Quick answer: I don't know, but it's less likely than it might initially appear.
Earlier this month several sources, including Wired, reported that over 30 large companies, including Google and Adobe, had been victims of a sophisticated hack, which Microsoft admits was made possible by a weakness in Internet Explorer 6. Microsoft also admits that it learned of the flaw in September, and that it was holding back a patch so that it could be released in a cumulative update that was due out next month. Given the above, and the notoriously litigious nature of the American public, it would seem that Microsoft is almost guaranteed to be hit by a lawsuit seeking damages based on the failure to release the patch earlier. Certainly, when I read that Microsoft had learned about the flaw and withheld the patch, my first thought was that this was something that would keep their lawyers busy in court for months (if not years) to come.
However, the more I think about the situation, the less I think Microsoft is guaranteed to go to court. If this had happened 3-4 years ago, I'd expect Microsoft would already have been hit by a class action lawsuit filed on behalf of consumers who used IE6. However, since that time, courts have been pretty uniformly unreceptive to claims that consumers are damaged by increased risks caused by unauthorized access to data by third parties (e.g., here). A consumer wanting to sue Microsoft for vulnerabilities in IE6 would be even less likely to succeed, since (unlike the unsuccessful plaintiffs in the security breach cases) the hypothetical consumer suing Microsoft wouldn't even be able to show that an unauthorized third party had accessed their system, only that they were at an increased risk of such access due to using IE6. Looking at that history, the chances of a consumer class action against Microsoft seem pretty slim.*
So, consumers aren't likely to sue Microsoft, what about the businesses who were victimized because of the flaw? While they'd have an easier time proving damages (after all, it is known that they were hacked, and at least some of what the hackers did), there are also forces which could prevent them from going to court. For one thing, most businesses try and work things out before involving the judiciary. In this case, I assume that Google, Adobe, et al have contacted Microsoft about helping them clean up the damage. Microsoft has a significant interested in trying to make sure those out of court efforts are successful, since a drawn out court battle could only hurt Microsoft's brand in the already competitive browser market. Similarly, the companies that have been hacked would probably like to avoid going to court as well, since any lawsuit would invariably have the effect of calling their own security into question, even if they could convince the public that the reason their systems weren't secure is because they were using unsafe products, rather than that their own internal practices were deficient.
Of course, strong incentives to avoid a court battle don't necessarily mean there won't be one. If the damage caused by the hackers is too expensive, Microsoft might be willing to fight not to pay it, and the injured company might be willing to fight to get paid. At this point it's impossible to say how likely that is to play out. However, I think, given the incentives on all sides to avoid it, the likelihood of a lawsuit against Microsoft on this is much lower than it would initially appear.
*Obviously, the chances aren't zero. If there was going to be a suit against Microsoft, I would expect it in a state which has allowed suits for increased risk of health problems as a result of a chemical spill. The analogy isn't perfect, but it does make it somewhat easier to prove damages.
Showing posts with label litigation. Show all posts
Showing posts with label litigation. Show all posts
Sunday, January 24, 2010
Tuesday, March 11, 2008
Limits to Depending on Europe
In this post I posited that U.S. consumers might benefit from Europe's generally more protective attitude towards individual privacy. However a court case from last year dealing with obligations to turn over material in litigation demonstrated that there are limits to relying on European privacy laws. The case was Columbia Pictures v. Bunnell, and it was part of the ongoing battle that record companies have been fighting against peer to peer networks. In this case, Bunnell decided to put his server in the Netherlands, hoping that that country's relatively strong privacy laws would benefit his customers if the MPAA ever came calling. It turns out that that strategy doesn't work when you're sued in the U.S. As the court emphasized in ordering Bunnell to produce records of his customer's requests, "it is well settled that foreign blocking statutes do not deprive an American court of the power to order a party subject to its jurisdiction to produce (let alone preserve) evidence even though the act of production may violate that statute" (emphasis added). The bottom line: if you care about privacy, you need to fight for it at home (wherever that may be), because depending on foreign standards to protect you won't work if you're before a local judge who sees privacy as simply an obstacle to the proper function of the law.
Labels:
blocking statutes,
discovery,
Europe,
litigation
Wednesday, December 5, 2007
The Forgotten Side of the TJX Litigation
As it happens, the TJX litigation isn't only about TJX. That litigation is actually about lawsuits against both TJX and Fifth Third, TJX's bank. The relationship between Fifth Third and TJX was that, when a consumer would make a credit card purchase, the information from that purchase would be sent from TJX to Fifth Third. The information would then be sent to the bank that issued the credit card to the consumer, who would say either yea or nay, then the information would be passed back to TJX through Fifth Third. For some purposes in the litigation, TJX and Fifth Third could be (and were) given the same treatment. However, the unique status of Fifth Third came to the fore when the judge in the TJX litigation decided to deny class certification to the issuing banks in their suit against TJX. For class certification, it was necessary that there be some assurance that the issuing banks would vigorously prosecute the litigation, and that there be no conflict between the members of the class as a whole. The problem raised by Fifth Third's relationship with TJX is that some of the issuing banks suing TJX were also acquiring banks, that is, they functioned in the same capacity for their customers as Fifth Third had for TJX. The result was that the court found that a verdict which imposed liability on Fifth Third could actually be negative for some of the banks filing suit - leading to a conflict between those banks and the banks which only issued credit cards, but did not act as acquiring banks. For the court, that conflict provided an independent reason why class certification in the parallel action against Fifth Third was inappropriate.
Sunday, December 2, 2007
TJX Settling Out?
According to this article from Computer World TJX has proposed to pay $40.9 million to banks that issued Visa cards potentially affected by TJX's massive data breach if the affected banks agree not to pursue litigation against TJX. The article describes TJX's offer a move which could save "tens of millions of dollars in lawsuit damages." Actually, that's understating things quite a bit. In paragraph 96 of the fifth amended complaint in the ongoing litigation regarding the TJX breach (case number 1:07-cv-10162), a bankers association seeking class certification alleged that "The cancellation and reissuance of cards resulted in damages and losses to Plaintiff Banks and members of the proposed Class of up to $25 per card." As the first paragraph of that same complaint alleged that "approximately 100 million credit cards were compromised because of TJX's acts and omissions," it seems that there were potentially up to 2.5 billion (25 dollars/card * 100 million cards) dollars in damages. Even assuming that the $25 per card cited as the maximum in the lawsuit is unrepresentative, and the real cost is lower (e.g., the 10 dollars/card quoted in this posting), the cost of canceling and reissuing almost 100 million cards is certainly greater than the $40.9 million offered by TJX. Of course, there's no guarantee that the banks would win if they did pursue litigation. However, if TJX ends up eliminating its litigation risks from banks who had to reissue cards for only $40.9 million, then TJX would dodge a very big bullet at only a (relatively) low cost.
Friday, November 30, 2007
VA case going to mediation
The case I wrote about here and flagged as interesting and worth watching has gone to mediation (article here). Now, this doesn't mean that the case is necessarily going away (I've been involved in unsuccessful mediations - if the parties are simply too far away, there's very little the mediation can do). However, it does mean that there likely won't be any further developments in the case for the time being. From my perspective as an outside lawyer, that's too bad. As I wrote previously, the case looked interesting and I would have liked to have watch it play out.
Tuesday, November 20, 2007
Data Exposure Claim Survives Motion to Dismiss
The D.C. District court has issued a noteworthy opinion in the ongoing consolidated litigation related to last year's potential theft of 26.5 million records (article here, case number 1:06-mc-00506). As described in this article, the plaintiffs in the case alleged damages based on "embarrassment, mental distress, emotional trauma and the threat of future identity theft." Some plaintiffs also requested compensation for having to pay for credit monitoring services. As has been noted previously (e.g., here), Plaintiffs alleging those types of damages generally lose. In fact, earlier this year, the D.C. District court dismissed a data exposure case alleging similar damages based on the proposition that "an allegation of increased risk of identity theft due to lost or stolen personal data, without more, is insufficient to demonstrate a cognizable injury." Randolph v. ING, 486 F. Supp. 2d 1, 7 (D.D.C. 2007). Given that history, the court's decision to let the litigation against the department of veteran's affairs seems, at least initially, to be a departure from what had been settled precedent. While it is unclear what effect this decision will have in the future, because of it, the underlying case is definitely worth watching.
Subscribe to:
Posts (Atom)