The NCBC's FIRST data breach case, and using the UVTA to collect a judgment from a Defendant which is rapidly shedding its assets

Before I get into the guts of this week's edition, I want to say a few words about the website that is associated with this newsletter. It is www.ncbclastmonth.com. When I started this Newsletter in February of this year I didn't think much about the website. But now, I have realized that it is essential to the readers of this Newsletter. Every single edition of this Newsletter, once it is published to you, appears on the website.

I have mentioned before restricting access to the website to paid subscribers to the Newsletter. For now, I have not done that. The website is accessible to anyone with an Internet connection, with no payment or subscription required.. It contains analysis of almost every Opinion and Order of Significance issued by the North Carolina Business Court this year. And it will continue to deliver that coverage so long as I get a critical mass of paid subscribers.

This means that despite the pay wall blocking access to part of this week's edition and previous editions, you can get around that by going to the website. You will be able to continue to avoid payment by doing that that, but you should feel guilty for even doing it now. Please subscribe. I work really hard on this Newsletter and I can't continue giving it away for free. In future weeks, I plan on tightening up on the restriction of the website.

What’s in This Edition

I covered five of the Business Court’s twelve Opinions issued in June 2026 in a recent edition of this Newsletter (June 2026 Opinions Part 1). I covered another five in the last Newsletter: (June 2026 Opinions Part 2). This edition covers the remaining two, plus one of the Orders of Significance of the four handed down that month. Don't think that I missed any of those. Two were Orders on Designation (which you know by now I do not write about), and one I wrote about in the May 2026 Orders of Significance edition.

I am breaking with my own protocol in this edition. Instead of all of the content discussed below being behind a paywall, I include the entirety of my discussion of two of those cases , The first is Dougherty v. Bojangles Rests., Inc., 2026 NCBC 60 (Earp, J.), which I believe is the first Opinion from the Business Court dealing with a data breach case. The next is McCarron v. Howell, 2026 NCBC Order 56 (Davis, J.), In which Judge Davis adds a valuable weapon for a Plaintiff attempting to collect on a judgment while the defendant is dissipating its assets.

  • A Detailed Examination of Multiple Claimed Trade Secrets and a Texas Noncompete (You will have to be a paid subscriber to read this part)

The Claims That Will Survive A Motion To Dismiss In A Data Breach Class Action (And Those That Won’t)

The Opinion in Dougherty v. Bojangles Rests., Inc., 2026 NCBC 60 (Earp, J.) deals with a class action about a data breach. The nine class action representatives say that defendant Bojangles is responsible for the breach of their personal identifying information (PII) and their protected health information (PHI). As far as I know, this is the first time that the Business Court has considered a data breach case.

Facts of the Data Breach

The nine class action Plaintiffs were all former employees of the Defendant Bojangles. Op. ¶6. They had provided their PII and PHI as a condition of their employment. Bojangles uses this information for payroll and other employment-related purposes. Op. ¶7.

The privacy policy set out by Bojangles stated that:

Bojangles has security policies and practices in place designed to protect your Personal Information against unauthorized access or disclosure, theft, misuse, and loss.’ It promises that Bojangles will ‘make commercially reasonable efforts for secure handling of this information[.]

Op. ¶8.

The security of Bojangles’ computer systems was breached for a 22 day period between February 19, 2024 through March 12, 2024. The nine putative class action Plaintiffs contend that over 100 current or former employees of Bojangles had their names, addresses, Social Security numbers, driver's license numbers, government-issued ID numbers, passport numbers, credit card numbers, health insurance information and medical information compromised during this period.

Plaintiffs further allege that the data breach was the work of an entity called Hunters International, which they describe as an "infamous Russian Ransomware-As-A-Service” operator. Op. ¶13.

Hunters International made no secret of its breach. It posted on its “dedicated ‘leak site’ on the dark web ”that it had “exfiltated 294.8 gigabytes of data from Bojangles.” Op. ¶13. Plaintiffs claim that their PII and PHI was included in the breached data. Id.

Plaintiffs say It was difficult to track the stolen data because the modus operandi of Hunters International is to give its affiliates access to its server containing stolen files, which can then be downloaded and stored by the affiliate. Op. ¶14. Hunters international allegedly has hundreds of affiliates, which Plaintiffs claim makes their PII/PHI "available for other cybercriminals to download and use at their discretion.” Op. ¶14.

Further complicating the situation, Plaintiffs allege that Bojangles kept them in the dark until November 19, 2024, when it began notifying them of the data breach. Op. ¶15. The Notice, when it ultimately came, said little more than that Plaintiffs were at a:

‘present, continuing, and significant risk’ of identity theft and recommended that Plaintiffs ‘remain vigilant against incidents of identity theft by reviewing account statements and credit reports for unusual activity and to detect errors.’ It [also] recommended that the Plaintiffs ‘further educate themselves regarding identity theft, fraud alerts, credit freezes, and the steps consumers can take to protect personal information by contacting the consumer reporting bureaus, the Federal Trade Commission [FTC], or their state attorney general.’

Op. ¶16.

The Damages

As far as financial damages, plaintiffs allege that they had suffered loss of the value of their PII/PHI, had spent time and money to mitigate and remediate the effects of the breach and that they had lost the "benefit of the bargain.” Five of the plaintiffs allege that they had experienced an increase in the number of spam and scam phone calls. Those telephone numbers might have been derived from cross-referencing the stolen data and combining it with information about Plaintiffs generally on the Internet. Op. ¶20. One Plaintiff alleged that her debit card had been fraudulently used for an $80 purchase. She believed that this incident was caused by the breach.

As for nonmonetary damages, plaintiffs allege that they had "spent, and will continue to spend, significant time and effort monitoring their accounts to protect themselves from identity theft.” One Plaintiff claimed to have spent over 50 hours "dealing with the consequences of the Data Breach, which includes . . . self-monitoring his accounts.” All of the Plaintiffs anticipated “continuing to spend considerable amounts of time and money to try to mitigate future consequences of the Data Breach.” Op. ¶28

”The following sets out what claims Judge Earp says will survive a Motion to Dismiss and which will not go forward in a data breach class action:

The Claims That will Withstand A Motion to Dismiss:

Negligence

Judge Earp said that”’[t]o state a common law negligence claim, plaintiff must show (1) a legal duty; (2) a breach thereof; and (3) injury proximately caused by the breach.’ Op. ¶ 52(quoting Bridges v. Parrish, 366 N.C. 539, 541 (2013)).

Plaintiffs adequately allege that defendant Bojangles had a legal duty to protect their data. They said also that it was foreseeable that cyber criminals would attempt a future data breach and that they will be successful given Bojangles’ inadequate security measures. They also allege that Bojangles had a duty to notify them of the data breach within a reasonable timeframe.

Judge Earp was not stepping onto untrodden ground on this question. She observed that courts applying the North Carolina law in other data breach cases found that one in possession of another's PII/PHI has a duty of care to safeguard and protect that information. Op. ¶55 (relying on Curry v. Schletter Inc., No. 1:17-cv-0001-MR-DLH, 2018 U.S. Dist. LEXIS 49442, at *9–10 (W.D.N.C. Mar. 26, 2018)).

She also ruled that plaintiffs had satisfied their pleading obligation as to causation. They had alleged that Bojangles' breach of its duty to them had resulted in the data breach that harmed them. Plaintiffs also allege that by failing to provide timely notice of the breach, Bojangles had exacerbated their injuries. They also alleged they suffered damages “as a direct and traceable result of Bojangles’ negligence. Op. ¶56. Whether Bojangles’ breach had caused their injury was “a question of fact for the jury to decide.” Id.

Finally, as to damages, the Court held that “at the pleading stage. . . The plaintiff's allegations of damages “cleared the ‘low bar’ of notice pleading.” Op. ¶58. Those allegations were that Plaintiffs had suffered damages of a ”pain and suffering” nature. Relying on a Court of Appeals decision, Judge Earp rejected the argument that the plaintiffs could not recover general damages for pain and suffering without proof of “severe emotional distress.” Op. ¶59 (citing Iadanza v. Harper, 169 N.C. App. 776, 780 (2005)).

Plaintiffs also alleged that the time and money they had spent mitigating harm and loss of the value of their PII/PHI were recoverable damages. Judge Earp agreed, relying on federal court precedent from a North Carolina federal court and other courts within the Fourth Circuit. Op. ¶61 (citing Capiau v. Ascendum Mach., Inc., No. 3:24-cv-00142-MOC-SCR, 2024 U.S. Dist. LEXIS 142393 (W.D.N.C. Aug. 8, 2024); In re Marriott Int’l, Inc., 440 F. Supp. 3d 447, 494 (D. Md. 2020); Holmes v. Elephant Ins. Co., 156 F.4th 413, 425–26 (4th Cir. 2025)

For all those reasons the negligence claim was allowed to proceed.

Breach of Implied Contract

As to breach of implied contract, Judge Earp held that since plaintiffs had provided to Defendant Bojangles their PII/PHI that this carried with it an obligation on behalf of Bojangles to adequately safeguard that information.. Op. ¶67. Again, she relied on North Carolina federal court precedent for this conclusion. See, e.g., Midkiff v. Shoe Show, Inc., No. 1:24-cv-858, 2026 U.S. Dist. LEXIS 66944 (M.D.N.C. Mar. 30, 2026); and Capiau, supra.

Unjust Enrichment

The Defendant seemed to have a pretty solid argument that the unjust enrichment claim could not stand because the Plaintiffs did not expect to receive a benefit that was specific to the provision of their personal information.

Judge Earp disagreed with that contention. She said that the Plaintiffs had alleged that they "reasonably understood that, in exchange for receiving their PHH/PII that Bojangles “would use adequate cyber security measures to protect” that information. Op. ¶80. That allegation was sufficient to survive the Motion to Dismiss

Unfair and Deceptive Trade Practices

Judge Earp Found that the Plaintiffs had adequately pleaded their claim for unfair and deceptive trade practices.

She rejected the argument that the claim had to meet the pleading particularity requirements of Rule 9(b) because their UDTPA claims were framed as being for fraudulent omissions. Plaintiffs’ counsel had conceded that they were not pursuing a claim for deceptive conduct and that it was limited to alleged unfair conduct. Judge Earp therefore concluded that she did not have to analyze the claim as one for deception. Op. ¶ 88.

She then relied on a Western District Court of North Carolina Ct. decision which had concluded that failure to implement and maintain reasonable data security measures may be unfair conduct that amounts to a violation of the North Carolina UDTPA. Op. ¶89 (citing Capiau, supra, at*37).

Declaratory Judgment Claim

The declaratory judgment claim was based on Bojangles’ continued retention of the Defendants’ PII/PHI. The Plaintiffs sought judgment declaring that Bojangles continued to owe a legal duty to use reasonable data security measures to secure data entrusted to it; to notify impacted individuals of the breach; and be required to implement “adequate security consistent with industry standards” to protect their PII/PHI. Op. ¶91.

Bojangles argued that there was no actual controversy warranting a declaratory judgment.

Judge Earp disagreed. She denied that aspect of the Motion to Dismiss, accepting Plaintiffs argument that because Bojangles still retained their PII/PHI and their belief that it continued to fail to implement “appropriate and adequate security measures” that they had adequately stated a claim for declaratory judgment.

The Ones That Couldn't Withstand A Motion to Dismiss:

Negligence Per Se

Plaintiff voluntarily abandoned their claim for negligence per se, so Judge Earp treated that portion of the motion to dismiss as being uncontested. That claim rested on plaintiff's argument that the negligence per se resulted from Bojangles's violation of its duty under section 5 of the Federal Trade Commission Act and its obligations under HIPAA.

That claim wouldn’t have survived anyway. Judge Earp had previously determined that “neither the FTCA nor HIPAA is a public safety law and therefore neither can form the basis of a negligence per se claim.” Op. ¶41 (citing Weddle v. WakeMed Health, 2023 NCBC LEXIS 162, at *6–7 (N.C. Super. Ct. Dec. 4, 2023))

Invasion of Privacy

The invasion of privacy claim rested upon “intrusion into seclusion”. That is an intentional tort, making Defendant's intent an essential element of the claim. Since the Plaintiffs had voluntarily provided this information to Bojangles there could not be an intrusion into seclusion, and the Plaintiffs could not make out this claim. Op. ¶75.

______________________________________

It is a little surprising to me that Judge Earp delivered this very detailed Opinion without mentioning the North Carolina Identity Theft Protection Act, G.S. §75-65, which seems to cover the field on this type of issue.

How To Collect On A Judgment From A Defendant Which Is Rapidly Dissipating Its Assets

This is based on a true story: you have done a great job for your client. You have obtained a jury verdict against its corporate adversary for hundreds of thousands of dollars. All is good, but the client starts calling you and asking you "where is the money?” And then you learn that corporate Defendant has been administratively dissolved, but is continuing to make payments to the principal of the company, who is using them to pay off a HELOC, pay for a new car, and take his family to Disney World and who knows what else?

These are the basic facts of McCarron v. Howell, 2026 NCBC Order 56 (Davis, J.). Plaintiff McCarron had obtained a judgment of $373,110.99 in another lawsuit against Defendant risk Risk Solutions. That judgment was obtained years ago, on October 31, 2022 The lead Defendant in the case before the court was Defendant Harold Howell, who had been the president of Risk Solutions and was its sole officer and shareholder.

Op. ¶5.

Plaintiff McCarron tried to collect on his Judgment, but had no success. He served two writs of execution in Union County, where the Judgment had been obtained. Both were returned by the Union County Sheriff's Office with nothing after the Sheriff was unable to identify any property which could be seized in satisfaction of the judgment;

Plaintiff served supplemental discovery thereafter. Defendant Risk Solutions responded that it held no accounts, promissory notes, causes of action and that there were no other obligations owed to Risk Solutions. It said it had no property other than paper files, supplies, and all brochures. It said it had no possessions or personal property.

In response to questions about its bank accounts, Risk Solutions identified only two accounts holding a total of approximately $1500. It responded in the negative to any other interrogatories regarding future payments to which it might be due. It also noted its administrative dissolution by the Secretary of State of North Carolina. Order ¶14.

As Judge Davis observed "several of these responses were false at the time they were made.” Order ¶ 15 defendant Risk Solutions had in fact continue to operate as an active business despite its administrative dissolution. Bank records obtained during post judgment discovery revealed that Defendant Risk Solutions had transferred hundreds of thousands of dollars to its principal, Defendant Howell. Howell admitted at his postjudgment deposition that these funds were used to finance his family’s vacations, including trips to Walt Disney World. Order ¶ 56. In an aside at his deposition, Defendant Howell made an unpromped statement that surely deserved a kick under the table from his counsel. He said that “Yeah, we’re going this year, too, by the way.” Id.

Plaintiff McCarron filed a Motion asking that the court enter an Injunction against each of the Defendants (Defendant Harold Howell, his wife, and a corporation formed during the pendency of the original lawsuit [Spartan Corporate Advisors, Inc.] which is doing business as Risk Solutions prohibiting those persons and entities from making further asset transfers among themselves, and also to have a receiver appointed to take control of the assets and management of Risk Solutions.

If you frequently go to Court for injunctive relief, you're probably thinking “wait a minute. You can't get injunctive relief just over money damages. Plaintiff had to show irreparable harm and something that can be cured by the payment of money is not irreparable.

You're right about that, but the Uniform Voidable Transfers Act (the “UVTA”) can get you around that obstacle. It provides the Court with the power to enter an injunction against future transfers in violation of the UVTA. It says that:

In an action for relief against a transfer or obligation under this Article, a creditor, subject to the limitations in N.C.G.S. § 39-23.8, may obtain: . . . (3) Subject to applicable principles of equity and in accordance with applicable rules of civil procedure: a. An injunction against further disposition by the debtor or a transferee, or both, of the asset transferred or of other property; b. Appointment of a receiver to take charge of the asset transferred or of other property of the transferee; or c. Any other relief the circumstances may require. N.C.G.S. § 39-23.7(a)

UVTA

Order ¶ 30 (emphasis added).

Likelihood of Success on the Merits

Okay, putting aside the issue of irreparable harm, Plaintiff McCarron was also obligated to show that he had a likelihood of success on the merits. The UVTA deals with this issue specifically also. It specifies that transfers made by a “debtor” (which Defendant Risk Solutions was per the terms of the Act) are voidable if they are made “with intent to hinder, delay, or defraud any creditor of the debtor.’ G.S. §39-23.4(a).

How do you show that? The UVTA helpfully provides a list of 13 factors that can be considered in determining whether a transfer was made "with the intent to hinder, delay, or defraud a creditor.” I will not list them all in this post (though they are set out in this footnote 1). I will instead focus on the five factors that Judge Davis identified in determining that these transfers had been made in violation of the Act.

First, Judge Davis observed that there was evidence that many of the challenged transactions involved payments to corporate “insiders” under N.C.G.S. §39-23.4(b)(1). “Insiders” are defined under the statute as:

(1) a director of the debtor; (2) an officer of the debtor; (3) a person in control of the debtor; (4) a partnership in which the debtor is a general partner; (5) a general partner in a partnership in which the debtor is a general partner; or (6) a relative of a general partner, director, officer, or person in control of the debtor.”

N.C.G.S. § 39-23.1(7)b. All of Defendant Howell’s transfers were made to himself, to his wife, and to his family. Transfers to family members “trigger closer scrutiny of the circumstances.” Order ¶44 (quoting In re Schofield-Johnson, LLC, 462 B.R. 539, 543 (Bankr. M.D.N.C. 2011).

Second, plaintiff had presented evidence that the challenged transactions, as well as Risk Solution’s assets were concealed from from him. The false discovery responses established this factor.

Third, plaintiff had presented evidence that Risk Solutions had “absconded” for purposes of G.S. §39-23.4(b)(6).That may not fit your definition of “absconded,” But Defendant Risk Solutions’ administrative dissolution filled the bill for Judge Davis. Risk Solutions continue to do business after its administrative dissolution, which Judge Davis noted that would be inconsistent with the limitations imposed upon a dissolved entity under G.S.§57D-6-07, which requires the company to wind up its affairs. Order ¶52. The false responses to interrogatories regarding the legal status of Risk Solutions also did a disservice. Risk Solutions had allowed the administrative dissolution to occur during the pendency of the original lawsuit by failing to file its annual report with the Secretary of State. Judge Davis cited multiple decisions holding that a corporation had absconded when it was administrative dissolved in the face of liability. Order ¶53.

The fourth factor leading to the entry of the preliminary injunction was that the challenged transfers were made shortly after Risk Solutions had been sued in the original action and shortly before the substantial Judgment was obtained against it. This factor weighed in favor of finding that the challenged transactions were made with the intent to hinder, delay, or defraud Plaintiff McCarron. Order ¶ 57

Finally, the challenged transfers had made while Risk Solutions was “insolvent” under G.S. §39 – 23.4(b)(9). For purposes of the UVTA, a debtor is presumed to be insolvent if it is “generally not paying the debtor’s debts as they become due.” N.C.G.S. §§ 39-23.2(a)–(b).Risk Solutions had not made any voluntary payments in satisfaction of its debt to Plaintiff. The interrogatory response stating that the only assets of the Defendant were worthless “paper files, paper supplies, and old brochures” sealed the deal on insolvency when faced with plaintiff’s valid judgment for more than $300,000

MHereoreover, it was also “insolvent” for purposes of the statute because it’s debts were greater than the sum of its assets.

The Question of Irreparable Harm

Judge Davis then turned to the question of irreparable harm. Here he was guided by the decisions of courts construing the UVTA. Several had concluded that “a creditor is likely to suffer irreparable harm if a debtor is not enjoined from continuing to make potentially fraudulent transfers.” Order ¶71.

He concluded that “the potential harm to McCarron would not be capable of being remedied solely through an award of monetary damages if the assets of Risk Solutions are further depleted.” Order ¶72. A bond of $100,000 was required as a condition of the injunction entered by Judge Davis. Order ¶84. The Plaintiff certified the filing of the bond with the court on June 16, 2026., (ECF No. 66)

The Injunction and the Appointment of the Receiver

Judge Davis entered a comprehensive injunction (contained in paragraph 17-24 at the end of the Order). Read in its entirety, it prohibits any of the Defendants (as well as their “agents, servants, officers, directors, and employees”) from taking a dime from either of the Defendant companies so long as the Injunction remains in effect it also prohibits them from depositing any payments made payable to either of the corporate Defendants.

Further adding a cherry on the top for this victorious Plaintiff, Judge Davis appointed a Receiver to take control of the corporate Defendants’ operations and finances. As I read the Receivership Order (contained in paragraphs 1 through 16 at the end of the Order), the Receiver is granted total control of the operations and property of the corporate defendants. (Judge Davis rejected the Plaintiff’s request that the receivership extend to the individual Defendants). The Receiver is Forrest D. Bridges, former Superior Court Judge for Cleveland and Lincoln Counties. He is to be compensated at the rate of $400 per hour

The Receiver is obligated to report to the Court on a periodic basis. He filed his first report on July 22, 2025. I found this aspect of his first report on his efforts to take control of the accounts held in financial institutions by the corporate Defendants a little amusing. He said:

Upon being provided with a copy of the Order Appointing Receiver, Truist Bank and FirstBank cooperated by transferring each of their accounts to the Receiver, although each account contained only nominal amounts. Bank of America proved more challenging, refusing to recognize the Receivership and insisting throughout that it “does not allow Receivership Accounts.” Eventually Bank of America, facing threats of contempt, agreed to close each of its accounts and forward cashier checks to the Receiver representing the amounts on deposit.

Go receiver go!

Subscribe to premium content to read the rest.

Become a paying subscriber to get access to the post below and future premium-only content.

Become a Paid Subscriber

Reply

Avatar

or to participate

Keep Reading