Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • AGENCY NEWS: Meador grilled on independence of FTC at nomination hearing
    • ADVERTISING—D. Conn.: Lawyer’s federal false advertising claims against former law firm dismissed
    • ANTITRUST—D.N.J. : Claims against fragrance maker foreign defendants survive jurisdictional challenge — for now
    • ANTITRUST—N.D. Tex.: Requests for production pruned back by court in All Star Cheer group boycott litigation
    • FRANCHISING & DISTRIBUTION—D. Ariz.: Court transfers Mail Center franchise dispute to Missouri despite TRO
    • PRIVACY NEWS: House data privacy working group seeks public input
    • PRIVACY—N.D. Ind.: Negligence claims advance in putative class action against data provider resulting from data breach
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Antitrust Law Daily Wrap Up, PRIVACY—N.D. Ind.: Negligence claims advance in putative class action against data provider resulting from data breach, (Feb 25, 2025)

    Law Firms Mentioned:Cohen & Malad LLP | Mullen Coughlin LLC
    Organizations Mentioned:Bradford-Scott Data, LLC d/b/a Sharetec

    By Seth Abrams, J.D., M.A.

    Court found Article III standing due to data breach combined with plaintiffs’ mitigation efforts.

    The federal district court in Fort Wayne, Indiana granted in part and denied in part defendant Bradford-Scott’s motion to dismiss putative ...

    By Seth Abrams, J.D., M.A.

    Court found Article III standing due to data breach combined with plaintiffs’ mitigation efforts.

    The federal district court in Fort Wayne, Indiana granted in part and denied in part defendant Bradford-Scott’s motion to dismiss putative class action claims brought by two customers due a data breach. Before proceeding, the court first determined that the customers had standing to bring this action. The court permitted claims for negligence and negligence per se to go forward, while dismissing claims for breach of implied contract, invasion of privacy, unjust enrichment, and breach of bailment (Webster v. Bradford-Scott Data LLC, No. 1:24-cv-00117-HAB-SLC (N.D. Ind. Feb. 20, 2025)).

    Background. Bradford-Scott is a technology and data service for over 280 credit unions. During May 2023, Bradford-Scott’s system was hacked and hackers gained access to customers PII. The breach was detected by Bradford-Scott in July 2023, and they began notifying customers who were affected in February 2024. Webster is a former customer of StagePoint Federal Credit Union, who received a notice letter that his “name, and Social Security number and date of birth” was compromised. Smith is a former customer of another credit union serviced by Bradford-Scott. He received notice that his name, Social Security number, and financial account number was compromised. Webster and Smith, in this putative class action on behalf of all in the United States whose PII was compromised by the data breach, assert that they have “sustained damages—and will continue to suffer damages—in the form of monetary losses, lost time, anxiety, and emotional distress.” As a result, the plaintiffs sued Bradford-Scott for (1) negligence; (2) negligence per se under Section 5 of the FTC Act; (3) breach of implied contract; (4) invasion of privacy; (5) unjust enrichment; and (6) breach of bailment.

    Standing. Bradford-Scott argued that the plaintiffs “have not suffered any actual injury, such as identity theft, actual misuse of their information, or economic harm” and also “failed to allege any risk of future harm that can confer standing.” The court disagreed noting that “it is common sense that hackers steal information to profit from it, so there is no need ‘to wait until hackers commit identity theft or credit card fraud’... because there is an objectively reasonable likelihood that such injury will occur.” The court also analyzed TransUnion, LLC v. Ramirez, 594 U.S. 413 (2021), which held that a separate harm is needed in addition to the identity theft itself. To the extent that this is required, plaintiffs undertook mitigation efforts “to combat a harm that was imminent or certainly impending.” As a result, plaintiffs had standing to bring their claims against Bradford-Scott.

    Negligence. Common law negligence in Indiana requires a “(1) duty owed to plaintiff by defendant, (2) breach of duty by allowing conduct to fall below the applicable standard of care, and (3) compensable injury proximately caused by defendant’s breach of that duty.” Bradford-Scott argued that “(1) Indiana does not recognize a duty to protect information; (2) Plaintiffs do not properly plead... that they have suffered any cognizable injury; and (3) Plaintiffs’ negligence claim is barred by the economic loss doctrine.” The court found that Plaintiffs’ complaint “checks all the boxes for a negligence claim under Indiana law.” It concluded that Bradford-Scott “owed a duty to Plaintiffs to keep their PII safe and that Plaintiffs adequately pled that element in their complaint.” Bradford-Scott argued that Plaintiffs fail to plead any “cognizable loss that would sustain a negligence claim.” The court disagreed, finding that the “increased risk of identity theft that Plaintiffs now face and the costs to mitigate those risks are cognizable injuries and adequately pled.” Plaintiffs’ “emotional distress and anxiety related damages” are also plausible. However, the “diminished value of Plaintiffs’ PII is simply ‘too speculative’ to establish a cognizable injury. The court also concluded that the damages are not barred by the economic loss rule as plaintiffs allege more than purely economic losses, including “lost time, anxiety, embarrassment, humiliation, frustration, and emotional distress.” As a result, the court denied the motion to dismiss the negligence claim.

    Negligence. Plaintiffs also alleged negligence per se under Section 5 of the FTC Act. The Plaintiffs asserted that they were not pursuing a private cause of action for violations of the FTC Act. The court agreed and found that the Plaintiffs “assert that Bradford-Scott’s violations of those statutes evince a breach of its duty to protect Plaintiffs’ PII.” The court also was unpersuaded by Bradford-Scott’s arguments on proximate cause, noting that it is almost always a question of fact for the factfinder. It added that “plaintiffs plead that Bradford-Scott’s alleged breach of its duties under the [FTC Act] proximately caused their harm.” The court held that summary judgment is the appropriate mechanism to determine whether these “alleged breaches did, in-fact, cause Plaintiffs’ injuries.” Plaintiffs plausibly alleged a claim in which the FTC Act “can serve as the basis of a negligence per se claim.”

    Dismissed claims. The court dismissed claims for breach of implied contract, invasion of privacy, unjust enrichment, and breach of bailment. For breach of implied contract, the court held that “the parties had no direct dealings and the complaint does not even support that the plaintiff knew that the defendant existed” prior to the data breach. For invasion of privacy, the complaint “fails to establish that Plaintiffs’ PII reached the public at large.” The court found the unjust enrichment claim too speculative to survive dismissal, and the bailment claim failed because Bradford-Scott did not exclusively possess the data. Finally, the court denied a motion to strike paragraphs of the amended complaint that contained statistics about cybercrimes. It found that they are “generally relevant to the foreseeability of the [i]ncident.”

    The Case is No. 1:24-cv-00117-HAB-SLC.

    Judge: Brady, H.

    Attorneys: Lynn A. Toops (Cohen & Malad LLP) for Anthony Webster. Claudia D. McCarron (Mullen Coughlin LLC) for Bradford-Scott Data, LLC d/b/a Sharetec.

    Companies: Bradford-Scott Data, LLC d/b/a Sharetec

    Cases: Privacy CyberPrivacyFeed DataPrivacy IndianaNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use