Cybersecurity lawsuit against French digital wallet company

[ad_1]

Wednesday, January 18, 2023

Customer lists held by vendors and personal information entered by users to obtain digital wallets or create crypto exchange accounts are enviable targets for hackers. This data can be used to launch targeted phishing programs and related scams to trick holders into divulging their private keys or unknowingly transferring anonymized crypto assets to hackers. A recent case involves a lawsuit brought by customers who purchased a hardware wallet to secure cryptocurrency assets and seek compensation for harms they allegedly suffered as a result of data breaches that exposed their personal information.

A recent Ninth Circuit decision analyzed whether a federal court had personal jurisdiction over a foreign crypto asset wallet provider, an issue that can be important when litigating in this area, given the borderless nature of the crypto asset world. and related services. (Baton v. Ledger SAS, No. 21-17036 (9th Cir. Dec. 1, 2022) (unreported)).

In the case, plaintiffs purchased hardware wallets to store crypto assets. Following data breaches that allegedly exposed personal information provided in connection with wallet purchases (e.g., names, email addresses, mailing addresses, and phone numbers), plaintiffs filed suit against Ledger SAS (Ledger ), the French company that produced and sold the wallets and Shopify Inc., (Shopify) the Canadian company that provided e-commerce services for the Ledgers store, and its US subsidiary (collectively, the defendants). Plaintiffs filed various claims in the California District Court, including negligence and consumer claims in California and other states based on their allegation that Ledger failed to exercise due diligence to secure their personal information.

In seeking dismissal, the defendants asserted that the court did not have personal jurisdiction over them: Shopify Inc. argued that it is a Canadian company that is not registered to do business in California and has no employees in California and that the rogue individuals who were responsible for a data breach of the Shopify, Inc. platform (including, allegedly, certain ledger customer transactional records) were not Shopify employees, but foreign contractors; Ledger maintained that it was a French company with no Californian or American employees. The district court granted the motions and dismissed the action for lack of personal jurisdiction over the defendants. The lower court found no specific jurisdiction over Shopify simply because it provided a software product that allowed Ledger to run an online store for consumers around the world, because it was Ledger, not Shopify, that makes the conscious choice to deliberately direct its product to the Californian forum. . Second, the court dismissed, as the speculative and unwarranted plaintiffs requested a judicial inquiry seeking information on, among other things, the existence of employees who may have worked with the dishonest contractors implicated in a breach and the alleged activities of a California-based data provider. protection officer at Shopify. As for the Ledger defendant, the lower court also found that the mere operation of a universally accessible website alone is generally insufficient to satisfy the requirement that Ledger expressly directed its conduct to California.

The Ninth Circuit reversed the dismissal of the action, affirming in part and reversing in part the lower courts’ findings on jurisdiction. (Baton v. Ledger SAS, No. 21-17036 (9th Cir. Dec. 1, 2022) (unreported)). The appeals court found that the court had personal jurisdiction over Ledger due to its sales in the state, totaling approximately 70,000 wallets sold to Californians, generating millions of dollars in revenue. The court also said that the Ledgers website is designed to collect California sales tax applicable to buyers whose IP addresses are in California. Taken together, these facts establish intentional use, as Ledgers’ contacts with the forum cannot be characterized as random, isolated or incidental. The court also said the plaintiffs’ claims arose from these wallet sales since the personal information was collected for e-commerce and marketing purposes. Yet the court limited the potential universe of claims that the putative class of plaintiffs could bring based on the existence of a broad forum selection clause in terms of Ledgers that compels [a]Any dispute, controversy, dispute or claim arising out of or relating to the present will be brought exclusively before the French courts. The court held that the forum selection clause was enforceable except with respect to claims under California consumer laws brought by California residents, finding that such claims could not be waived on grounds of ‘public order.

With respect to Shopify, the Ninth Circuit agreed that the present record did not support personal jurisdiction, but ruled that the lower court wrongly denied plaintiffs claims for jurisdictional discovery and an opportunity to amend the complaint at the following such a discovery. The court noted that Shopify USA employs a number of people who work remotely from California, and that apparently one of those employees, at the relevant time, held the title of Vice President, Legal; Data Protection Officer. In the opinion of the appellate courts, it is reasonable to infer that the data protection officer of Shopifys in California may have had a role in the data breach, as he appears to have overseen the privacy policies and Shopify’s response, but that more facts were needed to determine whether these activities support the exercise of jurisdiction.

2022 saw a record increase in the number of crypto-related hacking incidents (one report found over $3 billion worth of cryptocurrency stolen from January to October). The security incidents have particularly affected decentralized protocols, including the cross-chain bridges and smart contracts underlying DeFi, some of which may have been built on flawed code. These hacking incidents are occurring during the enduring crypto winter downturn, which has been exacerbated by the recent high-profile collapses and bankruptcies in the industry. One would expect more litigation by users against vendors over crypto assets stolen by hackers.

Additionally, this case signals that crypto-related businesses outside of the United States may be subject to the jurisdiction of the country, despite limited contact within its borders. Given the size of the US market, this may be a risk worth taking. To minimize the risk, depending on the company in question, steps can be taken to reduce the likelihood of such a finding.

Jonathan Mollod also contributed to this article.

2023 Proskauer Rose LLP. National Law Review, Volume XIII, Number 18

Sources

1/ https://Google.com/

2/ https://news.google.com/__i/rss/rd/articles/CBMicGh0dHBzOi8vd3d3Lm5hdGxhd3Jldmlldy5jb20vYXJ0aWNsZS9jb25zdW1lci1sYXctY2xhaW1zLWFnYWluc3QtZnJlbmNoLWNyeXB0by1hc3NldC13YWxsZXQtcHJvdmlkZXItbWF5LXByb2NlZWTSAXRodHRwczovL3d3dy5uYXRsYXdyZXZpZXcuY29tL2FydGljbGUvY29uc3VtZXItbGF3LWNsYWltcy1hZ2FpbnN0LWZyZW5jaC1jcnlwdG8tYXNzZXQtd2FsbGV0LXByb3ZpZGVyLW1heS1wcm9jZWVkP2FtcA?oc=5

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts