Purifoy v. Peachtree Group challenges hotel chain's data security practices under FTC Act in class action suit.
Micha Purifoy has filed a class action lawsuit against Peachtree Hotel Group II, LLC, operating as Peachtree Group, in the United States District Court for the Northern District of Georgia. The complaint, submitted on May 5, 2026, alleges that Peachtree Group's inadequate data security measures led to a significant breach of sensitive consumer information, in violation of federal statutes including Section 5 of the FTC Act, 15 U.S.C. § 45.
The legal filing contends that the data breach exposed personal information of potentially thousands of consumers, posing risks to their privacy and financial security. This action underscores ongoing concerns about corporate responsibility and data management practices in an era of increasing digital vulnerabilities.
According to the complaint, Peachtree Group failed to implement adequate safeguards to protect its customers' personal data, leading to unauthorized access by third parties. The breach allegedly occurred over a period before it was discovered, significantly impacting the security of consumer data. Purifoy claims that despite the growing prevalence of data breaches, Peachtree Group did not take necessary preventive steps or respond appropriately to unauthorized intrusions.
The complaint details how affected individuals, including Purifoy, were left vulnerable to identity theft and other fraudulent activities due to the compromised personal information. It alleges that Peachtree Group’s negligence in managing sensitive data directly resulted in this breach, highlighting a pattern of insufficient security protocols in place at the hospitality giant.
Plaintiff Purifoy brings forth claims under Section 5 of the FTC Act for unfair practices, citing the company's failure to secure consumer data as deceptive and unfair. Purifoy asserts that Peachtree Group’s inadequate data security is a violation because it failed to protect consumer information effectively, which directly affected commerce.
Additionally, the lawsuit leverages 28 U.S.C. § 1332(d)(2), arguing the federal court’s jurisdiction given the class action status and the diversity of citizenship between the parties involved. Purifoy relies on these legal frameworks to argue the Peachtree Group failed in their duty to protect consumer data under existing regulations.
The lawsuit seeks substantial damages exceeding million, as well as injunctive relief to compel Peachtree Group to overhaul their data security measures. The case may set a significant precedent for how companies address data security under federal consumer protection laws. By highlighting these gaps in Peachtree Group’s policies, the court's decision could have broad implications for industry standards and the regulatory landscape associated with data protection.
This case also brings into question the responsibilities corporations have under federal law to maintain robust data security practices, potentially influencing legislative and policy shifts aimed at consumer data protection and corporate accountability.
Following the filing, Peachtree Group is expected to be served with the complaint and will likely prepare a response or motion to dismiss. The procedural developments that follow, including possible discovery, motion practice, and potential settlement talks, will unfold as the case progresses in U.S. District Court.
Given the gravity of the allegations and the potential impact on Peachtree Group’s business operations, this case will be closely watched by stakeholders across various industries concerned with data security and privacy.
David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.
From the Complaint Public Court Record
1 UNITED STATES DISTRICT COURT NORTHERN DISTRICT OF GEORGIA ATLANTA DIVISION MICHA PURIFOY, on behalf of herself and others similarly situated, Plaintiff, v. PEACHTREE HOTEL GROUP II, LLC d/b/a PEACHTREE GROUP, Defendant. Case No. DEMAND FOR JURY TRIAL CLASS ACTION COMPLAINT Plaintiff Micha Purifoy (“Plaintiff”), by and through undersigned counsel, on behalf of herself and all others similarly situated (“Class Members”), alleges the following Class Action Complaint (the “Action”) against Defendant Peachtree Hotel Group II, LLC (“Defendant”) upon personal knowledge as to herself and her own actions, and upon information and belief, including the investigation of counsel, as follows: INTRODUCTION 1. This class action arises out of the recent targeted ransomware attack and data breach (“Data Breach”) on Defendant’s network that resulted in unauthorized access to highly sensitive data. As a result of the Data Breach, Class
2 Members suffered ascertainable losses in the form of the benefit of their bargain, out-of-pocket expenses, and the value of their time reasonably incurred to remedy or mitigate the effects of the attack, emotional distress, and the present risk of imminent harm caused by the compromise of their sensitive personal information. 2. Defendant is a Georgia-based investment firm with over $2.4 billion in acquisitions, $10.6 billion in credit/lending transactions, and $2.1 billion in development investments in its portfolio which involves clients and properties located across dozens of states. 1 Defendant also provides investment services, including asset management, construction project management, and hotel management services. 2 3. As such, Defendant stores a litany of highly sensitive information. But Defendant lost control over that data when cybercriminals infiltrated its insufficiently protected computer systems in a data breach. 4. As explained in detail herein, on or around April 30,
Questions about this topic: david@newmanbrunk.com