United Statesa Fed. Sav. Bank v. PLS Fin. Servs., Inc.
United Statesa Fed. Sav. Bank v. PLS Fin. Servs., Inc.
Opinion of the Court
After Plaintiff USAA Federal Savings Bank ("USAA") lost over $7,000,000 in a fraudulent check cashing scheme, USAA filed suit against Defendants PLS Financial Services, Inc., PLS Group, Inc., The Payday Loan Store of Illinois, Inc.
BACKGROUND
USAA provides banking services to members and veterans of the United States military. PLS, through the four individually named Defendants, provides check cashing and payday lending services at approximately 300 retail locations in eleven states, including Illinois. The individual Defendants share common directors, officers, and office locations, with centralized recordkeeping and computer systems, and have similar business practices. PLS is not a bank and does not provide bank accounts to its customers. Instead, PLS charges customers a fee to cash checks, obtain money orders, and use other financial services.
As part of its business, PLS cashes checks drawn on USAA. In cashing these checks, as with any other checks, PLS obtains certain information about the drawer of the check and the bank on which the check is drawn from the face of the check, including the drawer's name, the check number, account number, bank routing number, drawer's signature, and MICR information.
In October 2012, the Federal Trade Commission ("FTC") and PLS agreed to settle a suit brought by the FTC against PLS in which the FTC alleged that PLS
*724did not properly secure its customers' personal information. The stipulated final judgment required PLS to develop a comprehensive information security program to protect the security, confidentiality, and integrity of consumers' personal information, including consumers' names, addresses, and financial institution account numbers. PLS also agreed to take reasonable measures to protect against unauthorized access to or use of such information. PLS thereafter adopted several internal policies, requiring unique user IDs and difficult-to-guess passwords that users must change every thirty days.
Problems with unauthorized access to PLS customers' personal information continued, however. Specifically, a group of individuals engaged in a check-cashing scheme, creating counterfeit checks using information obtained from PLS employees. The government has charged or indicted at least nine individuals for their involvement in this scheme. To facilitate the scheme, PLS employees provided third parties with access to PLS' computer systems, allowing these third parties to copy check images and produce counterfeit checks based off those images. The checks ranged from between $5 and $10,000. The third parties then used these counterfeit checks, which included checks drawn on USAA, to obtain money through various schemes. PLS employees involved in the scheme took a portion of the illegally obtained funds when they were withdrawn through PLS. The payor banks on the counterfeit checks, including USAA, ultimately bore the loss because the checks were unauthorized, meaning the members on whose accounts the checks were drawn could not be held liable for them. USAA has discovered over 2,000 original checks from its members that members cashed at PLS and schemers subsequently counterfeited, causing USAA to incur $7,865,518.31 in damages associated with the payment of the forged checks.
In October 2014, USAA notified PLS of the counterfeiting and requested help in coordinating an investigation into the issue. Another bank in New York also notified PLS of a similar scheme in December 2014. PLS then began investigating the issue, learning that an individual accessed Digicheck, PLS' database of check images, from within PLS to obtain the information needed to create counterfeit checks. In February 2015, PLS found internal weaknesses related to application controls and memorialized these findings in an April 2015 memorandum. In addition to this investigation, PLS also undertook an audit in 2015, which revealed that PLS was not following its access control policies. Despite discovering these weaknesses, however, PLS did not act and instead allowed the fraudulent check scheme to continue. And while USAA implemented several rules to restrict fund availability in an attempt to respond to the check scheme, these efforts did not fully address the harm.
LEGAL STANDARD
A motion to dismiss under Rule 12(b)(6) challenges the sufficiency of the complaint, not its merits. Fed. R. Civ. P. 12(b)(6) ; Gibson v. City of Chicago ,
ANALYSIS
PLS seeks the dismissal of USAA's negligence claim. To succeed on its negligence claim, USAA must establish that (1) PLS owed USAA a duty, (2) PLS breached that duty, and (3) PLS' breach proximately caused USAA injury. Rhodes v. Ill. Cent. Gulf R.R. ,
A. The GLBA, the Privacy Rule, and the Safeguards Rule
First, PLS argues that to the extent USAA's negligence claim depends on the GLBA, the Privacy Rule, and the Safeguards Rule, it fails because Congress did not intend to create a private right of action to enforce this statute and its regulations. To pursue a negligence claim based on a violation of a statute or regulation, USAA must show (1) that it falls within the class intended to be protected by the statute or regulation, and (2) the injury USAA suffered directly and proximately resulted from the violation. Kalata ,
PLS argues that Martin forecloses this part of USAA's claim because Congress did not intend to create a private right of action under the GLBA, the Privacy Rule, and the Safeguards Rule. Notwithstanding the GLBA's stated policy that "each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers' nonpublic personal information,"
This does not mean, as USAA argues, that PLS had no duty to safeguard personal information and is "invulnerable to these laws." See Doc. 103 at 1, 9. It only means that USAA cannot enforce violations of these rules, with enforcement left instead to state and federal regulators. See Am. Fam. Mut. Ins. Co. ,
B. FTC Stipulated Final Judgment
USAA also argues that the stipulated final judgment between PLS and the FTC creates a duty because it is an administrative order designed to protect property. See Davis ,
As USAA acknowledges, the stipulated final judgment between PLS and the FTC amounts to a consent decree, with "the parties' agreement ... serv[ing] as the source of the court's authority to enter any judgment at all." Local No. 93, Int'l Ass'n of Firefighters, AFL-CIO C.L.C. v. City of Cleveland ,
C. USAA's Request to Amend
In its response to PLS' motion, USAA included a request to amend to include the violation of the Illinois Personal Information Protection Act as a basis for a prima facie negligence claim. The Court granted USAA leave to file a third amended complaint after USAA made this request. Despite having previously identified the Illinois Personal Information Protection Act as a potential basis for such claim, USAA did not include it as a basis for its negligence claim in the third amended complaint. Having considered the viability of USAA's evolving negligence claim on more than one occasion and allowed USAA to amend its complaint three times, the Court finds USAA's latest attempt to salvage its negligence claim comes too late. For that reason, the Court denies USAA's request for leave to amend and dismisses USAA's negligence claim with prejudice.
CONCLUSION
For the foregoing reasons, the Court grants PLS' motion for judgment on the pleadings [87]. The Court dismisses the negligence claim (Count I) with prejudice.
The Payday Loan Store of Illinois, Inc. is now known as PLS Financial Solutions of Illinois, Inc.
PLS filed its motion for judgment on the pleadings with respect to USAA's second amended complaint. After the parties completed briefing on the motion, USAA moved for leave to file a third amended complaint that added PLS Check as a party and included additional facts to support its claims. The parties acknowledged that the third amended complaint does not affect the legal arguments at issue. But because PLS has not yet filed an answer to the third amended complaint, the Court treats PLS' motion as one to dismiss the negligence claim in the third amended complaint. Although PLS Check has not yet filed an appearance in the case, because PLS' arguments for dismissal apply equally to PLS Check, the Court extends them to PLS Check because USAA had the opportunity to respond to them. See Malak v. Associated Physicians, Inc. ,
The facts in the background section are taken from USAA's third amended complaint and the exhibits attached thereto and are presumed true for the purpose of resolving PLS' motion. See Virnich v. Vorwald ,
MICR stands for magnetic ink character recognition. The MICR information contains certain encoded information used to verify the legitimacy of checks.
The Court notes that PLS' current argument seeking dismissal of the negligence claim differs from the argument it raised to oppose the filing of USAA's second amended complaint. In opposing that filing, PLS argued that the statutes, regulations, and orders on which USAA relied did not apply to the relationship between USAA and PLS because they relate to the protection of a financial institution's customers' information and not PLS' handling of non-customers' personal information. See Doc. 53 at 2. The Court allowed USAA to file its amended negligence claim, concluding that USAA had set forth a sufficient basis to proceed, particularly in light of legislative history suggesting that the Safeguards Rule covered more than just a financial institution's own customers' information.
Reference
- Full Case Name
- USAA FEDERAL SAVINGS BANK v. PLS FINANCIAL SERVICES, INC., PLS Group, Inc., The Payday Loan Store of Illinois, Inc., and PLS Check Cashers of Illinois
- Cited By
- 12 cases
- Status
- Published