Texas Case Summaries
Federal Enforcement »

Gulshan Management Services Data Breach — Court partially denies motion to dismiss, allowing negligence claims to proceed

Reported / Citable

Case
In Re Gulshan Management Services Data Breach Litigation
Court
U.S. District Court, Southern District of Texas (Houston Division)
Judge
Nathan Ochsner, Clerk (Judges of the U.S. District Court, Southern District of Texas, 2021)
Date Decided
June 29, 2026
Docket No.
4:26-cv-00200
Topics
Data breach liability; Negligence; Cybersecurity; Consumer protection
Source
Read the full opinion

Background

Gulshan Management Services, Inc., which operates gas stations, restaurants, and IT/point-of-sale systems for convenience store chains, suffered a September 2025 data breach. Hackers accessed Gulshan’s systems through a successful phishing attack and deployed malicious software, compromising personally identifiable information—including Social Security numbers, driver’s license numbers, financial account information, and credit card data—of more than 377,000 customers and employees. The plaintiffs alleged that their stolen data was posted to the dark web, criminals attempted unauthorized account access, and they experienced increased spam communications.

Consolidated plaintiffs filed a class action alleging that Gulshan failed to implement reasonable security measures such as data encryption, anti-phishing training programs, spam filtering, email scanning, and anti-malware software. The complaint asserted claims for negligence, breach of implied contract, unjust enrichment, and violation of the Illinois Consumer Fraud and Deceptive Business Practices Act. Gulshan moved to dismiss all claims.

The Court’s Holding

The court granted in part and denied in part Gulshan’s motion to dismiss. On the negligence claim, the court held that Gulshan owes a legal duty to protect personal information it collects and maintains. The court recognized that under Texas law and the Restatement (Third) of Torts, an entity that affirmatively collects sensitive personal information and fails to exercise reasonable care to prevent third-party access may be liable, even when a criminal act intervenes. The plaintiffs adequately pleaded breach by identifying specific industry-standard security measures that Gulshan failed to implement, such as encryption. The court further held that foreseeability of a cyberhack was adequately alleged: cyberattacks are increasing, widespread, and highly publicized; Gulshan stored large volumes of personally identifiable information making it a likely target; and industry data supports that data breaches are foreseeable consequences of inadequate security measures.

The court denied in part Gulshan’s argument that intervening criminal acts break the causation chain. Under Texas law, a third party’s illegal conduct does not negate proximate causation when that conduct is foreseeable. The court rejected Gulshan’s contention that foreseeability must be “specific” to the defendant, holding that industry-wide patterns and statistics can establish foreseeability at the pleading stage. The court allowed the negligence claims to proceed but deferred resolution of whether the economic-loss doctrine bars recovery, requesting more detailed briefing on this issue.

On the implied breach-of-contract claim, the court granted dismissal with prejudice. Because the plaintiffs had express contracts with Gulshan (customer policies or employment agreements), an implied contract could not exist on the same subject matter. Providing sensitive data under an express contract does not create a separate implied duty to protect that data.

Key Takeaways

  • Companies that collect personal information owe a common-law duty to protect it through reasonable security measures; such a duty arises both from tort law and from Texas’s statutory requirement of “reasonable procedures” to protect sensitive data.
  • At the motion-to-dismiss stage, plaintiffs can satisfy the plausibility requirement for negligence by identifying specific, industry-standard security measures that a defendant failed to implement and explaining how those measures relate to the manner of breach.
  • Cyberhacks are foreseeable as a matter of law when industry statistics, widespread publicity, and the defendant’s knowledge of cyber risks are alleged; foreseeability is not limited to defendant-specific prior incidents and can be established through industry-wide crime trends.
  • An implied contract claim fails when the subject matter is covered by an express contract between the same parties.

Why It Matters

This decision significantly strengthens data-breach litigation against companies that store personal information. By holding that cyberhacks are foreseeable based on industry trends rather than requiring proof of attacks specific to the defendant, the court makes it substantially easier for plaintiffs to survive motions to dismiss on causation grounds. The ruling establishes that businesses cannot hide behind the intervention of third-party criminals when they have failed to implement standard protective measures that the cybersecurity industry recommends. For companies collecting consumer or employee data, the decision signals that reasonable data security is not aspirational but legally mandated.

The court’s framework also leaves open the question of whether plaintiffs can recover purely economic losses (such as credit monitoring costs, diminished value of personal information, and risk of future identity theft) from data breaches, indicating that appellate courts may ultimately need to address whether the economic-loss rule applies to cybersecurity failures. This unresolved issue is critical to class-action settlements and damages calculations in data-breach litigation.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top