Citations
- 313 F. Supp. 3d 1113
Full opinion text
LUCY H. KOH, United States District Judge
Plaintiffs Kimberly Heines, Hashmatullah Essar, Paul Dugas, Matthew Ridolfo, Deana Ridolfo, Yaniv Rivlin, Mali Granot, Brian Neff, and Andrew Mortensen (collectively, "Plaintiffs") bring a putative class action against Defendant Yahoo! Inc. ("Yahoo"). Plaintiff Brian Neff also brings a putative class action against Defendant Aabaco Small Business, LLC ("Aabaco") (collectively with Yahoo, "Defendants"). Before the Court is Defendants' motion to dismiss Plaintiffs' First Amended Consolidated Class Action Complaint ("FAC"), ECF No. 196. ECF No. 205 ("Mot."). Having considered the parties' submissions, the relevant law, and the record in this case, the Court hereby GRANTS in part and DENIES in part the motion to dismiss.
I. BACKGROUND
A. Factual Background
Defendant Yahoo was founded in 1994 and has since grown into a source for internet searches, email, shopping, news, and many other internet services. FAC ¶ 32. One of Yahoo's most important services is Yahoo Mail, a free email service. Id. ¶ 33. Plaintiffs allege that "[m]any users have built their digital identities around Yahoo Mail, using the service for everything from their bank and stock trading accounts to photo albums and even medical information." Id.
Yahoo also offers online services for small businesses, including website hosting and email services (hereinafter, "Small Business Services"). Id. ¶ 34. Users must pay for Small Business Services, and users are required to provide credit or debit card information for automatic monthly payments for Small Business Services. Id. Prior to November 2015, Yahoo provided these services through a division called Yahoo Small Business. Id. "Since November 2015, Yahoo has provided its small business services through its wholly owned subsidiary Aabaco." Id.
Plaintiffs allege that in order to obtain email services and Small Business Services from Defendants, users are required to provide personal identification information ("PII") to Defendants. Id. ¶ 35. This PII includes the user's name, email address, birth date, gender, ZIP code, occupation, industry, and personal interests. Id. ¶ 37. For some Yahoo accounts, including the small business accounts, users are required to submit additional information, including credit or debit card numbers and other financial information. Id. ¶¶ 34, 36.
In addition to the PII that Plaintiffs submitted directly to Defendants, Plaintiffs also allege that users used their Yahoo email accounts to send and receive a variety of personal information. Id. ¶ 7. Each named Plaintiff alleges that he or she included sensitive information in the content of his or her Yahoo emails. See, e.g. , id. ¶¶ 18-21. The individual allegations of the named Plaintiffs, including allegations regarding the personal information that these named Plaintiffs included in their Yahoo email accounts, are discussed further below.
1. Earlier Data Security Issues Putting Yahoo on Notice
Plaintiffs allege that Defendants have a long history of data security failures that should have put Defendants on notice of the need to enhance their data security. For example, in 2008 and 2009, "multiple hosts on Yahoo's corporate network were compromised." Id. ¶¶ 64-65. In 2010, Google notified Yahoo that attackers were using Yahoo systems to attack Google. Id. ¶ 66. In 2011, then-Chief Information Security Officer ("CISO") Justin Somaini gave a presentation "identifying gaping holes in Yahoo's data security." Id. ¶ 67. In 2012, a third party informed Yahoo of a vulnerability within its system. Id. ¶ 72.
Yahoo also experienced a breach in 2012. Although the Federal Trade Commission found as early as 2003 that "SQL injection attacks" were a known and preventable data security threat, "in 2012, Yahoo admitted that more than 450,000 user accounts were compromised through an SQL injection attack-with the passwords simply stored in plain text." Id. ¶¶ 77-78. Plaintiffs allege that according to news stories at the time, "[s]ecurity experts were befuddled ... as to why a company as large as Yahoo would fail to cryptographically store the passwords in its database. Instead, [the passwords] were left in plain text, which means a hacker could easily read them." Id. ¶ 77.
According to Plaintiffs, the 2012 hackers intended the 2012 attack as a wake-up call, and the hackers left a message stating: "We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat ... There have been many security holes exploited in Web servers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly." Id. ¶ 79. However, despite this warning, Plaintiffs allege that "Yahoo's culture actively discouraged emphasis on data security." Id. ¶ 89. Plaintiffs allege that "former Yahoo security staffers interviewed later told Reuters that requests made by Yahoo's security team for new tools and features such as strengthened cryptography protections were, at times, rejected on the grounds that the requests would cost too much money, were too complicated, or were simply too low a priority." Id.
Yahoo also hired security firms who identified problems with Yahoo's systems. For example, in 2012, Yahoo retained Mandiant, an outside cybersecurity firm, to perform a threat assessment; Mandiant's subsequent report detailed issues with Yahoo's security and attack groups in Yahoo's systems. Id. ¶¶ 70, 73, 75. Similarly, Dell SecureWorks and Leaf SR conducted security assessments at various times between 2013 and 2016 that turned up vulnerabilities. Id. ¶¶ 83-84, 87-88.
2. Three Data Breaches at Issue in the Instant Case
The instant lawsuit involves three data breaches that occurred between 2013 and 2016. According to Plaintiffs, Defendants represented to users that users' accounts with Defendants were secure. For example, Yahoo's website stated that "protecting our systems and our users' information is paramount to ensuring Yahoo users enjoy a secure user experience and maintaining our users' trust" and that "[w]e deploy industry standard physical, technical, and procedural safeguards that comply with relevant regulations to protect your personal information." Id. ¶ 43. Similarly, Aabaco's website stated that "[w]e have physical, electronic, and procedural safeguards that comply with federal regulations to protect your Personal Information." Id. ¶ 46. Nonetheless, despite these representations, Plaintiffs allege that Defendants did not use appropriate safeguards to protect users' PII and that Plaintiffs' PII was thus exposed to hackers who infiltrated Defendants' systems. Specifically, Plaintiffs allege three separate data breaches: a breach that occurred in 2013, a breach that occurred in 2014, and a "forged cookie breach" that occurred in 2015 and 2016. The Court refers to these breaches collectively as the "Data Breaches." The Court discusses each below.
a. The 2013 Breach
The first breach occurred in August 2013 ("2013 Breach"). Id. ¶ 133. Hackers gained access to Yahoo accounts and stole users' Yahoo logins, country codes, recovery emails, dates of birth, hashed passwords, cell phone numbers, and zip codes. Id. ¶ 134. Significantly, the 2013 Breach also gave hackers access to the contents of users' emails, and thus exposed any sensitive information that users included in the contents of their emails. Id. Plaintiffs allege that users used their Yahoo emails for a variety of personal and financial transactions, and thus that Yahoo email accounts contained "credit card numbers, ... bank account numbers, Social Security numbers, driver's license numbers, passport information, birth certificates, deeds, mortgages, and contracts." Id.
On December 14, 2016, more than three years after the 2013 Breach occurred, Yahoo disclosed the 2013 Breach but underestimated its true scope. Id. ¶ 133. Specifically, Yahoo stated that "an unauthorized third party ... stole data associated with more than one billion user accounts." Id. Almost a year later, on October 3, 2017, Yahoo announced that the 2013 Breach had actually affected every user account-approximately three billion, not one billion, accounts. Id. ¶¶ 145-46. Plaintiffs allege that the 2013 Breach occurred because Yahoo did not timely move away from an outdated encryption technology known as MD5. Id. ¶ 90. According to Plaintiffs, it was widely recognized in the data security industry long before the 2013 Breach that MD5 was "cryptographically broken and unsuitable for further use. " Id. ¶ 91. Nevertheless, Yahoo did not begin to upgrade from MD5 until the summer of 2013. Id. ¶ 93. Plaintiffs allege, however, that Yahoo's move from MD5 in the summer of 2013 was too late to prevent the 2013 Breach. Id. ¶¶ 94-96.
b. The 2014 Breach
The second breach occurred in late 2014 ("2014 Breach"). Id. ¶ 102. Plaintiffs allege that "the 2014 breach began with a 'spear phishing' email campaign sent to upper-level Yahoo employees. One or more of these employees fell for the bait, and Yahoo's data security was so lax, that this action was enough to hand over the proverbial keys to the kingdom." Id. ¶ 154 (footnote omitted). Through this attack, hackers gained access to at least 500 million Yahoo user accounts. Id. ¶ 102.
According to Plaintiffs, in August 2016, a hacker posted for sale on the dark web the personal information of 200 million Yahoo users. Id. ¶ 122. Plaintiffs also allege that "a geographically dispersed hacking group based in Eastern Europe managed to sell copies of the database to three buyers for $300,000 apiece months before Yahoo disclosed the 2014 Breach." Id. ¶ 123.
Plaintiffs allege that Yahoo knew about the 2014 Breach as it was happening, but that Yahoo did not publicly disclose the existence of the 2014 Breach until September 22, 2016, approximately two years later. Id. ¶¶ 126, 129. Plaintiffs allege that Yahoo's announcement of the 2014 Breach "came just two months after Yahoo announced Verizon's plan to acquire its operating assets, and just weeks after Yahoo reported to the SEC that it knew of no incidents of unauthorized access of personal data that might adversely affect the potential acquisition." Id. ¶ 126. Plaintiffs allege that Yahoo delayed notifying users or the public about the 2014 Breach while "Yahoo solicited offers to buy the company. Reportedly, Yahoo wanted the offers in by April 19, 2016," and thus waited to disclose the breach until September 2016. Id. ¶ 121.
Plaintiffs also allege that "[b]y intentionally failing to disclose the breach in a timely manner as required by law, Yahoo misled consumers into continuing to sign up for Yahoo services and products, thus providing Yahoo a continuing income stream and a better chance of finalizing a sale of the company to Verizon." Id. ¶ 130. In the September 22, 2016 announcement of the 2014 Breach, Yahoo stated that the affected "account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers." Id. ¶ 126.
Plaintiffs allege that Yahoo's claim that it had not known about the 2014 Breach for two years was "met with immediate skepticism." Id. ¶ 128. Indeed, in a 2016 10-K filing with the SEC, Yahoo revealed that an independent investigation determined that Yahoo had contemporaneous knowledge of the 2014 Breach, yet failed to properly investigate and analyze the breach, due in part to "failures in communication, management, inquiry and internal reporting" that led to a "lack of proper comprehension and handling" of the 2014 Breach. Id. ¶ 129.
c. The Forged Cookie Breach
The third data breach occurred sometime in 2015-2016 ("Forged Cookie Breach"). Id. ¶ 117. According to the FAC, the attackers in the Forged Cookie Breach used forged cookies to access Yahoo users' accounts. Id. "Cookies" are text files that Yahoo places on users' computers to store login information so that users do not need to reenter login information every time the users access their accounts. Id. By forging these cookies, hackers were able to access Yahoo accounts without needing a password to the accounts. Id. ¶ 118. Moreover, by forging cookies, hackers were able to remain logged on to accounts for long periods of time. Id.
According to Plaintiffs, the attackers in the Forged Cookie Breach are "thought to be the same parties involved in the 2014 Breach." Id. Specifically, Plaintiffs allege that "the hackers in the 2014 Breach used some of the data obtained in the 2014 Breach to then forge cookies, help others forge cookies, or use the cookies to gain actual access to specific accounts." Id. ¶ 119. "The 2014 Breach and Forged Cookie Breach have since been attributed to two Russian FSB agents, a Russian hacker, and a Canadian hacker." Id. ¶ 153. Plaintiffs allege that in a 2016 10-K filing with the SEC, Yahoo disclosed that an independent committee of Yahoo's Board of Directors had determined that Yahoo's information security team knew, at a minimum, about the Forged Cookie Breach as it was happening, "but took no real action in the face of that knowledge." Id. ¶ 149. Instead, Plaintiffs allege, Yahoo "quietly divulged" the existence of the Forged Cookie Breach in Yahoo's 10-Q filing with the SEC on November 9, 2016 and did not begin notifying users about the Forged Cookie Breach until February 2017. Id. ¶¶ 139, 142.
3. Allegations of Individual Named Plaintiffs
The FAC is brought by nine named Plaintiffs on behalf of four putative classes and one putative subclass. The Court briefly discusses the allegations of these individual named Plaintiffs below.
a. Named Plaintiffs Representing the United States Class and California Subclass
Plaintiffs Kimberly Heines, Hashmatullah Essar, Paul Dugas, Matthew Ridolfo, and Deana Ridolfo ("United States Plaintiffs") assert claims on behalf of the putative United States Class, which consists of all free Yahoo account holders in the United States whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 18-22, 161. Additionally, California Plaintiffs Heines and Dugas assert claims on behalf of the putative California subclass, which consists of all California Yahoo account holders whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 18, 20, 163.
Plaintiff Kimberly Heines, a resident of California, alleges that she used her Yahoo email account in conjunction with Direct Express, which is the service through which Plaintiff Heines receives her Social Security, and thus her Yahoo email account "included ... information relating to her account with Direct Express." Id. ¶ 18. In 2015, Plaintiff Heines discovered that her monthly Social Security benefits had been stolen from her Direct Express account and used to purchase gift cards. Id. As a result, Plaintiff Heines fell behind on her bills, and she paid late fees as a result. Id. After the theft, Plaintiff Heines began receiving debt collection calls for debts she had not herself incurred, and she saw unfamiliar debts on her credit report, which harmed her credit score. Id. Plaintiff Heines alleges that she has spent over 40 hours dealing with the consequences of the identity theft. Id.
Plaintiff Hashmatullah Essar, a resident of Colorado, used two free Yahoo email accounts. Id. ¶ 19. Plaintiff Essar used these accounts "for all of his personal, financial, and business needs" including receiving bank statements, applying for jobs, and securing a mortgage. Id. Plaintiff Essar began receiving "phishing emails from a credit card company purporting to be affiliated with American Express, asking him to follow a link to log-in to his 'Serve' account," which Plaintiff Essar did not own. Id. After Plaintiff Essar was notified of the 2014 Breach, he signed up for and has paid $35.98 per month for LifeLock credit monitoring service. Id. In February 2017, "an unauthorized person fraudulently filed a tax return under his Social Security Number," and in March 2017 he was denied credit and had freezes placed on his credit. Id.
Plaintiff Paul Dugas, a resident of California, used four Yahoo email accounts "for his banking, investment accounts, business emails, and personal emails." Id. ¶ 20. In April 2016, Plaintiff Dugas was unable to file his personal tax return because a tax return had already been filed under his Social Security Number. Id. As a result, "both of his college-aged daughters missed deadlines to submit" their financial aid applications, and Plaintiff Dugas was forced to pay $9,000 in educational expenses that he otherwise would not have had to pay. Id. Moreover, Plaintiff Dugas has also experienced numerous fraudulent charges on his credit cards, he has had to replace his credit cards, and he has had to pay money to three different credit bureaus to freeze his accounts. Id.
Plaintiffs Matthew Ridolfo and Deana Ridolfo, a married couple, are residents of New Jersey. Id. ¶ 21. They both "used their Yahoo accounts for nearly twenty years for general banking, credit card management and communications, a mortgage refinance, and communication with friends and family." Id. Both Plaintiffs Matthew and Deana Ridolfo experienced numerous instances of credit card fraud as a result of the Data Breaches. Id. Specifically, eleven credit card or bank accounts were opened or attempted to be opened in Plaintiff Matthew Ridolfo's name, and at least eight accounts were opened or attempted to be opened in Plaintiff Deana Ridolfo's name. Id. The Ridolfos experienced fraudulent charges on their credit cards. Id. The Ridolfos eventually purchased and enrolled in LifeLock to help monitor their credit and finances, and they each pay $30.00 per month for these services. Id. ¶ 22. Nonetheless, as late as January 31, 2017, an unauthorized person attempted to open an additional credit card in Plaintiff Deana Ridolfo's name. Id.
b. Named Plaintiffs Representing the Israel Class
Plaintiffs Yaniv Rivlin and Mali Granot ("Israel Plaintiffs") assert claims on behalf of the putative Israel Class, which consists of all Yahoo account holders in Israel whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 23-24, 161.
Plaintiff Yaniv Rivlin, a resident of Tel Aviv, Israel, used his Yahoo email account "mainly for personal purposes, including banking, friends and family, credit card statements, and social security administration." Id. ¶ 25. Plaintiff Rivlin also pays Yahoo $20.00 per year for an email forwarding service and keeps a credit card on file with Yahoo to pay for the service. Id. After being notified that his account had been breached, Plaintiff Rivlin has noticed an increase in spam and unsolicited advertisements, and Plaintiff Rivlin has spent considerable time changing many user names and passwords on many accounts to prevent fraud. Id.
Plaintiff Mali Granot, a resident of Raanana, Israel, uses her Yahoo email account "to correspond with family, friends and school." Id. ¶ 24. Plaintiff Granot was unexpectedly locked out of her account and, when she regained access, she received numerous unsolicited chat requests and other unsolicited services. Id.
c. Named Plaintiff Representing the Small Business Users Class
Plaintiff Brian Neff ("Small Business Users Plaintiff") asserts claims on behalf of a putative Small Business Users Class, which consists of all Yahoo or Aabaco business account holders in the United States whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 25-27, 161.
Plaintiff Neff, a resident of Texas, "contracted with Yahoo for two services, Yahoo! Web Hosting for www.TheInsuranceSuite.com and Yahoo! Business Email, for which he has paid Yahoo $13.94 every month." Id. ¶ 25. Plaintiff Neff has also used Yahoo and Aabaco's web hosting services "in connection with another 54 websites, paying anywhere from $3.94 to $15.94 per month for each website." Id. In May 2015, Plaintiff Neff incurred fraudulent charges on two of his credit cards, both of which were on file with Yahoo to pay for the services described above. Id. ¶ 26. Additionally, a credit card was fraudulently opened in Plaintiff Neff's name. Id. Plaintiff Neff has spent "significant time and incurred expenses mitigating the harm to him from these security breaches and identity theft." Id. Plaintiff Neff has "stopped using the TheInsuranceSuite.com website" and "is in the process of migrating that website to a more secure provider," which Plaintiff Neff alleges will require significant expenses. Id. ¶ 27.
d. Named Plaintiff Representing the Paid Users Class
Plaintiff Andrew Mortensen ("Paid Users Plaintiff") asserts claims on behalf of a putative Paid Users Class, which consists of all paid Yahoo account holders in the United States and Israel whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 28, 161.
Plaintiff Mortensen, a resident of Texas, opened an email account with Yahoo and has used his account for personal and business purposes, ranging from sharing personal information with friends and family to managing banking and financial information. Id. ¶ 28. Plaintiff Mortensen has also "paid $19.95 per year for Yahoo's premium email service." Id. Plaintiff Mortensen has received spam calls every week and spam texts every two weeks. Id. Plaintiff Mortensen alleges that he has been "forced to expend approximately three hours of time and effort checking credit and opening accounts." Id.
B. Procedural History
After the 2014 Breach was announced on September 22, 2016, a number of lawsuits were filed against Defendants. These lawsuits generally alleged that Yahoo failed to adequately protect its users' accounts, failed to disclose its inadequate data security practices, and failed to timely notify users of the data breach.
In late 2016, Plaintiffs in several lawsuits moved to centralize pretrial proceedings in a single judicial district. See 28 U.S.C. § 1407(a) ("When civil actions involving one or more common questions of fact are pending in different districts, such actions may be transferred to any district for coordinated or consolidated pretrial proceedings."). On December 7, 2016, the Judicial Panel on Multidistrict Litigation ("JPML") issued a transfer order selecting the undersigned judge as the transferee court for "coordinated or consolidated pretrial proceedings" in the multidistrict litigation ("MDL") arising out of the 2014 Breach. See ECF No. 1 at 1-2.
On December 14, 2016, one week after the JPML issued the transfer order for cases arising from the 2014 Breach, Yahoo announced the existence of the 2013 Breach. Plaintiffs in several lawsuits that had been filed regarding the 2014 Data Breach then amended their complaints to include claims regarding the 2013 Breach. Additionally, more lawsuits were filed in the Northern District of California regarding the 2013 Breach and the 2014 Breach. Again, these lawsuits generally alleged that Yahoo failed to adequately protect its users' accounts, failed to disclose its inadequate data security practices, and failed to timely notify users of the data breach. These lawsuits were related or transferred to the undersigned judge. ECF Nos. 7, 9, 30, 33, 40, 64.
Plaintiffs filed a Consolidated Class Action Complaint covering all three Data Breaches on April 12, 2017. ECF No. 80. On May 22, 2017, Defendants filed a first round motion to dismiss. ECF No. 94. On August 30, 2017, the Court granted in part and denied in part the first round motion to dismiss. ECF No. 132 ("First MTD Order").
After the Court had issued its ruling on the first round motion to dismiss, Yahoo disclosed on October 3, 2017 that the 2013 data breach had affected an additional two billion Yahoo user accounts. In response, the Court amended the case schedule to allow Plaintiffs enough time to amend their complaint and to conduct discovery. ECF No. 147.
Plaintiffs filed the instant FAC on December 15, 2017. ECF No. 174. On January 19, 2018, Defendants filed the instant motion to dismiss. ECF No. 205 ("Mot."). The same day, Defendants filed a request for judicial notice in connection with their motion to dismiss. ECF No. 206. On February 9, 2018, Plaintiffs filed an opposition to Defendants' motion to dismiss. ECF No. 211 ("Opp."). On February 19, 2018, Defendants filed a reply in support of their motion to dismiss. ECF No. 212 ("Reply").
II. LEGAL STANDARD
A. Motion to Dismiss Under Rule 12(b)(6)
Pursuant to Federal Rule of Civil Procedure 12(b)(6), a defendant may move to dismiss an action for failure to allege "enough facts to state a claim to relief that is plausible on its face." Bell Atl. Corp. v. Twombly , 550 U.S. 544, 570, 127 S.Ct. 1955, 167 L.Ed.2d 929 (2007). "A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged. The plausibility standard is not akin to a 'probability requirement,' but it asks for more than a sheer possibility that a defendant has acted unlawfully." Ashcroft v. Iqbal , 556 U.S. 662, 678, 129 S.Ct. 1937, 173 L.Ed.2d 868 (2009) (citations omitted).
For purposes of ruling on a Rule 12(b)(6) motion, the Court "accept[s] factual allegations in the complaint as true and construe[s] the pleadings in the light most favorable to the nonmoving party." Manzarek v. St. Paul Fire & Marine Ins. Co. , 519 F.3d 1025, 1031 (9th Cir. 2008). However, a court need not accept as true allegations contradicted by judicially noticeable facts, Shwarz v. United States , 234 F.3d 428, 435 (9th Cir. 2000), and a "court may look beyond the plaintiff's complaint to matters of public record" without converting the Rule 12(b)(6) motion into one for summary judgment, Shaw v. Hahn , 56 F.3d 1128, 1129 (9th Cir. 1995). Mere "conclusory allegations of law and unwarranted inferences are insufficient to defeat a motion to dismiss." Adams v. Johnson , 355 F.3d 1179, 1183 (9th Cir. 2004).
B. Leave to Amend
If the Court concludes that a motion to dismiss should be granted, it must then decide whether to grant leave to amend. Under Rule 15(a) of the Federal Rules of Civil Procedure, leave to amend "shall be freely given when justice so requires," bearing in mind "the underlying purpose of Rule 15... [is] to facilitate decision on the merits, rather than on the pleadings or technicalities." Lopez v. Smith , 203 F.3d 1122, 1127 (9th Cir. 2000) (citation omitted). Nonetheless, a district court may deny leave to amend a complaint due to "undue delay, bad faith or dilatory motive on the part of the movant, repeated failure to cure deficiencies by amendments previously allowed, undue prejudice to the opposing party by virtue of allowance of the amendment, [and] futility of amendment." See Leadsinger, Inc. v. BMG Music Publ'g , 512 F.3d 522, 532 (9th Cir. 2008) (alteration in original) (citation omitted).
III. REQUEST FOR JUDICIAL NOTICE
The Court first addresses Defendants' request for judicial notice. ECF No. 206. The Court may take judicial notice of matters that are either "generally known within the trial court's territorial jurisdiction" or "can be accurately and readily determined from sources whose accuracy cannot reasonably be questioned." Fed. R. Evid. 201(b). Public records, including judgments and other publicly filed documents, are proper subjects of judicial notice. See, e.g. , United States v. Black , 482 F.3d 1035, 1041 (9th Cir. 2007) ("[Courts] may take notice of proceedings in other courts, both within and without the federal judicial system, if those proceedings have a direct relation to matters at issue."); Rothman v. Gregor , 220 F.3d 81, 92 (2d Cir. 2000) (taking judicial notice of a filed complaint as a public record).
However, to the extent any facts in documents subject to judicial notice are subject to reasonable dispute, the Court will not take judicial notice of those facts. See Lee v. City of L.A. , 250 F.3d 668, 689 (9th Cir. 2001) ("A court may take judicial notice of matters of public record.... But a court may not take judicial notice of a fact that is subject to reasonable dispute." (internal quotation marks and citation omitted) ), overruled on other grounds by Galbraith v. Cty. of Santa Clara , 307 F.3d 1119 (9th Cir. 2002).
Defendants request judicial notice of the following documents:
Ex. A: Legislative Counsel's Digest for California Assembly Bill 1541;
Ex. B: California Assembly, Committee on Privacy and Consumer Protection, Analysis of Assembly Bill 1541.
Plaintiffs do not object to Defendants' request for judicial notice. The Court agrees that these documents are proper subjects of judicial notice. See Anderson v. Holder , 673 F.3d 1089, 1094 n.1 (9th Cir. 2012) ("Legislative history is properly a subject of judicial notice."). Therefore, the Court GRANTS Defendants' unopposed request for judicial notice of Exhibits A and B. The Court next turns to address the substance of Defendants' motion to dismiss the FAC.
IV. DISCUSSION
As set forth above, the United States Plaintiffs assert claims on behalf of the putative United States Class, which consists of all free Yahoo account holders in the United States whose accounts were compromised in any of the Data Breaches. FAC ¶¶ 18-22, 161. Additionally, the California Plaintiffs assert claims on behalf of the putative California subclass, which consists of all California Yahoo account holders whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 18, 20, 163.
The Israel Plaintiffs assert claims on behalf of the putative Israel Class, which consists of all Yahoo account holders in Israel whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 23-24, 161.
The Small Business Users Plaintiff asserts claims on behalf of a putative Small Business Users Class, which consists of all Yahoo or Aabaco business account holders in the United States whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 25-27, 161.
The Paid Users Plaintiff asserts claims on behalf of a putative Paid Users Class, which consists of all paid Yahoo account holders in the United States and Israel whose accounts were compromised in any of the Data Breaches. Id. ¶¶ 28, 161.
The FAC asserts a total of thirteen causes of action: six California statutory claims and seven California common-law claims on behalf of the putative classes. Specifically, the FAC asserts the following thirteen causes of action: (1) a claim under the unlawful prong of the California Unfair Competition Law ("UCL") on behalf of all classes (Count One); (2) a claim under the unfair prong of the UCL on behalf of all classes (Count Two); (3) a claim for deceit by concealment on behalf of all classes (Count Three); (4) a claim for negligence on behalf of all classes (Count Four); (5) a claim for breach of contract on behalf of all classes (Count Five); (6) a claim for breach of implied contract on behalf of all classes (Count Six); (7) a claim for breach of the implied covenant of good faith and fair dealing on behalf of all classes (Count Seven); (8) a claim for declaratory relief on behalf of all classes (Count Eight); (9) a claim under the fraudulent prong of the UCL on behalf of the Small Business Users Class (Count Nine); (10) a claim for misrepresentation on behalf of the Small Business Users Class (Count Ten); (11) a claim under the California Consumers Legal Remedies Act ("CLRA") on behalf of the Paid Users Class (Count Eleven); (12) a claim under § 1798.81.5 of the California Customer Records Act ("CRA") on behalf of the California subclass (Count Twelve); and (13) a claim under § 1798.82 of the CRA on behalf of the California subclass (Count Thirteen). Id. ¶¶ 180-312.
Defendants move to dismiss claims that were either dismissed with leave to amend in the First MTD Order or were newly added in the FAC. First, Defendants raise particular objections to eleven of Plaintiffs' thirteen causes of action-i.e., all claims except the claim under the fraudulent prong of the UCL on behalf of the Small Business Users Class (Count Nine) and the claim for misrepresentation on behalf of the Small Business Users Class (Count Ten). Next, Defendants argue that Plaintiffs may not seek punitive damages as to any of their claims.
The Court first considers Defendants' challenges to Plaintiffs' causes of action in turn, then considers Defendants' arguments regarding punitive damages.
A. UCL
In Count One, all Plaintiffs allege a claim under the unlawful prong of the UCL. In Count Two, all Plaintiffs allege a claim under the unfair prong of the UCL. Defendants move to dismiss the UCL unlawful and unfair claims of Plaintiffs Rivlin, Granot, and Mortensen on the ground that those three Plaintiffs lack standing to bring claims under the UCL. Mot. at 5-6.
In order to establish standing for a UCL claim, Plaintiffs must show that they personally "lost money or property as a result of the unfair competition." Cal. Bus. & Prof. Code § 17204 ; Kwikset Corp. v. Superior Court , 51 Cal.4th 310, 120 Cal.Rptr.3d 741, 246 P.3d 877, 887 (2011). As the California Supreme Court has explained:
There are innumerable ways in which economic injury from unfair competition may be shown. A plaintiff may (1) surrender in a transaction more, or acquire in a transaction less, than he or she otherwise would have; (2) have a present or future property interest diminished; (3) be deprived of money or property to which he or she has a cognizable claim; (4) be required to enter into a transaction, costing money or property, that would otherwise have been unnecessary.
Kwikset , 120 Cal.Rptr.3d 741, 246 P.3d at 885-86.
Under those standards, this Court previously dismissed the UCL claims of Plaintiffs Rivlin and Granot because they did not sufficiently allege standing under the UCL. First MTD Order at 39. The Court explained that "Plaintiffs' imminent risk of future costs as a result of the Data Breaches ... is not sufficient to allege 'lost money or property' under the UCL." Id.
Plaintiffs Rivlin and Granot's amended allegations fare no better. Again, the FAC states that "the Yahoo Data Breaches have caused [Plaintiffs Rivlin and Granot] to be at substantial risk for identity theft, if in fact [their] identit[ies]
ha[ve] not already been stolen." FAC ¶¶ 23-24. As the Court has already concluded, such reliance on the threat of future harm does not satisfy the UCL's "lost money or property" standing requirement. Indeed, Plaintiffs concede that, based on the Court's prior ruling, the UCL claims of Plaintiffs Rivlin and Granot cannot proceed. Opp. at 4 n.6. Thus, the Court GRANTS Defendants' motion to dismiss the UCL unlawful and unfair claims of Plaintiffs Rivlin and Granot. The Court dismisses with prejudice because Plaintiffs Rivlin and Granot have failed to cure the deficiencies addressed in the First MTD Order.
The Court reaches a different conclusion as to Paid Users Plaintiff Mortensen. To the extent that Plaintiff Mortensen claims a "greater risk of identity theft and other fraud," FAC ¶ 28, like Plaintiffs Rivlin and Granot, he has failed to allege "lost money or property" under the UCL. However, Plaintiff Mortensen offers further allegations beyond those of Plaintiffs Rivlin and Granot. Plaintiffs argue that these allegations establish standing under the UCL because he has alleged lost benefit of the bargain. Opp. at 4. The Court agrees.
Plaintiff Mortensen's allegations are sufficient to allege that he suffered benefit-of-the-bargain losses. In particular, Plaintiff Mortensen pleads that he has paid $19.95 each year since December 2007 for Yahoo's premium email service. FAC ¶ 28. Defendants represented that their email services were "secure." Id. ¶ 40. Plaintiff Mortensen alleges that he "would not have provided [his] PII to Yahoo or signed up for the supposedly secure services" had he known that Yahoo's email service was not as secure as Defendants represented. Id. ¶ 285. Accordingly, Plaintiff Mortensen claims that he was damaged because he paid for services "either worth nothing or worth less than was paid for them because of their lack of security." Id. ¶ 210. These allegations closely parallel the Small Business Users Plaintiff Neff's allegations, which the Court concluded adequately alleged lost benefit of the bargain. First MTD Order at 36-37.
Defendants' central response is that Plaintiff Mortensen does not allege that he was deprived of the premium services for which he paid. Mot. at 6. In other words, Defendants argue that because added security was not a benefit of Plaintiff Mortensen's bargain with Defendants, Plaintiff Mortensen has failed to allege lost benefit of the bargain. Reply at 3.
Based on Plaintiff Mortensen's specific allegations, the Court rejects Defendants' argument in this context. Plaintiff Mortensen's request for lost benefit of the bargain mirrors the California Supreme Court's determination in Kwikset that a plaintiff who has "surrender[ed] in a transaction more, or acquire[d] in a transaction less, than he or she otherwise would have" may bring a UCL claim. 120 Cal.Rptr.3d 741, 246 P.3d at 885. Plaintiff Mortensen's allegations state that he expected to receive secure email services and that he would not have signed up for the services in the absence of such assurances. FAC ¶ 285. Even if his annual fee did not provide for security measures above and beyond those for free accounts, Plaintiff Mortensen pleads that Defendants' representations about security formed part of the reason for him to use Yahoo Mail in the first place and to pay $19.95 per year for the premium email service. Id. Moreover, Plaintiff Mortensen alleges that he would not have signed up for the supposedly secure services or turned over his PII at all if Defendants had disclosed the security issues. Id. Defendants' argument does not undermine Plaintiff Mortensen's plausible allegations that he lost the benefit of the bargain.
Such benefit-of-the-bargain losses are sufficient to allege "lost money or property," and thus standing, under the UCL. See In re Anthem, Inc. Data Breach Litig. , No. 15-MD-02617-LHK, 2016 WL 3029783, at *30 (N.D. Cal. May 27, 2016) (finding plaintiffs' alleged benefit of the bargain losses were sufficient to establish standing under the UCL); In re Adobe Sys., Inc. Privacy Litig. , 66 F.Supp.3d 1197, 1224 (N.D. Cal. 2014) (finding allegations that plaintiffs "personally spent more on Adobe products than they would had they known Adobe was not providing the reasonable security Adobe represented it was providing" to be sufficient to allege standing under the UCL). Accordingly, Paid Users Plaintiff Mortensen has adequately alleged standing under the UCL, and the Court DENIES Defendants' motion to dismiss Plaintiff Mortensen's UCL unlawful and unfair claims for lack of UCL standing.
B. Deceit by Concealment and Negligence
All Plaintiffs bring a claim for deceit by concealment in Count Three and a claim for negligence in Count Four. Defendants first argue that the economic loss rule bars both sets of claims. Mot. at 22-24. Defendants separately contend that, with respect to the deceit by concealment claim, Plaintiffs have failed to plead either reliance or damages. Id. at 19-22. The Court addresses each of these arguments in turn.
1. Economic Loss Rule
Defendants first contend that Plaintiffs' deceit by concealment and negligence claims fail under the economic loss rule. Mot. at 22-24.
Under the economic loss rule, "purely economic losses are not recoverable in tort." NuCal Foods, Inc. v. Quality Egg LLC , 918 F.Supp.2d 1023, 1028 (E.D. Cal. 2013) (citing S.M. Wilson & Co. v. Smith Int'l, Inc. , 587 F.2d 1363, 1376 (9th Cir. 1978) ); Robinson Helicopter Co. v. Dana Corp. , 34 Cal.4th 979, 22 Cal.Rptr.3d 352, 102 P.3d 268, 272 (2004) ("The economic loss rule requires a purchaser to recover in contract for purely economic loss due to disappointed expectations, unless he can demonstrate harm above and beyond a broken contractual promise."). The purpose of the rule is to "prevent[ ] the law of contract and the law of tort from dissolving one into the other." Robinson Helicopter , 22 Cal.Rptr.3d 352, 102 P.3d at 273 (citation omitted); Aas v. Superior Court , 24 Cal.4th 627, 101 Cal.Rptr.2d 718, 12 P.3d 1125, 1135 (2000) ("A person may not ordinarily recover in tort for the breach of duties that merely restate contractual obligations."), superseded by statute on other grounds as recognized in McMillin Albany LLC v. Superior Court , 4 Cal.5th 241, 227 Cal.Rptr.3d 191, 408 P.3d 797 (2018). However, the economic loss rule does not prevent recovery in tort if a "special relationship" exists between the plaintiff and the defendant. J'Aire Corp. v. Gregory , 24 Cal.3d 799, 157 Cal.Rptr. 407, 598 P.2d 60, 63 (1979) ; Biakanja v. Irving , 49 Cal.2d 647, 320 P.2d 16, 19 (1958).
Although Defendants argue that the "special relationship" exception never applies when the plaintiff and the defendant are in privity, Mot. at 23, this Court has previously rejected that argument. As the Court explained, "[w]hen determining whether a special relationship exists under J'aire between parties that are in privity of contract, California courts have drawn a distinction between contracts involving goods and contracts involving services." R Power Biofuels, LLC v. Chemex LLC , No. 16-CV-00716-LHK, 2016 WL 6663002, at *5 (N.D. Cal. Nov. 11, 2016). Specifically, the California Court of Appeal's decision in North American Chemical Co. v. Superior Court held that where parties are in privity of contract, the J'aire exception applies if the contracts are for services. 59 Cal.App.4th 764, 69 Cal.Rptr.2d 466, 477 (1997). Other courts in this district have reached the same conclusion. See, e.g. , Corelogic, Inc. v. Zurich Am. Ins. Co. , No. 15-CV-03081-RS, 2016 WL 4698902, at *5 (N.D. Cal. Sept. 8, 2016). Thus, the crucial issue for applying the J'aire exception here is whether the contract at issue is one for goods or services. R Power Biofuels , 2016 WL 6663002, at *7.
The allegations in the FAC counsel that the contract between Plaintiffs and Defendants is one for services, not goods. A contract for "goods" involves the purchase or sale of "all things ... which are movable at the time of identification to the contract for sale," Cal. Com. Code § 2105(1), while a contract for services involves the purchase of labor and the "knowledge, skill, and ability" of the contracting party. TK Power, Inc. v. Textron, Inc. , 433 F.Supp.2d 1058, 1062 (N.D. Cal. 2006). Here, Plaintiffs plead that Defendants provided email and other related services by maintaining a web-based platform where users can set up accounts. FAC ¶¶ 33-34. Not only does the FAC repeatedly refer to what Defendants provide as "services," see, e.g. , id. ¶¶ 24-28, 30, 32, 173, but Defendants themselves have Terms of Service, which state that "Yahoo! provides the Yahoo! Services," id. , Ex. 1, at 1. Thus, Plaintiffs' contract with Defendants is properly characterized as a contract for services.
Having concluded that the contract is for services, the J'aire exception is available to Plaintiffs if they have adequately pled a "special relationship." The J'aire court utilized six factors for determining when a "special relationship" exists:
(1) the extent to which the transaction was intended to affect the plaintiff, (2) the foreseeability of harm to the plaintiff, (3) the degree of certainty that the plaintiff suffered injury, (4) the closeness of the connection between the defendant's conduct and the injury suffered, (5) the moral blame attached to the defendant's conduct and (6) the policy of preventing future harm.
157 Cal.Rptr. 407, 598 P.2d at 63. Applying these criteria to the facts as pled, it is evident that a duty was owed by Defendants to Plaintiffs in the present case.
First, the contract entered into between the parties related to email services for Plaintiffs. Plaintiffs were required to turn over their PII to Defendants and did so with the understanding that Defendants would adequately protect Plaintiffs' PII and inform Plaintiffs of breaches. FAC ¶ 215. Second, it was plainly foreseeable that Plaintiffs would suffer injury if Defendants did not adequately protect the PII. Id. Third, the FAC asserts that hackers were able to gain access to the PII and that Defendants did not promptly notify Plaintiffs, thereby causing injury to Plaintiffs. See, e.g. , ¶ 221. Fourth, the injury was allegedly suffered exactly because Defendants provided inadequate security and knew that their system was insufficient. Id. ¶ 215. Fifth, Defendants "knew their data security was inadequate" and that "they [did not] have the tools to detect and document intrusions or exfiltration of PII." Id. "Defendants are morally culpable, given their repeated security breaches, wholly inadequate safeguards, and refusal to notify Plaintiffs ... of breaches or security vulnerabilities." Id. Sixth, and finally, Defendants' concealment of their knowledge and failure to adequately protect Plaintiffs' PII implicates the consumer data protection concerns expressed in California statutes, such as the CRA and CLRA. See In re Adobe Sys. , 66 F.Supp.3d at 1227.
Although Defendants seek to short-circuit this analysis by referring to general propositions, Mot. at 23-24, the Ninth Circuit has admonished district courts for failing to examine all of J'aire 's six factors. Kalitta Air, L.L.C. v. Cent. Tex. Airborne Sys., Inc. , 315 F. App'x 603, 606 (9th Cir. 2008). Under those factors, Plaintiffs have adequately pled a "special relationship" with Defendants, so Plaintiffs' negligence and deceit by concealment claims are not barred by the economic-loss rule. Because Defendants make no other arguments with respect to the negligence claim, the Court DENIES Defendants' motion to dismiss Plaintiffs' negligence claim.
Defendants make additional arguments for dismissal of the deceit by concealment claim. Specifically, Defendants contend that Plaintiffs' deceit by concealment claim fails to plead either reliance or damages. The Court therefore turns to these remaining arguments.
2. Deceit by Concealment
Under California law, a plaintiff may assert a claim for deceit by concealment based on "[t]he suppression of a fact, by one who is bound to disclose it, or who gives information of other facts which are likely to mislead for want of communication of that fact." Cal. Civ. Code § 1710(3). An action for fraud and deceit based on concealment has five elements:
(1) the defendant must have concealed or suppressed a material fact, (2) the defendant must have been under a duty to disclose the fact to the plaintiff, (3) the defendant must have intentionally concealed or suppressed the fact with the intent to defraud the plaintiff, (4) the plaintiff must have been unaware of the fact and would not have acted as he did if he had known of the concealed or suppressed fact, and (5) as a result of the concealment or suppression of the fact, the plaintiff must have sustained damage.
Tenet Healthsystem Desert, Inc. v. Blue Cross of Cal. , 245 Cal.App.4th 821, 199 Cal.Rptr.3d 901, 920 (2016) (quoting Mktg. W., Inc. v. Sanyo Fisher (USA) Corp. , 6 Cal.App.4th 603, 7 Cal.Rptr.2d 859, 864 (1992) ). Defendants challenge only the last two elements, contending that Plaintiffs fail to sufficiently plead reliance or damages in connection with their deceit by concealment claims. Mot. at 19-22. The Court addresses each of these arguments in turn.
i. Reliance
Defendants first contend that the deceit by concealment claims of all Plaintiffs (except Plaintiff Neff) must be dismissed because there is no allegation that any Plaintiff read Yahoo's Privacy Policy when signing up for a Yahoo Mail account. Mot. at 19-20. The Court disagrees.
As noted above, under the reliance element, the plaintiff must demonstrate that he "would not have acted as he did if he had known of the concealed or suppressed fact." Tenet Healthsystem , 199 Cal.Rptr.3d at 920 (quoting Mktg. W. , 7 Cal.Rptr.2d at 864 ). Plaintiffs' allegations satisfy that requirement. Plaintiffs allege that Defendants knew that their system was vulnerable to attack by at least 2012 and learned of the 2014 Breach while it was happening. FAC ¶ 201. In spite of this knowledge, Defendants did not warn Plaintiffs about the security problems or the 2014 Breach. Id. ¶¶ 202-04, 207. The FAC highlights the importance of Defendants' security measures as a factor in Plaintiffs' decision whether to use Defendants' services. See, e.g. , id. ¶¶ 184, 191, 205-06. Finally, Plaintiffs explain that, had they known about the inadequacy of these security measures, they "would have taken measures to protect themselves." Id. ¶ 205. Plaintiffs' allegations are sufficient to show that they would have behaved differently had Defendants disclosed the security weaknesses of the Yahoo Mail system.
The sole argument raised in Defendants' motion to dismiss is unpersuasive. Harkening back to the dismissal of Plaintiffs' UCL fraud claim in this Court's First MTD Order, Defendants argue that Plaintiffs do not plead that they read Yahoo's Privacy Policy. Mot. at 19-20. Defendants' reliance on this portion of the First MTD Order is misplaced. The Court required Plaintiffs to plead that they actually read and relied on the Privacy Policy because Plaintiffs' theory was that Defendants made misrepresentations in the Privacy Policy. First MTD Order at 48-49. Here, in contrast, Plaintiffs' deceit by concealment claim is not based on statements in the Privacy Policy, so whether Plaintiffs read the Privacy Policy is immaterial.
Perhaps sensing this deficiency, Defendants do not repeat the same argument in their reply but instead raise two new contentions. Even if the Court were to consider these belated assertions, they are unavailing. See Pham v. Fin. Indus. Regulatory Auth. Inc. , No. 12-CV-06374-EMC, 2013 WL 1320635, at *1 (N.D. Cal. Apr. 1, 2013) ("[T]hese arguments-raised for the first time on reply-have been waived."), aff'd sub nom. Huy Pham v. Fin. Indus. Regulatory Auth., Inc. , 589 F. App'x 345 (9th Cir. 2014). First, Defendants argue that Plaintiffs must provide more detail about Defendants' omissions, Reply at 11-12, but they offer no explanation of what more Plaintiffs need to identify, and the Court finds that what Plaintiffs have identified is sufficiently specific.
Second, Defendants also criticize Plaintiffs for continuing to use Yahoo Mail and taking no remedial actions after learning of Defendants' allegedly inadequate security. Id. at 12. However, Defendants fail to acknowledge that Defendants' delayed disclosures are likely to have harmed Plaintiffs in the interim. Plaintiffs did not even know that they should take any remedial actions during the periods of Defendants' delayed disclosures. Moreover, contrary to Defendants' suggestion, the actions that Plaintiffs took after the fact do not conclusively determine what actions they would have taken if they had been alerted before the fact. The FAC provides at least one good reason why Plaintiffs may not have ceased their use of Yahoo Mail after the fact-namely, Plaintiffs have already established their "digital identities around Yahoo Mail." FAC ¶ 33. Plaintiffs can consistently plead that they took minimal or no action after learning of the security defects but that they "would have taken measures to protect themselves" if they had been informed beforehand. Id. ¶ 205. Accordingly, Plaintiffs have plausibly alleged the necessary element of reliance.
ii. Damages
Defendants argue that, except for Plaintiff Neff, Plaintiffs do not properly plead damages from the concealment. Mot. at 21. Specifically, Defendants contend that Plaintiffs are limited to recovering out-of-pocket losses. Id. at 20. The out-of-pocket measure is designed to put the plaintiff in the financial position he or she was in prior to the transaction. All. Mortg. Co. v. Rothwell , 10 Cal.4th 1226, 44 Cal.Rptr.2d 352, 900 P.2d 601, 609 (1995). Under that measure, Defendants contend, Plaintiffs with free Yahoo accounts have suffered no damage because they did not pay anything to use Yahoo Mail. Mot. at 21.
In arguing that Plaintiffs are limited to out-of-pocket losses, Defendants rely on California Civil Code § 3343. Section 3343(a) states that "[o]ne defrauded in the purchase, sale or exchange of property is entitled to recover the difference between the actual value of that with which the defrauded person parted and the actual value of that which he received." In other words, in § 3343(a), the California legislature has expressly provided that the out-of-pocket measure is applicable in fraud cases involving the "purchase, sale or exchange of property." All. Mortg. , 44 Cal.Rptr.2d 352, 900 P.2d at 609 (quoting Cal. Civ. Code § 3343(a) ). The question in the instant case is whether § 3343(a) governs Plaintiffs' deceit by concealment claims. It does not.
By its terms, § 3343(a) is restricted to cases where the plaintiff is "defrauded in the purchase, sale or exchange of property." The same limitation appears in the title of the statutory section: "Fraud in purchase, sale or exchange of property; additional damages." Defendants' cited California state authorities follow that pattern. In Alliance Mortgage , the plaintiff claimed fraud in the inducement of a loan for the purchase of real property. 44 Cal.Rptr.2d 352, 900 P.2d at 605. In Fladeboe v. American Isuzu Motors Inc. , the plaintiff alleged fraud and negligent misrepresentation in connection with the sale of automobiles. 150 Cal.App.4th 42, 58 Cal.Rptr.3d 225, 233 (2007). Moreover, in all of Defendants' district court cases, the underlying fraud claim was based in contract. See Song Fi, Inc. v. Google, Inc. , No. 14-CV-05080-CW, 2016 WL 1298999, at *7 (N.D. Cal. Apr. 4, 2016) (concerning fraud claim where plaintiffs alleged that defendants had duty to disclose based on the Terms of Service contract between the parties); Daly v. Viacom, Inc. , 238 F.Supp.2d 1118, 1125 (N.D. Cal. 2002) (concerning fraud claim where "plaintiff allege[d] that defendant misrepresented material facts when it induced plaintiff to sign a contract").
This case is different, as no exchange of property occurred and Plaintiffs' claim does not sound in contract. FAC ¶¶ 200-11. Rather, Plaintiffs allege that Defendants committed deceit by concealment under California Civil Code § 1709 by violating the duty to disclose. The California Court of Appeal has ruled that, for the tort of deceit, "the appropriate measure of damages is defined by Civil Code sections 1709 and 3333." Sprague v. Frank J. Sanders Lincoln Mercury, Inc. , 120 Cal.App.3d 412, 174 Cal.Rptr. 608, 610 (1981) ; see also Romo v. Stewart Title of Cal. , 35 Cal.App.4th 1609, 42 Cal.Rptr.2d 414, 422 (1995) ("A tort victim is not limited to his or her 'out-of-pocket' losses; rather, he or she is entitled to compensatory damages for any actual loss, as well as punitive damages for fraud (if the fraud consisted of an intentional misrepresentation or concealment)."). Neither of those statutes is limited to out-of-pocket losses. California Civil Code § 1709 permits recovery of "any damage which [the plaintiff] thereby suffers." Similarly, California Civil Code § 3333 instructs that "[f]or the breach of an obligation not arising from contract, the measure of damages ... is the amount which will compensate for all the detriment proximately caused thereby, whether it could have been anticipated or not." Thus, the out-of-pocket restriction in § 3343 does not apply, and Plaintiffs are entitled to recover their compensatory damages.
Accordingly, the Court DENIES Defendants' motion to dismiss Plaintiffs' deceit by concealment claim.
C. Contract Claims
In Counts Five through Seven, all Plaintiffs assert contract claims against Defendants. Specifically, Plaintiffs assert breach of contract in Count Five, breach of implied contract in Count Six, and breach of the implied covenant of good faith and fair dealing in Count Seven. Defendants move to dismiss these claims to the extent that they seek consequential damages in light of the limitations of liability in Defendants' Terms of Service. Mot. at 6-7. Plaintiffs argue that they have adequately pled that Defendants' limitation-of-liability provisions are unconscionable. Opp. at 5-12. Alternatively, Plaintiffs argue that their claims seek direct damages from Defendants' breach of contractual obligations. Id. at 13-14. Because the Court agrees that Plaintiffs have adequately pled unconscionability, the Court need not address Plaintiffs' alternative argument.
Defendants argue that their Terms of Service bar recovery for damages other than direct damages. Specifically, Defendants point out that Yahoo's Terms of Service contained the following clause limiting Yahoo's liability:
YOU EXPRESSLY UNDERSTAND AND AGREE THAT YAHOO! ... SHALL NOT BE LIABLE TO YOU FOR ANY PUNITIVE, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES , INCLUDING, BUT NOT LIMITED TO, DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER INTANGIBLE LOSSES (EVEN IF YAHOO! HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES), RESULTING FROM: ... UNAUTHORIZED ACCESS TO OR ALTERATION OF YOUR TRANSMISSIONS OR DATA ... OR ... ANY OTHER MATTER RELATING TO THE YAHOO! SERVICE.
FAC, Ex. 1, at 10 (emphasis added). Aabaco's Terms of Service contained the same clause limiting Aabaco's liability. Id. , Ex. 16, at 17. Plaintiffs argue that these limitations of liability are unconscionable. Opp. at 5-12.
In order to state a claim that a contractual term is unconscionable, Plaintiffs must allege facts showing that the term is both procedurally and substantively unconscionable. Pokorny v. Quixtar, Inc. , 601 F.3d 987, 996 (9th Cir. 2010) ; In re iPhone Application Litig. , No. 11-MD-02250-LHK, 2011 WL 4403963, at *7 (N.D. Cal. Sept. 20, 2011). "The procedural element of unconscionability focuses on two factors: oppression and surprise." Aron v. U-Haul Co. of Cal. , 143 Cal.App.4th 796, 49 Cal.Rptr.3d 555, 564 (2006). "The substantive element of unconscionability focuses on the actual terms of the agreement and evaluates whether they create overly harsh or one-sided results as to shock the conscience." Id. (internal quotation marks and citation omitted). Although unconscionability is ultimately a question of law, "numerous factual inquiries bear upon that question." A & M Produce Co. v. FMC Corp. , 135 Cal.App.3d 473, 186 Cal.Rptr. 114, 123 (1982).
Plaintiffs have adequately alleged oppression and surprise to support procedural unconscionability. "Oppression arises from an inequality of bargaining power which results in no real negotiation and an absence of meaningful choice." Id. at 122 (internal quotation marks and citation omitted). "Surprise involves the extent to which the supposedly agreed-upon terms of the bargain are hidden in a prolix printed form drafted by the party seeking to enforce the disputed terms." Id. (internal quotation marks omitted). The Ninth Circuit has held that "a contract is procedurally unconscionable under California law if it is 'a standardized contract, drafted by the party of superior bargaining strength, that relegates to the subscribing party only the opportunity to adhere to the contract or reject it.' "
Pokorny , 601 F.3d at 996 (quoting Ting v. AT & T , 319 F.3d 1126, 1148 (9th Cir. 2003) ). Plaintiffs plead such a circumstance in alleging that Defendants' liability limitations appear near the end of the 12-page legal Terms of Service document where the Terms of Service are contained in an adhesion contract and customers may not negotiate or modify any terms. FAC ¶¶ 236-37. Although the fact that Plaintiffs could have used other email services may weaken their procedural unconscionability claim, the Ninth Circuit has "consistently followed the [California] courts that r