Case Overview: A federal court has denied bellwether defendants' second attempt to dismiss negligence claims in the MOVEit file-transfer data breach multi-district litigation, allowing cases to proceed under the laws of California, Indiana, Michigan, and Ohio.
Consumers Affected: Individuals whose personal data was exposed through the 2023 MOVEit file-transfer vulnerability
Court: Federal court overseeing the MOVEit MDL
Latest Development: Court rejects defendants' second motion to dismiss negligence claims, rejecting economic-loss rule arguments

Bellwether defendants in the sprawling MOVEit data breach litigation have suffered another significant setback, as a federal court rejected their second bid to have negligence claims thrown out. According to reporting from Databreaches.net, the court declined to dismiss negligence claims brought under the laws of California, Indiana, Michigan, and Ohio — a development that keeps substantial portions of the litigation alive and moving forward.
The defendants — Progress Software and several of its corporate customers — had argued that the negligence claims were barred under the economic-loss rule, a legal doctrine that generally limits plaintiffs' ability to recover purely financial damages through tort claims. The court was not persuaded.
The litigation stems from a 2023 cyberattack that exploited a critical vulnerability in Progress Software's MOVEit Transfer application, a widely used managed file-transfer tool. The attack, attributed to the Cl0p ransomware group, affected hundreds of organizations that relied on the software to securely move sensitive data — and, by extension, exposed the personal information of millions of individuals across multiple industries.
Because so many companies and their customers were affected, cases were consolidated into multi-district litigation (MDL), a procedural mechanism that coordinates similar federal lawsuits before a single judge to promote efficiency. Bellwether cases — a smaller set of representative claims selected to be litigated first — are being used to help both sides gauge the strength of the broader litigation and potentially guide settlement discussions.
Defendants mounted two arguments in their second motion to dismiss. First, they contended that the economic-loss rule shielded them from negligence liability because the plaintiffs' alleged harms were financial rather than physical in nature. Second, they applied this argument across the specific legal standards of four states — California, Indiana, Michigan, and Ohio — where the bellwether claims are rooted.
The court rejected those arguments and allowed the negligence claims to proceed. The ruling marks the second time defendants have been unable to convince the court to dispose of negligence theories at the pleading stage, indicating that plaintiffs have adequately alleged the elements necessary to move their claims forward.
For the millions of individuals whose data may have been exposed in the MOVEit breach, the ruling means litigation continues to progress rather than being cut short before the parties can fully develop the record. Surviving a second motion to dismiss suggests that plaintiffs' negligence theories have demonstrated enough legal viability to withstand early challenges — though significant litigation hurdles, including potential summary judgment motions and trial, remain ahead.
The outcome of the bellwether cases, once they are tried or resolved, could substantially influence how the remaining cases in the MDL are handled and whether broader settlement negotiations accelerate.
With the motion to dismiss denied, the bellwether cases are expected to continue toward discovery and, potentially, trial. The parties will likely turn their attention to developing the factual record — including questions about what security measures Progress Software and its customers had in place, when they became aware of the vulnerability, and what steps were taken in response.
Progress Software has previously faced scrutiny over how quickly it disclosed and patched the vulnerability after it became known. How the litigation addresses those questions in the bellwether phase could shape the broader MDL's trajectory.
Lawsuit: In re: MOVEit Customer Data Security Breach Litigation
Case Number: Not specified in available reporting
Court: Federal court (MDL)
MDL Number: Not specified in available reporting
Status: Negligence claims survive second motion to dismiss; bellwether cases proceeding
Were you notified that your personal information may have been compromised in the MOVEit data breach? You may be eligible to participate in the ongoing litigation — check eligibility below.
Loading...
Injury Claims keeps you informed about lawsuits large and small that could affect your daily life. We simplify the complexities of Class Action Lawsuit, open Class Action Lawsuit settlements, mass torts, and individual cases to ensure you understand how these legal matters could impact your rights and interests.
If you think a recent legal case might affect you, action is required. Select a Class Action Lawsuit or Class Action Lawsuit settlement, share your details, and connect with a qualified attorney who will explain your legal options and assist in pursuing any compensation due. Take the first step now to secure your rights.