the theft of a laptop 25 containing their unencrypted personal data.” Id. at 1143 . 26 Several years later, the Ninth Circuit reaffirmed Krottner in Zappos. In the 27 intervening period, the Supreme Court had decided Clapper v. Amnesty Int’l USA,
— 28 —
— 1 —
568 U.S. 398, 416 (2013), raising the question of whether Krottner remained good 2 law. 888 F.3d at 1025 . In Zappos, plaintiffs sued after hackers breached the 3 server of an online retailer. 888 F. 3d at 1023 . The hackers allegedly stole the 4 names, account numbers, passwords, email addresses, billing and shipping 5 addresses, telephone numbers, and credit and debit card information of over 24 6 million Zappos customers. Id. The Ninth Circuit rejected Zappos’s argument that 7 Krottner was no longer good law and held that plaintiffs sufficiently alleged 8 standing based on risk of identity theft. Id. The court found that “[t]he sensitivity 9 of the stolen data in this case [was] sufficiently similar to that in Krottner to 10 require the same conclusion.” Id. at 1027 . 11 Following Krottner and Zappos, district courts in the Ninth Circuit have 12 focused on the nature of the information that was stolen in determining whether 13 a plaintiff faces an imminent risk of harm. Medoff, 2023 WL 4291973 , at *5 14 (collecting cases); see also In re Sequoia Benefits & Ins. Data Breach Litig., No. 2215 CV-08217-RFL, 2024 WL 1091195 , at *1 (N.D. Cal. Feb. 22, 2024). The Ninth 16 Circuit has followed this approach since TransUnion, albeit in unpublished 17 opinions, suggesting that Krottner and Zappos remain good law. See Abdulaziz,
— 18 —
2024 WL 4688893 , at *1; Greenstein v. Noblr Reciprocal Exch., No. 22-17023,
— 19 —
2024 WL 3886977 , at *1 (9th Cir. Aug. 21, 2024) (distinguishing from Krottner 20 and Zappos on the facts because plaintiffs failed to allege that their driver’s 21 license numbers were stolen). 22 Here, Plaintiffs allege that highly sensitive PII, including driver’s license 23 numbers and social security numbers, were stolen during the breach. (ECF No. 24 81 at ¶¶ 227, 233, 229.) Unlike the subset of plaintiffs in TransUnion whose 25 reports were not disseminated, Plaintiffs’ personal information here is already in 26 the hands of hackers. Plaintiffs allege that this PII has already been found on the 27 dark web and, in some cases, already been misused for fraud. (Id. at ¶¶ 271,
— 28 —
1 273.) Drawing all reasonable inferences in Plaintiffs’ favor, these allegations 2 plausibly allege that they face a substantial and imminent risk of identity theft. 3 See Medoff, 2023 WL 4291973 , at *6 (allegations that plaintiff’s name and social 4 security number were published on the dark web after hackers accessed the 5 information through defendant’s computer systems sufficient to allege injury in 6 fact); Greenstein v. Noblr Reciprocal Exch., 585 F. Supp. 3d 1220 , 1227 (N.D. Cal. 7 2022) (“the injury-in-fact requirement will be satisfied when highly sensitive 8 personal data, such as social security numbers and credit card numbers, are 9 inappropriately revealed to the public and increase the risk of immediate future 10 harm to the plaintiff”). The concrete harm that Plaintiffs have suffered in this case 11 is akin to the harm suffered by the group of plaintiffs in TransUnion whose credit 12 reports were actually disseminated to third parties. 13 Accordingly, the Court finds that Plaintiffs have sufficiently alleged a 14 concrete and imminent threat of future harm sufficient to establish Article III 15 injury in fact at the pleadings stage. 16 ii. Actual or Attempted Fraud 17 Some of the named Plaintiffs allege fraud, attempted fraud, identity theft, 18 and misuse of PII. Plaintiff Gedwill alleges that he experienced a phishing attempt 19 during which a stranger sent him money and requested that he return it. (ECF 20 No. 81 at ¶ 71–72.) Caesars argues that this allegation is implausible because 21 “[a] stranger would not need [] Gedwill’s social security number, for instance, in 22 order to send him money.” (ECF No. 91 at 22.) This argument may be appropriate 23 at summary judgment but does not support a facial challenge to standing at the 24 motion to dismiss stage. See Zappos, 888 F.3d at 1028 . 25 iii. Loss of Value of PII 26 Plaintiffs also allege injury in the form of loss of value and control over their 27 PII. (ECF No. 81 at ¶¶ 18, 29, 50, 235–37, 276–85.) Plaintiffs allege that a “robust
— 28 —
1 market exists for stolen PII, which is sold and distributed on the dark web and 2 through illicit criminal networks at specific, identifiable prices.” (Id. at ¶ 277.) 3 Plaintiffs allege that “[a] consumer’s ability to use their PII is encumbered when 4 their identity or credit profile is infected by misuse or fraud,” for example when 5 they are denied credit or unable to open an electronic account. (Id. at ¶ 284.) 6 Consumers also lose their ability to “negotiate sharing their PII for services” and 7 are therefore deprived of that negotiated value. (Id. at ¶ 285.) 8 A court in this district recently upheld diminution in the value of PII as a 9 cognizable theory of damages sufficient to survive a motion to dismiss where 10 plaintiffs alleged “details about the existence of an economic market for selling 11 stolen PII, including the fact that PII can be bought and sold at identifiable prices 12 on established markets.” Smallman v. MGM Resorts Int'l, 638 F. Supp. 3d 1175 , 13 1191 (D. Nev. 2022). Defendants argue that Plaintiffs must allege both the 14 existence of a market for their personal information and an impairment of their 15 ability to participate in that market, citing Pruchnicki v. Envision Healthcare Corp.,
— 16 —
439 F. Supp. 3d 1226 , 1234 (D. Nev. 2020), aff’d, 845 F. App’x 613 (9th Cir. 17 2021). But Smallman and other district courts have rejected Pruchnicki’s 18 formulation of the test as unsupported by Ninth Circuit precedent. Smallman, 19 638 F. Supp. 3d at 1190 (collecting cases). 20 The Court declines to adopt Defendants’ interpretation of the pleading 21 requirements. Plaintiffs have plausibly alleged injury in the form of diminution in 22 value of PII by alleging the existence of a market for their stolen personal 23 information and need not also allege an impairment of their ability to participate 24 in that market. See Smallman, 638 F. Supp. 3d at 1191. 25 iv. Overpayment Theory 26 Plaintiffs allege that they suffered injury when they “overpaid for Caesars’ 27 services that should have been—but were not—accompanied by adequate data
— 28 —
1 security.” (ECF No. 81 at ¶ 287.) Plaintiffs allege that, had they known about 2 Caesars’ deficient data security practices, “they would not have stayed at Caesars 3 properties or would have paid less than they did for their rooms.” (Id. at ¶ 290.) 4 Caesars argues that this theory fails because only six of the named Plaintiffs are 5 alleged to have stayed in Caesars’ hotels and the remainder participated in a free 6 rewards program. (ECF No. 91 at 24.) Caesars also argues that Plaintiffs are 7 required to demonstrate that the price incorporated a particular sum that was 8 understood by both parties to be allocated towards the protection on customer 9 data. (Id.) 10 Plaintiffs point to Smallman, where the court acknowledged that “courts 11 are divided on the level of detailed factual allegation required to show that data 12 security was part of the bargain” but found more persuasive “the line of cases 13 that accept at the pleading stage more general factual allegations about the 14 plaintiff’s expectations for data security and the contours of the parties’ bargain.” 15 638 F. Supp. 3d at 1190 (citing In re Intel Corp. CPU Marketing, Sales Practices 16 and Products Liability Litigation, No. 3:18-2828, 2020 WL 1495304 , at *8 (D. Or.
17 Mar. 27 , 2020)). Following Smallman, this Court considers, but does not find 18 persuasive, cases that “requir[e] allegations of a particular sum of the purchase 19 price being explicitly allocated for data security.” Id. (internal quotation marks 20 and citation omitted). 21 Plaintiffs do not respond to Caesars’ argument that only six of the named 22 Plaintiffs are alleged to have paid for a room at Caesars. And both cases Plaintiffs 23 rely upon, Bowen v. Energizer Holdings, Inc., 118 F.4th 1134, 1145 (9th Cir. 2024) 24 and Smallman, 638 F. Supp. 3d at 1189–90, involved allegations of payments for 25 products (as opposed to participation in free rewards programs). The Court finds 26 that only those Plaintiffs who allege that they paid for Caesars’ hotel rooms, and 27 not those who merely signed up for the free rewards program, have alleged injury
— 28 —
1 in fact under this theory of harm. 2 v. Mitigation Efforts 3 Caesars argues that Plaintiffs cannot establish injury based on out-of4 pocket costs or time spent on mitigation because to do so would be to 5 “manufacture standing merely by inflicting harm on themselves based on their 6 fears of hypothetical future harm that is not certainly impending.” (ECF No. 91 7 at 21 (citing Clapper, 568 U.S. at 416 )). But as courts have found in other data 8 breach lawsuits, “because the risk of harm here is a sufficient injury, the 9 allegations of mitigation injuries made by these Plaintiffs are also sufficient.” In 10 re Equifax Inc. Customer Data Sec. Breach Litig., 999 F.3d 1247, 1263 (11th Cir. 11 2021); see also In re Yahoo! Inc. Customer Data Sec. Breach Litig., No. 16-MD12 02752-LHK, 2017 WL 3727318 , at *13 (N.D. Cal. Aug. 30, 2017) (allegations of 13 out-of-pocket mitigation expenses, including payment for credit monitoring 14 services, sufficient to allege injury arising from data breaches); In re Adobe Sys., 15 Inc. Priv. Litig., 66 F. Supp. 3d 1197, 1217 (N.D. Cal. 2014) (costs incurred to 16 mitigate future identity theft sufficient to establish injury in fact). 17 2. Traceability 18 Caesars next (briefly) contends that Plaintiffs cannot establish Article III 19 standing because Plaintiffs’ injuries are not “fairly traceable” to the data breach. 20 (ECF No. 91 at 20–22.) 21 To establish traceability, “there must be a causal connection between the 22 injury and the conduct complained of—the injury has to be fairly traceable to the 23 challenged action of the defendant, and not the result of the independent action 24 of some third party not before the court.” Lujan, 504 U.S. at 560 . “Proximate 25 causation is not a requirement of Article III standing, which requires only that 26 the plaintiff’s injury be fairly traceable to the defendant's conduct.” Lexmark Int'l, 27 Inc. v. Static Control Components, Inc., 572 U.S. 118, 134 (2014).
— 28 —
1 Plaintiffs allege that, after the breach, their information was misused or 2 exploited to commit fraud. (ECF No. 81 at ¶¶ 271, 273.) Caesars’ argument that 3 Plaintiffs must allege that the breach included credit card or banking information 4 to be traceable to fraud attempts is unpersuasive. Given the scope and sensitivity 5 of the stolen PII (social security and driver’s license numbers), it is reasonable to 6 infer that such information could plausibly have been used to commit the fraud 7 and other injuries that Plaintiffs allege. See In re Sequoia, 2024 WL 1091195 , at 8 *2 (plaintiffs sufficiently alleged that fraud was traceable to data breach that 9 exposed sensitive data, though not banking or credit card information); see also 10 In re Marriott Int'l, Inc., Customer Data Sec. Breach Litig., 440 F. Supp. 3d 447 , 11 467 (D. Md. 2020) (injuries of fraudulent charges on personal checking account 12 and opening of “accounts for credit cards, consolidated loans, consumer 13 accounts, and other lines of credit” were fairly traceable to data breach, even 14 where no social security numbers or banking information was accessed). 15 B. Standing for Injunctive Relief 16 Caesars next challenges Plaintiffs’ standing to seek injunctive relief, 17 arguing that they cannot show a threat of repeated injury and again pointing to 18 TransUnion. (ECF No. 91 at 26.) Plaintiffs respond that they are seeking injunctive 19 relief to address the harms caused by Caesars’ inadequate security protocols. 20 (ECF No. 96 at 21.) 21 Plaintiffs allege that Caesars’ inadequate security protocols remain in place 22 today and that Caesars continues to hold their data. (ECF No. 81 at ¶¶ 304–305, 23 306.) These allegations are sufficient, at this stage in the proceedings, to 24 demonstrate standing for injunctive relief. See Baton v. Ledger SAS, 740 F. Supp. 25 3d 847, 881 (N.D. Cal. 2024) (standing to seek injunctive relief as to inadequate 26 security where plaintiffs alleged that they remain at imminent risk that further 27 compromises of their personal information will occur in the future); Stallone v.
— 28 —
1 Farmers Group, Inc., No. 221CV01659GMNVCF, 2022 WL 10091489 , at *9 (D. 2 Nev. Oct. 15, 2022) (standing for injunctive relief where plaintiffs alleged that 3 without injunctive relief, Plaintiff's PII could be “obtained again in the same 4 unauthorized manner”). 5 C. Damages for Common Law Claims 6 Caesars argues that Plaintiffs’ common law claims fail because their alleged 7 harms are too speculative, relying on the same arguments that it makes with 8 regard to standing. (ECF No. 91 at 26–27.) Caesars primarily relies on its 9 arguments regarding injury in fact, and only specifically challenges (as an 10 example) mitigation expenses. But courts in this Circuit have acknowledged that, 11 at the motion to dismiss stage, allegations of lost time are plausible allegations of 12 damages. Stasi v. Inmediata Health Grp. Corp., 501 F. Supp. 3d 898 , 918 (S.D.
13 Cal. 2020 ); see also In re Solara Med. Supplies, LLC Customer Data Sec. Breach
14 Litig., 613 F. Supp. 3d 1284, 1296 (S.D. Cal. 2020) (“[i]ncreased time spent 15 monitoring one’s credit and other tasks associated with responding to a data 16 breach have been found by other courts to be specific, concrete, and non17 speculative”). 18 At this early stage of litigation, Plaintiffs allege plausible damages in the 19 form of actual and attempted fraud and identity theft, loss of value of PII, and 20 lost time. 21 D. Negligence 22 Under Nevada law, a negligence claim requires “four elements: (1) the 23 existence of a duty of care, (2) breach of that duty, (3) legal causation, and (4) 24 damages.” Sanchez ex rel. Sanchez v. Wal-Mart Stores, Inc., 221 P.3d 1276 , 1280 25 (Nev. 2009). Caesars argues that Plaintiffs do not adequately allege duty, breach, 26 or damages. (ECF No. 91 at 27–34.)
— 27 —
— 28 —
1 1. Duty 2 Caesars argues that it had no duty to protect Plaintiffs’ PII “from being 3 exposed to cybercriminals.” (ECF No. 91 at 27.) This is not an accurate 4 description of Plaintiffs’ allegations. Plaintiffs contend that Caesars owed 5 Plaintiffs a duty “to protect their PII once Caesars collected it.” (ECF No. 96 at 6 22.) Plaintiffs allege that Caesars had “a duty to exercise reasonable care in 7 safeguarding, securing, and protecting Class Members’ PII.” (ECF No. 81 at ¶ 8 328.) Plaintiffs allege that Caesars’ duty arose from, among other things, the 9 special relationship between Caesars and its customers, the FTC Act, state law, 10 industry standards, and representations made to Plaintiffs. (Id. at ¶ 219.) 11 District courts have found comparable allegations sufficient to survive 12 motions to dismiss negligence claims. See, e.g., Smallman, 638 F. Supp. 3d at 13 1188 (defendant breached duty of care in manner of collecting, maintaining, and 14 controlling customers’ sensitive personal and financial information); In re 15 Accellion, Inc. Data Breach Litig., 713 F. Supp. 3d 623 , 634 (N.D. Cal. 2024), 16 reconsideration denied, No. 21-CV-01155-EJD, 2024 WL 4592367 (N.D. Cal. Oct. 17 28, 2024) (California recognizes a duty by companies to take reasonable steps to 18 protect all sensitive information they obtain from individuals); In re Equifax, Inc., 19 Customer Data Sec. Breach Litig., 362 F. Supp. 3d 1295, 1325 (N.D. Ga. 2019) 20 (duty of care to safeguard personal information in its custody where defendants 21 “knew of a foreseeable risk to its data security systems but failed to implement 22 reasonable security measures”); Stasi, 501 F. Supp. 3d at 914 (collecting cases). 23 Plaintiffs have adequately alleged that the risk of harm was foreseeable. 24 They allege that, just months before the data breach, Caesars told investors that 25 cyberattacks were a significant risk factor. (ECF No. 81 at ¶ 250.) They allege that 26 Caesars was aware that several of its competitors had experienced data breaches 27 in recent years, and that as many as 15 to 20 percent of data breaches occur
— 28 —
1 within the hospitality industry. (Id. at ¶¶ 244–45.) Accordingly, at this stage in 2 the proceedings, Plaintiffs plausibly allege duty. 3 Caesars also argues that Plaintiffs’ claim for negligence per se does not 4 supply duty. (ECF No. 91 at 29–30.) Because Plaintiffs have adequately alleged 5 duty and because Caesars does not move to dismiss the negligence per se claim, 6 the Court does not address this argument. 7 2. Breach 8 Caesars argues that Plaintiffs have not alleged breach because they have 9 not specified exactly how Caesars’ data security measures were inadequate. (ECF 10 No. 91 at 30–31.) Plaintiffs allege that Caesars retained their PII for longer than 11 necessary, thus failing to adhere to standard purging and data minimization 12 processes. (ECF No. 81 at ¶¶ 396, 253.) Plaintiffs allege that Caesars 13 “intentionally failed to encrypt the PII while it was store on Caesars’ server.” (Id. 14 at ¶ 430.) And Plaintiffs allege that Caesars allowed an intruder to download the 15 PII five days after it noticed the suspicious activity. (Id. at ¶ 225.) At this stage of 16 the proceedings, Plaintiffs have sufficiently alleged that Caesars breached the 17 duty of care owed to them. See Smallman, 638 F. Supp. 3d at 1188. 18 3. Economic Loss Doctrine 19 Caesars argues that Plaintiffs’ damages are barred by the economic loss 20 doctrine. (ECF No. 91 at 31–32.) Plaintiffs argue that the economic loss doctrine 21 is not applicable because they allege non-economic damages, because Caesars’ 22 duty is based on statutory obligations, and because a special relationship exists. 23 (ECF No. 96 at 25.) 24 “Under the economic loss doctrine ‘there can be no recovery in tort for 25 purely economic losses.’” Urban Outfitters, Inc. v. Dermody Operating Co., LLC,
— 26 —
572 F. Supp. 3d 977 , 995 (D. Nev. 2021) (quoting Calloway v. City of Reno, 993
27 P.2d 1259 , 1263 (Nev. 2000)). But “[i]n the data breach context, courts within the
— 28 —
1 Ninth Circuit have found that an individual’s loss of control over the use of their 2 identity due to a data breach and the accompanying impairment in value of PII 3 constitutes non-economic harms.” Smallman, 638 F. Supp. 3d at 1188 (collecting 4 cases). 5 Plaintiffs have alleged loss of control over use of their identity, loss of time, 6 and imminent risk of identity theft, all of which are non-economic harms. 7 Accordingly, the economic loss doctrine does not bar Plaintiffs’ negligence claims. 8 E. Implied Contract 9 Caesars argues that Plaintiffs’ claim for breach of implied contract fails 10 because Plaintiffs have not pled the existence of an implied contract, breach, or 11 damages. (ECF No. 91 at 32–33.) Specifically, Caesars argues that Plaintiffs fail 12 to identity any specific promise that was allegedly breached and fail to explain 13 how the promise was breached. (Id.) Plaintiffs argue that the existence of an 14 implied contract is a question of fact that the Court should decline to address on 15 a Rule 12(b)(6) motion. (ECF No. 96 at 28–30.) 16 Nevada law requires the plaintiff in a breach of contract action to show: (1) 17 the existence of a valid contract; (2) a breach by the defendant; and (3) damage 18 as a result of the breach. Saini v. Int'l Game Tech., 434 F. Supp. 2d 913 , 919–20 19 (D. Nev. 2006) (citing Richardson v. Jones, 1 Nev. 405 (Nev. 1865)). Although the 20 terms of an implied contract are manifested by conduct rather than written words 21 as in an express contract, both “are founded upon an ascertainable agreement.” 22 Smith v. Recrion Corp., 541 P.2d 663 , 664–65 (Nev. 1975). 23 At this stage, Plaintiffs have adequately stated a claim for breach of implied 24 contract. Plaintiffs allege that Caesars required that Plaintiffs provide their PII to 25 participate in the rewards program. (ECF No. 81 at ¶ 4.) Plaintiffs allege that they 26 provided their PII to Caesars with the understanding that Caesars would take 27 adequate data security measures. (Id. at ¶ 214.) Plaintiffs allege that this mutual
— 28 —
1 understanding was based in part on Caesars’ privacy policy, which stated that 2 Caesars “maintain[s] physical, electronic and organizational safeguards that 3 reasonably and appropriately protect against the loss, misuse and alteration of 4 the information under [their] control.” (Id. at ¶ 215–16.) As to breach, Plaintiffs 5 allege that Caesars did not take adequate data security measures. And for the 6 reasons set forth above, supra Part III.C, Plaintiffs have adequately alleged 7 damages. Accordingly, the Court denies Caesars’ motion to dismiss the implied 8 contract claim. 9 F. Unjust Enrichment 10 Caesars argues that Plaintiffs’ unjust enrichment claim fails for two 11 reasons. First, Caesars contends that Plaintiffs cannot pursue equitable remedies 12 without showing that they lack an adequate remedy at law. (ECF No. 91 at 34– 13 35.) Second, Caesars contends that Plaintiffs fail to plead that they conferred any 14 benefit on Caesars, arguing that PII does not have any independent monetary 15 value. (Id.) Plaintiffs respond that they do not have an adequate remedy at law 16 because Caesars retains their information and because they are seeking 17 injunctive relief requiring Caesars to improve its data security systems. (ECF No. 18 96 at 30–31.) Plaintiffs also point to their allegations that PII has independent 19 monetary value. (Id.) 20 In Nevada, the elements of an unjust enrichment claim are: “a benefit 21 conferred on the defendant by the plaintiff, appreciation by the defendant of such 22 benefit, and acceptance and retention by the defendant under circumstances 23 such that it would be inequitable for him to retain the benefit without payment 24 of the value thereof.” Leasepartners Corp. v. Robert L. Brooks Tr. Dated Nov. 12, 25 1975, 942 P.2d 182, 187 (Nev. 1997). “An action based on a theory of unjust 26 enrichment is not available when there is an express, written contract, because 27 no agreement can be implied when there is an express agreement.” Id.
— 28 —
1 Plaintiffs allege that they conferred a benefit on Caesars in the form of their 2 valuable PII and that Caesars appreciated that benefit without employing 3 adequate data security measures. (ECF No. 81 at ¶¶ 357–68.) Plaintiffs allege that 4 they have no adequate remedy at law because Caesars retains their PII, exposing 5 Plaintiffs to a risk of future data breaches. (Id. at ¶ 366.) Cf Smallman, 638 F. 6 Supp. 3d at 1198 (dismissing plaintiffs’ unjust enrichment claim because 7 plaintiffs did not allege lack of adequate remedy at law). And Plaintiffs allege that 8 PII has independent monetary value, as discussed above. See supra Part 9 III.A.1.iii. 10 Accordingly, the Court denies Caesars’ motion to dismiss Plaintiffs’ unjust 11 enrichment claim. 12 G. Statutory Claims 13 Caesars argues that Plaintiffs’ consumer protection claims fail because 14 they are insufficiently pled under Rule 9(b), and that Plaintiffs’ data breach 15 notification statute claims fail because they do not allege cognizable harm. (ECF 16 No. 91 at 35–41.) Caesars separately challenges several individual statutory 17 claims. (Id. at 41–53.) 18 1. Consumer Protection Claims 19 Caesars argues that Plaintiffs’ consumer protection (or “misrepresentation20 based”) claims (Counts IV, V, VI, IX, X, XI, XII, XIII, XV, XVI, XVIII) should be 21 dismissed for failure to comply with Rule 9(b)’s heightened pleading standard. 22 (ECF No. 91 at 35–41.) Plaintiffs contend that Rule 9(b) does not apply because 23 Plaintiffs allege only negligence-based or reckless conduct, and in the alternative 24 that Plaintiffs have met Rule 9(b) pleading requirements. (ECF No. 96 at 31–33.) 25 Plaintiffs also argue that Caesars’ tactic of arguing in the aggregate “elides 26 important distinctions between the statutes [and] their varying pleading 27 requirements.” (ECF No. 96 at 31.) The Court agrees.
— 28 —
1 Assuming but not deciding that Rule 9(b) applies to all nine statutes, 2 Plaintiffs’ allegations meet the particularity requirements of Rule 9(b). Plaintiffs 3 allege that Caesars knew its data security practices were deficient (ECF No. 81 at 4 ¶¶ 252–68), that Caesars knew the hotel industry is a frequent target of 5 cyberattacks (Id. at ¶¶ 243–51), and that Caesars failed to disclose its deficient 6 management of PII (Id. at ¶¶ 239-42). Plaintiffs sufficiently allege that Caesars’ 7 failure to disclose its data security deficiencies to Plaintiffs constitutes a knowing 8 omission. See Smallman, 638 F. Supp. 3d at 1200. 9 Accordingly, the Court denies Caesars’ motion dismiss Plaintiffs’ consumer 10 protection claims. 11 2. Data Breach Notification Statute Claims 12 Caesars argues that Plaintiffs’ data breach notification statutes claims 13 (Counts VII, VIII, and XVII) should be dismissed for failure to allege unreasonable 14 delay or harm caused by the delay. (ECF No. 91 at 40–41.) Plaintiffs argue that 15 they sufficiently allege cognizable and incremental harm. (ECF No. 96 at 33–34.) 16 The California, Illinois, and Virginia data breach notification statutes 17 require companies to notify individuals of data breaches without unreasonable 18 delay. See In re Ambry Genetics Data Breach Litig., 567 F. Supp. 3d 1130 , 1149 19 (C.D. Cal. 2021) (the CCRA requires businesses doing business in California to 20 make disclosure of data breaches “in the most expedient time possible and 21 without unreasonable delay”) (quoting Cal. Civ. Code § 1798.82 ); 815 Ill. Comp.
22 Stat. 530 /10(a) (businesses must provide a “disclosure notification ... in the most 23 expedient time possible and without unreasonable delay”); Va. Code. § 18.224 186.6(B) (notice of the data breach must occur “without unreasonable delay”). 25 Plaintiffs allege that Caesars’ nearly two-week delay in notifying states’ 26 attorneys’ generals and in sending individual notices “exacerbated harm to Class 27 Members by preventing them from taking steps to mitigate Caesars failures and
— 28 —
1 trying to protect themselves.” (ECF No. 81 at ¶ 230.) Plaintiffs also allege that 2 Caesars still has not disclosed several important facts, including how many 3 rewards program members were affected by the breach, what information was 4 taken, and what steps Caesars has taken to ensure that such an attack does not 5 happen again. (Id. at ¶ 232.) 6 Courts have found such allegations sufficient under the California, Illinois, 7 and Virginia timely disclosure statutes. See In re Solara, 613 F. Supp. 3d at 1300 8 (plaintiffs adequately alleged incremental harm under California Consumer 9 Records Act as a result of delay where five-month delay prevented them from 10 taking steps to protect personal information); In re Arthur J. Gallagher Data 11 Breach Litig., 631 F. Supp. 3d 573 , 590 (N.D. Ill. 2022) (denying motion to dismiss 12 claims under Illinois and California data notification statutes because allegations 13 of post-remedial actions and harm from the breach make it “plausible to conclude 14 that Defendants’ more timely disclosure would have prevented additional 15 incremental injury”); In re Cap. One Consumer Data Sec. Breach Litig., 488 F. 16 Supp. 3d 374, 417 (E.D. Va. 2020) (“additional monitoring costs” plausibly fall 17 within the scope of the Virginia Personal Information Breach Notification Act). 18 Accordingly, the Court denies Caesars’ motion to dismiss Plaintiffs’ data 19 breach notification statute claims. 20 3. Texas Deceptive Practices Act 21 Caesars argues that Plaintiff Huddleston did not comply with the Texas 22 Deceptive Practices Act’s (“DTPA”) pre-suit written notice requirements because 23 notice was given too late and did not provide sufficient detail. (ECF No. 91 at 41– 24 42.) Under the DTPA, a plaintiff must give written notice at least 60 days before 25 filing suit “advising the person in reasonable detail of the consumer’s specific 26 complaint and the amount of economic damages . . . .” Tex. Bus. & Com. Code 27 Ann. § 17.505. Here, Plaintiffs provided written notice of the lawsuit
— 28 —
1 approximately thirty days before filing the Consolidated Class Action Complaint. 2 (ECF No. 96-1.) The letter noted that counsel was already aware of the allegations 3 from previously filed complaints and that it was providing the letter as “additional 4 notice.” (Id. at 4.) Those complaints were filed more than 90 days before the 5 Consolidated Class Action Complaint. (ECF No. 81 at ¶ 560.) 6 “The notice requirement is intended to give the defendant an opportunity 7 to make a settlement offer and minimize litigation expense.” Star Houston, Inc. v. 8 Kundak, 843 S.W.2d 294, 297 (Tex. App. 1992). Caesars has failed to show any 9 harm from Huddleston’s alleged technical violation of the sixty-day notice 10 requirement. See id. The Court therefore declines to dismiss the TDPA claim or 11 abate the lawsuit. 12 4. Nevada Consumer Fraud Act 13 Plaintiffs allege two violations of two subsections of NRS § 598 (the Nevada 14 Deceptive Trade Practices Act (“NDTPA”)) under their Nevada Consumer Fraud 15 Act (“NCFA”) claim. (ECF No. 81 at ¶¶369–381.) The NCFA provides that an action 16 may be brought by any person who is a victim of consumer fraud, and defines 17 “consumer fraud” to mean, among other things, “[a] deceptive trade practice as 18 defined in NRS 598.0915 to 598.0925, inclusive.” NRS 41.600(1)(e). Plaintiffs 19 allege a violation of that statute under two definitions of “deceptive trade 20 practice.” 21 A person engages in a “deceptive trade practice” when they knowingly “fail[] 22 to disclose a material fact in connection with the sale or lease of goods or 23 services.” NRS 598.0923(1)(b). (ECF No. 81 at ¶ 371.) Plaintiffs allege that 24 Caesars violated this provision by failing to disclose the material fact that its data 25 security practices were deficient and that its cloud server security settings were 26 not adequate to protect consumers’ PII. (Id. at ¶ 371.) Caesars argues that this 27 claim fails because Plaintiffs did not allege a duty to disclose, relying on Soffer v.
— 28 —
1 Five Mile Cap. Partners, LLC, No. 2:12-CV-1407 JCM GWF, 2013 WL 638832 (D. 2 Nev. Feb. 19, 2013) and Taddeo v. Taddeo, No. 2:08-CV-01463-KJD, 2011 WL 3 4074433, at *5 (D. Nev. Sept. 13, 2011). But those cases involved claims for 4 common law fraud, not statutory fraud, and “[s]tatutory offenses that sound in 5 fraud are separate and distinct from common law fraud.” Betsinger v. D.R. Horton, 6 Inc., 232 P.3d 433, 436 (Nev. 2010); see Smallman, 638 F. Supp. 3d at 1199. 7 Caesars has therefore failed to show that Plaintiffs are required to demonstrate 8 that Caesars had a duty to disclose. 9 A deceptive trade practice also includes knowingly “violat[ing] a state or 10 federal statute or regulation relating to the sale or lease of goods or services.” NRS 11 598.0923(1)(c). Plaintiffs allege that Caesars violated this provision by breaching 12 several federal and state statutes, including NRS 603A.210(1), which requires 13 that “[a] data collector that maintains records which contain personal information 14 of a resident of this States shall implement and maintain reasonable security 15 measures to protect those records from unauthorized access, acquisition, 16 destruction, use, modification or disclosure.” NRS 603A.210(1). Caesars argues 17 that Plaintiffs must plead with particularity how the facts of this case pertain to 18 that specific statute, but the only case it relies upon for that proposition, Baba v. 19 Hewlett-Packard Company, discusses California’s UCL. No. C 09-05946 RS, 2010
20 WL 2486353 , at *6 (N.D. Cal. June 16, 2010). Caesars does not cite to any Nevada 21 law requiring such specificity at the pleading stage. The NDTPA is a “remedial 22 statutory scheme” which is afforded a “liberal construction.” Yip v. Bank of Am., 23 N.A., No. 2:21-CV-01254-ART-EJY, 2024 WL 3742910 , at *12 (D. Nev. Aug. 9, 24 2024) (citing Poole v. Nevada Auto Dealership Invs., LLC, 449 P.3d 479 , 485 (Nev.
25 App. 2019 ) and R.J. Reynolds Tobacco Co. v. Eighth Jud. Dist. Ct. in & for Cnty. of 26 Clark, 514 P.3d 425, 430 (Nev. 2022)). Plaintiffs allege that Caesars is a data 27 collector that maintains records of in-state residents, and that it failed to
— 28 —
1 implement reasonable security measures. The Court therefore denies Caesars’ 2 motion to dismiss on this ground. 3 Plaintiffs also allege that Caesars’ violation of the FTC Act constitutes a 4 violation of the NDTPA under NRS 598.0923(1)(c). (ECF No. 81 at ¶ 375.) Caesars 5 argues again that this allegation is not specific enough. For the same reasons, 6 the Court denies Caesars’ motion to dismiss on this ground. 7 5. California Statutory Claims 8 Caesars argues that California Plaintiffs’ claims under California’s Unfair 9 Competition Law (“UCL”) and the Consumer Legal Remedies Act (“CLRA”) fail for 10 lack of statutory standing and failure to state a claim. 11 i. Standing 12 Caesars contends that Plaintiffs lack standing under the UCL and CLRA 13 because Plaintiffs fail to allege “lost money or property” (as required for the UCL) 14 or “economic injury” (as required for the CLRA). (ECF No. 91 at 44–45.) 15 To satisfy the statutory standing requirement under the UCL, a plaintiff 16 must merely suffer an injury in fact that is an “economic injury.” Calhoun v. 17 Google LLC, 526 F. Supp. 3d 605 , 636 (N.D. Cal. 2021) (citing Kwikset Corp. v. 18 Superior Court, 51 Cal. 4th 310 , 321–22, (2011)). “[A]ny plaintiff who has standing 19 under the UCL’s . . . ‘lost money or property’ requirement will, a fortiori, have 20 suffered ‘any damage’ for purposes of establishing CLRA standing.” Hinojos v. 21 Kohl’s Corp., 718 F.3d 1098, 1108 (9th Cir. 2013), as amended on denial of reh’g 22 and reh’g en banc (July 8, 2013). 23 Plaintiffs point to allegations of loss of value of PII, benefit of the bargain 24 damages, including overpayment for hotel rooms, out-of-pocket costs in 25 mitigation efforts, and the purchase of identity protection services. (ECF No. 96 26 at 37–38.) These allegations are sufficient to establish standing under the UCL 27 and CLRA. See Smallman, 638 F. Supp. 3d at 1202 (allegations that plaintiffs
— 28 —
1 paid more for hotel rooms as a result of defendant’s omissions regarding data 2 security policies sufficient to establish standing under the UCL); In re Vizio, Inc., 3 Consumer Priv. Litig., 238 F. Supp. 3d 1204, 1219 (C.D. Cal. 2017) (allegations 4 that plaintiffs would have paid less for products had defendant properly disclosed 5 its consumer data collection and disclosure practices cognizable under UCL and 6 CLRA); In re Yahoo! Inc., 2017 WL 3727318 , at *21 (benefit of the bargain losses 7 sufficient to allege standing under the UCL); Calhoun, 526 F. Supp. 3d at 636 8 (loss of personal information is economic injury conferring standing under the 9 UCL). 10 ii. UCL 11 Caesars argues that Plaintiffs have failed to allege reliance, which is 12 required for claims under the fraud prong of the UCL. (ECF No. 91 at 45–46); In 13 re Tobacco II Cases, 207 P.3d 20, 39 (Cal. 2009). 14 “[A]t the motion to dismiss stage, actual reliance . . . is inferred from the 15 misrepresentation of a material fact.” Moore v. Mars Petcare US, Inc., 966 F.3d 16 1007, 1021 (9th Cir. 2020). “Whether a misrepresentation is sufficiently material 17 to allow for an inference of reliance is generally a question of fact that cannot be 18 decided at the motion to dismiss stage.” Id. Plaintiffs allege that Caesars neglected 19 specific data security practices, explain what Caesars should have done, and 20 allege that Caesars misrepresented that it would protect Plaintiffs’ PII. (ECF No. 21 81 at ¶¶ 394, 395, 398–404.) These allegations are sufficient to survive a motion 22 to dismiss. 23 The Court similarly rejects Caesars’ argument that Plaintiffs have failed to 24 show unlawful, unfair, or fraudulent conduct as premature. See Broomfield v. 25 Craft Brew All., Inc., No. 17-CV-01027-BLF, 2017 WL 3838453 , at *5 (N.D. Cal. 26 Sept. 1, 2017) (“the deceptive nature of a business practice under California’s 27 consumer protection statutes is usually a question of fact that is inappropriate
— 28 —
1 for decision on . . . a motion to dismiss”). 2 Caesars also argues that Plaintiffs’ UCL claim should be dismissed because 3 they do not plead that they lack an adequate remedy at law. (ECF No. 91 at 46.) 4 The Court already considered and rejected this argument above. See supra Part 5 III.F. 6 iii. CLRA 7 Caesars asserts that Plaintiffs’ CLRA claim fails for the same reasons as 8 the UCL claim. (ECF No. 91 at 48.) For the same reasons, the Court denies the 9 motion to dismiss this claim. 6. Pennsylvania Unfair Trade Practice and Consumer
— 10 —
Protection Law 11 Caesars argues that Plaintiffs Smith and Katz’s claims under the 12 Pennsylvania Unfair Trade Practice and Consumer Protection Law (“UTPCPL”) 13 should be dismissed for failure to establish any “ascertainable loss of money or 14 property,” as required under the UTPCPL. Benner v. Bank of Am., N.A., 917 F. 15 Supp. 2d 338, 359 (E.D. Pa. 2013); (ECF No. 91 at 48–49.) Both Plaintiffs allege 16 loss of value of their PII (ECF No. 81 at ¶¶ 170, 179), “which serves as [a] form of 17 lost property” under the UTPCPL.” Opris v. Sincera Reprod. Med., No. CV 21-3072,
— 18 —
2022 WL 1639417 , at *13 (E.D. Pa. May 24, 2022). That is sufficient to survive a 19 motion to dismiss. 20 7. Virginia Consumer Protection Act 21 Caesars argues that Plaintiff Lackey’s Virginia Consumer Protection Act 22 (“VCPA”) claim should be dismissed, in addition to its generalized arguments 23 about particularity, for failure to plead “actual damages,” and because Lackey 24 cannot bring the claim on behalf of a class. (ECF No. 91 at 49.) 25 First, the VCPA’s loss requirement is “expansive” compared to other state 26 consumer protection statutes. In re Gen. Motors LLC Ignition Switch Litig., 339 F. 27 Supp. 3d 262, 332 (S.D.N.Y. 2018); Attias v. CareFirst, Inc., 518 F. Supp. 3d 43 ,
— 28 —
1 56 (D.D.C. 2021). Plaintiff Lackey pleads the loss of value of PII, benefit of the 2 bargain damages, and mitigation efforts. (ECF No. 81 at ¶¶ 199, 200.) These 3 allegations are sufficient at this stage. 4 Second, “[t]he question of whether a class action may be maintained with 5 respect to the [VCPA] is proper to consider at the class certification stage rather 6 than in considering a motion to dismiss.” Mouzon v. Radiancy, Inc., 200 F. Supp. 7 3d 83, 90 (D.D.C. 2016). 8 8. Minnesota Statutory Claims 9 Caesars argues that the Minnesota Plaintiffs fail to state a claim under the 10 Minnesota Deceptive Trade Practices Act (“MDTPA”) and Minnesota Consumer 11 Fraud Act (“MCFA”) because they do not allege deceptive or misleading practices 12 in connection with the sale or advertisement of “merchandise.” (ECF No. 91 at 13 50.) Plaintiffs point to the broad statutory definition of “merchandise,” which 14 includes, among other things, “services.” (ECF No. 96 at 44); Minn. Stat. § 15 325F.68(2). To the extent that Caesars argues that “the only viable data breach 16 class action lawsuits would be those asserting claims against companies that sell 17 data security services,” the Court agrees with Plaintiffs that “such an argument 18 would be nonsensical. Perdue v. Hy-Vee, Inc., 455 F. Supp. 3d 749 , 772–73 (C.D.
19 Ill. 2020 ). 20 Caesars argues that the MDTPA claim also fails because the MDTPA only 21 permits injunctive relief. Plaintiffs have plausibly pled likelihood of future harm 22 and seek injunctive relief, as addressed above. Supra Part III.B. Accordingly, the 23 Court denies Caesars’ motion to dismiss the Minnesota Plaintiffs’ statutory 24 claims. 25 9. Illinois Statutory Claims 26 Caesars argues that Plaintiffs’ claims under the Illinois Deceptive Trade 27 Practices Act (“IDTPA”) and Illinois Consumer Fraud Act (“ICFA”) fail for the same
— 28 —
1 reasons. (ECF No. 91 at 50.) 2 For the reasons set forth above, the Illinois Plaintiffs have plausibly pled 3 likelihood of future harm based on Caesars’ continued possession of their data. 4 They have also alleged actual damages under ICFA based on loss of value of PII, 5 mitigation efforts, and loss of time. And they have alleged that they received 6 communication from Caesars. (ECF No. 81 at ¶¶ 236–37.) Accordingly, the Court 7 denies Caesars’ motion to dismiss the Illinois Plaintiffs’ statutory claims. 8 10. New York General Business Law Claim 9 Caesars finally argues that the New York Plaintiffs’ New York General 10 Business Law (“GBL”) claim should be dismissed for failure to identify a 11 misleading representation or omission by Caesars. (ECF No. 91 at 52.) 12 Section 349 of the GBL prohibits “[d]eceptive acts or practices in the 13 conduct of any business, trade or commerce or in the furnishing of any service.”
— 14 —
N.Y. Gen. Bus. § 349 (a). To state a GBL claim, the New York Plaintiffs must allege 15 (1) that Caesars’ “act or practice was consumer-oriented,” (2) that the act or 16 practice “was misleading in a material way,” and (3) that plaintiff “suffered injury 17 as a result of the deceptive act.” Stutman v. Chem. Bank, 731 N.E.2d 608 , 611 18 (N.Y. 2000). Caesars challenges only the second element. Plaintiffs have satisfied 19 this element by alleging that Caesars misrepresented that it would protect their 20 PII, and that Caesars failed to comply with statutory duties regarding the security 21 and privacy of Plaintiffs’ personal information, including duties imposed by the 22 FTC Act, 15 U.S.C. § 45 . See Smallman, 638 F. Supp. 3d at 1206 (declining to 23 dismiss claims based on similar allegations); In re Marriott Int'l, Inc., 440 F. Supp. 24 3d at 493 (duties imposed by the FTC Act serve as predicate for violations of the 25 GBL). Accordingly, the Court denies Caesars’ motion to dismiss Plaintiffs’ GBL 26 claim.
— 27 —
— 28 —
1 IV. CONCLUSION 2 The Court therefore DENIES Defendant’s to dismiss (ECF No. 91). 3 The Court GRANTS Plaintiffs’ motion for leave to file supplemental 4 || authorities (ECF No. 114).
— 5 —
6 DATED: August 15, 2025
— 7 —
8 Awe jloset qn 9 ANNER.TRAUM 10 UNITED STATES DISTRICT JUDGE
— 11 —
— 12 —
— 13 —
— 14 —
— 15 —
— 16 —
— 17 —
— 18 —
— 19 —
— 20 —
— 21 —
— 22 —
— 23 —
— 24 —
— 25 —
— 26 —
— 27 —
— 28 —
— 29 —
