Court Dismissed Privacy Suit Against Edw. C. Levy Co.

A federal court ruled that the plaintiff lacked standing to sue over the risk of future data misuse.

Updated on Oct. 4, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a single steel gear on a concrete block, representing a data security legal ruling.
A federal judge dismissed a class-action lawsuit against Edw. C. Levy Co. on Tuesday, ruling that the plaintiff failed to demonstrate actual injury following the 2023 ransomware attack. AI Illustration. Upload story photo >

Live Poll

Should victims be able to sue companies for potential future risks following a data breach?

A federal court has dismissed a class action lawsuit filed by Michael Malone against Edw. C. Levy Co. following a 2023 ransomware attack. The judge ruled that the plaintiff failed to state a claim under Michigan law and lacked standing for prospective injury.

Why it matters

The ruling clarifies that Michigan negligence law requires a concrete, cognizable injury rather than just the risk of future identity theft. This decision sets a precedent for how data breach litigation is evaluated in the state.

The court evaluated the complaint under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6), ultimately finding that the plaintiff failed to state a claim under Michigan law. The six asserted claims included negligence, breach of implied contract, and invasion of privacy.

The players

Edw. C. Levy Co.

A company specializing in industrial services and material processing that operates a computer network storing employee data.

Michael Malone

The plaintiff who sought class action status after his personal information was exposed in a network security incident.

The details

The court determined that for negligence claims, Michigan law requires evidence of actual injury rather than the mere threat of future data misuse. In November 2023, Edw. C. Levy Co. suffered a ransomware attack—malicious software that encrypts files and demands payment—which exposed employee personally identifiable information (PII). Because the plaintiff, who provided his Social Security number as a condition of employment, could not demonstrate a current injury, the court ruled he lacked standing.

Timeline

  1. November 2023: A ransomware attack hit the Edw. C. Levy Co. network.

  2. April 16, 2025: The plaintiff filed the initial class action lawsuit.

  3. October 4, 2026: The court granted the motion to dismiss the complaint.

The Tech Race

This ruling follows established federal precedents regarding Article III standing, which strictly limit plaintiffs to cases where a concrete, realized injury has occurred. It underscores the high evidentiary burden for employees seeking damages based on the potential future misuse of their PII.

This outcome limits the ability of employees in Michigan to recover damages for data breaches unless they can prove specific, tangible harm has already resulted from the exposure. Residents should continue to monitor their credit reports if their employer experiences a security incident, as legal recourse remains tied to demonstrable financial loss.

The takeaway

The court has set a clear boundary: potential risk is not enough for a negligence claim under Michigan law. Observers should track if this ruling influences future filings in the state or leads to legislative efforts to redefine standing for data breach victims.

Further reading

For more on how state and federal courts are handling data breach claims, visit Cybersecurity.

Source note: This article includes information reported by Michigan Lawyers Weekly.

Live Poll

Should victims be able to sue companies for potential future risks following a data breach?