Hanna Andersson, Salesforce Data Breach Sparks Class Action Under New California Privacy Law
by Erin Shaak
Barnes v. Hanna Andersson, LLC et al.
Filed: February 3, 2020 ◆§ 3:20-cv-00812
A class action claims Hanna Andersson's and Salesforce's lax security systems and delayed response to a data breach exposed online customers to a heightened risk of fraud and identity theft.
Hanna Andersson, LLC and Salesforce.com, Inc. face a proposed class action lawsuit after a Fall 2019 data breach reportedly compromised the personal information of “tens of thousands” of the high-end children’s clothing retailer’s online customers. The lawsuit alleges that due to the defendants’ lax security systems and delayed response to the breach, cybercriminals “got everything they needed” to commit fraud and identity theft using customers’ stolen information.
The case claims Hanna Andersson notified customers in a letter dated January 15, 2020 that a “widespread” data breach had occurred from September 16 to November 11, 2019. During the incident, the suit says, unauthorized parties gained access to the retailer’s online payment platform provided by Salesforce’s Commerce Cloud Unit. The hackers “scraped” customers’ names, billing and shipping addresses, payment card numbers, CVV codes and credit card expiration dates, the lawsuit says.
Although Hanna claimed the malware had been removed from its payment platform by November 11, a different letter, sent to the attorneys general of the states affected by the incident, the suit says, stated that Hanna was first notified of the breach by law enforcement back on December 5. The lawsuit questions Hanna’s timeline in the two letters, noting that the company claimed to have removed the malware three weeks earlier than it was purportedly made aware of the incident.
“Hanna admits it did not detect this breach on its own, nor did Salesforce notify Hanna about it – law enforcement did,” the complaint states. “How was the malware removed on November 11, 2019, without Defendants noticing it?”
The lawsuit decries the defendants’ “negligent and/or careless” conduct, arguing that the two companies’ inadequate security systems and inattentive approach to data security have exposed customers to a heightened risk of identity theft. Moreover, the case claims Hanna and Salesforce should have discovered the breach months earlier and notified consumers as soon as possible rather than wait “over another month” after being made aware of the incident.
In addition to possible violations of the California Unfair Competition Law, the lawsuit alleges abuses of the newly minted California Consumer Privacy Act, which went into effect on January 1, 2020. This lawsuit is believed to be among the first to mention the new statute, which aims to grant California consumers more control over how companies collect and use their personal information.
The full lawsuit can be read below.
Video Game Addiction Lawsuits
If your child suffers from video game addiction — including Fortnite addiction or Roblox addiction — you may be able to take legal action. Gamers 18 to 22 may also qualify.
Learn more:Video Game Addiction Lawsuit
Depo-Provera Lawsuits
Anyone who received Depo-Provera or Depo-Provera SubQ injections and has been diagnosed with meningioma, a type of brain tumor, may be able to take legal action.
Read more: Depo-Provera Lawsuit
How Do I Join a Class Action Lawsuit?
Did you know there's usually nothing you need to do to join, sign up for, or add your name to new class action lawsuits when they're initially filed?
Read more here: How Do I Join a Class Action Lawsuit?
Stay Current
Sign Up For
Our Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Before commenting, please review our comment policy.