MOVEit Breach Defendants Fail in Second Attempt to Dismiss Negligence Claims

Case Overview: A federal court has denied bellwether defendants' second attempt to dismiss negligence claims in the MOVEit file-transfer data breach multi-district litigation, allowing cases to proceed under the laws of California, Indiana, Michigan, and Ohio.

Consumers Affected: Individuals whose personal data was exposed through the 2023 MOVEit file-transfer vulnerability

Court: Federal court overseeing the MOVEit MDL

Latest Development: Court rejects defendants' second motion to dismiss negligence claims, rejecting economic-loss rule arguments

MOVEit Breach Defendants Fail in Second Attempt to Dismiss Negligence Claims

A federal court denied bellwether defendants' second motion to dismiss negligence claims in the MOVEit data breach MDL, keeping cases alive in four states.

MOVEit Breach Defendants Fail in Second Attempt to Dismiss Negligence Claims

Bellwether defendants in the sprawling MOVEit data breach litigation have suffered another significant setback, as a federal court rejected their second bid to have negligence claims thrown out. According to reporting from Databreaches.net, the court declined to dismiss negligence claims brought under the laws of California, Indiana, Michigan, and Ohio — a development that keeps substantial portions of the litigation alive and moving forward.

The defendants — Progress Software and several of its corporate customers — had argued that the negligence claims were barred under the economic-loss rule, a legal doctrine that generally limits plaintiffs' ability to recover purely financial damages through tort claims. The court was not persuaded.

Background: The MOVEit Breach

The litigation stems from a 2023 cyberattack that exploited a critical vulnerability in Progress Software's MOVEit Transfer application, a widely used managed file-transfer tool. The attack, attributed to the Cl0p ransomware group, affected hundreds of organizations that relied on the software to securely move sensitive data — and, by extension, exposed the personal information of millions of individuals across multiple industries.

Because so many companies and their customers were affected, cases were consolidated into multi-district litigation (MDL), a procedural mechanism that coordinates similar federal lawsuits before a single judge to promote efficiency. Bellwether cases — a smaller set of representative claims selected to be litigated first — are being used to help both sides gauge the strength of the broader litigation and potentially guide settlement discussions.

What the Court Decided

Defendants mounted two arguments in their second motion to dismiss. First, they contended that the economic-loss rule shielded them from negligence liability because the plaintiffs' alleged harms were financial rather than physical in nature. Second, they applied this argument across the specific legal standards of four states — California, Indiana, Michigan, and Ohio — where the bellwether claims are rooted.

The court rejected those arguments and allowed the negligence claims to proceed. The ruling marks the second time defendants have been unable to convince the court to dispose of negligence theories at the pleading stage, indicating that plaintiffs have adequately alleged the elements necessary to move their claims forward.

What This Means for Plaintiffs

For the millions of individuals whose data may have been exposed in the MOVEit breach, the ruling means litigation continues to progress rather than being cut short before the parties can fully develop the record. Surviving a second motion to dismiss suggests that plaintiffs' negligence theories have demonstrated enough legal viability to withstand early challenges — though significant litigation hurdles, including potential summary judgment motions and trial, remain ahead.

The outcome of the bellwether cases, once they are tried or resolved, could substantially influence how the remaining cases in the MDL are handled and whether broader settlement negotiations accelerate.

What's Next

With the motion to dismiss denied, the bellwether cases are expected to continue toward discovery and, potentially, trial. The parties will likely turn their attention to developing the factual record — including questions about what security measures Progress Software and its customers had in place, when they became aware of the vulnerability, and what steps were taken in response.

Progress Software has previously faced scrutiny over how quickly it disclosed and patched the vulnerability after it became known. How the litigation addresses those questions in the bellwether phase could shape the broader MDL's trajectory.


Lawsuit: In re: MOVEit Customer Data Security Breach Litigation

Case Number: Not specified in available reporting

Court: Federal court (MDL)

MDL Number: Not specified in available reporting

Status: Negligence claims survive second motion to dismiss; bellwether cases proceeding


Were you notified that your personal information may have been compromised in the MOVEit data breach? You may be eligible to participate in the ongoing litigation — check eligibility below.

Latest News

Loading...

Illustration of a mobile device getting an email notification