District Court, D. Maryland, 2026

Steven Birks v. Arena Technical Resources, LLC

Steven Birks v. Arena Technical Resources, LLC
District Court, D. Maryland · Decided March 23, 2026
Steven Birks v. Arena Technical Resources, LLC

Trial Court Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND (Southern Division) STEVEN BIRKS, * * Plaintiff, * * v. * Civ. No. GLS 25-164 * ARENA TECHNICAL RESOURCES, LLC, * * Defendant, * * ******* MEMORANDUM OPINION Plaintiff Steven Birks(“Plaintiff”), on behalf of himself and others similarly situated, filed an Amended Class Action Complaint against Arena Technical Resources, LLC (“Defendant”), after a data breach of Defendant’s network systems. (ECF No. 15). The Amended Class Action Complaint (“Amended Complaint”) alleges that the Defendant failed to protect Plaintiff’s and others’ personally identifiable information (“PII”) from being stolen by “hackers.” In particular, the Amended Complaint advances the following claims against the Defendant: negligence/negligence per se (Count I); breach of implied contract (Count II); and unjust enrichment(Count III). (Id.). The remedies sought by Plaintiff include declaratory and injunctive relief. (Id.). Pending before the Court1 is Defendant’s motion to dismiss the Amended Class Action Complaint (the “Motion”) and a memorandum in law in support thereto. (ECF Nos. 33, 33-1). Plaintiff filed an Opposition, and the Defendant has filed a Reply. (ECF Nos. 34, 35). The issues have been fully briefed, and no hearing is necessary. See Local Rule 105.6 (D. Md. 2025). For the reasons set forth herein, Defendant’s Motion is GRANTED, and the Amended Class Action 1 This matter has been referred to the undersigned for all further proceedings, pursuant to 28 U.S.C. § 636(c), and with the consent of the parties. (ECF Nos. 28, 30). Complaint is DISMISSED WITHOUT PREJUDICE. I. FACTUAL AND PROCEDURAL BACKGROUND2 Defendant, a Maryland limited liability company, is “an information technology consulting, staffing, and placement organization” that “provides technical and staffing services for prospects and employers.” (ECF No. 15, “Amended Complaint,” ¶¶ 3, 17, 21). As part of its duties, Defendant collects from its clients the names and Social Security numbers of their employees and stores them in its system. (Amended Complaint, ¶¶23, 109). Plaintiff is a Department of Defense employee residing in North Carolina who provided his employer with his PII as a condition of employment. (Amended Complaint, ¶¶ 16, 109). A. The Data Breach On August 10, 2024, Defendant suffered a breach of its network systems and obtained Plaintiff’s name and Social Security number that was stored on them. (Amended Complaint, ¶¶ 2, 7, 42; ECF No. 15-1).3 The “hackers’ who accessed Defendant’s systems obtained the “Private Information” (Social Security numbers and names) of Plaintiff and others, exposing them to “an untold number of unauthorized individuals.” (Amended Complaint, ¶ 11). On December 17, 2024, Plaintiff received a notice of the data breach from Defendant informing him about the breach and thathis name and Social Security number had been accessed. (Amended Complaint, ¶¶ 37-38, 114). The notice informed Plaintiff of the steps that Defendant took in response to learning of the incursion, about the review that Defendant performed to identify which files were affected, and that Plaintiff’s name and Social Security number were the data 2 In resolving the Motion, the Court accepts as true the well-pleaded facts in the Amended Class Action Complaint. (ECF No. 15). See Wikimedia Found. v. Nat’l Sec. Agency, 857 F.3d 193, 208 (4th Cir. 2017). The Court also considers the document attached to the Amended Class Action Complaint. (ECF No. 15-1). 3 See Goines v. Valley Cmty. Servs. Bd., 822 F.3d 159, 166 (4th Cir. 2016); see also Fed. R. Civ. P. 10(c). accessed. The notice stated in part: What Happened?On August 11, 2024, we learned that certain files on our computer systems were locked by a computer virus. In response, we took steps to verify the security of our computer network, securely recover our systems from backups, and determine what occurred. During our review of this matter, we identified that certain files were copied without permission on August 10, 2024. After identifying the files, we completed a comprehensive review to determine their contents and to whom the contents related. We also worked to identify contact information so we could let those individuals know about this matter, which was complete on or around December 5, 2024. We then arranged to provide notification with complimentary identity monitoring services. What Information Was Involved? The information identified during the file review included your name and the following: Social Security number. (Amended Complaint, ¶ 38). Because of the “highly sensitive information” and the “volume” of information that Defendant collects, Defendant knew that it was especially vulnerable to cyberattacks. (Amended Complaint, ¶¶ 9, 10, 49-52, 56). Because of this knowledge, Defendant had a common law duty to employ and follow “reasonable measures to protect such information from disclosure to unauthorized third parties.” (Amended Complaint, ¶¶ 5, 10, 57, 73-74). The cyberattack occurred because Defendant failed to use “reasonable security procedures and practices,” like encrypting, monitoring, or deleting data “when it [was] no longer needed.” (Amended Complaint, ¶¶ 9-10, 44, 47, 73-78). Defendant’s inadequate security measures also deviated from “industry-standards,” and did not comply with the Federal Trade Commission’s rules and guidance issued. (Amended Complaint, ¶¶ 46, 59-66, 68-72). B. Injuries The data breach “directly and proximately injured Plaintiff and Class Members by the resulting disclosure of their Private Information.” (Amended Complaint, ¶ 79). Once stolen, “fraudulent use of [PII] and damage to victims may continue for years,” and because their information remains in Defendant’s compromised computer systems, “Plaintiff and Class Members are also at a continued risk.” (Id., ¶¶ 79-81). According to Plaintiff, the data breach resulted in the following injuries to himself and other similarly situated individuals: (a) financial costs incurred mitigating the materialized risk and imminent threat of identity theft; (b) loss of time and loss of productivity incurred mitigating the materialized risk and imminent threat of identity theft; (c) actual identity theft and fraud or actual identity theft, or the imminent and substantial risk of identity theft or fraud; (d) financial costs incurred due to actual identity theft; (e) loss of time incurred due to actual identity theft; (f) deprivation of value of their PII; (g) loss of privacy/invasion of privacy; (h) emotional distress including anxiety and stress in dealing with the Data Breach and thinking about how their PII has been disclosed to cybercriminals; (i) the continued risk to their sensitive PII, which remains in Defendant’s possession and subject to further breaches, so long as Defendant fails to undertake adequate measures to protect the data it collects and maintains. (Amended Complaint, ¶¶ 13, 82, 157). The Amended Complaint also chronicles Plaintiff’s experiences. For instance, after receiving the December 17 notice, Plaintiff attempted to reasonably mitigate the impact of the data breach by “researching” it,obtaining his credit reports and reviewing “financial account statements for any indications of actual or attempted identity theft or fraud,” which he now reviews and monitors “multiple times a week.” (Amended Complaint, ¶115). Plaintiff “further anticipates spending considerable time and money on an ongoing basis to try to mitigate and address harms caused by the Data Breach.” (Id., ¶ 116). In addition, “[t]he risk of identity theft is impending and has materialized, as there is evidence that Plaintiff’s and Class Members’ Private Information was targeted, accessed, and misused, including through publication and dissemination on the dark web.” (Amended Complaint, ¶ 117). Relatedly, Plaintiff “believes that his [PII], and that of Class Members, was and will be sold and disseminated on the dark web following the Data Breach.” (Amended Complaint, ¶118). Moreover, Plaintiff has suffered “fear, anxiety, and stress” thinking about how his PII is “in the hands of cybercriminals, which has been compounded by the fact that Defendant still has not fully informed him of key details about the Data Breach’s occurrence or the information stolen.” (Id., ¶ 119). Furthermore, since the data breach, “Plaintiff has experienced suspicious spam emails using his Private Information compromised in the Data Breach.” (Id. ¶ 120). C. Motion to Dismiss Defendant has moved to dismiss the Amended Class Action Complaint with prejudice under Fed. R. Civ. P. 12(b)(1) and 12(b)(6). Defendant asserts that the Amended Class Action Complaint fails to allege facts upon which subject-matter jurisdiction can be based, so dismissal for lack of standing is appropriate under Fed. R. Civ. 12(b)(1). In particular, Defendant argues that Plaintiff lacks Article III standing: (1) because Plaintiff fails to allege actual data misuse or theft of his own PII or of the PII of any other person as a result of the data breach; and (2) because Plaintiff’s alleged future injuries, mitigation efforts, diminution in value of his PII, and emotional distress, as pleaded, do not constitute concrete injuries-in-fact. Defendant also contends that Plaintiff lacks standing to pursue injunctive relief, as this remedy cannot be designed to prevent a future data breach. (ECF No. 33- 1, “Memorandum,” pp. 10-15).4 Plaintiff first counters that he does have standing because he has established actual misuse of PII. Next, Plaintiff contends that the targeted theft of his PII “establishes his imminent risk of identity theft,” which he characterizes as a cognizable injury. Third, Plaintiff avers that his mitigation efforts, the diminished value of his PII, and his emotional distress resulting from the data breach are concrete injuries-in-fact. Finally, Plaintiff maintains that he has established a sufficiently imminent risk of harm to have standing to pursue injunctive relief. (ECF No. 34, “Opposition,” pp. 10-16). As set forth herein, Defendant’s Rule 12(b)(1) motion will be granted for lack of standing. Thus, the Court declines to address Defendant’s alternative Rule 12(b)(6) arguments. II. DISCUSSION A. Federal Rule of Civil Procedure 12(b)(1) Pursuant to Fed. R. Civ. P. 12(b)(1), a party may move to dismiss a complaint for lack of subject-matter jurisdiction. Barnett v. United States, 193 F. Supp. 3d 515, 518 (D. Md. 2016). Where the movant challenges the other party’s standing, Rule 12(b)(1) applies. Griffin v. Dep’t of Lab. Fed. Credit Union, 912 F.3d 649, 652-53 (4th Cir. 2019). A Rule 12(b)(1) challenge to subject-matter jurisdiction may proceed “in one of two ways”: first, by mounting a facial challenge, asserting that the allegations pleaded in the complaint are insufficient to establish subject-matter jurisdiction; or second, a factual challenge, asserting “that the jurisdictional allegations of the complaint [are] not true.” Kerns v. United States, 585 F.3d 187, 192 (4th Cir. 2009) (alteration in original) (citation omitted). In a facial challenge, “the facts alleged in the complaint are taken as true, and the motion must be denied if the complaint alleges 4 When citing to page numbers of the parties’ briefing, the Court uses the CM/ECF numbers at the top of the page. sufficient facts to invoke subject matter jurisdiction.” Id.; see also Ministry of Def. of State of Kuwait v. Naffa, 105 F.4th 154, 159 (4th Cir. 2024) (same). In a factual challenge, however, “the presumption of truthfulness normally accorded a complaint’s allegations does not apply,” which means that a “district court is entitled to decide disputed issues of fact with respect to subject matter jurisdiction.” Kerns, 585 F.3d at 192. The court should grant the 12(b)(1) motion “only if the material jurisdictional facts are not in dispute and the moving party is entitled to prevail as a matter of law.” Richmond, Fredericksburg & Potomac R.R. Co. v. United States, 945 F.2d 765, 768 (4th Cir. 1991). When a defendant challenges subject-matter jurisdiction, the plaintiff bears the burden of establishing that subject-matter jurisdiction exists. Evans v. B.F. Perkins Co., 166 F.3d 642, 647 (4th Cir. 1999). B. Standing for Amended Class Action Complaint Pursuant to Article III of the United States Constitution, a federal court’s jurisdiction extends only to “cases” or “controversies.” U.S. Const. art. III, § 2, cl. 1; see also Eden, LLC v. Justice, 36 F.4th 166, 169–70 (4th Cir. 2022). Thus, to pursue a claim in federal court, a plaintiff must establish that she/he has “standing to sue.’” Clapper v. Amnesty Int’l USA, 568 U.S. 398, 408 (2013) (citations omitted). Put another way, the burden of establishing standing rests with a plaintiff. Lujan v. Defs. of Wildlife, 504 U.S. 555, 561 (1992). The timing of a defendant’s challenge to a plaintiff’s standing “dictates the plaintiff’s burden as to standing.” Beck v. McDonald, 848 F.3d 262, 270 (4th Cir. 2017) (citing Lujan, 504 U.S. at 561). If a defendant has filed a motion to dismiss, a court is to carefully analyze the plaintiff’s complaint and “general factual allegations of injury resulting from the defendant’s conduct may suffice.” Id. (quoting Lujan, 504 U.S. at 561).5 At this procedural stage, a court must also “construe the complaint in favor of the [plaintiff].” Deal v. Mercer Cnty. Bd. of Educ., 911 F.3d 183, 187 (4th Cir. 2018) (further citation omitted). In addition, when a plaintiff advances an action on behalf of himself and a putative class, “[e]very class member must have Article III standing in order to recover individual damages.” TransUnion LLC v. Ramirez, 594 U.S. 413, 431 (2021). In this case, the Court must begin by analyzing the named Plaintiff’s allegations of harm. Beck, 848 F.3d at 269 (citing Doe v. Obama, 631 F.3d 157, 160 (4th Cir. 2011)). Accordingly, if the named Plaintiff fails to sufficiently plead facts to demonstrate injury, then the putative class cannot meet their burden of establishing standing. Id. at 270. To establish standing, a plaintiff must establish the following three elements: (1) that she suffered an injury-in-fact; (2) causation, i.e., can the plaintiff’s harm be “fairly traceable to the challenged action of the defendant”; and (3) redressability, i.e., “it must be likely, as opposed to merely speculative, that the injury will be redressed by a favorable decision.” Dep’t of Educ. v. Brown, 600 U.S. 551, 561 (2023) (quoting Lujan, 504 U.S. at 560-61). In the instant case, it is the first part of the three-part test at issue. Namely, Defendant challenges whether Plaintiff has met his burden of adequately pleading that he and the putative Class Members suffered a cognizable injury-in-fact after the data breach. To establish injury-in-fact, “a plaintiff must show that he or she suffered ‘an invasion of a legally protected interest’ that is ‘concrete and particularized’ and ‘actual or imminent, not 5In performing its analysis, the Court is also mindful of the pleading requirements of Fed. R. Civ. P. 8(a)(2), and that a complaint with mere “‘naked assertions’ of wrongdoing” are insufficient to state a claim for relief. Francis v. Giacomelli, 588 F.3d 186, 193 (4th Cir. 2009). Put another way, a complaint that contains bald accusations or “no more than labels and conclusions” or “a formulaic recitation of the elements of a cause of action” is insufficient to state a plausible claim for relief. Bell Atl. Corp. v. Twombly, 550 U.S. 544, 556 (2007) (complaint must set forth enough facts as to suggest a “cognizable cause of action”). conjectural or hypothetical.’” Spokeo, Inc. v. Robins, 578 U.S. 330, 339 (2016) (quoting Lujan, 504 U.S. at 560). The Court analyzed the Amended Complaint to determine whether the named plaintiff, Steven Birks, has met his burden on adequately alleging that he suffered an injury-in-fact. C. Data Misuse or Targeted Theft of PII Defendant argues that Plaintiff cannot establish standing because he does not allege that he actually was the victim of identity theft or fraud as a result of the data breach. (Memorandum, p. 10). Plaintiff first counters that he has met his burden in establishing that he and the putative Class Members have “suffered concrete and cognizable injuries due to Zeroed-In’s [sic] conduct,” including actual misuse. (Opposition, pp. 9-10). 1. No Actual Data Misuse As a preliminary matter, the Court reviewed the Amended Complaint and found that in a couple of instances Plaintiff seems to plead that he was the victim of identity theft and fraud. For instance, the Amended Complaint says “[a]s a result of the Data Breach, Plaintiff and Class Members suffered and will continue to suffer concrete injuries in fact, including . . .(c) actual identity theft and fraud,” and “[a]s a direct and proximate result of Defendant’s negligence, Plaintiff and Class Members have suffered and will duffer injuries, including. . .(c) actual identity theft.” (Amended Complaint, ¶¶ 13, 157) (emphasis added). In addition, Plaintiff pleads that he “believes his [PII], and that of Class Members, was and will be sold and disseminated on the dark web following the Data Breach.” (Amended Complaint, ¶118) (emphasis added). However, contradictorily, in other parts of the pleading, Plaintiff does not allege that he was actually victimized by identify theft, pleading instead that he was at imminent risk of such theft. See, e.g., Amended Complaint, ¶¶ 82, 115, 117. Even when the Court construes the facts in Plaintiff’s favor, the Court must find that Plaintiff has insufficiently pleaded that he or the putative Class Membersactually suffered identity theft and/or fraud. The Court finds that the Amended Complaint is devoid of any dates, times or specific actions, and contains bald accusations and “labels and conclusions” that actual identity theft or fraud occurred. Thus, to the extent that Plaintiff believes that he has met his burden on plausibly pleading that these actions have occurred, the Court declines to so find. Twombly, 550 U.S. at 556. Next, Plaintiff contends that his receipt of spam demonstrates that his PII has been actually misused. (Opposition, p. 11). Specifically, Plaintiff alleges that, “since the Data Breach [he] has experienced suspicious spam emails using his Private Information compromised in the Data Breach, and believes this to be an attempt to secure additional information from or about him.” (Amended Complaint, ¶ 120). Even when construing the facts in Plaintiff’s favor, the Court must find that Plaintiff fails to particularly plead any events, including the dates or substance of the alleged spam emails, to sufficiently allege an injury in fact. See Stuart v. Kyocera AVX Components Corp., 769 F. Supp. 3d 476, 489 (D.S.C. 2025). Instead, Plaintiff merely pleads conclusory allegations. The Court thus finds that “the generic allegation of increased spam calls and emails, if an injury at all, fails to plausibly show that [Plaintiff’s] alleged injuries were the result of Defendant’s conduct.” Burger v. Healthcare Mgmt. Sols., LLC, Civ. No. RDB-23-1215, 2024 WL 473735, at *6 (D. Md. Feb. 7, 2024) (quotation marks omitted). Accordingly, the Court cannot find that Plaintiff’s allegation regarding an increase in spam emails is sufficient to establish standing. See Stuart, 769 F. Supp. 3d at 489. Next, the Amended Complaint generally alleges that “Plaintiff’s and Class Members’ Private Information was targeted, accessed, and misused, including through publication and dissemination on the dark web” (Amended Complaint, ¶ 117). In addition, Plaintiff believes that his PII “was and will be sold and disseminated on the dark web following the Data Breach as that is the modus operandi of cybercriminals that commit cyber-attacks of this type.” (Id., ¶ 118). Even when construing the pleaded facts in Plaintiff’s favor, the Court finds that the Amended Complaint is devoid of any dates, times or specific actions related to publication or dissemination, and contains bald accusations and “labels and conclusions” that misuse on the dark web actually occurred. The Court finds this insufficient. See Stuart¸ 769 F. Supp. 3d at 486 n.6 (“The [class action complaint] includes a conclusory allegation that Plaintiffs’ PII was ‘subsequently sold on the dark web’ but does not allege facts to support that contention other than that it ‘is the modus operandi of cybercriminals.’”). In sum, to the extent that Plaintiff believes that he has plausibly pleaded actual misuse of his PII obtained during the Data Breach that is sufficient to confer standing, the Court declines to so find. 2. Targeted Theft of Plaintiff’s PII In the Amended Complaint, Plaintiff also alleges that “[h]ackers targeted and obtained Plaintiff’s and Class Members’ Private Information from Defendant’s network because of the data’s value in exploiting and stealing identities.” (Amended Complaint, ¶ 11). According to Plaintiff, then, he does not need to allege actual misuse of data in order to establish standing. Rather, because he has alleged that PII was the “specific target” of the Data Breach, that is sufficient to confer standing. (Opposition, p. 10). The Court disagrees. The Fourth Circuit has held that a “mere compromise of personal information, without more, fails to satisfy the injury-in-fact element in the absence of an identity theft.” Hutton v. Nat’l Bd. of Exam’rs in Optometry, Inc., 892 F.3d 613, 621 (4th Cir. 2018) (citing Beck, 848 F.3d at 274-75). In Beck, a laptop and boxes with PII were stolen, but there was no evidence of misuse of the plaintiffs’ PII. Plaintiff argued an imminent threat of injury from future identify theft existed, at that he had incurred costs to try to protect against identity theft. Beck, 848 F.3d at 271-72. Where plaintiffs’ PII was compromised, but they did not allege that they experienced actual identity theft or fraud as a result, the Fourth Circuit found no concrete injury-in-fact. Thus, the Fourth Circuit held that Plaintiff failed to establish Article III standing based solely on allegations of harm resulting from an increased risk of future identity theft and based on costs associated with mitigating any future harm. Id.at 274-75. InHutton, the Fourth Circuit held that plaintiffs suffered concrete injury from the data breach because they had sufficiently alleged that their PII had been used to open credit cards without their knowledge. The Fourth Circuit found this harm was sufficient to allege injury-in-fact because it was actual, not speculative. 892 F.3d at 622. Following Beck and Hutton, district courts have continued to find actual misuse to be the “keystone of Article III injury in Fourth Circuit data breach case law.” Capiau v. Ascendum Mach., Inc., Civ. No. 24-00142-MOC-SCR, 2024 WL 3747191, at *4 (W.D.N.C. Aug. 9, 2024) (collecting district court cases from Maryland, North Carolina, and Virginia). For instance, in In re Marriott International, Inc., Customer Data Security Breach Litigation, 440 F. Supp. 3d 447, 459 (D. Md. 2020), the district court held that the plaintiffs established injury in fact because the complaint alleged more than just “the targeting of personal information for misuse”; instead, it alleged that some of the plaintiffs suffered identify theft and fraud (e.g., unauthorized credit cards applied for or unauthorized charges on credit cards). Thus, courts have held that, “without evidence of actual misuse, a data breach plaintiff fails to ‘push the threatened injury of future identity theft beyond the speculative to the sufficiently imminent.’” Capiau, 2024 WL 3747191, at *3 (citing Galaria v. Nationwide Mut. Ins. Co., 663 F. App’x 384, 386 (6th Cir. 2016)). In addition, after Hutton, in 2022, a district judge in Marylandcollected and analyzed data breach cases, finding that courts have found plaintiffs establish standing when they allege “actual misuse of the stolen data[,]” and that courts “frequently dismiss cases for lack of standing when the plaintiffs fails to show any resulting misuse of their data.” Stamat v. Grandizio Wilkins Little & Matthews, LLP, Civil No. SAG-22-00747, 2022 WL 3919685, at *5 (D. Md. Aug. 31, 2022). In sum, the Court cannot find that the mere targeting of personal information plus the absence of actual data misuse to be sufficient to establish injury-in-fact. Thus, the Court must now analyze whether the targeted theft of Plaintiff’s PII “establishes his imminent risk of identity theft,” which he characterizes as a cognizable injury. 3. Imminent or Heightened Risk of Identity Fraud or Theft In the Amended Complaint, Plaintiff alleges that: (a) he is “at a heightened risk of identity theft for years to come because of the Data Breach” (Amended Complaint, ¶ 83); and (b) he is “at a present and ongoing risk of fraud and identity theft for many years into the future” (Amended Complaint, ¶ 104). In addition, Plaintiff alleges that his injuries include “the continued and certainly increased risk to [his PII], which remains in Defendant’s possession.” (Id., ¶ 157). Plaintiff further alleges that the “fraudulent use of [PII] and damage to victims may continue for years,” and because PII remains in Defendant’s compromised computer systems “Plaintiff and Class Members are also at a continued risk.” (Id., ¶¶ 79-81). Furthermore, Plaintiff “believes his [PII], and that of Class Members, was and will be sold and disseminated on the dark web following the Data Breach.” (Amended Complaint, ¶118). Moreover, since the data breach, “Plaintiff has experienced suspicious spam emails using his Private Information compromised in the Data Breach.” (Id. ¶ 120). Plaintiff argues that his imminent risk of identity theft confers standing. (Opposition, pp. 12-13). According to Plaintiff, “the reasonable inference here is that the targeted theft of [his] Private Information makes his risk of identity theft substantial and imminent, supporting Article III standing.” (Id. at 13). Although a “threatened rather than actual injury can satisfy Article III standing requirements,” the Fourth Circuit has found that “not all threatened injuries constitute an injury- in-fact.” Beck, 848 F.3d at 271 (quoting Friends of the Earth, Inc. v. Gaston Copper Recycling Corp., 204 F.3d 149, 160 (4th Cir. 2000) (en banc)). Instead, the “threatened injury must be certainly impending to constitute injury in fact,” and allegations of possible future injury are not sufficient. Stamat, 2022 WL 3919685, at *3 (quoting Clapper, 568 U.S. at 409). Furthermore, being victimized by a data breach is not “in and of itself sufficient to establish Article III standing without a nonspeculative, increased risk of identity theft.” O’Leary v. TrustedID, Inc., 60 F.4th 240, 244 (4th Cir. 2023). A threatened event can be reasonably likely to occur but still be insufficiently imminent to constitute an injury-in-fact. Beck, 848 F.3d at 276. In Stamat, the plaintiff alleged the “current and imminent risk of fraud and identity theft” as an injury for standing purposes. Stamat, 2022 WL 3919685, at *3. However, the court found that the plaintiff alleged no actual misuse of his personal data and that, “[w]ithout allegations of existing misuse, the potential for fraudulent use of [the plaintiff’s] PII remain[ed] too speculative to confer an imminent injury.” Id. at *6. In Gordon v. Zeroed-In Tech., LLC, Civil No. BAH 23- 3284, 2025 WL 936415 (D. Md. Mar. 26, 2025), 23 of the 25 plaintiffs alleged actual misuse of PII after the data breach (e.g., actual incidents of fraud and identity theft) as well as being notified by third parties that their information was on the dark web and receiving spam calls, texts, or emails. 2025 WL 936415, at *5. Thus, the court found that the complaint brought “the actual and threatened harm out [of] the realm of speculation and into the realm of sufficiently imminent and particularized harm to satisfy the injury-in-fact requirement for Article III standing.” Id. at *6 (alteration in original) (quoting In re Marriott, 440 F. Supp. 3d at 459). In short, Gordon stands for the proposition that a plaintiff “fails to establish Article III standing based solely on harm resulting from the increased risk of future identity theft and the cost of measures to protect against it.” Id. In the instant case, there are no well-pleaded allegations of identity fraud or theft, nor are there any well-pleaded allegations that Plaintiff’s PII appears on the dark web. Nor are there any well-pleaded allegations related to suspicious spam emails. Plaintiff’s allegation of “the continued and certainly increased risk to [Plaintiff’s and Class Members’ PII], which remains in Defendant’s possession,” (Amended Complaint, ¶ 157), “does not amount to ‘certainly impending’ or concrete harm.” Stamat, 2022 WL 3919685, at *6. Thus, the Court finds that, “even assuming that [Defendant] maintains PII inadequately in the general course, because even the actual data breach fails to establish injury-in-fact, any continued risk of another data breach is equally unsatisfactory for Article III standing purposes.” Id. In sum, even when construing the facts in Plaintiff’s favor, the Court must find that the “potential for fraudulent use of [the plaintiff’s] PII [is] too speculative to confer an imminent injury.” Stamat, 2022 WL 3919685, at *6. D. Plaintiff’s Other Allegations of Concrete Injury-in-Fact Plaintiff avers that the following constitute concrete injuries-in-fact: his mitigation efforts undertaken to minimize the risk of identity theft and fraud; the diminished value of his PII; the loss of Plaintiff’s and the Putative Class Members’ benefit of their bargain; and the emotional distress he experienced. (Amended Complaint, ¶¶ 13, 82, 94-95, 96-99, 106-08, 120, 157). 1. Mitigation Efforts Defendant contends that allegations of mitigation efforts, “without a corresponding imminent risk of future harm shown through actual misuse of data, are insufficient to establish standing.” (Memorandum, pp. 13-14). Plaintiff alleges that the Putative Class Members and he have suffered and will continue to suffer financial costs and the loss of time incurred from “mitigating the materialized risk and imminent threat of identity theft.” (Amended Complaint, ¶¶ 13, 82, 94-95, 115). The Court agrees with Defendant. Because the Court has already found that the prospect of future identity theft pleaded here is speculative, the Court finds that mitigation expenses “do not qualify as actual injuries where the harm is not imminent.” Beck, 848 F.3d at 277 (quoting Remijas v. Neiman Marcus Grp., LLC, 794 F.3d 688, 694 (7th Cir. 2015)). 2. Diminished Value Defendant argues that Plaintiff’s claimed injury in the form of diminished value of his PII is speculative and does not provide Plaintiff with standing. (Memorandum, p. 14). Plaintiff has pleaded that, “[a]s a result of the Data Breach, Plaintiff’s and Class Members’ Private Information, which has an inherent market value in both legitimate and black markets, has been damaged and diminished in its value by its unauthorized and likely release onto the dark web, where [it] holds significant value for the threat actors.” (Amended Complaint, ¶ 98). Plaintiff further alleges that “this transfer of value occurred without any consideration paid to Plaintiff or Class Members for their property, resulting in an economic loss.” (Id. ¶ 99). In arguing that the diminished value of Plaintiff’s PII is a cognizable injury, Plaintiff relies on In re Marriott, supra, 440 F. Supp. 3d at 462. In In re Marriott, the district court held that several plaintiffs had established injury in fact because they sufficiently alleged that some of the plaintiffs suffered identify theft and fraud (e.g., unauthorized credit cards applied for or unauthorized charges on credit cards). With that backdrop, the Court ultimately held that “the diminished value of compromised PII [was a] concrete injury based on allegations that the defendant collected and paid to analyze that information.” Gordon, 2025 WL 936415, at *7 (citing In re Marriott, 440 F. Supp. 3d at 461-62). In the instant case, however, as held above, Plaintiff has not established actual misuse, nor has he alleged that Defendant “collected and paid to analyze that information.” Gordon, 2025 WL 936415, at *7. Thus, the Court finds that Plaintiff has not established injury-in-fact based on diminished value to his PII. Accord Stuart, 769 F. Supp. 3d at 487-88 (plaintiffs did not plead standing based on the diminution in value of their PII because plaintiffs’ complaint failed to allege any facts explaining how plaintiffs actually lost value because of the disclosure of their PII); see also In re Cap. One Consumer Data Sec. Breach Litig., 488 F. Supp. 3d 374, 403 (E.D. Va. 2020) (determining that, “[e]ven assuming that Plaintiffs’ PII has monetary value, Plaintiffs do not allege any facts explaining how their PII became less valuable as a result of the breach. For instance, there are no allegations that Plaintiff attempted to sell their information and were refused a sale because of or related to their PII’s prior exposure arising from the Data Breach. Nor is there any allegation that Plaintiff[s] have attempted to purchase goods or services, which requires the exchange of their PII, and Plaintiffs were denied receipt of that good or service or were only offered less-than-desirable terms because of their PII’s prior exposure through the Data Breach.”); see also Khan v. Child.’s Nat’l Health Sys., 188 F. Supp. 3d 524, 533 (D. Md. 2016) (holding that alleged loss of value of personal information did not establish injury-in-fact because plaintiff did not “explain how the hackers’ possession of that information has diminished its value, nor does she assert that she would ever actually sell her own personal information”); cf. Gordon, 2025 WL 936415, at *7 (finding that “Plaintiffs have sufficiently alleged diminution in value of PII as a basis for standing given there are allegations of concrete injury, including, inter alia, fraudulent accounts and loan applications opened in Plaintiffs’ names, along with other specific allegations that the Data Breach interfered with Plaintiffs’ fiscal autonomy by impairing their ability to participate in the economic marketplace”). Accordingly, Plaintiff has not plausibly alleged that he has been injured under the theory of lost value of his PII. 3. Loss of Benefit of Bargain Plaintiff alleges that he and the Putative Class Members have lost the benefit of their bargain with Defendant. (Amended Complaint, ¶¶82, 106-08). According to Plaintiff, “[w]hen agreeing to provide their Private Information, which was a condition precedent to obtain employment from Defendant or Defendant’s clients, Plaintiff and Class Members, as employees or prospects, understood and expected that Defendant maintained adequate data security to protect the Private Information they were required to provide.” (Amended Complaint, ¶ 107). Relatedly, “Defendant did not provide the expected data security,” so the “Plaintiff and the Putative Class Members received services of a lesser value than what they reasonably expected to receive under the bargains struck with Defendant.” (Id. ¶ 108). The Fourth Circuit “has never held that an overpayment or benefit-of-the-bargain theory in a data breach context is sufficient to confer standing.” Podroykin v. Am. Armed Forces Mut. Aid Ass’n, 634 F. Supp. 3d 265, 272 (E.D. Va. 2022). In addition, Plaintiff’s allegations that he “understood and expected that Defendant maintained adequate data security to protect the Private Information they were required to provide,” (Amended Complaint, ¶107), but “Defendant did not provide the expected data security,” (Amended Complaint, ¶108), so Plaintiff “received services of a lesser value than what [he] reasonably expected to receive under the bargains struck with Defendant” (Id.), are not sufficient to confer standing. See Stuart, 769 F. Supp. 3d at 490 (holding that conclusory allegations that plaintiffs applied for positions with defendant with the expectation that defendant would protect their PII and that they “received employment positions of lesser value than what they reasonably expected to receive under the bargains they struck with Defendant” were “insufficient to support standing based on a benefit-of-the-bargain injury theory”). 4. Emotional Distress Fourth, Defendant argues that Plaintiff’s assertions of emotional injury do not provide Plaintiff with standing. (Memorandum, p. 15). Plaintiff alleges that he and the putative Class Members have and will continue to suffer “emotional distress including anxiety and stress in with [sic] dealing with the Data Breach.” (Amended Complaint, ¶¶ 13, 82, 157). Plaintiff further asserts that he has suffered “fear, anxiety, and stress” thinking about how his PII is “in the hands of cybercriminals, which has been compounded by the fact that Defendant still has not fully informed him of key details about the Data Breach’s occurrence or the information stolen.” (Id., ¶ 119). As a preliminary matter, the Court finds that Plaintiff’s bald accusations and “labels and conclusions” are insufficient to state a plausible claim of any kind. Twombly, 550 U.S. at 556; see also Capiau, 2024 WL 374191, at *7 (generalized allegations about “anxiety, sleep disruptions, stress, fear, frustration” insufficient to confer Article III standing). In addition, Plaintiff relies upon TransUnion LLC, 594 U.S. at 436 n.7, asserting that his knowledge “that [he] is exposed to a risk of future physical, monetary, or reputational harm could cause its own current emotional or psychological harm.” (Opposition, p. 15). The Court first finds that TransUnion LLC was a case involving allegations that TransUnion kept alerts in the credit files of more than 8,000 consumers, which represented that they were “potential matches” to a list of terrorists and drug traffickers kept by the U.S. Department of Treasury’s Office of Foreign Assets Control; in other words, it was not a data breach case. Thus, the Court does not find TransUnion to be persuasive. Next, the Court has already found that the mere targeting of PII without actual data misuse is insufficient to establish injury-in-fact. Furthermore, the Court has already found that the risk of identity theft and fraud is insufficiently present on the facts pleaded here. Accordingly, the Court finds that, because Plaintiff does not sufficiently allege emotional injuries that amount to a concrete harm, the allegations in the Amended Class Action Complaint are insufficient to support standing. See Capiau, 2024 WL 374191, at *7; Stuart, 769 F. Supp. 3d at 489; Stamat, 2022 WL 3919685, at *7 (no standing, where plaintiff cursorily alleged “emotional distress,” “lost time, annoyance, interference, and inconvenience,” yet failed to offer particular facts to support alleged emotional injuries). E. Injunctive Relief In the Amended Complaint, Plaintiff seeks injunctive relief “requiring Defendant to (a) strengthen its data security systems and monitoring procedures; (b) submit to future annual audits of those systems and monitoring procedures; and (c) provide adequate and lifetime credit monitoring to Plaintiff and all Class Members.” (Amended Complaint, ¶¶ 159, 177). Defendant contends that Plaintiff does not have standing to pursue injunctive relief. In particular, Defendant asserts that injunctive relief is designed to address harm related to this data breach and “cannot be designed to prevent a future” incident. (Memorandum, p. 16). In support of its arguments, Defendant cites to I.C. v. Zynga, Inc., 600 F. Supp. 3d 1034, 1055 (N.D. Cal. 2022). In Zynga, the plaintiffs had created accounts with the defendant, a social gaming company, which collected PII from its users. Zynga, Inc., 600 F. Supp. 3d at 1038. In September 2019, a hacker breached the defendant’s database of customers and acquired the PII of more than 218 million users. Id. at 1039. The plaintiffs brought a consolidated putative class action against the defendant, alleging that the defendant failed to protect its customers’information by, among other things, using password encryption methods that were outdated and banned by the federal government. Id. at 1045. The plaintiffs sought both damages and injunctive relief for 29 causes of action under state law. Id. at 1045, 1047. The court found that the plaintiffs’ alleged injuries of private disclosure of private facts and intrusion upon seclusion were not sufficiently concrete to provide standing. Id. at 1050. The court also found that, because the plaintiffs did not allege any actual identity theft or fraud, they could not claim an injury in fact. Id.at 1052. The court further found that the plaintiffs did not plausibly allege other injuries caused by the risk of identity theft, such as unsolicited emails, mitigation costs, emotional distress, and diminution in value of the PII. Id. at 1052-55. Thus, the court dismissed the plaintiffs’ claims for damages because the plaintiffs failed to allege actual identity theft or other concrete injuries caused by the risk of identity theft. Id. at 1055. The courtalso dismissed the plaintiffs’ claims for injunctive relief for lack of standing because the risk of harm to the plaintiffs was “not sufficiently imminent or substantial.” Id.(citing, inter alia, TransUnion, 594 U.S. at 435-36). In the Opposition, Plaintiff relies upon TransUnion. (Opposition, pp.15-16). According to Plaintiff, TransUnion provides that a“person exposed to a risk of future harm may pursue forward- looking, injunctive relief to prevent the harm from occurring, at least so long as the risk of harm is sufficiently imminent and substantial.” 594 U.S. at 435. In the instant case, the Court has found that Plaintiff’s allegation of the increased risk to Plaintiff’s PII does not establish concrete harm for Article III standing purposes. See supra Part II.C.3. Thus, Plaintiff also lacks standing to pursue injunctive relief. See Stuart, 769 F. Supp. 3d at 487 n.7 (concluding that, because plaintiffs did not demonstrate injury in fact based on their risk of future fraud or identity, plaintiffs lacked standing to pursue injunctive relief; plaintiffs’ conclusory allegation that defendant did not have “adequate safeguards” to protect plaintiffs’ PII, without more, did not establish standing for injunctive relief (citing, inter alia, TransUnion LLC, 594 U.S. at 435)). In sum, because Plaintiff has failed to establish standing based on a sufficiently imminent and substantial risk of harm, the Court also finds that Plaintiff’s reliance on TransUnion to be unavailing. IV. CONCLUSION For the foregoing reasons, the Motion, ECF No. 33, is GRANTED,6 and Plaintiff’s Amended Class Action Complaint (ECF No. 15) is DISMISSED WITHOUT PREJUDICE.7 A separate Order follows. /s/ The Honorable GinaL.Simms UnitedStatesMagistrateJudge 6 Because Plaintiff fails to sufficiently plead facts to demonstrate concrete injury-in-fact, the Court finds that the putative Class Members cannot meet their burden of establishing standing. Beck, 848 F.3d at 270. 7See Nat’l Fair Hous. All. v. Bank of Am., N.A., Civil No. SAG-18-1919, 2025 WL 2030225, at *10 n.9 (D. Md. July 21, 2025) (“Of course, Rule 12(b)(1) dismissal is without prejudice, typically affording the plaintiff an opportunity to seek leave to amend the pleading to establish standing.” (citing Ali v. Hogan, 26 F.4th 587, 600 (4th Cir. 2022))).

Case-law data current through December 31, 2025. Source: CourtListener bulk data.