The Ohio Court of Appeals has ruled in favor of a group of plaintiffs in a significant case concerning a data breach involving the City of Columbus. The court's decision, rendered on September 24, 2026, reverses a lower court's dismissal of claims related to a cyberattack that compromised the personal information of city employees and citizens. This ruling could have wide-ranging implications for how municipalities handle cybersecurity and data protection.

The plaintiffs, identified as John Doe Nos. 1 through 5 and Jane Doe, filed their complaints after a cyberattack in July 2024 compromised the city’s information technology (IT) system. The plaintiffs allege that their personally identifiable information (PII) was exposed due to the city’s negligence in maintaining adequate cybersecurity measures. The case, docketed as 25AP-798 and 25AP-799, highlights the responsibilities of public entities in safeguarding sensitive data.

The dispute began when the plaintiffs filed two separate lawsuits against Columbus in August 2024, shortly after the cyberattack. These lawsuits were consolidated, and the plaintiffs argued that the city failed to implement reasonable security protocols that would have protected their PII. They claimed the city’s negligence led to their data being accessed and potentially sold on the Dark Web by cybercriminals. The plaintiffs sought damages for the emotional distress and financial harm caused by the breach.

The City of Columbus responded by filing a motion to dismiss the lawsuits, asserting that it was entitled to political subdivision immunity under Ohio law, which generally protects government entities from liability for tort claims. The lower court agreed with the city and dismissed the case, leading the plaintiffs to appeal the decision.

In its ruling, the Ohio Court of Appeals reversed the lower court's decision. The court found that the plaintiffs had sufficiently alleged that the city’s IT operations were a proprietary function rather than a governmental function, which would exempt the city from immunity. The court stated, “The activities of [the city] at issue in this litigation—the operation of a city-wide IT infrastructure—are Proprietary Activities as defined by [R.C.] 2744.01(G)(1).” This distinction is crucial because it determines whether the city can be held liable for negligence in its cybersecurity practices.

The panel of judges, led by Presiding Judge Boggs, emphasized that the city’s failure to protect sensitive data could not be shielded by political subdivision immunity. The court noted that the plaintiffs had alleged specific facts indicating that the city’s cybersecurity measures were inadequate and that this negligence led directly to the data breach. The judges indicated that the city’s IT operations should be treated as a service that could be provided by private entities, thus not granting immunity.

This ruling is significant as it sets a precedent for how public entities in Ohio must approach cybersecurity. It underscores the importance of maintaining robust data protection measures and the potential legal consequences of failing to do so. The decision also highlights the evolving nature of cybersecurity law, particularly as it pertains to public institutions.

The impact of this ruling extends beyond the immediate case. It suggests that other municipalities may face similar legal challenges if they do not prioritize cybersecurity. The court’s decision could encourage more stringent security practices among public entities, as they may now be more vulnerable to lawsuits related to data breaches.

Moving forward, the City of Columbus may seek to appeal this decision to the Ohio Supreme Court, although details regarding any potential appeal were not available in the court filing. The outcome of this case could influence future litigation involving data breaches and the responsibilities of governmental entities in protecting sensitive information.

As this case progresses, it will be essential for other cities and municipalities to monitor the developments closely. The ruling may prompt a reassessment of existing cybersecurity policies and practices across public sectors, ensuring that they align with the legal standards established by this decision.