Data Breach Class Action Against Barnes & Noble Dismissed for Lack of Standing
Client Alert | 3 min read | 09.10.13
On September 3, 2013, the U.S. District Court for the Northern District of Illinois dismissed a class action complaint against Barnes & Noble seeking damages based on a data security incident, finding that the plaintiffs lacked standing to bring the claims. This decision reaffirms that retailers may be able to avoid damages for data breaches where the plaintiffs cannot allege or establish actual damages.
In October 2012, Barnes & Noble notified the public, through a press release and a notice on its website, that it had discovered hackers were stealing credit and debit card information from its PIN pad devices at 63 stores across the country. The hackers obtained the data by tampering with the PIN pad devices used to process transactions. Barnes & Noble made the announcement approximately six (6) weeks after it discovered the fraudulent activity. Barnes & Noble did not directly notify individual customers.
Plaintiffs filed multiple claims under Illinois and California state law alleging various injuries including: untimely and inadequate notification of the incident; improper disclosure of their personally identifiable information (PII); loss of privacy; expenses incurred in efforts to mitigate the increased risk of identity theft or fraud; an increased risk of identity theft; deprivation of the value of their PII; and anxiety and emotional distress.
Judge John W. Darrah ruled that these alleged injuries were insufficient to establish actual injury for purposes of standing. Following closely the recent Supreme Court decision in Clapper v. Amnesty Int'l USA, the court explained that although an injury that is "certainly impending" can establish injury sufficient to support standing, "[a]llegations of possible future injury are not sufficient." Clapper v. Amnesty Int'l USA, 133 S. Ct. 1138, 1147 (2013). Though the Clapper decision involved a challenge to the constitutionality of the Foreign Intelligence Surveillance Act (FISA), its standing rationale is readily applicable to data breach lawsuits.
Applying Clapper, the court determined that plaintiffs' allegations claiming untimely notification were insufficient because they merely posed an increased risk of actual injury such as identity theft, not an actual injury or "certainly impending" injury. The court further ruled that even if Barnes & Noble violated the state statutes at issue, that alone did not establish standing in lieu of actual damages. The court next held that plaintiffs did not state facts to support a claim that their information was in fact disclosed. "The inference that their data was stolen, based merely on the security breach, is too tenuous to support a reasonable inference that can be made in Plaintiff's favor." The court also rejected plaintiffs' claims regarding the time and expenses incurred to mitigate the risks of identity theft, finding that plaintiffs "cannot manufacture standing by incurring costs in anticipation of non-imminent harm."
Finally, the court addressed the claim of one named plaintiff who alleged a fraudulent charge had been made on her credit card following a purchase made at an affected Barnes & Noble store. The court found that the only injury suffered was "a time lag of an unknown length between learning of the fraudulent charge and receiving a new credit card" as the credit card company absorbed the cost of the alleged fraudulent transaction. In order to suffer actual injury, the court explained, there would need to be an unreimbursed charge on her credit card. The court also rejected standing for this plaintiff because "it is not directly apparent that the fraudulent charge was in any way related to the security breach at Barnes & Noble."
This decision, like the previously reported LinkedIn User Privacy Litigation decision (March 15, 2013), further establishes lack of standing as a strong defense against class action lawsuits seeking millions of dollars in damages for security incidents where the putative class members cannot allege or prove actual injury.
Contacts
Insights
Client Alert | 5 min read | 12.12.25
Eleventh Circuit Hears Argument on False Claims Act Qui Tam Constitutionality
On the morning of December 12, 2025, the Eleventh Circuit heard argument in United States ex rel. Zafirov v. Florida Medical Associates, LLC, et al., No. 24-13581 (11th Cir. 2025). This case concerns the constitutionality of the False Claims Act (FCA) qui tam provisions and a groundbreaking September 2024 opinion in which the United States District Court for the Middle District of Florida held that the FCA’s qui tam provisions were unconstitutional under Article II. See United States ex rel. Zafirov v. Fla. Med. Assocs., LLC, 751 F. Supp. 3d 1293 (M.D. Fla. 2024). That decision, penned by District Judge Kathryn Kimball Mizelle, was the first success story for a legal theory that has been gaining steam ever since Justices Thomas, Barrett, and Kavanaugh indicated they would be willing to consider arguments about the constitutionality of the qui tam provisions in U.S. ex rel. Polansky v. Exec. Health Res., 599 U.S. 419 (2023). In her opinion, Judge Mizelle held (1) qui tam relators are officers of the U.S. who must be appointed under the Appointments Clause; and (2) historical practice treating qui tam and similar relators as less than “officers” for constitutional purposes was not enough to save the qui tam provisions from the fundamental Article II infirmity the court identified. That ruling was appealed and, after full briefing, including by the government and a bevy of amici, the litigants stepped up to the plate this morning for oral argument.
Client Alert | 8 min read | 12.11.25
Director Squires Revamps the Workings of the U.S. Patent Office
Client Alert | 8 min read | 12.10.25
Creativity You Can Use: CJEU Clarifies Copyright for Applied Art
Client Alert | 4 min read | 12.10.25
Federal Court Strikes Down Interior Order Suspending Wind Energy Development

