Marriott Moves to Dismiss Data Breach Lawsuit, Says Passport Numbers Useless to Hackers
In its motion to dismiss, Marriott insisted the breach caused no harm to its guests and attached a declaration by a former government official who wrote: "A U.S. passport is virtually impossible to forge successfully."
September 24, 2019 at 03:23 PM
5 minute read
Marriott is insisting that last year's cyberattack did no harm to its hotel guests, not least of which because hackers cannot use stolen passport numbers.
In a motion filed on Monday, Marriott International Inc. sought to dismiss a consolidated consumer class action brought over the data breach, which compromised the personal information of 383 million guests of its Starwood Hotels and Resorts Worldwide properties. Parroting the argument of other defendants in data breach cases, Marriott insisted that none of the named plaintiffs in the case suffered harm, which is required to establish standing to sue in federal court.
But, in a more unusual move, the hotel chain, which admitted that hackers stole passport numbers, attached a declaration from Brenda Sprague, who held the "highest-ranking position in the U.S. government with responsibility for passports" at the U.S. Department of State Bureau of Consular Affairs. In that declaration, she said that hackers need more than a passport number to create a forged passport.
"The bellwether plaintiffs have not alleged they have suffered any form of passport fraud," wrote Marriott's attorney, Daniel Warren, a partner at Baker & Hostetler in Cleveland.
He added that the complaint included "an everything-but-the-kitchen-sink" list of alleged harms, few of which even happened to the named plaintiffs. "Plaintiffs' one-size-fits-all pleading style is entitled to zero weight on a motion to dismiss," he wrote.
A Marriott spokesman declined to comment, and Warren did not respond to a request for comment. Lead plaintiffs attorneys in the data breach case—Andrew Friedman, a partner at Cohen Milstein Sellers & Toll in Washington, D.C.; Amy Keller of Chicago's DiCello Levitt; and James Pizzirusso, a partner at Hausfeld in Washington, D.C.—also did not respond.
On Nov. 30, Marriott announced that a breach compromised the personal data of 500 million guests of its Starwood Hotels and Resorts Worldwide properties. Marriott later lowered that figure to fewer than 383 million.
Marriott's motion comes as U.S. District Judge Paul Grimm, who is overseeing the multidistrict litigation in Maryland, has put the data breach case on a fast track. He has told lawyers he plans to rule on the motions to dismiss by the end of the year.
Hotel guests are not the only ones suing Marriott over the breach. Financial institutions and shareholders have brought separate cases, as has the city of Chicago.
On July 31, Marriott filed a motion to dismiss the class action for financial institutions, which alleged they had to reissue payment cards to customers impacted by the breach. The motion says the lead plaintiff, the Bank of Louisiana, lacked standing to sue over such costs, which were preventative. Further, the bank, which was a lead plaintiff in the Equifax data breach case, could not prove that the Marriott breach, as opposed to another cyber-attack, caused any unauthorized charges.
In a July 15 motion, Marriott insisted that the city of Chicago lacked legal authority to sue over a breach that is national in scope. Marriott's motions to dismiss the shareholder cases are due in November.
In the consumer case, Marriott argued that the majority of the plaintiffs did not allege hackers misused their information. Of those who did, many of the nine million credit and debit cards, and 24 million passport numbers, could have been expired, given that the breach involved information dating back to 2002—making the prospect of identity theft "pure conjecture." Further, hackers would have had to decrypt most of the payment cards and passport information, and plaintiffs provided no evidence that such information was for sale on the "dark web."
Sprague, who is immediate past deputy assistant secretary of state for passport services in the U.S. Department of State Bureau of Consular Affairs, said in her declaration that criminals have to obtain real passport books, not just the numbers, to create forgeries, both online and at the U.S. border. She also said that electronic passports, available since 2005, have coded chips embedded in them.
"A U.S. passport is virtually impossible to forge successfully," she wrote. "In my ten years in charge of passport services, I was aware of no incidents in which the Department encountered a credible forgery of a U.S. passport."
Two plaintiffs also alleged they had bank accounts opened in their name, one of whom also alleged an unauthorized individual collected a tax refund, but Marriott insisted in its motion that both those actions require Social Security numbers, which hackers did not take.
Marriott also said plaintiffs failed to alleged sufficient facts under various state statutes, citing "sloppy pleading" and "vague allegations."
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllFederal Judge Sends Novel Damages Question in Employment Dispute to State Court
5 minute readBank of America's Cash Sweep Program Attracts New Legal Fire in Class Action
3 minute readCounty Reps: Appeal Likely Following State Court's Sales Tax Ruling for Retail Marijuana
6 minute read'Don't Be Afraid to Dumb It Down': Top Fed Magistrate Judge Gives Tips on Explaining Complex Discovery Disputes
Trending Stories
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250