Citations
- 357 F. Supp. 3d 1189
Full opinion text
THOMAS W. THRASH, JR., United States District Judge
This is a securities fraud class action. It is before the Court on the Defendants' Joint Motion to Dismiss [Doc. 62]. For the reasons set forth below, the Defendants' Joint Motion to Dismiss [Doc. 62] is GRANTED in part and DENIED in part.
I. Background
This case arises out of a massive data breach incident. On September 7, 2017, the Defendant Equifax Inc. announced that it was the subject of a data breach affecting more than 148 million Americans (the "Data Breach"). Criminal hackers breached Equifax's Computer network and obtained a vast amount of personally identifiable information in the company's custody. The Lead Plaintiff, Union Asset Management Holding AG, seeks to represent a putative class of investors that purchased the securities of Equifax from February 25, 2016 through September 15, 2017. The Plaintiff alleges that the Defendants committed fraud in connection with the Data Breach that caused a loss in value of the class's investments. Specifically, the Plaintiff alleges that the Defendants made multiple false or misleading statements and omissions about the sensitive personal information in Equifax's custody, the vulnerability of its internal systems to cyberattack, and its compliance with data protection laws and cybersecurity best practices. Despite these assurances, Equifax allegedly failed to take some of the most basic precautions to protect its computer systems from hackers. According to the Plaintiff, these material misrepresentations artificially inflated the value of Equifax's securities, causing a loss in value of the class's investments when the truth was revealed after the Data Breach.
Equifax is a Georgia corporation with its headquarters in Atlanta, Georgia. It is one of the three largest credit reporting agencies in the world. Equifax operates primarily through four segments: U.S. Information Solutions, a segment that provides products and services to businesses; Equifax's International operating segment, which includes its Asia, Europe, Latin America, and Canada business units; Equifax's Workforce Solutions segment, which provides verification and employer services; and Global Consumer Solutions, its direct-to-consumer business that provides consumers with products to protect and monitor their credit and identity. The Defendants Richard F. Smith, John W. Gamble, Jr., Rodolfo O. Ploder, and Jeffrey L. Dodge (the "Individual Defendants") were corporate officers at Equifax during the putative class period. The Defendant Richard F. Smith is the former Chief Executive Officer and Chairman of the Board of Directors of Equifax. Smith resigned from both of these positions on September 26, 2017. The Defendant John W. Gamble is the Corporate Vice President and Chief Financial Officer of Equifax. The Defendant Rodolfo O. Ploder is the President of Equifax's Workforce Solutions operating segment. The Defendant Jeffrey L. Dodge is the Senior Vice President of Investor Relations at Equifax.
As part of its business, Equifax collects, maintains, and sells a huge quantity of personal data about consumers and employees all over the world. This personally identifiable information is highly sensitive. It includes Social Security numbers, addresses, birthdays, employment history, driver's license information, detailed payment history, loans, credit card information, and more. Credit bureaus such as Equifax acquire this information from banks, mortgage lenders, credit card issuers, and other financing companies. This personally identifiable information is a highly valuable target for cybercriminals; it includes some of the most private information about consumers. This information can be used to enter into a mortgage, set up a bank account, change a phone number, and even more.
The Defendants recognized the importance of safeguarding this highly sensitive personal information. In its SEC filings, Equifax acknowledged that it collected and stored sensitive data, including the personally identifiable information of consumers, and stated that safeguarding this data was "critical" to its "business operations and strategy." It noted that its success was dependent upon its "reputation as a trusted steward of information." Equifax also acknowledged that it was a valuable target for cybercriminals due to the vast trove of information it collected. In its SEC filings, Equifax recognized that it was regularly the target of criminal hackers, and that a cybersecurity incident could subject it to a variety of serious consequences.
Acknowledging the importance of protecting the data in its custody, the Defendants made a number of statements during the class period regarding Equifax's networks and the security of the personal data in its custody. According to the Plaintiff, the Defendants issued statements concerning the strength of Equifax's cybersecurity systems, its compliance with data protection laws, and the integrity of its internal controls. For example, with regard to the strength of its data security, Equifax's website provided that the company employed "strong data security and confidentiality standards" and maintained "a highly sophisticated data information network that includes advanced security, protections and redundancies." With regard to Equifax's compliance with data protection laws, regulations, and standards, the Defendants stated in SEC filings that they continuously monitored federal and state legislative and regulatory activities "in order to remain in compliance" with those laws. The Defendants also certified in SEC filings during the class period that Equifax had effective internal controls that would provide "reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of our assets."
However, despite these assurances, Equifax's cybersecurity was dangerously deficient. The Data Breach, according to the Plaintiff, was the inevitable result of widespread shortcomings in Equifax's data security systems. According to the Plaintiff's allegations, Equifax's data protection measures were "grossly inadequate," "failed to meet the most basic industry standards," and "ran afoul of the well-established mandates of applicable data protection laws." These shortcomings spanned a number of facets of cybersecurity practices, including a failure to implement proper patching protocols, failure to encrypt sensitive information, the storage of sensitive data on public-facing servers, the use of inadequate network monitoring practices, the use of obsolete software, and more. Overall, according to cybersecurity experts, a "catastrophic breach of Equifax's systems was inevitable because of systemic organizational disregard for cybersecurity and cyber-hygiene best practices."
According to the Plaintiff, Equifax failed to implement an adequate patch management process, while also failing to remediate known deficiencies in its cybersecurity infrastructure. The company relied upon a single individual to manually implement its patching process across its entire network. This individual had no way to know where vulnerable software in need of patching was being run on Equifax's systems. This protocol was far less secure than the automatic patching processes that many other companies, including Equifax's peers, employ in their systems. According to cybersecurity experts, this patching process fell far short of industry standards.
Equifax also failed to encrypt sensitive data in its custody. According to the Amended Complaint, Equifax admitted that sensitive personal information relating to hundreds of millions of Americans was not encrypted, but instead was stored in plaintext, making it easy for unauthorized users to read and misuse. Not only was this information unencrypted, but it also was accessible through a public-facing, widely used website. This enabled any attacker that compromised the website's server to immediately have access to this sensitive personal data in plaintext. Smith also admitted during congressional testimony that, with respect to its core credit databases, Equifax failed to encrypt any of its data. It also failed to encrypt its highly vulnerable mobile applications, meaning that in addition to keeping sensitive data unencrypted in its own systems, it also failed to encrypt data being transmitted over the internet. This, according to experts, was a major security failure. And, when Equifax did encrypt data, it left the keys to unlocking the encryption on the same public-facing servers, making it easy to remove the encryption from the data. These inadequacies in Equifax's encryption protocol fell far short of industry standards and data security laws, and showed that Equifax did not "know what they were doing" with respect to data security.
Moreover, Equifax also failed to implement adequate authentication measures. Authentication measures are mechanisms, such as passwords, that verify that a party attempting to access a system or network is authorized to do so. According to the Amended Complaint, Equifax's authentication measures were insufficient to protect the sensitive personal data in its custody from unauthorized access. These mechanisms included weak passwords and security questions. For example, Equifax relied upon four digit pins derived from Social Security numbers and birthdays to guard personal information, despite the fact that these weak passwords had already been compromised in previous breaches. Furthermore, Equifax employed the username "admin" and the password "admin" to protect a portal used to manage credit disputes, a password that "is a surefire way to get hacked." This portal contained a vast trove of personal information. According to cybersecurity experts, these shortcomings demonstrated "poor security policy and a lack of due diligence." Equifax's authentication practices fell short of the data security standards, which recommend the use of multi-factor authentication.
Equifax also failed to adequately monitor its networks and systems, which greatly exacerbated the fallout of the Data Breach. According to the Plaintiff, Equifax failed to establish mechanisms for monitoring its networks and systems to alert when a threat existed. Such mechanisms include maintaining activity logs, setting up processes for tracking malicious scripts, and implementing file integrity monitoring. According to cybersecurity experts, logging is a "simple but crucial cybersecurity technique" in which a company monitors its systems by continuously logging network access so as to identify unauthorized users. This failure by Equifax greatly compounded the magnitude of the Data Breach's impact. According to experts, a breach as large scale as this one would not have occurred if Equifax had implemented better monitoring systems. If adequate monitoring systems had been in place, Equifax could have identified the breach much earlier and prevented the exfiltration of consumer data from its network. Improved logging techniques also could have enabled Equifax to expel the hackers from its systems and minimize the impact of the breach. Instead, due in part to Equifax's failure to implement effective logging techniques, hackers were able to continuously access this sensitive personal data for over 75 days. Equifax's failure to utilize proper network monitoring, one of the most basic cybersecurity practices, demonstrates the fundamental deficiencies in its networks.
Equifax's handling of the sensitive data in its custody also reflected a poor cybersecurity regime. There were two main shortcomings as to this category. First, Equifax stored sensitive personal information, in unencrypted plaintext form, on public-facing servers and web portals. Second, it failed to partition this sensitive information to limit the exposure if a breach occurred. In contrast, standard security best practices recommend that companies ensure that sensitive data is stored on non-public servers and is inaccessible through public-facing networks. Equifax's failure to properly segment its networks also contravened standard cybersecurity practices. Experts note that network segmentation, which consists of dividing a network into smaller partitions, isolates critical assets from one another and controls the access to sensitive data. Equifax's failure to properly handle this sensitive data is another example of the deficiencies in its cybersecurity regime.
Many other aspects of Equifax's cybersecurity practices were also deficient. According to the Plaintiff, Equifax relied upon outdated security systems and software, allowed its "attack surface" to grow too big by leaving thousands of servers exposed on the internet; allowed unused data to accumulate and failed to dispose of unneeded data; failed to restrict access to sensitive data to only those employees whose job responsibilities required such access; failed to adequately train its security personnel; failed to perform adequate reviews of its systems, networks, and security; and failed to develop a data breach management plan. However, despite the woeful state of Equifax's cybersecurity, the Defendants made a number of statements touting the strength of Equifax's data systems and the cybersecurity practices that it employed.
According to the Plaintiff, the Defendants also ignored a number of warnings that Equifax's data security measures were inadequate. In 2014, KPMG performed a security audit of Equifax which found that, among other deficiencies, Equifax left encryption keys on the same public servers where encrypted data was stored. Then, in 2016, Equifax hired Deloitte to perform another security audit. Deloitte discovered several problems in its audit, including inadequate patching systems. However, according to former cybersecurity employees at Equifax, the company's management did not take the security audit seriously. Equifax employees and cybersecurity researchers continued to warn Equifax of deficiencies in its cybersecurity protocol. They warned Equifax about its inadequate patching systems, its failure to encrypt sensitive personal data, its storage of personal data on public-facing servers, and more. Furthermore, in March 2017, Equifax hired Mandiant, a cybersecurity firm, to investigate weaknesses in its data protection systems. This investigation, which was described as a "top-secret project," was personally overseen by Smith. Mandiant concluded that Equifax's data protection systems were grossly inadequate. Mandiant specifically identified Equifax's unpatched systems and "misconfigured security policies" as indicative of major problems. However, instead of heeding Mandiant's advice, Equifax squelched a broader review of Equifax's security systems.
Equifax also experienced other, smaller data breaches prior to the Data Breach here. According to the Plaintiff, these previous breaches should have warned the Defendants that Equifax's cybersecurity, including its authentication and network monitoring measures, was severely deficient. In April 2016, hackers breached Equifax's W2Express website, a service that offers downloadable W-2 forms for companies. The hackers were able to access the W-2 data of hundreds of thousands of employees of numerous companies that contracted with Equifax to use this service. The hackers were able to access this information by entering an employee's default PIN code, which was the last four digits of the employee's Social Security number and their four-digit birth year. According to cybersecurity experts, these authentication measures fell short of data security best practices. The hackers were also able to remain undetected in Equifax's networks for approximately one year before they were discovered, which the Plaintiff alleges reflected a failure to employ adequate network monitoring practices. Then, in February 2017, Equifax learned that another breach occurred in its Workforce Solutions segment. From April 2016 to March 2017, hackers were able to obtain wage and W-2 data maintained by Equifax's TALX division, now called Equifax Workforce Solutions. The hackers were again able to exploit Equifax's use of personal identifiers and weak four-digit PIN codes to protect this sensitive data. The hackers also were able to remain in Equifax's network for over a year. Cybersecurity experts opined that Equifax's authentication protections, which were exploited in this breach, were inadequate and failed to meet basic industry standards. After this incident Equifax promised to make improvements in its cybersecurity defenses, but failed to do so.
On or about March 7, 2017, security firms began issuing warnings that attackers were exploiting a vulnerability in Apache Struts, an open-source software application used to build interactive websites. This software is commonly used for websites where customers submit online forms. Apache Struts is widely used by large businesses, including a substantial percentage of the Fortune 100 companies. Equifax used Apache Struts at this time. Security firms began reporting that Apache Struts was vulnerable to a "remote code execution attack." This attack is a dangerous type of exploit that allows attackers to force the vulnerable systems into running computer programs written by the attackers, which can make it easy to either steal data or establish a foothold in the vulnerable system. This weakness in Apache Struts was not just highly dangerous - it was also especially easy to exploit. Due to both the dangerous nature of this vulnerability and the widespread use of Apache Struts in the business community, the vulnerability and the corresponding update to the software aimed at addressing the vulnerability were widely publicized. Both Apache itself and security firms publicized the vulnerability. By March 8, 2017, Apache released updated versions of Apache Struts to mitigate this vulnerability in the software.
In March 2017, hackers breached Equifax's network using the Apache Struts vulnerability. On or about May 13, 2017, the hackers accessed files containing Equifax usernames and passwords, which they then used to access documents and sensitive information in Equifax's "legacy environment," an area where it stored old data that it no longer used. The attackers accessed numerous databases and compromised multiple systems. The collection of information that the hackers obtained was so large that they had to break it up into smaller pieces to avoid setting off alarms. The hackers ultimately stole the names, Social Security numbers, birthdays, addresses, drivers license information, tax identification numbers, and other personal data of 148 million Americans, as well as personal information of nearly one million foreign consumers and employees. They also obtained the credit card information for 209,000 consumers.
On July 29 and 30 of 2017, Equifax discovered that criminal hackers had gained unauthorized access to its network. Susan Mauldin, Equifax's Chief Security Officer, notified John Kelly, Equifax's Chief Legal Officer, about the Data Breach on July 31. Mauldin informed Kelly that personally identifiable information may have been compromised in the Data Breach. Under Equifax's data security protocol, the chief of security is alerted about any issues, who then determines the severity of the breach. If the chief of security determines the breach to be severe, he or she then informs the executive leadership of the issue. On July 31, Smith was notified about the Data Breach. Kelly told Smith that Chief Information Officer David Webb would meet with him in person to discuss a data security issue. In this meeting, Webb notified Smith of the Data Breach, informing him that it had occurred in an online consumer dispute portal.
On August 2, 2017, Equifax notified the FBI of the Data Breach. It also retained legal counsel to guide its investigation into the breach. The same day, Equifax's legal counsel retained Mandiant to assist in the investigation into the incident. Experts would later note that these steps suggested that Equifax knew that the Data Breach was serious. In the days immediately following the discovery of the Data Breach, Gamble and Ploder sold more than $ 1 million in Equifax stock. On August 1, Gamble, Equifax's Chief Financial Officer, sold stock for $ 946,374, representing more than thirteen percent of his holdings. On August 2, Ploder sold stock for $ 250,458, representing four percent of his holdings. These sales were not made pursuant to a Rule 10b5-1 trading plan. Smith would later state in congressional testimony that Ploder and Gamble would have been in many of the meetings he had concerning the Data Breach.
By August 11, 2017, Mandiant confirmed that hackers accessed databases containing a large amount of consumers' personally identifiable information. Smith requested a briefing on the Data Breach on August 15, 2017. At this briefing, Smith was informed that it was likely that personally identifiable information had been stolen. On August 16, 2017, at an Equifax investor conference, the Defendants stated that Equifax's "role as a Trusted Steward is a Key Execution Enabler" and stated that it was making "investments to address critical data security throughout the company." On August 17, 2017, Smith spoke at an event at the Terry College of Business at the University of Georgia. When asked by an audience member how Equifax prepares for data fraud, Smith responded "when you have the size database we have, it's very attractive for others to try to get into our database, so it is a huge priority for us as you might guess. [ ] [Data fraud] is my number one worry, obviously."
On September 7, 2017, Equifax disclosed the Data Breach to the public for the first time. In a press release after the close of trading that day, Equifax revealed that it had suffered a data breach affecting the personal information of approximately 143 million American consumers. Equifax continued to make subsequent disclosures over the following days, ending on September 15, 2017, providing additional details concerning the Data Breach. The company stated that it had engaged Mandiant, a cybersecurity firm, to conduct a review, and that it had reported the breach to law enforcement. Experts, analysts, and the media immediately began to weigh in, with one analyst describing the breach as "one of the biggest cyber-attacks in US history." Cybersecurity experts opined that massive cybersecurity failures on Equifax's part resulted in the Data Breach, and that its public response and outreach were "haphazard and ill-conceived." Financial experts also began to weigh in. Some financial analysts predicted from the outset of this public revelation that, due to the unprecedented size of this incident, Equifax's stock price would decline. Other analysts predicted that Equifax would incur substantial costs relating to the Data Breach for years to come.
On September 8, 2017, the price of Equifax's common stock dropped nearly fifteen percent, closing at $ 123.13 per share. There was also an extraordinarily high trading volume of 16.85 million shares of Equifax stock. On Monday, September 11, 2017, in response to more revelations made over the weekend, Equifax's stock price fell another nine percent to $ 113.32 per share. Over the course of the next few days, more information concerning Equifax's cybersecurity and the Data Breach was revealed to the public. By September 15, 2017, Equifax's stock price had fallen to $ 92.98, nearly a thirty-six percent decline since the initial public disclosure of the Data Breach.
On September 8, 2017, this action was commenced. In the Amended Complaint, the Plaintiff asserts one claim for violation of section 10(b) of the Exchange Act and Rule 10b-5 promulgated thereunder against all of the Defendants (Count I), and one claim for violation of section 20(a) of the Exchange Act against the Individual Defendants (Count II). The Plaintiff alleges that the Defendants made false or misleading statements on Equifax's website, in Equifax's SEC filings, and at Equifax Investor Conferences and Presentations. According to the Plaintiff, these false or misleading statements concerned the state of Equifax's cybersecurity, Equifax's compliance with data protection laws, regulations, and industry best practices, and Equifax's internal controls. On June 18, 2018, this Court modified the PSLRA's automatic stay of discovery to allow for limited case management and discovery planning activities. The Defendants now move to dismiss.
II. Legal Standard
A complaint should be dismissed under Rule 12(b)(6) only where it appears that the facts alleged fail to state a "plausible" claim for relief. A complaint may survive a motion to dismiss for failure to state a claim, however, even if it is "improbable" that a plaintiff would be able to prove those facts; even if the possibility of recovery is extremely "remote and unlikely." In ruling on a motion to dismiss, the court must accept the facts pleaded in the complaint as true and construe them in the light most favorable to the plaintiff. Generally, notice pleading is all that is required for a valid complaint. Under notice pleading, the plaintiff need only give the defendant fair notice of the plaintiff's claim and the grounds upon which it rests.
Complaints that allege fraud under federal securities law must satisfy the heightened pleading requirements of both Rule 9(b) and the Private Securities Litigation Reform Act of 1995. Rule 9(b) requires a complaint to "state with particularity the circumstances constituting fraud." "A complaint satisfies Rule 9(b) if it sets forth precisely what statements or omissions were made in what documents or oral representations, who made the statements, the time and place of the statements, the content of the statements and manner in which they misled the plaintiff, and what benefit the defendant gained as a consequence of the fraud."
The PSLRA also sets forth heightened pleading standards. This law was "enacted to cure perceived abuses in prosecuting class actions brought pursuant to federal securities laws." The PSLRA supplements Rule 9(b) in two ways. First, a plaintiff must specify "the reason or reasons why the statement is misleading, and, if an allegation regarding the statement or omission is made on information and belief, the complaint shall state with particularity all facts on which that belief is formed." Second, a plaintiff must set forth particular facts that give rise to a strong inference that the defendants acted with the required state of mind. Specifically, it requires that "the complaint shall, with respect to each act or omission alleged to violate this chapter, state with particularity facts giving rise to a strong inference that the defendant acted with the required state of mind." A complaint that fails to comply with any of these requirements must be dismissed.
III. Discussion
Section 10(b) of the Exchange Act of 1934 makes it unlawful "[t]o use or employ, in connection with the purchase or sale of any security ... any manipulative or deceptive device or contrivance in contravention of such rules and regulations as the Commission may prescribe." Rule 10b-5, promulgated thereunder by the Commission, states:
It shall be unlawful for any person, directly or indirectly, by use of any means or instrumentality of interstate commerce, or of the mails or of any facility of any national securities exchange, (a) To employ any device, scheme, or artifice to defraud, (b) To make any untrue statement of a material fact or to omit to state a material fact necessary in order to make the statements made, in the light of the circumstances under which they were made, not misleading, or (c) To engage in any act, practice, or course of business which operates or would operate as a fraud or deceit upon any person, in connection with the purchase or sale of any security.
To establish a securities fraud claim under these provisions, a plaintiff must allege: "(1) a material misrepresentation or omission; (2) made with scienter; (3) a connection with the purchase or sale of a security; (4) reliance on the misstatement or omission; (5) economic loss; and (6) a causal connection between the material misrepresentation or omission and the loss, commonly called 'loss causation.' "
The Defendants make four main arguments. First, they argue that the Plaintiff has failed to adequately plead that they made false or misleading statements. Second, they contend that the Plaintiff has failed to plead a strong inference of scienter, as required under the PSLRA. Third, they argue that the Plaintiff fails to adequately plead loss causation, an essential element of a section 10(b) claim. Finally, they argue that the Plaintiff's section 20(a) claim fails. The Court addresses each of these arguments in turn.
A. False or Misleading Statements
The Defendants first argue that the Plaintiff fails to sufficiently plead that the statements in question were false or misleading, as required by the PSLRA. Complaints alleging fraud must meet the heightened-pleading standards of Rule 9(b), which requires that in "alleging fraud or mistake, a party must state with particularity the circumstances constituting fraud or mistake." A fraud claim meets the requirements of Rule 9(b) if it sets forth precisely what statements or omissions were made in what documents or oral presentations, who made the statements, the time and place of the statements, the contents of the statements or manner in which they misled the plaintiff, and what the defendants gained as a consequence. Additionally, the PSLRA requires a securities-fraud plaintiff to "specify each statement alleged to have been misleading" and "the reason or reasons why the statement is misleading." "To show falsity, one typically juxtaposes an alleged misrepresentation to a contrary true fact." "A statement is misleading if in the light of the facts existing at the time of the statement a reasonable investor, in the exercise of due care, would have been misled by it." If an allegation regarding a statement or omission is made on information and belief, the complaint must state with particularity the facts on which the belief is formed.
This securities-fraud case is based primarily on the Defendants' alleged misrepresentations during the class period about the security of Equifax's networks and its efforts to ensure the protection of the data in its custody. The Defendants' purported misrepresentations can be grouped into three main categories: (1) statements concerning Equifax's cybersecurity and its efforts to protect consumer data; (2) statements concerning Equifax's compliance with data protection laws, regulations, and industry best practices; and (3) statements concerning Equifax's internal controls. The Defendants make four main arguments in favor of dismissal. First, they argue that many of the Plaintiff's claims allege mere corporate mismanagement. Second, they argue that the Plaintiff has not sufficiently pleaded the falsity of the alleged statements as required by the PSLRA. Third, they argue alleged statements of opinion or belief are not actionable. Fourth, they argue that they were under no duty to disclose the Data Breach prior to September 7, 2017. The Court addresses each of these.
1. Corporate Mismanagement
The Defendants first contend that many of the Plaintiff's allegations concern mere corporate mismanagement, which is not actionable under the federal securities laws. Specifically, the Defendants contend that "[a]llegations that Defendants should have implemented different or better security measures to protect data are, at most, allegations of 'mismanagement,' for which the securities laws do not provide a remedy." In Santa Fe Industries, Inc. v. Green , the Supreme Court held that allegations of corporate mismanagement are not actionable under section 10(b) because the federal securities laws do not regulate corporate fiduciary duties. There, the Supreme Court rejected a minority shareholder's claim that the company's majority shareholders violated section 10(b) by utilizing a short-form merger to eliminate the minority's interest. The Court concluded that the transaction at issue was not manipulative or deceptive within the meaning of section10(b), and consequently not actionable. Thus, a plaintiff who alleges mere corporate mismanagement or breach of fiduciary duty does not state a claim under section10(b). From this, the Defendants argue that many of the Plaintiff's claims fail because they merely make hindsight criticisms of the adequacy of Equifax's management of its data security efforts.
"However, 'false or misleading statements or omissions concerning material facts about management or internal operations may be actionable,' such as when a defendant 'makes certain statements while that defendant knows that existing mismanagement makes those statements false or misleading.' " Thus, while allegations that Equifax engaged in mismanagement would fail under section 10(b), allegations that the Defendants made false or misleading statements or omissions concerning such corporate mismanagement at Equifax can constitute basis for a section 10(b) claim. The Defendants misconstrue the Plaintiff's argument. The Plaintiff does not argue that the Defendants violated section 10(b) by failing to implement better cybersecurity practices. Instead, the Plaintiff contends that the Defendants violated section 10(b) by making false or misleading statements as to the strength and quality of Equifax's cybersecurity. Such a claim is not barred by Santa Fe.
2. The Adequacy of Equifax's Data Security
Next, the Defendants argue that the statements touting the strength of Equifax's data security systems and the adequacy of Equifax's efforts to promote cybersecurity do not constitute material misrepresentations. In the Amended Complaint, the Plaintiff alleges that the Defendants made a variety of material misrepresentations as to the state of Equifax's data security and Equifax's efforts to promote cybersecurity. For example, the Defendants allegedly stated that Equifax was a "trusted steward" of personal data and that it employed "strong data security and confidentiality standards on the data that we provide and on the access to that data." They allegedly stated that Equifax "maintain[ed] a highly sophisticated data information network that includes advanced security, protections and redundancies." According to the Plaintiff, the fundamental shortcomings in Equifax's cybersecurity, including a failure to take some of the most elementary precautions, render these statements false or misleading.
The Defendants make two main arguments for why these statements are not material misrepresentations. First, they argue that the alleged statements are not actually false or misleading because the facts pleaded do not show that Equifax's data security was actually inadequate. Second, they contend that these statements constitute inactionable puffery. According to the Defendants, these statements were vague, meaningless, statements of corporate optimism that no reasonable shareholder would rely upon in making investment decisions. The Court addresses each of these arguments in turn.
i. Falsity
The Defendants contend that the Plaintiff has failed to plead the falsity of each of the alleged statements concerning the strength of Equifax's systems. They argue that the Plaintiff has not shown that the statements boasting of the strength and complexity of Equifax's cybersecurity are actually false. Instead, according to the Defendants, the Plaintiff has only alleged that Equifax was the victim of a criminal attack that was out of its control. They contend that the fact that a company suffered a significant cyberattack does not necessarily mean that its cybersecurity was deficient, and thus does not render its prior statements about its commitment to data security false.
However, the Plaintiff alleges more than just the mere occurrence of the Data Breach. The Plaintiff has pleaded a multitude of specific, detailed factual allegations demonstrating that Equifax's cybersecurity systems were grossly deficient and outdated, despite the Defendants' various assurances to the contrary. In the Amended Complaint, the Plaintiff alleges that Equifax failed to implement even the most basic security measures, reflecting a "systemic organizational disregard for cybersecurity and cyber-hygiene best practices." Cybersecurity experts opined that Equifax's data security failures flowed from an inadequate "tone at the top" and that "the real problem was a very poor focus on information security at the highest levels of the company." For example, according to the Plaintiff, Equifax failed to implement an effective patch management process, relying upon a single employee to manually implement the company's patching process across its entire network. This process failed to meet the most basic industry standards - application of security patches is a critical cybersecurity practice. Because of this shortcoming, Equifax allegedly failed to remediate known deficiencies in its cybersecurity infrastructure, such as the Apache Struts vulnerability. Furthermore, according to the Plaintiff, Equifax failed to implement adequate encryption measures to protect sensitive information, in contrast to its representation that it encrypted confidential information. Equifax allegedly stored and transmitted the personal information of hundreds of millions of consumers in unencrypted, plaintext, making it easy for intruders to read and misuse.
Overall, the Plaintiff alleges that, among other things, Equifax: (1) failed to implement adequate patching processes; (2) failed to create adequate encryption measures to protect the information in its custody; (3) failed to implement adequate authentication measures to ensure that parties attempting to access its networks were authorized to do so; (4) failed to establish mechanisms for monitoring its networks for security breaches; (5) stored personal data in easily accessible public channels; (6) relied on outdated and obsolete software; and (7) failed to warehouse obsolete personal information. Together, according to the Plaintiff, each of these shortcomings created an inadequate cybersecurity system.
Given the dangerously deficient state of Equifax's cybersecurity, the Court concludes it was false, or at least misleading, for Equifax to tout its advanced cybersecurity protections. In contrast to the Defendants' representations that, among other things, Equifax employed a "highly sophisticated data information network"
and "advanced security protections," Equifax's data security was dangerously lacking. While it is true that the mere occurrence of a data breach may not necessarily mean that a company's data security systems are inadequate, the Plaintiff here does not rely solely upon the occurrence of the Data Breach to establish that the Defendants' statements were false. Instead, the Plaintiff has pleaded a variety of facts showing that Equifax's cybersecurity systems were outdated, below industry standards, and vulnerable to cyberattack, and that Equifax did not prioritize data security efforts.
Furthermore, as the Plaintiff points out, a number of courts have come to a similar conclusion, holding that statements touting the strength or quality of an important business operation are false, and thus actionable, when those operations are, in reality, deficient. For example, in In re ValuJet, Inc., Securities Litigation the court explained that:
The Plaintiffs allege that, despite the numerous safety-related incidents and FAA heightened scrutiny of ValuJet's operations, (1) Defendants Jordon and Priddy fraudulently represented in the 1995 report to shareholders that ValuJet's paramount goal was profitability while maintaining operational integrity; (2) Defendant Priddy fraudulently represented at an investor's conference in April, 1996 that ValuJet planned to add additional aircraft and that growth would be significant; and (3) Defendant Jordan fraudulently represented in a press release in April, 1996 that ValuJet's safety record had been certifiably among the very best in the airline industry. When viewing the allegations in the Complaint as true, the Court finds that Defendants Jordan and Priddy's alleged misrepresentations during the class period are sufficiently plead under the PSLRA heightened-pleading standards to constitute false statements for the purposes of a Rule 10b-5 claim.
Similarly, the Defendants' representations that Equifax employed a highly sophisticated data information network are allegedly false given the actual state of its systems.
The case that the Defendants primarily rely upon, In re Heartland Payment Systems, Inc. Securities Litigation is distinguishable. In Heartland , the corporate defendant, a provider of bank card payment processing services to merchants, suffered a "Structured Query Language" attack by criminal hackers. This attack placed hidden, malicious software on the defendant's network, which infected its payment processing system. Because of this, hackers were able to steal 130 million credit card and debit card numbers. After this incident, the plaintiffs filed a securities action, alleging that the defendants misrepresented the state of Heartland's network security, that they concealed the occurrence of data breach from investors, and they made false statements concerning the adequacy of its security systems and the efforts they took for network security. Specifically, Heartland had stated that it " 'place[d] significant emphasis on maintaining a high level of security' and maintained a network configuration that 'provides multiple layers of security to isolate our databases from unauthorized access.' " The plaintiffs argued that those statements were untruthful "because Heartland had suffered the SQL attack and had not fully resolved security issues arising out of that attack." The court concluded, however, that these statements were not false or misleading because there was "nothing inconsistent" between these statements and "the fact that Heartland had suffered an SQL attack." "The fact that a company has suffered a security breach does not demonstrate that the company did not 'place significant emphasis on maintaining a high level of security.' " The court further explained that it was "equally plausible" that Heartland did place a high emphasis upon security.
In contrast, the Plaintiff here has not alleged that the Defendants' statements concerning Equifax's cybersecurity practices are false merely because Equifax suffered a security breach. Instead, the Plaintiff has asserted specific factual allegations describing the poor state of Equifax's cybersecurity. These allegations depict a data security system that was dangerously deficient and fell far short of industry standards. Unlike in Heartland , where it was plausible that the company placed a high emphasis on security but nonetheless was a victim of a breach, Equifax's data security is alleged to have been in disrepair, in contrast to the Defendants' statements otherwise. Thus, Heartland is distinguishable.
The Defendants also argue that these allegations fail because the Plaintiff has failed to plead the falsity of the statements concerning the adequacy of cybersecurity with particularity. The PSLRA requires a plaintiff to specify "the reason or reasons why the statement is misleading." For example, the Defendants contend that the Plaintiff has not adequately alleged the falsity of the statement that the "Equifax network is reviewed on a continual basis by external security experts who conduct intrusion testing, vulnerability assessments, on-site inspections, and policy/incident management reviews." However, the Court concludes that the Plaintiff has satisfied its requirement to plead the falsity of these statements with particularity. The Plaintiff alleges in the Amended Complaint that this statement was false or misleading because Equifax "ignored advice issued by those external 'security experts' warning the Company about gross inadequacies in its cybersecurity," because Equifax "failed to heed the calls of its cybersecurity consultants to perform comprehensive system reviews," and because Equifax's vulnerability scanning was deficient since scans were performed "infrequently, examined only portions of Equifax's systems, relied on outdated technology, and lacked appropriate redundancies." The Defendants argue that these allegations merely second-guess the extent or efficacy of these efforts. However, the Court concludes that these allegations are sufficient because they explain why this statement was false, or at a minimum, misleading. These allegations explain that it was misleading to state that cybersecurity experts continually review Equifax's systems when Equifax ignored those experts' suggestions and used superficial vulnerability scanning.
The Defendants also challenge the statements that Equifax had a "rigorous enterprise risk management program" that targeted its cybersecurity risks, that Equifax used "a variety of technical, administrative and physical ways to keep personal credit data safe," that Equifax "regularly review[ed] and update[d] [its] security protocols," and that Equifax "develop[ed], maintain[ed], and enhance[d] secured proprietary information databases." According to the Defendants, the Plaintiff's allegations that Equifax's efforts were inadequate fail because they do not show that Equifax did not have a risk management program, or that it did not attempt to comply with data security regulations. However, the Plaintiff adequately alleges the falsity of each of these statements with particularity. With each of these statements, the Plaintiff explains how the context of Equifax's cybersecurity makes them false or misleading. The Plaintiff alleges that each of these areas of cybersecurity was so deficient that it was misleading for Equifax to assure investors that these efforts were promoting the security of its data systems. These statements do more than merely tell investors that a risk management program existed or that it used various cybersecurity techniques. Instead, Equifax used these statements to assure investors that they were taking cybersecurity seriously.
Furthermore, the Defendants also take many of these statements out of context in their brief. For example, the Defendants argue that the Plaintiff has not shown that it was false or misleading to state that Equifax had an enterprise risk management program. But, in the Amended Complaint, the Plaintiff alleges that Equifax stated that it has "a rigorous enterprise risk management program targeting ... data security." An assurance that Equifax employed a rigorous enterprise risk management program is more misleading to investors than simply affirming the existence of an enterprise risk management program. Similarly, the Defendants argue that the Plaintiff has not alleged that it was false to state that Equifax "regularly review[ed] and update[d] [its] security protocols," even if those efforts were not effective or to the necessary extent. However, in the Amended Complaint, the Plaintiff alleges that Equifax stated that "[w]e regularly review and update our security protocols to ensure that they continue to meet or exceed established best practices at all times. " This statement does not merely state that Equifax reviewed and updated its security protocols, but instead that it did so to ensure that it met established best practices. Furthermore, the Defendants argue that the Plaintiff has not shown that the statement that Equifax "monitor[ed] federal and state legislative and regulatory activities that involve credit reporting, data privacy and security" is false, when in reality the Plaintiff alleges that Equifax stated that "[w]e continuously monitor federal and state legislative and regulatory activities that involve credit reporting, data privacy and security to identify issues in order to remain in compliance with all applicable laws and regulations. " This context, omitted by the Defendants in their argument, is important in determining whether the statements were false or misleading.
ii. Puffery
Next, the Defendants argue that many of the challenged statements concerning Equifax's commitment to data security constitute inactionable puffery. Alleged misrepresentations must be based upon a material fact to give rise to a securities law violation. "Subjective characterizations of a company's current performance or predictions about future performance, absent a false misstatement of fact, are generally not actionable." Such statements of "corporate optimism" or "puffery" are not actionable because they both lack an underlying factual basis and also fail the materiality requirement of Rule 10b-5. Thus, "vague, optimistic statements are not actionable because reasonable investors do not rely on them in making investment decisions." Statements constitute "puffery" if they are "too general to cause a reasonable investor to rely upon them." According to the Defendants, many of the alleged statements reflected corporate optimism and aspiration that a reasonable investor would not rely upon, and thus constitute puffery. Such statements of puffery cannot serve as the basis for a section 10(b) claim because a reasonable investor would not rely upon them. For example, the Defendants contend that many of the statements "generally avow a commitment to data security or characterize security as a priority for Equifax." According to the Defendants, a reasonable investor would not rely upon statements such as these, which are "generalized, non-verifiable, and vague statements of commitment to and aspirations about data security."
However, the Court finds that these alleged statements are not inactionable puffery. An alleged misstatement or omission must be "so obviously unimportant to a reasonable investor that reasonable minds could not differ on the question of their importance" to be deemed inactionable puffery. For example, in the context of a drilling company's statements concerning its safety and training efforts, one court noted that it could not "say, as a matter of law, that Transocean's representation that such efforts were extensive was 'obviously unimportant' to GSF shareholders" since "[i]n an industry as dangerous as deepwater drilling, it is to be expected that investors will be greatly concerned about an operator's safety and training efforts." Likewise, the Court cannot say, as a matter of law, that Equifax's representations that its cybersecurity efforts were extensive or that it was "committed" to data security were so "obviously unimportant" to its shareholders that they should be considered immaterial. Furthermore, the fact that these statements relate to a core aspect of Equifax's business makes it even more likely that a reasonable investor would assign weight to them. Since data security plays an important part of a business such as Equifax, investors would be even more likely to find these types of representations important in making their investment decisions. For these reasons, the Court cannot, as a matter of law, conclude that these statements are obviously unimportant to Equifax's investors.
Moreover, the context of these alleged statements is important to this determination. Although the alleged statements, when viewed in isolation, might constitute puffery, the fact that they were made repeatedly to assure investors that Equifax's systems were secure could lead a reasonable investor to rely upon them as reflecting the state of Equifax's cybersecurity. Thus, the context of these supposedly "aspirational" statements matters: the Defendants repeatedly stated that cybersecurity, an important aspect of their business, was a top priority for senior management, despite the fact that Equifax failed to employ some of the most elementary cybersecurity practices. Even if, in a vacuum, each of these statements seems like a meaningless, corporate vaguery, when taken together a reasonable investor would rely upon them to conclude that Equifax made cybersecurity a serious priority.
The cases cited by the Defendants are unpersuasive. For example, in Ong v. Chipotle Mexican Grill, Inc. (Chipotle II) , the court concluded that statements that Chipotle was "committed to serving safe, high quality food" and that its "food safety programs are ... designed to ensure" that Chipotle "compl[ies] with applicable federal, state and local food safety regulations"
were inactionable puffery. However, the court provided little analysis for why those statements constituted puffery. Here, statements affirming a commitment to cybersecurity can be actionable because a reasonable investor might rely upon such statements in making investment decisions. Although the court in Chipotle II found statements that the company was "committed" to serving safe food to constitute puffery, the Court concludes that the statements here are not so obviously unimportant to investors given the repeated nature of these statements, the context of Equifax's business, and the widespread nature of the deficiencies alleged in the Amended Complaint. Therefore, for these reasons, Chipotle II is unpersuasive.
3. Failure to Disclose the Data Breach
Next, the Defendants move to dismiss the Plaintiff's allegations based upon their purported failure to disclose the Data Breach earlier. In the Amended Complaint, the Plaintiff alleges that some of the alleged statements were or became misleading by omission because the Defendants did not publicly disclose the Data Breach until September 7, 2017. According to the Plaintiff, the Defendants' statements after March 2017 lauding Equifax's data security were false or misleading because Equifax "knew or recklessly disregarded that hackers had already penetrated its databases."
However, the Court concludes that the Defendants were under no duty to disclose the Data Breach prior to becoming aware of the incident in July 2017. The Plaintiff has not alleged that the Defendants knew about the Data Breach before July 29, 2017, but instead argues that they were reckless as to its occurrence. It bases its argument upon warnings that the Defendants allegedly received as to the deficient state of Equifax's cybersecurity, its failure to employ adequate patching processes, and its failure to use proper network monitoring. These warnings might demonstrate that the Defendants knew of, or were reckless as to, Equifax's ability to prevent or detect a breach. However, these warnings do not establish that the Defendants knew, or were reckless to the existence of, the specific Data Breach at issue here. The allegations also do not demonstrate that the Defendants knew of, or were reckless as to the existence of, Equifax's failure to patch the Apache Struts vulnerability. Therefore, the Defendants were under no duty to disclose the existence of the Data Breach before they knew it had occurred.
Second, the Plaintiff argues that the Defendants were under a duty to correct their prior misstatements once they became aware of the Data Breach in July 2017. According to the Plaintiff, even if some of the Defendants' statements may not have been misleading at the time they were made, the Defendants had a duty to correct the statements once they learned that the Data Breach had occurred. A duty to disclose can be created by a defendant's previous decision to speak on the subject. "Where a defendant's failure to speak would render the defendant's own prior speech misleading or deceptive, a duty to disclose arises." According to the Plaintiff, the Defendants had a duty to disclose once they learned that their prior statements concerning the security of Equifax's systems became false due to the Data Breach.
However, the Court finds that the occurrence of the Data Breach did not itself make those prior statements false or misleading, and thus did not create a duty to disclose. As the Court noted above, the occurrence of a data breach does not necessarily imply that a company's data security is inadequate. In Heartland, the court concluded that the defendants were not under a duty to disclose the occurrence of a data breach because the plaintiffs had not alleged that the company's systems were actually deficient. The court noted that the occurrence of a data breach itself does not establish that a company's data security is inadequate. Similarly, here, the occurrence of the Data Breach itself did not necessarily render the Defendants' prior statements false, and thus did not impose a duty to correct those statements by disclosing the occurrence of the Data Breach. Therefore, the Court finds this argument unavailing.
4. Statements About Cybersecurity Risks
Next, the Defendants move to dismiss the Plaintiff's allegations regarding Equifax's warnings of its cybersecurity risks. In the Amended Complaint, the Plaintiff alleges that Equifax, Smith, and Gamble made false or misleading statements in SEC filings concerning the cybersecurity risks that Equifax faced. The Plaintiff alleges that Equifax stated in its 2015 and 2016 Forms 10-K that:
Despite our substantial investment in physical and technological security measures, employee training, contractual precautions and business continuity plans, our information technology networks and infrastructure or those of our third-party vendors and other service providers could be vulnerable to damage, disruptions, shutdowns, or breaches of confidential information due to criminal conduct, denial of service or other advanced persistent attacks by hackers[.]
However, according to the Plaintiff, it was false or misleading to state that Equifax "could be vulnerable" to a breach "when, in fact, Equifax was highly vulnerable to such an attack, as, in fact, Defendants had been warned on numerous occasions both before and during the Class Period."
The Defendants argue that these allegations fail to state a claim because, through these statements, the Defendants warned of the precise risk that caused the Plaintiff's losses. The Court finds that these statements are not actionable. The difference between disclosing that Equifax "could be vulnerable" and that it was "highly vulnerable" would not mislead a reasonable investor in making an investment decision. The case that the Plaintiff relies upon, In re Van der Moolen Holding N.V. Securities Litigation , is distinguishable. There, the court concluded that cautionary statements can give rise to a section 10(b) violation. The court noted that "to caution that it is only possible for the unfavorable events to happen when they have already occurred is deceit." However, that case is distinguishable. There, the defendant warned investors about regulatory risks, even though it knew or was recklessly ignorant that its employees were violating NYSE rules. Here, in contrast, the risk warned of is different. The Defendants warned that Equifax could be vulnerable to a data breach, but they did not fail to disclose the existence of a breach when they made that statement. Thus, unlike in Van der Moolen , the Defendants did not warn that Equifax could be at risk, when it in fact was suffering a data breach. Therefore, the Court finds these risk statements inactionable.
5. Equifax's Compliance With Data Protection Laws
Next, the Defendants move to dismiss the Plaintiff's claims concerning statements about Equifax's compliance with data protection laws, regulations, and best practices. In the Amended Complaint, the Plaintiff alleges that the Defendants made various statements assuring that Equifax complied with relevant data protection laws, regulations, standards, and best practices. For example, the Plaintiff alleges that Equifax stated on its website that it "takes gr