Second Amended Consolidated Class Action Complaint.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Case 5:16-md-02752-LHK Document 387-4 Filed 07/11/19 Page 1 of 97 1 MORGAN & MORGAN CASEY GERRY SCHENK COMPLEX LITIGATION GROUP FRANCAVILLA BLATT & PENFIELD 2 John A. Yanchunis (Admitted Pro Hac Vice) LLP 3 201 N. Franklin Street, 7th Floor Gayle M. Blatt, SBN 122048 Tampa, Florida 33602 110 Laurel Street 4 Telephone: 813/223-5505 San Diego, CA 92101 813/223-5402 (fax) Telephone: 619/238-1811 5 [email protected] 619/544-9232 (fax) [email protected] 6 7 Ariana J. Tadler (Pro Hac Vice) ROBBINS GELLER RUDMAN [email protected] & DOWD LLP TADLER LAW, LLP 8 Stuart A. Davidson (Admitted Pro Hac One Penn Plaza Vice) 9 New York, New York T: 212-946-9453 120 East Palmetto Park Road, Suite 500 10 F: 212-273-4375 Boca Raton, FL 33432 Telephone: 561/750-3000 11 561/750-3364 (fax) [email protected] 12 LOCKRIDGE GRINDAL NAUEN 13 P.L.L.P. 14 Karen Hanson Riebel (Admitted Pro Hac Vice) 15 100 Washington Ave. South, Suite 2200 Minneapolis, MN 55401 16 Telephone: 612/339-6900 17 612/339-0981 (fax) [email protected] 18 Attorneys for Plaintiffs and the Class 19 20 UNITED STATES DISTRICT COURT 21 NORTHERN DISTRICT OF CALIFORNIA 22 SAN JOSE DIVISION 23 IN RE: YAHOO! INC. CUSTOMER DATA CASE NO. 16-MD-02752-LHK 24 SECURITY BREACH LITIGATION SECOND AMENDED CONSOLIDATED 25 CLASS ACTION COMPLAINT 26 JURY TRIAL DEMANDED 27 28 16-MD-02752 Second Amended Consolidated Class Action Complaint Case 5:16-md-02752-LHK Document 387-4 Filed 07/11/19 Page 2 of 97 1 TABLE OF CONTENTS 2 I. SUMMARY OF THE CASE .............................................................................1 3 II. JURISDICTION AND VENUE ........................................................................6 4 III. PARTIES ...........................................................................................................6 5 A. Class Representatives Who Signed up for Yahoo Services in the United States ..........................................................................................6 6 B. Class Representatives for the Israel Class ...........................................11 7 C. Class Representative for the Small Business Users Class ...................12 8 D. Class Representative for the Paid Users Class .....................................14 9 E. Defendants ...........................................................................................15 10 IV. FACTUAL BACKGROUND ..........................................................................16 11 A. Yahoo Collects and Stores PII for its Own Financial Gain .................16 12 B. Yahoo’s Small Business Customers Depended on Defendants’ PII 13 Security Practices .................................................................................19 14 C. PII is Very Valuable on the Black Market ...........................................22 15 D. Yahoo Turns a Blind Eye to Gaping Holes in Its Security, Refusing to Upgrade After Repeated Intrusions and Negative Assessments ..........25 16 E. Yahoo’s Inadequate Data Security Allows the Massive Breach of 1 17 Billion User Accounts in 2013, Which Yahoo Then Fails to Disclose ..............................................................................................................32 18 F. Yahoo’s Security Is Breached Again and Again—in 2014, 2015, and 19 2016—Yet Yahoo Still Does Not Alert Its Users ................................34 20 G. Yahoo Reveals the 2014 Breach Years After It Happened ..................43 21 H. More Than Three Years After the Fact, Yahoo Finally Acknowledges the 2013 Breach ...................................................................................47 22 I. Despite All of This, Yahoo Still Waits to Notify Users Affected by the 23 Forged Cookie Breach .........................................................................48 24 J. The Full Extent of the Fallout from the Breaches is Not Yet Known .50 25 V. CLASS ACTION ALLEGATIONS ................................................................55 26 VI. CHOICE OF LAW ..........................................................................................61 27 VII. CLAIMS ALLEGED ON BEHALF OF ALL CLASSES ...............................63 28 First Claim for Relief: Violation of California’s Unfair Competition Law i 16-MD-02752 Second Amended Consolidated Class Action Complaint Case 5:16-md-02752-LHK Document 387-4 Filed 07/11/19 Page 3 of 97 (“UCL”) – Unlawful Business Practice ...............................................63 1 Second Claim for Relief: Violation of California’s Unfair Competition Law 2 (“UCL”) – Unfair Business Practice ....................................................66 3 Third Claim for Relief: Deceit by Concealment — Cal. Civil Code §§ 1709, 1710......................................................................................................70 4 Fourth Claim for Relief: Negligence ...............................................................72 5 Fifth Claim for Relief: Breach of Contract ......................................................74 6 Sixth Claim for Relief: Breach of Implied Contracts ......................................79 7 Seventh Claim for Relief: Breach of the Implied Covenant of Good Faith and 8 Fair Dealing .........................................................................................80 9 Eighth Claim for Relief: Declaratory Relief ....................................................81 10 VIII. ADDITONAL CLAIMS ALLEGED ON BEHALF OF THE SMALL BUSINESS USERS CLASS ONLY ..........................................................82 11 Ninth Claim for Relief: Violation of California’s Unfair Competition Law 12 (“UCL”) – Fraudulent Business Practice .............................................82 13 Tenth Claim for Relief: Misrepresentation ......................................................85 14 IX. ADDITONAL CLAIMS ALLEGED ON BEHALF OF THE PAID USERS CLASS ONLY ...........................................................................................87 15 Eleventh Claim for Relief: Violation of California’s Consumer Legal 16 Remedies Act (“CLRA”) .....................................................................87 17 X. ADDITONAL CLAIMS ALLEGED ON BEHALF OF THE CALIFORNIA SUBCLASS ONLY ...................................................................................90 18 Twelfth Claim for Relief: Violation of California’s Customer Records Act – 19 Inadequate Security ..............................................................................90 20 Thirteenth Claim for Relief: Violation of California’s Customer Records Act – Delayed Notification .......................... Error! Bookmark not defined. 21 XI. PRAYER FOR RELIEF ..................................................................................93 22 XII. JURY TRIAL DEMANDED ...........................................................................94 23 24 25 26 27 28 16-MD-02752 ii Second Amended Consolidated Class Action Complaint Case 5:16-md-02752-LHK Document 387-4 Filed 07/11/19 Page 4 of 97 1 For their Second Amended Consolidated Class Action Complaint, Plaintiffs Kimberly 2 Heines, Hashmatullah Essar, Paul Dugas, Matthew Ridolfo, Deana Ridolfo, Yaniv Rivlin, 3 Mali Granot, Brian Neff, and Andrew J. Mortensen, on behalf of themselves and all others 1 4 similarly situated, allege the following against Defendant Yahoo! Inc. (“Yahoo”), and 5 Plaintiff Brian Neff, on behalf of himself and all others similarly situated, alleges the 6 following against Defendants Yahoo and Aabaco Small Business, LLC (“Aabaco”) 7 (collectively with Yahoo, “Defendants”), based on personal knowledge as to Plaintiffs and 8 Plaintiffs’ own acts and on information and belief as to all other matters based upon, inter 9 alia, the investigation conducted by and through Plaintiffs’ undersigned counsel: 10 SUMMARY OF THE CASE 11 1. Giant information service providers such as Google, Facebook, Microsoft, and 12 Yahoo experience a consistent stream of attacks on their data security. Quickly identifying 13 and documenting those attacks, stopping them, and crafting better security measures to 14 prevent them in the future is a normal, expected part of the business – except in Yahoo’s 15 case. Inexplicably turning a blind eye to this key aspect of its business, Yahoo did not just 16 ignore security holes, it failed to set up the systems necessary to even detect or document 17 them. This practice was long-term. Yahoo’s own documents demonstrate that for nearly the 18 last decade, Yahoo’s systems have been breached again and again and again and that Yahoo 19 in essence did nothing to protect its user data. 20 2. As a telling example, law enforcement notified Yahoo of a potential breach in 21 late 2011. It took Yahoo until January 30, 2012, to retain an outside cybersecurity firm, 22 1 In June, 2017, Yahoo’s operating business was acquired by Verizon Communications 23 Inc. (“Verizon”), with Yahoo continuing to exist as a wholly-owned subsidiary of Oath, Inc., a subsidiary of Verizon. In the event Yahoo is unable to satisfy any judgment entered in this 24 case against it, and a successor entity is the proper defendant, plaintiffs will promptly move under Rule 25(c) to substitute Yahoo’s successor as a proper defendant, which may be done 25 at any time, including after judgment. See Fed. Ins. Co. v. Laney, No. C 12-04708 WHA, 26 2013 WL 3597309, at *2 (N.D. Cal. July 12, 2013) (noting that “Rule 25(c) has no time limit.”); Zest IP Holdings, LLC v. Implant Direct Mfg, LLC, No. 10CV0541-GPC-WVG, 27 2013 WL 1626111, at *2 (S.D. Cal. Apr. 15, 2013) (“Rule 25(c) does not have