← All Articles

Joshua Randolph v. Eisen. Claims Eisen Failed to Safeguard Data, Leading to Breach Affecting Over 100 Class Members

Joshua Randolph has initiated a class action lawsuit against Eisen, Inc., alleging that the company failed to secure private information, leading to a significant data breach. Filed on June 30, 2026, in the United States District Court, the complaint claims that the breach occurred on December 12, 2025, compromising sensitive personal details including Social Security numbers and financial information. Despite recognizing the risks of data breaches, Eisen allegedly neglected to implement necessary security measures, resulting in this incident.

The complaint outlines claims for negligence, invasion of privacy, breach of third-party beneficiary contract, unjust enrichment, and a demand for declaratory judgment. Among the allegations, Randolph contends that Eisen violated its obligation under the Federal Trade Commission Act by not maintaining adequate data security, constituting an "unfair practice" as defined by Section 5 of the FTCA (Compl. ¶46). Additionally, Eisen is alleged to have breached its duty to safeguard private information and was negligent or reckless in failing to protect data (Compl. ¶60-62). The filing suggests Eisen's failure to promptly inform affected individuals and adequately safeguard the data further exacerbates the damage caused.

The proposed class, consisting of over 100 members, seeks various forms of relief aimed at addressing the consequences of Eisen's alleged security lapses. These include compensatory damages, restitution, disgorgement, the certification of a constructive trust, and equitable measures such as enhanced data security protocols and long-term credit monitoring for those affected. The alleged amount in controversy exceeds $5 million (Compl. ¶19). Eisen's alleged inadequate response and lack of security measures are yet to be proven, and no response has been filed by Eisen as of the complaint's filing date.

Alleged Data Breach Mechanism and Failure

According to the filing, unauthorized access to Eisen, Inc.'s systems occurred on December 12, 2025, resulting in a data breach that compromised sensitive information including Social Security numbers, dates of birth, and financial details of class members. Specifically, plaintiff Joshua Randolph's compromised data included his name, Social Security number, date of birth, and unclaimed property balance (Compl. ¶91). Eisen is accused of having neglected to incorporate basic cybersecurity measures necessary to protect such information.

Joshua Randolph, the plaintiff, contends that Eisen's notification to affected individuals was unreasonably delayed. The company reportedly waited over five months before informing the public and those impacted by the data breach. Furthermore, the notification provided lacked essential information, failing to disclose the root cause of the breach, the specific vulnerabilities that were exploited, and the measures taken to address these issues and prevent future incidents.

These alleged failures form the crux of the complaint, suggesting that Eisen not only failed to prevent the breach but also continued to inadequately respond post-breach, thereby exacerbating the potential harm to individuals whose data was compromised.

Monetary Implications

The complaint filed in Joshua Randolph v. Eisen, Inc. contends that the data breach involving Eisen, Inc., a financial services provider, has substantial monetary implications. The alleged breach has placed more than $5 million at issue, which the suit claims is the amount in controversy (Compl. ¶19). This figure serves as an indicator of the potential financial burden and fallout from the incident, as well as the losses faced by the affected individuals.

Additionally, the complaint underscores the broader context of increasing data vulnerabilities, noting a significant rise in data breaches over the past years. Specifically, the filing points to a 72% increase in publicly reported data compromises in 2023 compared to the previous high set in earlier years, as well as a 78% rise over the figures from 2022 (Compl. ¶39). Furthermore, 29% of data breaches in 2023 resulted from a third-party attack vector (Compl. ¶40). These statistics highlight the escalating risks that financial institutions face regarding data security and the corresponding financial implications.

Randolph's complaint alleges that such increases in data breaches reflect a systemic failure on the part of organizations like Eisen to adopt more robust security measures. The complaint argues that the inadequacy of conventional security systems is costing significant amounts both in potential damages sought through litigation and in the direct losses suffered by individuals whose data is compromised. Notably, 29% of victims experience financial losses exceeding $10,000 (Compl. ¶86).

Total potential damages, including actual, statutory, and consequential damages, as well as requests for restitution and disgorgement, form part of the relief sought by the plaintiffs. Such financial claims aim to address not just immediate losses, but also the long-term economic impacts and risks, including potential identity theft and fraud faced by the class members.

These allegations remain unproven in court, and Eisen, Inc. has not yet filed a response to the complaint. The financial implications discussed in Randolph's case form part of broader concerns about the costs associated with data breaches in the digital age.

Parties and Their Roles

The class action complaint, filed in the United States District Court, names Joshua Randolph as the plaintiff, representing himself individually and on behalf of a proposed class of similarly situated individuals. Randolph contends that Eisen, Inc., the defendant, failed in its duty to secure private information, resulting in a data breach.

Randolph claims that Eisen, Inc., a financial services company engaged in providing AI-enabled regulatory technology, did not adhere to proper data protection protocols. This purported failure forms the basis of the allegations made against the company, central to the case's negligence and privacy-related claims.

The complaint also involves unnamed class members, who are part of the proposed class affected by the data breach. These individuals allegedly had their personal information compromised due to Eisen's security failures, and the complaint seeks to include them in the litigation to pursue collective remedies.

Various non-party organizations are referenced concerning standards in the complaint. The Federal Trade Commission (FTC) is cited, particularly regarding its guidelines on data security practices, underlining the obligations Eisen purportedly did not meet. Similarly, the Center for Internet Security (CIS), the National Institute of Standards and Technology (NIST), and the Cybersecurity and Infrastructure Security Agency (CISA) are mentioned for their respective roles in setting industry standards which the complaint argues Eisen neglected to follow.

Negligence and Related Claims

The class action complaint filed by Joshua Randolph against Eisen, Inc. initiates its legal arguments with a negligence claim, alleging that Eisen failed to protect the private information of Randolph and the proposed class members. According to the complaint, Eisen owed a duty to exercise reasonable care in safeguarding sensitive information, but instead negligently failed to maintain adequate data security systems. This negligence purportedly resulted in the unauthorized access and exfiltration of private data including Social Security numbers and dates of birth (Compl. ¶60-61).

In addition to the negligence claim, the complaint advances a claim of negligence per se under Section 5 of the Federal Trade Commission Act (FTCA), 15 U.S.C. § 45. This charge centers on Eisen's alleged failure to implement basic data protection measures considered as an unfair practice under the FTCA (Compl. ¶46). The complaint argues that Eisen's practices contravened known industry standards for data security.

Further expanding on the allegations, the complaint includes a claim for invasion of privacy grounded in the assertion that Eisen's security inadequacies led to the unauthorized disclosure of personal information. The breach of privacy claim underscores Eisen's purported failure to secure sensitive data, which the complaint characterizes as both unauthorized and offensive.

These claims seek various forms of redress, including damages for the increased risk of identity theft, emotional distress, and the diminished value of compromised information. As the complaint outlines, the alleged mishandling and disclosure of private data form the crux of these legal claims, which together aim to hold Eisen accountable under negligence and statutory frameworks. Eisen's failure to use reasonable measures breached its duty to safeguard private information (Compl. ¶136).

To date, the allegations remain unproven, and no defendants have yet responded in court filings.

Contractual and Unjust Claims

The complaint in Randolph v. Eisen, Inc. includes allegations of a breach of a third-party beneficiary contract, claiming that Eisen, Inc. failed to fulfill promises regarding the security of private information (Compl. ¶24). The complaint states that Eisen had committed to keeping private information secure, adhering to industry standards, and notifying clients promptly in the event of data breaches. However, the plaintiff contends that the unauthorized access to Eisen’s systems, which allegedly compromised sensitive consumer data, demonstrates a failure to meet these contractual obligations. The breach of these promises forms the basis for this contractual claim, as Eisen is alleged to have stored all class members’ data on systems that were unlawfully accessed (Compl. ¶127).

Additionally, the plaintiff asserts a claim of unjust enrichment against Eisen. According to the complaint, Eisen retained payments intended for cybersecurity measures yet failed to provide adequate protection for the private information of class members. This failure purportedly allowed Eisen to benefit financially without delivering the necessary improvements on its data security infrastructure. The class action seeks to recover these funds on the grounds that class members effectively overpaid for services that fell short of the security standards promised (Compl. ¶181).

The filed claims seek various forms of relief, including restitution and disgorgement, to address the alleged retention of funds by Eisen that were meant for cybersecurity but were not utilized for their intended purpose. The complaint also seeks certification of a constructive trust. These contractual and unjust enrichment claims underscore the central argument that Eisen did not uphold its commitments to protect sensitive information, thereby financially benefiting at the expense of data security.

The allegations outlined in the complaint remain unproven at this stage, and no response from the defendants has been filed in the docket as yet.

Other Specific Allegations

The complaint alleges that Eisen, Inc.'s data security practices violated Section 5 of the Federal Trade Commission Act (FTCA), 15 U.S.C. § 45. This provision prohibits unfair or deceptive trade practices, and the plaintiff claims that Eisen's inadequate data security measures constitute such an unfair trade practice under the Act (Compl. ¶46, ¶51, ¶53). According to the complaint, Eisen failed to maintain reasonable data security, thereby exposing sensitive personal information to unauthorized access and exploitation.

Furthermore, the plaintiff asserts that Eisen breached its duty to safeguard private information. The complaint notes that Eisen's negligence and recklessness in data protection led to the unauthorized access and exfiltration of private information on December 12, 2025 (Compl. ¶61-62). It is alleged that Eisen did not implement adequate cybersecurity measures despite being aware of the risks and obligations to protect such data, resulting in significant exposure of sensitive information.

These allegations suggest a pattern of insufficient attention to data security, reinforcing claims that Eisen's practices do not meet the standard of care required by the FTCA and industry guidelines. The plaintiff seeks to hold Eisen accountable for these purported failings through legal remedies including compensatory and statutory damages, as well as injunctive relief to improve Eisen's data security protocols.

These outlined allegations form part of the broader legal framework claimed in this class action, as they underscore both specific statutory violations and the broader negligence in corporate obligations to protect consumers' private information.

Relief Sought and Procedural Posture

In the lawsuit Joshua Randolph v. Eisen, Inc., the plaintiff seeks a range of remedies, including compensatory, actual, statutory, and consequential damages. These forms of relief are intended to address the impacts of the alleged data breach on the affected class members. The complaint further requests equitable relief to compel Eisen, Inc. to enhance its data security systems significantly, offer lifetime credit monitoring, and provide identity theft insurance to mitigate ongoing risks of fraud and identity theft that the affected individuals may face as a result of the breach.

Additionally, the plaintiff is pursuing the certification of nationwide and California-specific subclasses, arguing that the scope and scale of the breach justify such a classification under Federal Rule of Civil Procedure 23. This procedural step is critical for managing the case as a class action, allowing a collective resolution of claims related to the data breach.

The complaint highlights the economic significance of consumer data, noting the data brokering industry was estimated to be worth $200 billion in 2019. It asserts that compensating consumers for sharing web browsing history could cost up to $50 per year (Compl. ¶113).

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

1 UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF NEW YORK JOSHUA RANDOLPH, on behalf of himself and all others similarly situated, Plaintiff, v. EISEN, INC., Defendant. Case No. JURY TRIAL DEMANDED CLASS ACTION COMPLAINT Plaintiff Joshua Randolph (“Plaintiff”), individually and on behalf of all similarly situated persons, alleges the following against Eisen, Inc. (“Eisen” or “Defendant”) based upon personal knowledge with respect to himself and on information and belief derived from, among other things, investigation by Plaintiff’s counsel and review of public documents as to all other matters: I. INTRODUCTION 1. Plaintiff brings this class action against Eisen for its failure to properly secure and safeguard Plaintiff’s and other similarly situated persons’ names, addresses, email addresses, Social Security numbers, dates of birth, and information about their unclaimed property balances (the “Private Information”) from hackers. 2. Eisen, based in New York, is a financial services company that provides AI-enabled regulatory technology and compliance operations for financial institutions.

2 3. On or about June 24, 2026, Eisen filed official notice of a hacking incident with the Office of the California Attorney General. 1 4. On or about the same time, Eisen also sent out data breach letters (the “Notice”) to individuals whose information was compromised as a result of the hacking incident. 5. Based on Eisen’s Notice, on or about December 12, 2025, a threat actor impersonated the California State Controller’s Office and requested a file containing unclaimed property compliance records. Believing the request to be legitimate, an employee provided access to the file and the unauthorized actor copied and exfiltrated certain files containing Plaintiff’s and “Class Members’” (defined below) Private Information (the “Data Breach”). Shortly after, the company identified the fraudulent activity and conduct

Questions about this topic: david@newmanbrunk.com

Practice areas