News

News

Mangano, Zibas and Rolland Prevail in Significant Privacy Litigation Matter

Shawn Mangano (Of Counsel-Las Vegas, NV), Jura Zibas (Partner-New York, NY and Sarasota, FL) and Sean Rolland (Of Counsel-Orlando, FL) successfully defended a hybrid managed services provider in litigation before the U.S. District Court for the District of Nevada.

Plaintiffs’ claims involved the unauthorized access and alleged dissemination of personally identifiable information (“PII”) related to potentially over 600,000 potential data breach claimants that received services for a health provider with which Wilson Elser’s client was providing data storage and security services. The data breach at issue involved sophisticated Russian cybercriminals who allegedly gained access to another party’s protected data through cyber-spoofing, resulting in access to the provider’s information containing Plaintiffs’ PII. Plaintiffs filed a complaint for damages seeking recovery for negligence/negligence per se, breach of third-party beneficiary contract, invasion of privacy or intrusion upon seclusion, and unjust enrichment.

On August 18, 2026, our client received a report and recommendation recommending its motion to dismiss be granted on several key damage recovery issues that have not otherwise been confirmed in data breach actions filed in the jurisdiction.

These recommendations include the requirement that, for a negligence per se claim, a plaintiff must allege that his or her PPI was subject to an increased risk of fraud, identity theft, or nefarious misuse. Likewise, for a plaintiff seeking to recover for “lost time” under a negligence/negligence per se claim, recovery must be tied to out-of-pocket expenses for said lost time. Finally, a plaintiff’s claims of increased anxiety and emotional distress must assert the existence of a physical injury or illness to warrant recovery of damages for the unauthorized disclosure of his or her PII.

Regarding breach of third-party beneficiary contract, the Court concluded that mere allegations that “Defendant entered into contracts to provide IT services” were insufficient to establish data protection obligations on our client.

Finally, the Court determined that to recover for invasion of privacy/inclusion upon seclusion for the data breach, a Plaintiff must be under “highly offensive” circumstances. In this case, those “highly offensive” circumstances were determined to be possession of PII by a notorious cybercriminal gang, of which at least one Plaintiff had failed to assert.

Overall, this result serves to delineate the allegations necessary for Plaintiffs to survive a motion to dismiss in cyber breach cases in the District of Nevada, despite multiple other decisions that essentially rubberstamped allegations. 

Shawn A. Mangano, Jura Christine Zibas and Sean Rolland