Levine: Liability for third party supplier's data breaches. (US)
Court documents: https://drive.google.com/file/d/1-geCkToEjuBCLmJxBD_Ok98vtTOoYRlb/view
The short answer is YES. The federal court declined to dismiss the case, finding that a company might be negligent based on its law firm's breach.
Here is the background: the company makes snack food for retail sale. It retained a respected and well-known law firm to provide legal services. In the course of the representation, the company provided certain of its employees’ personally identifiable information to the law firm, including names, dates of birth, social security numbers and addresses.
In 2023, the law firm detected unauthorised access to its information systems and a forensic investigation revealed that the hackers obtained the personally identifiable information of 51,100 current and former employees of the company. Each of the named plaintiffs received a letter from the company to notify employees of the data breach and that their personally identifiable information had been exposed.
The plaintiffs alleged that they are at an increased risk of identity theft and they have taken prudent actions to mitigate the risk of identity theft, such as “signing up for credit monitoring and identity theft insurance, closing and opening new credit cards, and securing their financial accounts.” They filed a number of lawsuits against the company and its law firm.
Brian Levine can be contacted here: https://www.linkedin.com/in/brian-levine-cyberlaw/
The company moved to dismiss the lawsuits, arguing, among other things, that simply turning over employee information to its law firm cannot be negligent. In response, the plaintiffs pointed out that they alleged that the company should have ensured that its counsel followed proper data security practices and it should have deleted certain personal information that it no longer needed to maintain, rather than share it unnecessarily with counsel.
The Court declined to dismiss the negligence claim against the company, finding that the plaintiffs should have the opportunity to further "develop the facts." This means that the company is likely to spend thousands of dollars in legal fees during discovery, and is statistically likely to settle the case, rather than risking an adverse ruling at trial (or on summary judgment).
In the unlikely event that the law firm and its insurers end up having insufficient funds to satisfy any judgment, it is possible that the company may have exposure with respect to any judgment, regardless of its negligence or lack thereof.
-----------------------
Brian Levine is Cybersecurity & Data Privacy Leader with EY and a former DOJ Cybercrime Prosecutor, NYAG Regulator and Civil Litigator

