Class-action suit filed over Zappos computer data leak
Zappos CEO Tony Hsieh responds to questions from the media on Monday, January 16, 2012, one day after the online retailer’s website was hacked. The cyber-attack did not compromise Zappo’s credit card database, but the hacker may have accessed users’ personal data such as name, address, billing and shipping addresses, phone numbers, the last four digits of their credit card numbers and online passwords.
Wednesday
18 January 2012
9:34 a.m.
An attorney wasted little time this week in suing Amazon.com and its Zappos.com subsidiary over a data breach potentially affecting some 24 million Zappos.com customers.
Attorney Mark Gray filed suit Monday in Louisville, Ky., federal court in that city on behalf of Zappos customer Theresa D. Stevens, of Beaumont, Texas.
The suit is proposed to be a class action representing all affected Zappos customers.
"This is a consumer class-action lawsuit brought by plaintiff, individually and on behalf of over 24 million similarly-situated persons whose Zappos.com personal customer account information including names, account numbers, passwords, email addresses, billing and shipping addresses, phone numbers and the last four digits of credit cards used to make purchases was stolen by hackers who gained access to Zappos.com’s internal network through the company’s unprotected servers located in western Kentucky," the suit says.
Gray, of Louisville, contended in the suit that Amazon and Zappos violated the federal Fair Credit Reporting Act by failing to protect customers’ personal account information and that the companies' customers suffered an "invasion of privacy by the public disclosure of private facts."
The suit seeks damages that are unspecified but are more than $5 million. They include actual and statutory damages, mental anguish damages and exemplary damages "as punishment and to deter such wrongful conduct in the future."
Zappos CEO Tony Hsieh said in a blog post Sunday that the database that stores customers’ critical credit card and other payment data was not affected by the security breach.
But the lawsuit says customers nevertheless have to worry now about being targeted by identify theft schemes or even "phishing," in which a criminal may pose as being with Zappos, set up a fake Zappos website and try to contact customers to gain their bank account numbers, login information or Social Security numbers.
"Plaintiff and class members were and continue to be damaged in the form of expenses for credit monitoring and identity theft insurance, out-of-pocket expenses, anxiety, emotional distress, loss of privacy and other economic and non-economic harm,” the suit says.
Attorneys for Amazon, based in Seattle, and Zappos, based in Henderson, have not yet answered the lawsuit. A request for comment on the lawsuit was placed with the companies, but company officials couldn't immediately be reached for comment Wednesday.
Share
Join the Discussion:
Previous Discussion:
Discussion 5 comments
Only trusted comments are displayed on this page. Untrusted comments have expired from this story.
Most Popular
- Police: Suspects in fatal robbery targeted, stalked teen with iPad
- Coroner: Woman killed in apparent murder-suicide was shot, stabbed, beaten
- Witnesses offer ‘sketchy stories’ about Henderson brush fire, official says
- Coroner ID’s 3 people killed in wrong-way freeway crash
- Police release images of suspect sought in home invasion



That did not take long. There is always an attorney around when they smell money. 1000's of servers are hacked everyday, Zappo's did not leave the door open, someone broke in.
The new American way, don't work for what you want, find a reason to sue someone!
Wonder why this country is crashing, look at what has become of Americans.
Ambulance chasing at its finest.
Lawyers sniff money like a mouse to cheese. So is this lawyer going to hire computer experts to determine that Zappos security measures were inadequate? No. Did this client suffer a monetary damage yet? The lawyer has no clue nor does he care.
He's looking for a settlement, he runs off with his 1/3 take and the world goes round. The more and more you see how people run their lives...don't care about right or wrong, as long as they can make their Lexus payment.
I hope they fight this and crush that dirtbag lawyer.
Here are the results of my quick Theresa D Stevens internet search:
- Address -- available (typical dumpy Beaumont neighborhood)
- Phone Number -- available (area code 409)
- Email address -- available
- Pictures -- available (granted she could use a makeover)
- Names/Pictures of Relatives -- wow 800 Facebook "Friends"
- Age/Birth date -- available (196x)
- For $40 dollars, I can learn the ply count on her toilet paper.
If Theresa is concerned about privacy, it certainly is not demonstrated on the internet.
Another bottom feeding shyster lawyer looking for a big payday.
Mr. Jackson.
I spent 15 years on network security before selling my company to a nationwide company and retiring so yes, I do believe I know much more about this then you ever will.
Think before you post is something to consider.
MSNBC, Facebook and other large companies were hacked in 2011. Hackers go where the money and publicity are, Mr. Jackson. Count your blessings!!!!
Mr. Jackson, count your blessings!!!
Facebook, Capital One, JPMorgan, Brookstone, BestBuy, TiVo, Walgreens and Krogers have all been hacked. How many of you criticized and/or stopped patronizing thsese places?
"Think before you post. I know it's hard, but try."
brought to you by the same genius that gave us this gem on a Rebel article after the SDSU loss.
"Let the freefall begin. I will go out on a limb and predict that in 30 days from now, UNLV will be unranked and we won't have to keep reading articles about where a bunch of people THINK they stand."
@geenab65 - As you've mentioned in prior posts, you're a Zappos employee...so you're defense of them is no surprise.
Where are all of the Downtown LV residents & business owners? They're not coming to support their savior Tony Hsieh....which is hilarious. They're willing to take his investment dollars, but abandon him when he needs them most. Not surprising...