v.
AT&T Mobility, LLC
IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF NORTH CAROLINA WESTERN DIVISION No. 5:19-cv-475-BO JASON WILLIAMS, ) Plaintiff, ) V. ORDER AT&T MOBILITY, LLC, Defendant. )
This matter is before the Court on defendant’s motion to dismiss [DE 14]. For the reasons discussed below, the motion [DE 14] is DENIED. BACKGROUND Plaintiff brings this lawsuit against his former wireless carrier, AT&T Mobility, after the company effectuated seven unauthorized reassignments of his SIM card at the behest of hackers. A SIM (“subscriber identify modulc’) card is a small, removable chip that allows a cell phone to communicate with the wireless carrier and to know which subscriber is associated with that phone. The SIM card associated with a wireless phone can be changed, allowing customers to move their wireless number from one cell phone to another and to continue accessing the carrier network when they switch cell phones. The wireless carrier must effectuate the SIM card reassignment. A “SIM swap” refers to an unauthorized and illegitimate SIM card change. It is a hacking technique whereby the hacker induces the phone carrier to change the phone associated with the SIM card. rerouting the victim’s phone activity (e.g., phone calls, texts) to a third-party phone. The victim loses his or her phone connection while the hacker receives all of the text messages and phone calls intended for the victim. Once the hacker establishes control over the victim’s
phone number, he can utilize that number to access the victim’s other online accounts, which often utilize phone-based, two-factor authentication for access and password change requests. Plaintiff's complaint alleges that AT&T effectuated seven unauthorized reassignments of his SIM card between November 5, 2018 and February 8, 2019. These SIM swaps compromised much of his personal and financial data, exposed him and his family to threats to their physical safety. and put aspects of his business at risk. See Pl.°s Comp., DE 2. Plaintiff is a co-founder and partner of an asset management company that invests in blockchain technology and digital assets. /d. § 8. This included a large-scale bitcoin mining operation, which was discontinued in February 2019 in response to the SIM swaps. /d. ¥ 9. The first SIM swap occurred on November 5, 2018. /d. § 37. In the period between when AT&T etfectuated the unauthorized change and when plaintiff was able to reverse it, hackers (1) created a mirror image of his phone so that they could see every app: (2) accessed other online accounts, including his Coinbase and Slush Pool accounts;! (3) obtained his home address, his and his family members’ social security numbers, copies of their passports, TSA precheck information, and financial documents; and (4) threatened to sell his personal information on hacker exchange sites. /d. {§ 37-46. The hackers also stole $1,500 worth of bitcoin. Jd. § 42. After the attack, plaintiff contacted AT&T to discuss measures the company could take to prevent another SIM swap. /d. § 47. AT&T represented that it would add additional security protocols to plaintiff's account. Specifically. AT&T told plaintiff that it would only make SIM card changes in-person at a designated Raleigh AT&T location and that plaintiff would be required to authenticate his identity with two passports. /d. Plaintiff also put AT&T on notice that. given his involvement as a cryptocurrency trader, he faced a heightened risk of SIM swap
Coinbase is a cryptocurrency exchange. Slush Pool is a cryptocurrency mining platform.
attacks. Relying on AT&T's representations that it was adding these additional safety measures, plaintiff decided not to close his account with the company. /d. The fallout from the first SIM swap was not over, though, because after the attack, the hackers began sending threatening messages to plaintiff. /d. § 48. The messages specified his name. home address, and social security number. /d. The messages also threatened the physical safety of his family. Despite AT&T’s representations that it would not make any SIM card changes outside of the established protocols, the company effectuated a second SIM swap on November 30, 2018, less than a month later. /d. § 50. During the hack, plaintiff immediately went to the designated AT&T store with two passports to reverse the change. /d. § 52. At the store, he was told that an AT&T employee made the SIM card change at the behest of an impersonator who only provided a fake driver's license as proof of identity. /d. The next day, December 1, 2018, AT&T effected a third unauthorized SIM card change. Id © 53. Plaintiff went to the designated AT&T location the next day, disabled his SIM card, and bought a new iPhone for $700. Jd. § 57. Ile purchased the new phone because the AT&T employees represented that it would help mitigate the risk of additional attacks. /d. He was again assured that his account was subject to the agreed limitations for changing the SIM card. /d. What's more. he was informed that he was on a special list of customers designated as at a high risk for SIM swap attacks. /d. § 58. But that same evening, hours after being assured the company was well aware additional security was needed with respect to his account, AT&T made unauthorized changes to his SIM card a fourth time. /d. § 59. With control over his phone number, the hackers accessed his Twitter account and put out messages impersonating him, inducing plaintiff's friends and
associates to send them cryptocurrency. /d. § 61. Back at the AT&T store to undo the change, plaintiff asked the employees again to confirm that his account carried special instructions allowing only in-person changes at that location. /d. § 64. The employees confirmed the additional protocols. /d. On February 4, 2019, plaintiff was SIM swapped a fifth time. /d. § 66. While in control of his phone number, the hackers accessed his accounts on various cryptocurrency exchange platforms. /d. § 69. The hackers also accessed his Twitter account again and solicited the exchange of currency from his friends and associates. /d. 70. When he went to the AT&T store the next day, employees informed him the changes had been made to his account in response to an email request and an AT&T online representative changed his four-digit personal identification number (“PIN”). /d. § 71. A sixth unauthorized change to his account was made less than 24 hours later. /d. § 72. During this swap, hackers deleted his Slush Pool account, rendering aspects of his business useless. /d. § 73. Back at the AT&T store again, two employees helped him get a new SIM card. Id. © 74. They also told him that his four-digit PIN had been changed online. /d. An AT&T employee made this change to plaintiff's SIM card in response to an over-the-phone request. /d. [4] 75. Because of this hack and the continued risk that the currency generated through his bitcoin mining operations would be stolen, plaintiff discontinued bitcoin mining. /d. { 76. This meant shutting down the activity of 500 computer servers for which he had invested $1.4 million. /d. 76-77. A seventh unauthorized SIM card change was made a few days later. /d. [4] 78. The hackers transferred $6,500 from his bank account to his Coinbase account, which plaintiff is no
longer able to access. /d. § 79. Plaintiff went to the designated AT&T store to stop the hack and to notify the company that he was switching carriers. /d. § 80. The AT&T emplovees told him he was ineligible to take his new phone with him to the new carrier. /d. Consequently, plaintiff was forced to purchase a new phone from his new carrier. /d. § 81. In response to the seven unauthorized changes and the damage they caused in his life, plaintiff filed this action against AT&T in October 2019. He brings six claims: (1) violation of the Federal Communications Act, 47 U.S.C. § 201 ef seq.; (2) violation of the North Carolina Unfair and Deceptive Trade Practices Act (*UDTPA”). N.C. Gen. Stat. § 75-1.1: (3) Negligence; (4) Negligent Supervision; (5) violation of North Carolina’s computer trespass law, N.C. Gen. Stat. § 1-539.2A: and (6) violation of the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. § 1030. Defendant moves to dismiss the suit pursuant to Federal Rules of Civil Procedure 12(b)(1), 12(b)(6), and 9(b). raising a host of challenges to plaintiff's complaint. The motion ts fully briefed and is ripe for disposition. DISCUSSION AT&T challenges the sufficiency of plaintiff's complaint on many fronts. First, the company challenges plaintiff's allegations of proximate cause, arguing that the entire complaint should be dismissed because plaintiff's injuries are (1) unconnected to AT&T’s conduct, (2) attributable to plaintiff's own contributory negligence, and (3) attributable to the criminal acts of third parties. AT&T then challenges specific aspects of plaintiff's complaint, arguing: he lacks standing: his UDTPA claim fails to satisfy Federal Rule of Civil Procedure 9(b): his negligence- based claims are barred by the economic loss rule; North Carolina’s computer trespass law does
not apply to AT&T: the CFAA claim is inadequately pled; and that plaintiff is not entitled to certain types of relief. The Court addresses each of AT&T’s arguments below. Ultimately, the Court is unpersuaded by any of the company’s asserted grounds for dismissal. I. Plaintiff has standing to sue At the outset. the Court must address AT&T's argument that plaintiff lacks standing. For an action to constitute a case or controversy under Article II, a “plaintiff must have (1) suffered an injury in fact. (2) that is fairly traceable to the challenged conduct of the defendant, and (3) that is likely to be redressed by a favorable judicial decision.” Spokeo, Inc. v. Robins, 136 S. Ct. 1540. 1547 (2016). Plaintiff easily satisfies these requirements. His complaint is replete with asserted injuries that he personally suffered, including stolen money, deprivation of access to his other online accounts, reputational harm, and experiencing fear in the face of personal threats. These injuries are fairly traceable to AT&T's conduct and would likely be redressed by a favorable decision. AT&T argues that plaintiff lacks standing because he is seeking to recover on behalf of a business entity for which he is a shareholder. Aside from referring to himself as a “partner,” the precise legal structure of plaintiff's business is not specified in the complaint. But the business's legal structure is irrelevant at this juncture as plaintiff clearly has alleged his own injury-in-fact. Il. Plaintiff has properly alleged his claims for relief “A motion filed under Rule 12(b)(6) challenges the legal sufficiency of a complaint.” Francis vy. Giacomelli, 588 F.3d 186, 192 (4th Cir. 2009). To survive a Rule 12(b)(6) challenge, plaintiff's complaint must articulate facts, that when taken as true, show plaintiff has stated a claim entitling him to relief. /d. at 193. The Court need not accept the plaintiff's legal
conclusions drawn from the facts, nor need it accept unwarranted inferences, unreasonable conclusions, or arguments. Philips v. Pitt County Mem. Hosp., 572 F.3d 176, 180 (4th Cir. 2009). “(Wholly vague and conclusory allegations are not sufficient to withstand a motion to dismiss.” Doe y. Virginia Dep't of State Police, 713 F.3d 745, 754 (4th Cir. 2013).
[*10]Rather, he is seeking to recover for tortious conduct where the harms proliferated to every aspect of his life, well beyond his contractual relationship with AT&T. The economic loss rule does not bar his negligence and negligent supervision claims.
[*11]consequence.” /d. (internal quotations omitted). Under AT&T’s reading of the exception, business enterprises are incapable of committing computer crimes using their own computer systems because the software and hardware of their systems are always designed for the system to operate in the ordinary course of business. Here, plaintiff alleges that AT&T violated the statute through its employees, not through its contract terms, hardware, or software. Effectuating an unauthorized SIM card change in a manner that transgresses the explicit permissions of the customer cannot reasonably be said to fall within the ordinary course of lawful business. Given the number of unauthorized SIM card changes, the repeated failures by AT&T to follow the security protocols, and the additional unauthorized changes to his PIN, plaintiff's allegations state a plausible claim that AT&T violated North Carolina’s computer trespass law.
[*12][*13]anguish as a matter of law, without evidence. /d. The Court is inclined to agree that presumed damages are inappropriate. but the Court need not make such a determination right now as plaintiff's complaint does not appear to rely on presumed damages. Rather, plaintiff alleges substantial actual damages, including financial loss, dissemination of sensitive personal information, reputational damage, and mental anguish. AT&T's request for the Court to strike the prayer for punitive damages also fails. Under North Carolina law, punitive damages may be awarded against a corporation where “the officers, directors, or managers of the corporation participated in or condoned the conduct constituting the aggravating factor giving rise to punitive damages.” N.C. Gen. Stat. § 1D-15. The term “manager” has been interpreted as broadly as “one who conducts, directs, or supervises something.” Everhart y. O'Charley's Inc., 200 N.C. App. 142, 153 (2009) (internal quotations omitted). The term is clearly not limited to individuals at the highest level of a company but includes branch or shift managers and the like. See Everhart, 200 N.C. App. at 154 (concluding that an assistant dining room manager met the definition of “manager™). Ultimately, whether a “manager” participated or condoned an aggravating factor is a factual determination that is more appropriately left for later. At this stage, plaintiff's complaint states a plausible case that a “manager” was involved in the SIM swaps. which given the special security protocols established. could involve aggravating factors. CONCLUSION In sum, the Court concludes that plaintiff has standing and that he has alleged plausible claims for relief uader all of his causes of action. For the reasons stated above, defendanit’s motion to dismiss [DE 14] is DENIED.
[*14]SO ORDERED, this py , day of March, 2020.
TERRENCE W. BOYLE / CHIEF UNITED STATES DISTRICT JUDGE
[*15]