In a consolidated putative class action arising out of an alleged data breach, In re A-Line Staffing Solutions Data Security Incident Litigation, Case No. 24-cv-11917 (E.D. Mich. May 27, 2026), a Michigan district court declined to dismiss the complaint under Rule 12(b)(1) but granted the defendant’s motion to dismiss without prejudice on Rule 12(b)(6) grounds. The decision exemplifies a theme in such data breach cases: even where plaintiffs clear the Article III standing hurdle, their allegations may still fail to state a claim.
Plaintiffs in this case sued their former employer, a third-party contracting service, alleging that a ransomware attack against the company had compromised and subsequently published their personally identifiable information (PII) on the dark web. The complaint included elements typical of such data breach cases, including claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, and declaratory relief based on allegations that defendant failed to appropriately safeguard plaintiffs’ PII. Plaintiffs further alleged, among other things, that they had lost time and money on monitoring and mitigation efforts and incurred a substantially increased risk of fraud, with one plaintiff alleging that he had to close multiple accounts due to unspecified fraudulent activity following the breach.
Defendant moved to dismiss under both Rule 12(b)(1) and 12(b)(6). Following Galaria v. Nationwide Mutual Insurance, 663 F. App’x 384 (6th Cir. 2016) and its progeny, the district court rejected the Rule 12(b)(1) challenge, concluding that plaintiffs had plausibly alleged that bad actors had stolen their PII – even though they did not allege actual publication, misuse, or diminution in the value of their specific information – and that defendant’s lax security enabled the theft. This, the court concluded, was sufficient at the pleading stage to establish both injury-in-fact and traceability – a standard that required “more than speculative but less than but-for” causation.
After finding Article III’s standing requirements satisfied, however, the district court went on to grant defendant’s motion under Rule 12(b)(6). Following its prior decision in another recent data breach case, In re Grede Holdings LLC Data Breach Litigation, 2026 U.S. Dist. LEXIS 29721 (E.D. Mich. 2026), the court explained that plaintiffs had to establish both an “actual” and “present” injury and a “but for” causal link between those injuries and the complained-of breach to plead a negligence claim. The complaint failed to do this because it merely implied causation by pointing to “temporal proximity and correlation” between the breach and plaintiffs’ alleged injuries. Such implications were “too speculative and conclusory” to survive dismissal. The court also dismissed plaintiffs’ other claims, concluding that plaintiffs’ provision of PII to defendant was too “incidental” to establish either the consideration required for an implied contract theory or the “independent benefit” required for unjust enrichment; that plaintiffs had pled no special relationship with defendant that would give rise to a fiduciary duty; that breach of confidence required a disclosure by the defendant, which “courts have repeatedly found . . . lacking under circumstances like those here”; and that plaintiffs could not seek declaratory or injunctive relief “designed to prevent a future breach” as opposed to addressing a breach that had already occurred.
In sum, this decision highlights a key trend in data breach litigation: even when plaintiffs successfully plead standing based on risks of future harm or monitoring and mitigation efforts, their claims may be subject to dismissal when courts scrutinize the substance of their allegations. This underscores the importance of carefully parsing the allegations in such cases – for example, by evaluating whether a plaintiff has adequately pled a causal relationship or merely insinuated that one might exist – to identify potential grounds for dismissal.