Judge Rejects Salesforce's Attempt to Dismiss Data Breach Lawsuit, Case Moves to Discovery Phase

September 15, 2026
Judge Rejects Salesforce's Attempt to Dismiss Data Breach Lawsuit, Case Moves to Discovery Phase
  • The ruling moves the case toward discovery and preserves the possibility of ongoing scrutiny of Salesforce’s data security practices.

  • Upcoming proceedings are expected to focus on the adequacy of Salesforce’s security protocols, the breach’s scope, and potential damages or remedies for the plaintiffs.

  • The suit names 18 Salesforce clients affected by the breach, though specific client names are not disclosed in the available materials.

  • A federal judge in the Northern District of California largely denied Salesforce’s motion to dismiss a proposed class action over a 2025 data breach, allowing most claims to proceed and accusing Salesforce of security weaknesses that enabled hackers to access personal information of customers and employees linked to Allianz, Farmers Group, and TransUnion.

  • Plaintiffs allege systemic security flaws in Salesforce’s cloud infrastructure that allowed unauthorized access, and they seek to represent a class of affected customers and employees.

  • The court ruled that Salesforce must face most claims, enabling discovery and extended litigation into the company’s security practices.

  • The court accepted the plaintiffs’ allegation that they have standing in federal court, finding injury in fact from the breach.

  • The judge found the plaintiffs adequately pleaded negligence and violations of several state consumer protection and privacy laws, including the California Consumer Privacy Act, the Illinois Consumer Fraud Act, and the Washington Consumer Protection Act.

  • At issue is the data breach that exposed sensitive information of individuals connected to the clients, underscoring alleged failures in Salesforce’s security controls.

Summary based on 2 sources


Get a daily email with more Tech stories

More Stories