DecisionDepot
California legal research
All cases
25STCV21077·la·Civil·Data Breach Class Action
Hearing todaySustained without leave to amend in part; overruled in part

Anthony Ridio v. South Bay Credit Union

Demurrer

Hearing date
Sep 2, 2026
Department
11
Prevailing
Mixed

Motion type

Browse all Demurrer rulings statewide →

Causes of action

Parties

PlaintiffAnthony Ridio
DefendantSouth Bay Credit Union

Ruling

Practice Guide: Employment Litigation (The Rutter Group 2025) P. 17:830.) The parties must ensure that the settlement complies with these percentages. [2] The Court is only required to evaluate the PAGA part of the settlement. The Court offers no opinion regarding the settlement's reasonableness as to Plaintiff's non-PAGA individual claims.

Tentative Ruling

Re: Demurrer Date: 9/2/26 Time: 1:45 pm Moving Party: South Bay Credit Union ("SBCU" or "Defendant") Opposing Party: Anthony Ridio ("Plaintiff") Department: 11 Judge: Bruce G. Iwasaki ________________________________________________________________________

Defendant's demurrer is sustained without leave to amend in part (second cause of action) and overruled in part (first, third, fourth, and fifth causes of action). BACKGROUND This is a putative class action concerning a data breach. The operative complaint ("FAC") alleges: 1. This class action arises out of the recent data security incident and data breach that was perpetrated against Defendant (the "Data Breach"), which held in its possession certain personally identifiable information ("PII"), (the "Private Information") of Plaintiff and other current and former employees and credit union members of Defendant, the putative class members ("Class"). The Data Breach occurred on and around November 18, 2024.

2. The Private information compromised in the Data Breach included certain personal information of Defendant SBCU's employees and credit union members. The Private Information exposed to the hackers/cybercriminals included Plaintiff's and the Class Members' first and last name, Social Security number and individual tax identification number.

3. Defendant has reported to the Office of the Maine Attorney General that the sensitive personal information, the Private Information, of 7,479 individuals was compromised and disclosed to an unauthorized party in the Data Breach.

4. The hackers intentionally targeted SBCU for the highly sensitive Private Information it stores on its computer network, attacked the insufficiently secured network, then exfiltrated highly sensitive PII, including Social Security numbers. As a result, the Private Information of Plaintiff and Class Members remain in the hands of those cybercriminals.

5. The Data Breach resulted from Defendant's failure to implement adequate and reasonable cyber-security procedures and protocols necessary to protect individuals' Private Information with which they were entrusted for employment.

6. Plaintiff brings this first amended class action lawsuit on behalf of those similarly situated to address Defendant's inadequate safeguarding of Class Members' Private Information that they collected and maintained, and for failing to provide timely and adequate notice to Plaintiff and other Class Members that their information was subjected to unauthorized access by an unknown third party and precisely what specific type of information was accessed.

7. Defendant maintained the Private Information in a reckless manner. In particular, the Private Information was maintained on Defendant's computer network in a condition vulnerable to cyberattacks. Upon information and belief, the mechanism of the Data Breach and potential for improper disclosure of Plaintiff's and Class Members' Private Information was a known risk to Defendant, and thus Defendant was on notice that failing to take steps necessary to secure the Private Information from those risks left that property in a dangerous condition.

8. Defendant, through its employees, disregarded the rights of Plaintiff and Class Members (defined below) by, among other things, intentionally, willfully, recklessly, or negligently failing to take adequate and reasonable measures to ensure its data systems were protected against unauthorized intrusions. Defendant also failed to disclose that it did not have adequately robust computer systems and security practices to safeguard Plaintiff's and Class Members' Private Information and failed to take standard and reasonably available steps to prevent the Data Breach.

9. In addition, Defendant, through its employees, failed to properly monitor the computer network and systems that housed the Private Information. Had Defendant's employees (presumably in the IT department) properly monitored its property; it would have discovered the intrusion sooner.

10. Plaintiff's and Class Members' identities have been and are now at risk because of Defendant's negligent conduct since the Private Information that Defendant collected and maintained is now in the hands of data thieves.

11. Armed with the Private Information accessed in the Data Breach, hackers and/or data thieves can commit and have attempted a variety of crimes. These crimes include opening new financial accounts in Class Members' names, taking out loans in Class Members' names, using Class Members' information to obtain government benefits, filing fraudulent tax returns using Class Members' information, filing false medical claims using Class Members' information, obtaining driver's licenses in Class Members' names but with another person's photograph, and giving false information to police during an arrest.

12. Because of the Data Breach, Plaintiff and Class Members have been exposed to actual fraud and attempted identity theft and a heightened and imminent risk of further fraud and identity theft. Plaintiff and Class Members must now and in the future closely monitor their financial accounts to guard against fraud and identity theft.

13. Plaintiff and Class Members have also incurred out of pocket costs for, e.g., purchasing credit monitoring services, credit freezes, credit reports, or other protective measures to deter and detect identity theft.

14. Through this Complaint, Plaintiff seeks to remedy these harms on behalf of himself and all similarly situated individuals whose Private Information was accessed during the Data Breach. (FAC, P.P. 1-14, footnotes omitted.) Here, SBCU demurs to the first (negligence), second (invasion of privacy), third (breach of implied contract), fourth (unjust enrichment), and fifth (violation of Business and Professions Code section 17200, the Unfair Competition Law ("UCL")) causes of action. APPLICABLE LAW When considering demurrers, courts read the allegations liberally and in context, and "treat the demurrer as admitting all material facts properly pleaded, but not contentions, deductions or conclusions of fact or law." (Serrano v.

Priest (1971) 5 Cal.3d 584, 591.) " A demurrer tests the pleadings alone and not the evidence or other extrinsic matters. Therefore, it lies only where the defects appear on the face of the pleading or are judicially noticed." (Hahn v. Mirda (2007) 147 Cal.App.4th 740, 747.) It is error " to sustain a demurrer without leave to amend if the plaintiff shows there is a reasonable possibility any defect identified by the defendant can be cured by amendment." (Aubry v. Tri-City Hospital Dist. (1992) 2 Cal.4th 962, 967.)

DISCUSSION First Cause of Action (Negligence) Defendant: * The negligence claim is barred by the economic-loss rule. (See Demurrer, pp. 2-4.) * Plaintiff fails to allege facts showing breach and causation. (See id. at p. 4.) Plaintiff: * The FAC alleges non-economic injuries, so the economic-loss rule does not apply. (See Opposition, pp. 2-3.) * The allegations demonstrate breach and causation. (See id. at p. 4.) Reply: * The economic-loss rule controls because "Plaintiff's negligence theory is [] nothing more than a repackaged contract claim." (Reply, p. 2; see also id. at pp. 1, 3 [claiming Stasi v.

Immediata Health Group Corp. (S.D. Cal. 2023) 501 F.Supp.3d 898 is distinguishable because the data breach there exposed medical information].) * For the breach and causation elements, Plaintiff alleges conclusions rather than facts. (See id. at pp. 3-4.) Analysis: Defendant's first argument is unavailing. The economic-loss rule forecloses "recovery of purely economic loss[,]" yet many exceptions exist. (Gardiner v. Walmart Inc. (N.D. Cal. Mar. 5, 2021, No. 20-cv-04618-JSW) 2021 WL 2520103, at *8.)

The rule does not apply if there is "(1) personal injury, (2) physical damage to property, (3) a 'special relationship' existing between the parties, or (4) some other common law exception to the rule[.]" (Ibid.) In Stasi, the complaint alleged that the plaintiffs "noticed an increase in spam/phishing e-mails and/or calls . . ., which is harm that is [] not necessarily 'economic' in nature." (Stasi, supra, 501 F.Supp.3d at 913.) The district court found the rule inapplicable, reasoning that "the time spent responding to a data breach is a non-economic injury[.]" (Ibid.; see also id. at 913-914 [reasoning that the plaintiffs and defendant "were not in privity of contract, there was no commercial activity between" the plaintiffs and defendant, "and the case d[id] not involve a defective product or services resulting in mere 'disappointed expectations[]'"].)

Plaintiff alleges comparable allegations regarding time expended monitoring financial accounts, reviewing credit reports, and taking protective measures. (See, e.g., FAC, P.P. 94-95, 98.) Overall, the Court believes Stasi is more akin to Plaintiff's case than Moore v. Centrelake Medical Group, Inc. (2022) 83 Cal.App.5 th 515 is. (See also Flores-Mendez v. Zoosk, Inc. (N.D. Cal. Jan. 30, 2021, No. C 20-04929 WHA) 2021 WL 308543 [discussing Stasi].) Defendant's second argument - failure to allege facts for breach and causation - also fails.

Paragraphs 169 through 175 state: 169. Defendant's duty of care to use reasonable security measures arose because of the special relationship that existed between Defendant and its employees and credit union members, which is recognized by laws and regulations including, but not limited to, CCPA, as well as common law. More specifically, Defendant's duty of care to use reasonable security measures arose because of the master-servant relationship that existed between Defendant and its current and former employees outside of the Member Services Agreement between Defendant and Class Members.

Defendant should have ensured that its systems were sufficient to protect against the foreseeable risk of harm to Class Members from a data breach. 170. In addition, Defendant had a duty to employ reasonable security measures under Section 5 of the Federal Trade Commission Act, 15 U.S.C. Sec. 45, which prohibits "unfair . . . practices in or affecting commerce," including, as interpreted and enforced by the FTC, the unfair practice of failing to use reasonable measures to protect confidential data.

171. Defendant's duty to use reasonable care in protecting confidential data arose not only because of the statutes and regulations described above, but also because Defendant is bound by industry standards to protect confidential Private Information. 172. Defendant breached its duties, and thus was negligent, by failing to use reasonable measures to protect Class Members' Private Information. The specific negligent acts and omissions committed by Defendant include, but are not limited to, the following: a.

Failing to adopt, implement, and maintain adequate security measures to safeguard Class Members' Private Information; b. Failing to adequately monitor the security of its networks and systems; c. Failing to periodically ensure that its email system had plans in place to maintain reasonable data security safeguards; d. Failing to store sensitive information in an encrypted state; e. Allowing unauthorized access to Class Members' Private Information; f. Failing to detect timely that Class Members' Private Information had been compromised; g.

Failing to timely notify Class Members about the Data Breach so that they could take appropriate steps to mitigate the potential for identity theft and other damages; and h. Failing to secure its stand-alone personal computers, such as the reception desk computers, even after discovery of the data breach. 173. It was foreseeable that Defendant's failure to use reasonable measures to protect Class Members' Private Information would result in injury to Class Members. Further, the breach of security was reasonably foreseeable given the known high frequency of cyberattacks and data breaches in the financial services industry. 174.

It was therefore foreseeable that the failure to adequately safeguard Class Members' Private Information would result in one or more types of injuries to Class Members, specifically as it relates to Defendant's current and former employees. 175. As a direct result of Defendant's breach of its duty to use reasonable measures to protect Class Members' Private Information, Plaintiff and Class Members suffered actual damages. (FAC, P.P. 169-175.) These allegations provide ultimate facts that suffice to put Defendant on notice, especially since Defendant is in a better position to know the precise facts.

Further details should be fleshed out via discovery. The demurrer is overruled. Second Cause of Action (Invasion of Privacy) Defendant: * "Plaintiff fails to allege a public disclosure of private facts by SBCU[.]" (Demurrer, p. 5, bolding and capitalizing deleted.) * "Plaintiff fails to allege that any disclosure was 'highly offensive[.]'" (Ibid., bolding and capitalizing deleted; see also id. at p. 6.) Plaintiff: * The FAC alleges a public disclosure of private facts. (See Opposition, pp. 4-5.) * "The alleged disclosure was 'highly offensive[.]'" (Id. at p. 5, italicizing and capitalizing deleted.)

Reply: * "The FAC alleges only that unidentified third-party criminals gained unauthorized access to information contained in a single employee email account[,]" which "is not a public disclosure by SBCU." (Reply, p. 4.) * "[C]ourts routinely reject privacy claims based on disclosure of personal identifying information because such allegations do not meet the rigorous 'highly offensive' standard." (Id. at p. 5.) Analysis: The Court agrees with Defendant. To state a claim for invasion of privacy based on public disclosure of private facts, Plaintiff must allege "(1) public disclosure, (2) of a private fact, (3) which would be offensive and objectionable to the reasonable person, and (4) which is not of legitimate public concern." (Taus v.

Loftus (2007) 40 Cal.4 th 683, 717, internal quotation marks omitted.) Plaintiff alleges that Defendant failed to implement adequate security measures, not that Defendant made an actual public disclosure of facts. (See FAC, P.P. 1-8, 182-183.) The actual public disclosure, if any, was done by the hackers. Plaintiff fails to cite authority holding a hacked defendant liable for public disclosure under this circumstance. (See Opposition, pp. 4-5.) The demurrer to the second cause of action for invasion of privacy is sustained without leave to amend.

Third Cause of Action (Breach of Implied Contract) Defendant: * The third cause of action "fails as a matter of law because an express contract exists between the parties." (Demurrer, p. 6, bolding and capitalizing deleted.) Plaintiff: * "Defendant's argument there was no implied contract between itself and Plaintiff mischaracterizes the clear allegations of the FAC and prevailing law. At this stage in litigation, Plaintiff's allegations in support of his implied contract claim are sufficiently factually supported such that the FAC adequately states a claim." (Opposition, p. 6; see also id. at p. 5.)

Reply: * "[T]he FAC itself pleads the existence of contractual commitments concerning privacy and data security, and SBCU has submitted the Member Service Agreement that expressly governs those issues." (Reply, p. 5.) Analysis: The Court agrees with Plaintiff. "[I]t is well settled that an action based on an implied-in-fact or quasi-contract cannot lie where there exists between the parties a valid express contract covering the same subject matter." (Lance Camper Manufacturing Corp. v. Republic Indemnity Co. (1996) 44 Cal.App.4 th 194, 203.)

However, the FAC does not purport to allege a valid express contract. Plaintiff only asserts an implied-contract claim. The paragraphs cited by Defendant fail to change the result. Paragraphs 27, 31 through 32, and 169 do not state that there is an enforceable express contract that, subject-wise, covers the alleged hack. The paragraphs do not demonstrate, unambiguously, that the Member Service Agreement applies to the parties' dispute. (See FAC, P.P. 27, 31-32, 169.) The demurrer to the breach of implied contract cause of action is overruled.

Fourth Cause of Action (Unjust Enrichment) Defendant: * "Unjust enrichment . . . is not a recognized cause of action" in California. (Demurrer, p. 6, bolding and capitalizing deleted.) Plaintiff: * "California courts have routinely construed unjust enrichment claims as [quasi-contract] claims for equitable restitution." (Opposition, p. 6; see also id. at p. 7.) Reply: * Plaintiff's "quasi-contract theory fails because an express contract governs the parties' relationship and the subject matter of the dispute." (Reply, p. 6; see also id. at p. 5.)

Analysis: The Court agrees with Plaintiff. "[I]n California, there is not a standalone cause of action for 'unjust enrichment[.]'" (Saroya v. Univ. of the Pacific (N.D. Cal. 2020) 503 F.Supp.3d 986, 998.) Still, "[w]hen a plaintiff alleges unjust enrichment, a court may 'construe the cause of action as a quasi-contract claim seeking restitution.'" (Ibid.) The Court intends to adopt this approach. At this stage, the fourth cause of action shall be treated like a quasi-contract claim. [1] The demurrer to the fourth cause of action for unjust enrichment is overruled.

Fifth Cause of Action (UCL) Defendant: * "Plaintiff fails to adequately allege economic injury." (Demurrer, p. 7, bolding and capitalizing deleted; see also id. at p. 8.) * "Plaintiff fails to adequately allege unlawful, unfair, or fraudulent" conduct. (Id. at p. 8, bolding and capitalizing deleted.) Plaintiff: * The FAC "alleges economic injury[.]" (Opposition, p. 8, italicizing and capitalizing deleted.) * The FAC "alleges unlawful, unfair, or fraudulent business acts or practices[.]" (Ibid., italicizing and capitalizing deleted; see also id. at p. 9.)

Reply: * "Plaintiff's allegations of future risk, time spent monitoring accounts, anxiety, and speculative diminution in data value [are] insufficient" to establish standing. (Reply, p. 6.) * "The Opposition does not identify any pleaded facts suggesting that SBCU violated any particular statute, misrepresented any specific fact to Plaintiff, or engaged in conduct that satisfies any [] UCL test." (Id. at pp. 6-7.) Analysis: The Court disagrees with Defendant's first argument regarding pleading economic injury.

Proposition 64 limits "private standing . . . to any 'person who has suffered injury in fact and has lost money or property' as a result of unfair competition [citations]." (Kwikset Corp. v. Superior Court (2011) 51 Cal.4 th 310 320-321.) " The intent of this change was to confine standing to those actually injured by a defendant's business practices and to curtail the prior practice of filing suits on behalf of clients who have not used the defendant's product or service, viewed the defendant's advertising, or had any other business dealing with the defendant. . . ." (Id. at 321, internal quotation marks omitted.)

While there is a split of authority, the growing trend holds that "plaintiffs who suffer[] a loss of their personal information suffer[] economic injury and ha[ve] standing[.]" (A.B. v. Google LLC (N.D. Cal. 2024_ 737 F.Supp.3d 869, 881; see also Brown v. Google LLC (N.D. Cal. Dec. 22, 2021, No. 20-CV-03664-LHK) 2021 WL 6064009, at *15 [similar].) This trend has been followed in other cases on Department 11's docket. The Court will do the same here. Defendant's second argument fails. The UCL is disjunctive.

Alleging a violation of one prong is enough to defeat a demurrer. The Court finds that Plaintiff meets his pleading burden under the unlawful prong because (1) the first (negligence), third (breach of implied contract), and fourth (unjust enrichment) causes of action survive, and (2) the FAC partially grounds the unlawful-prong claim on violations of common law. (See FAC, P.P. 229-230.) The demurrer to the Unfair Competition Law cause of action is overruled. [1] Defendant's reply argument - that "an express contract governs the parties' relationship and the subject matter of the dispute" (Reply, p. 6) - fails for the reasons stated above in the section pertaining to the third cause of action. | Home -->)" -->

Cited authorities

Extracting citations from the ruling text…
Verify against the source PDF — LLM extraction may miss or mis-normalize citations.

Looking for case law or statutes not cited here? Search published authorities

Ask about this ruling

Examples: “Why did the court rule this way?” · “What were the procedural grounds?” · “Is appearance required?”

Answers reference only this ruling's text. Not legal advice — always verify against the source PDF.

Find similar rulings

Source

Share