Data Breach Lawsuits & Investigations
Every year, hundreds of millions of people are affected by data breaches that can leave them vulnerable to identity theft, credit damage, reputational harm and more.
Class action lawsuits remain one of the strongest ways to hold companies accountable for leaving consumers’, employees’ and patients’ private information unprotected. Indeed, some have resulted in multi-million-dollar settlements on behalf of those who – through no fault of their own – had their information stolen and, in the worst cases, even published on the dark web.
When a data breach lawsuit is successful, it can also require the company at fault to implement new security protocols to ensure the information it is entrusted with – medical, financial and otherwise – stays safe.
Got a data breach notice?
Scroll down to see the list of data breaches attorneys working with ClassAction.org are currently investigating. If you see one that looks familiar, click through to learn more about the breach and what you can do to potentially help get a class action lawsuit started.
And remember – don’t throw your notice away! It essentially serves as proof that you were affected by a specific security incident and can be vital if you choose to take legal action for the harm you suffered.
We update this page often with new data breach investigations, so make sure to bookmark it and come back regularly. You can also sign up for our free newsletter, which is sent on a weekly basis and includes our latest data breach alerts.
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Featured Data Breaches
St. Clair Orthopaedics & Sports Medicine Data Breach
January 2025
Michigan healthcare provider St. Clair Orthopaedics & Sports Medicine reported that personal and medical information was exposed in a data breach affecting 340,000 people.
ArdyssLife Data Breach
February 2025
Nutrition products company ArdyssLife is informing customers that a data breach at a third-party provider may have exposed their personal information.
New Era Life Insurance Data Breach
February 2025
New Era Life Insurance is reporting a data breach that may have exposed personal information belonging to policyholders, beneficiaries, independent agents and employees.
Innovative Renal Care Data Breach
February 2025
Innovative Renal Care, which manages a network of dialysis centers, is sending notice of a February 2024 data breach that exposed personal and medical information.
New York Blood Center Enterprises Data Breach
January 2025
New York Blood Center Enterprises, which operates blood centers across the country, recently reported that it was the victim of a ransomware attack.
Globe Life Data Breach
October 2024
Globe Life, Inc. has announced that an unknown threat actor is seeking to extort money in exchange for not revealing personal information related to subsidiary American Income Life Insurance Company and certain customers.
Recent Data Breaches
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Archie Cochrane Motors Data Breach
February 2025
Archie Cochrane Motors, which runs a Ford dealership in Billings, Montana, is notifying individuals about a 2024 data breach that may have exposed personal data.
Center for Digestive Health Data Breach
March 2025
Gastroenterology Associates of Central Florida has reported an April 2024 data breach that may have impacted patients of its Center for Digestive Health and Center for Digestive Endoscopy clinics.
Bay Cove Human Services Data Breach
March 2025
Bay Cove Human Services, Inc., which helps those in Southeastern Massachusetts with mental health, developmental disabilities and more, has announced a data security breach that may have compromised individuals' personal and protected health information.
Pacific Rehabilitation Centers Data Breach
February 2025
Pacific Rehabilitation Centers, which offers treatment services for injured workers in Washington, has reported a December 2024 data breach that may have impacted patients, employees and contractors.
Estrella Insurance Data Breach
March 2025
More than 16,000 people may have had their personal information exposed in an early 2025 data breach at Estrella Insurance.
Legacy Professionals LLP Data Breach
February 2025
Accounting firm Legacy Professionals LLP is notifying individuals whose Social Security numbers, medical information and more were exposed in a data breach.
Linn-Benton Community College Data Breach
February 2025
Linn-Benton Community College is notifying employees whose information may have been compromised in a data breach at retirement plan administrator Carruth Compliance Consulting.
AllTrust Data Breach
February 2025
AllTrust has reported a February 2024 data breach involving unauthorized activity on the network of its subsidiary Aspire USA.
Carruth Compliance Consulting Data Breach
January 2025
Retirement plan administrator Carruth Compliance Consulting reported a data breach that reportedly impacted its clients, including several Oregon school districts.
Carolina Arthritis Associates Data Breach
February 2025
Carolina Arthritis is notifying individuals whose medical information, Social Security numbers and more were exposed in a September 2024 data breach.
Service Access & Management Data Breach
February 2025
Service Access & Management, a nonprofit serving youth and families in Pennsylvania and New Jersey, has announced a data breach that may have exposed health information.
Restorix Health Data Breach
February 2025
Restorix Health, which provides wound care management services to hospitals, has reported that over 38,000 people were affected by a May 2024 data breach.
Medical Billing Specialists, Inc Data Breach
February 2025
Medical Billing Specialists, Inc., which provides billing services to healthcare organizations, has reported a data breach that may have compromised patients’ personal and medical information.
Central New York Cardiology Data Breach
February 2025
Central New York Cardiology is notifying individuals affected by a December 2024 data breach that exposed personal, medical and financial information.
St. Clair Orthopaedics & Sports Medicine Data Breach
January 2025
Michigan healthcare provider St. Clair Orthopaedics & Sports Medicine reported that personal and medical information was exposed in a data breach affecting 340,000 people.
Yes Communities, Inc. Data Breach
February 2025
Yes Communities, a real estate investment trust that owns and operates manufactured housing communities, has reported a late 2024 data breach in which an unauthorized party copied certain files from the company’s network.
Via Credit Union Data Breach
February 2025
Via Credit Union has reported a potential data breach affecting more than 60,000 individuals that may have compromised personal information.
Reading Cooperative Bank Data Breach
February 2025
Massachusetts-based Reading Cooperative Bank has reported that a data breach, which stemmed from a phishing attack, may have compromised the personal information of more than 24,000 people.
Oral Roberts University Data Breach
February 2025
Oral Roberts University has reported a December 2024 data breach that exposed names and Social Security numbers.
Heartland Community Health Center Data Breach
February 2025
Heartland Community Health Center, located in Lawrence, Kansas, has reported that more than 43,000 individuals may have had their personal and medical information exposed in a data breach discovered in October 2024.
Daedong-USA Data Breach
February 2025
Daedong-USA and subsidiary Kioti Tractor Division are notifying individuals whose personal, financial and/or medical information was exposed in a 2024 data breach.
Finastra Technology Data Breach
February 2025
Fintech company Finastra is notifying individuals affected by a late 2024 data breach involving unauthorized access to the company's secure file transfer platform.
ArdyssLife Data Breach
February 2025
Nutrition products company ArdyssLife is informing customers that a data breach at a third-party provider may have exposed their personal information.
Innovative Renal Care Data Breach
February 2025
Innovative Renal Care, which manages a network of dialysis centers, is sending notice of a February 2024 data breach that exposed personal and medical information.
The Pension Specialists Data Breach
February 2025
The Pension Specialists, a retirement plan administrator, is notifying individuals of a data breach that may have impacted their private information last year.
Humboldt Independent Practice Association Data Breach
November 2024
Third-party health insurance administrator Humboldt IPA reported a mid-2024 phishing incident that exposed individuals' personal and medical information.
New Era Life Insurance Data Breach
February 2025
New Era Life Insurance is reporting a data breach that may have exposed personal information belonging to policyholders, beneficiaries, independent agents and employees.
Lucent Health Solutions Data Breach
January 2025
Lucent Health Solutions has reported a potential data breach affecting 37,000 individuals that may have compromised personal and health insurance information.
St. Andrew’s Resources for Seniors System Data Breach
February 2025
St. Andrew’s Resources for Seniors System, which provides assisted living, in-home care and more, has reported a data breach that exposed personal, financial and health details and affects more than 16,800 individuals.
VectraRx Mail Pharmacy Services Data Breach
February 2025
Mail order pharmacy VectraRx has reported a data breach discovered in December 2024 that may have exposed personal and health information.
Star Solution Services Data Breach
February 2025
Star Solution Services is sending notice of a March 2024 data breach that may have compromised names and Social Security numbers of nearly 28,000 people.
Stock Development Data Breach
January 2025
Florida real estate developer Stock Development has reported a nearly year-long data breach that may have exposed personal and financial information of over 13,000 people from April 2023 to March 2024.
Mizuno USA Data Breach
January 2025
Sporting goods manufacturer Mizuno has reported a months-long data breach that may have compromised names, Social Security numbers, financial information and more.
Zenith American Solutions Data Breach
January 2025
Zenith American Solutions, a third-party employee benefits administration firm, is sending notice of a phishing attack that may have exposed the private information of more than 11,000 individuals.
New York Blood Center Enterprises Data Breach
January 2025
New York Blood Center Enterprises, which operates blood centers across the country, recently reported that it was the victim of a ransomware attack.
Benefits Management Group Data Breach
January 2025
Benefits Management Group, Inc. (BMGI), which provides health and retirement benefits administration, has announced that an unauthorized individual may have copied files containing personal information from company systems in November 2024.
UFCW Local 135 Data Breach
January 2025
San Diego-based UFCW Local 135 has announced a data breach that reportedly exposed the personal information of more than 62,000 individuals.
Mission Bank Data Breach
January 2025
Mission Bank is notifying impacted individuals about a December 2024 data security incident that involved unauthorized access to the California-based bank's network.
Furniture Mart USA Data Breach
January 2025
Furniture Mart USA is sending notice of a November 2024 data breach that impacted over 9,700 individuals.
Iannuzzi Manetta & Co, P.C. Data Breach
January 2025
The certified public accounting firm is notifying individuals about an August 2024 data breach in which threat actors gained access to the personal information of current and former clients.
Securitas Security Services USA Data Breach
January 2025
Securitas has reported a data breach to the Massachusetts Attorney General that may have exposed consumers' Social Security numbers and medical records.
Newport Harbor Pathology Medical Group Data Breach
January 2025
Patients of Newport Harbor Pathology Medical Group, Orange County Medical Group Pathology, Mission Laguna Pathology Medical Group and Barr Dermatopathology may have had their information exposed in a late 2024 data breach.
First Advantage has reported a late 2024 data breach that exposed personal information belonging to individuals with Profile Advantage accounts.
Lifetime Psychiatry Data Breach
December 2024
Nearly 17,000 individuals may have had their personal and medical data exposed in a September 2024 data breach affecting Lifetime Psychiatry.
McNall & Associates, P.C. Data Breach
January 2025
McNall & Associates, P.C. has reported a data breach that may have affected more than 10,000 individuals.
QuoteWizard Data Breach
July 2024
Names, addresses and driver's license numbers may have been compromised in a June 2024 data breach affecting QuoteWizard.
HCF Management Data Breach
January 2025
HCF Management has reported that a data breach exposed the personal and medical information of residents at more than a dozen of its senior care facilities in Ohio and Pennsylvania.
Gravy Analytics Data Breach
January 2025
Data broker Gravy Analytics has confirmed a data breach that, according to reports, may have exposed location information for millions of people.
North Los Angeles County Regional Center Data Breach
January 2025
North Los Angeles County Regional Center (NLACRC), which assists individuals with disabilities, has reported that a suspected ransomware attack from late 2024 has led to the exposure of personal, medical and financial information.
BayMark Health Services Data Breach
January 2025
BayMark, which operates substance use disorder treatment facilities, is notifying patients whose information may have been exposed in a late 2024 data breach.
Dignity Health Lassen Medical Clinic Data Breach
December 2024
Dignity Health has reported a 2024 data breach that affected its Lassen Medical Clinic locations, potentially compromising confidential patient information.
Pediatric Home Service Data Breach
January 2025
Pediatric Home Service, which offers home health care for children with complex medical needs, has reported a data breach that may have exposed personal and health information.
Familylinks Data Breach
November 2024
Familylinks Inc., a provider of community, social and behavioral programs in western Pennsylvania, experienced a data breach in May 2024 that exposed personal and protected health information.
Dobie Road Data Breach
December 2024
Current and former patients/residents of Ingham County Medical Care Facility (Dobie Road) may have had their information exposed in a data breach.
Sadiant Health Data Breach
January 2025
The healthcare staffing company has reported a data breach exposing personal, financial and medical information.
DBM Global Data Breach
December 2024
Construction and engineering firm DBM Global experienced a data breach that exposed individuals' Social Security numbers and other personal information.
Word & Brown Insurance Administrators Data Breach
December 2024
Word & Brown, which provides services to insurance brokers and carriers, has reported an October 2024 data breach that exposed protected health information.
Kotz Sangster Wysocki Data Breach
January 2025
Kotz Sangster has reportedly experienced a data breach, and the law firm is now sending notice to those whose private information may have been impacted.
Teton Orthopaedics Data Breach
January 2025
Personal, medical and financial information may have been compromised in a months-long data breach affecting the Jackson, Wyoming orthopedic practice.
CR&R Incorporated Data Breach
December 2024
The waste and recycling collection company is notifying individuals about a data breach that involved unauthorized network access and exposed personal data.
Bank of America Data Breach
January 2025
Bank of America is notifying individuals affected by an October 2024 data breach at one of its third-party providers that exposed mortgage loan information.
Jacobs Entertainment Data Breach
November 2024
Gaming, hospitality and entertainment company Jacobs Entertainment suffered a data breach in September 2024 during which an unauthorized party acquired files containing personal information.
Fiskars Group Data Breach
November 2024
A data breach affecting Fiskars Group may have exposed the private information of more than 6,300 people.
American Associated Pharmacies Data Breach
December 2024
American Associated Pharmacies (AAP) is notifying individuals of a data breach that may have exposed their names, Social Security numbers and health insurance information.
Inszone Insurance Services Data Breach
November 2024
Inszone Insurance Services was reportedly the victim of a ransomware attack that may have exposed the personal data of more than 20,000 people.
Access TeleCare Data Breach
December 2024
Telemedicine provider Access TeleCare is notifying individuals affected by a months-long data breach involving unauthorized access to employee email accounts.
Senior Citizens, Inc. Data Breach
January 2025
Senior Citizens, Inc. announced a data breach that may have exposed individuals’ names and Social Security numbers.
Saratoga Harness Racing Data Breach
December 2024
Saratoga Harness Racing, which operates Saratoga Casino Hotel, has reported a late 2024 data breach that affected over 5,800 people, including employees.
Indiana University Health Data Breach
December 2024
Indiana University Health has reported a data breach involving unauthorized access to a user account and resulting in the exposure of medical information.
Mastery Charter High School Data Breach
December 2024
In September 2024, Mastery Charter High School experienced a data breach that exposed individuals’ sensitive information.
Wonder CPA Firm Data Breach
December 2024
Wonder CPA Firm, which provides tax, accounting and payroll services, is notifying individuals whose information may have been exposed as part of a 2024 data breach.
Covaris Data Breach
December 2024
Covaris is notifying individuals of a February 2024 data breach that involved unauthorized access to its computer system, exposing individuals’ personal, financial and health information.
Arixa Capital Advisors Data Breach
December 2024
The private real estate lender is notifying individuals of a data breach that may have exposed their personal information.
Easterseals Rehabilitation Center Evansville has reported that a mid-2024 data breach may have impacted more than 8,300 individuals, potentially exposing medical and financial information.
Lexington Diagnostic Center Data Breach
December 2024
Lexington Diagnostic Center is alerting patients to an early 2024 data breach that exposed personal and protected health information.
River Region Cardiology Data Breach
December 2024
The Alabama cardiac imaging and treatment facility has reported a data breach affecting 500,000 individuals to the U.S. Department of Health and Human Services.
True World Data Breach
October 2024
True World is notifying customers and employees of an August 2024 data breach that may have compromised their personal information.
Delmar International Data Breach
December 2024
Delmar is notifying U.S. employees that their personal information may have been stolen in an attack reported to be a ransomware event.
Andrew Davidson & Co., Inc. Data Breach
December 2024
Andrew Davidson & Co. announced a data breach that may have exposed individuals’ names, dates of birth and Social Security numbers in November 2024.
Newman Ferrara Data Breach
December 2024
The New York City law firm is notifying individuals of a data breach that may have compromised their Social Security numbers, financial information and more.
The Coffee Bean & Tea Leaf Data Breach
December 2024
International Coffee & Tea, owner of The Coffee Bean & Tea Leaf coffee shop chain, is notifying individuals affected by a 2024 data breach.
Praedicat, Inc Data Breach
December 2024
Employees of the risk analytics company may have had their personal data exposed in a November 2024 data breach.
Devine Millimet & Branch Data Breach
December 2024
The New Hampshire law firm is notifying individuals whose names and Social Security numbers may have been exposed in a data breach.
Framingham Heart Study Data Breach
December 2024
All 15,000+ participants of Boston University's Framingham Heart Study had their personal information exposed in a September 2024 data breach.
Current and former patients of the fertility clinic are being notified about an April 2024 ransomware attack that exposed personal, medical and financial information.
The Alcohol & Drug Testing Service Data Breach
December 2024
The Alcohol & Drug Testing Service has reported a data breach that may have exposed individuals’ personal information.
Americhek Data Breach
December 2024
Background check company Americhek is notifying individuals whose personal information was exposed in a breach at one of its vendors, BackChecked LLC.
Kitsap Mental Health Services Data Breach
December 2024
A data breach that targeted Kitsap Mental Health Services in 2024 may have exposed individuals’ protected health information and other private details.
Crimson Wine Group Data Breach
December 2024
Winery and vineyard operator Crimson Wine Group is notifying individuals about a June 2024 data breach in which personal information may have been taken by an unauthorized party.
Martin Sprocket & Gear, Inc. Data Breach
December 2024
Martin Sprocket & Gear, an industrial equipment manufacturer, reported a data breach that exposed employees’ personal data around July 2024.
Young Life Data Breach
December 2024
Young Life is sending notice of a June 2024 data breach that may have exposed the personal information of employees, their dependents and certain volunteers.
Ames Goldsmith Data Breach
December 2024
Ames Goldsmith Corporation, a supplier of silver-based products and refining services, is sending notices to individuals regarding a 2024 data breach that may have exposed some of their personal information.
Rumpke Waste & Recycling Data Breach
December 2024
Rumpke Waste & Recycling is sending notice of a data breach that may have exposed the personal information of current and former employees, their spouses and dependents.
Citizens Bank Data Breach
December 2024
Citizens Bank is sending notice letters about a data breach that may have exposed the personal information of approximately 8,358 individuals.
Ferring Pharmaceuticals Data Breach
December 2024
The Swiss biopharmaceutical company has reported a data breach involving a phishing attack that may have exposed employees' personal information in October 2024.
Chemonics International Data Breach
December 2024
Chemonics International, Inc., a global sustainable development firm, has disclosed a months-long data breach that affected the personal information of more than 260,000 individuals.
Mid-Ohio Psychological Services, Inc. Data Breach
November 2024
Mid-Ohio Psychological Services, Inc., a provider of mental health and substance abuse support, has disclosed a data breach affecting 40,345 individuals.
ESHA Data Breach
November 2024
ESHA, Inc., a revenue cycle management company, has reported that the personal and health information of nearly 77,000 individuals may have been exposed in a July 2024 data breach.
Colonial Behavioral Health Data Breach
November 2024
Colonial Behavioral Health is notifying customers of a data breach that may have exposed their information in October 2024.
Mark Cerrone Data Breach
November 2024
Mark Cerrone, a construction company serving Western New York, is sending notice of a data breach that may have exposed individuals’ names and Social Security numbers.


Join the Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Data Breach FAQs
What is a data breach?
A data breach is a cybersecurity incident whereby an unauthorized party or parties gain access to sensitive, protected and/or confidential information belonging to an individual or organization.
The information stolen or compromised in a data breach can include, but may not be limited to, names, email addresses, physical addresses, passwords, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, credit card numbers, debit card numbers, CVV numbers, medical information, diagnoses, health insurance information, biometric data, and taxpayer ID numbers. Data breaches also may involve sensitive business information, trade secrets or national security matters.
The causes of a data breach, sometimes called a cyberattack, can include software vulnerabilities, email-based phishing attempts, ransomware, accidental disclosure, access improperly given to computer systems, a lack of encryption, or hacking perpetrated by cybercriminals.
I got a data breach notification. Does this definitely mean my info is being used fraudulently?
Not necessarily. When a company experiences a data breach, state law requires that it notify affected individuals. Receiving a letter does not automatically mean that your personal information is being used fraudulently – it just means your information was exposed in a data security incident and has the potential for being misused.
If your Social Security number is involved in a data breach, you’ll want to monitor and check your credit report and financial accounts for any signs of identity theft. Warning signs of identity theft can include withdrawals from your bank account that you can’t explain, missing bills or other mail, contact from debt collectors you don’t recognize, unfamiliar charges on your debit/credit cards, and unfamiliar accounts or charges on your credit report.
If your identity is in fact stolen from a data breach, report it to the Federal Trade Commission on IdentityTheft.gov and receive a personalized recovery plan.
To help protect yourself from identity theft, you can contact each of the three major credit bureaus—Equifax, Experian and TransUnion—to place a credit freeze on your credit report. A credit freeze will restrict access to your credit information and prevent anyone from opening a new credit account in your name.
Freezing your credit in the event of a data breach does not harm your credit score and will stay in place on your credit report until you decide to lift it.
In addition, you can also place a fraud alert on your credit reports, which alerts businesses to check with you before any new account is opened in your name. However, unlike a credit freeze, a fraud alert does not prevent businesses from seeing your credit report data, the FTC says.
Anyone who is concerned about identity theft can place an initial fraud alert on their credit report for free. To do this online, visit the Equifax, Experian or TransUnion website; you don’t have to contact all three. An initial fraud alert typically lasts for one year and can be renewed should a consumer opt to do so.
Another, more serious form of identity theft protection in the event of a data breach is an extended fraud alert, which, like an initial fraud alert, requires a business to contact you before any new credit is issued in your name. To create an extended fraud alert, you must have experienced identity theft and completed an FTC identity theft report or filed a police report.
An extended fraud alert will exist on your credit report for seven years, after which it can be renewed so long as an FTC identity theft or police report is resubmitted. An extended fraud alert can also be set up online through Equifax, Experian or TransUnion.
What should I do if I get a data breach letter?
If you get a data breach notice, make sure to read it closely. It should contain information on what happened, what information was involved, what the company is doing about it, steps you can take to protect yourself, and how you can get more information.
Some companies may offer free credit and/or identity theft monitoring for a period of time following a data breach, and the notice should include instructions on how to sign up. If you’re offered free monitoring, take advantage of it; signing up should not affect any legal claim you may have against the company.
Importantly, if you get a data breach letter, don’t throw it out! If you are interested in helping any of the investigations listed on this page, attorneys will want to see the letter you received.
Why do attorneys need to see my data breach notice?
Attorneys working with ClassAction.org are specifically looking to hear from people with a data breach notice because it essentially serves as proof that the individual was a victim of the incident and makes for a stronger legal claim.
So, I can sue over a data breach?
Yes. If your data was exposed in a security incident, you may be able to sue the company or companies responsible. Dozens of data breach class action lawsuits are filed each month, and this number only continues to increase. You can check out the proposed data breach class actions we’ve covered recently over on our newswire.
How do I know if a data breach letter is legitimate?
To verify whether a data breach notice letter you received is real, the first step is to Google the company name, along with the words “data breach.” More often than not, the search results, which may include news articles, will reveal whether the data breach letter in your possession stems from a real-world cyberattack.
You can also check ClassAction.org directly to see if we’ve reported on the data breach, though it’s important to note that we do not cover every incident.
If you are unsure of whether a data breach notice is legit, contact the company directly through a verified channel to confirm the data breach. Many times, companies post data breach notices on their websites.
Generally, a data breach notice you receive via email will come from a company or organization’s official email address and will usually address you by name.
Do not click on any links in the notice that may look suspicious or don’t match the company’s official website. Lastly, keep an eye out for spelling and grammar mistakes in a data breach notice, as they might indicate that the message is fake.
Can you give me an example of a data breach notification letter?
Absolutely. Here is an example of one sent to Forever 21 employees following a massive data breach that occurred in March 2023. This is the letter sent to consumers affected by the MAPFRE insurance data breach in late August 2023. In some cases, notices may be sent via email.
What if I never heard of the company that sent me a data breach notice?
It’s important to note that, in rare cases, you may not recognize the company sending the letter, but this does not mean it was sent in error.
For instance, a May 2023 data incident affecting a popular file transfer tool caused millions of individuals to have their information exposed. In this instance, many of the data breach letters were sent by a third-party vendor of the affected companies. For example, PBI Research Services sent this letter to customers of Corebridge Financial.
What if I threw my data breach notice out?
It’s important that, if you receive any data breach notice, you do not throw it out. If you’ve already done so, you may want to check the company’s website for their official notice of the breach – it should include the same information that was in your notice. You may also want to check the post for a dedicated number consumers can call with questions about the security incident. It’s worth a call to see if they can resend your notice, but this may not be possible.
What if I think I’m affected but haven’t received a notice?
Notices aren’t always sent immediately after a breach hits the news, so you may just have to be patient. Otherwise, you can check the company’s website to see if they’ve posted a notice about the breach – it may contain a number you can call with questions. They should, at the very least, be able to answer when notices are expected to go out and may also be able to confirm whether you were affected.
Be sure to bookmark our page and come back to it if you believe you’ve been affected by a data breach listed below but haven’t received a notice yet.
What kind of damages can I claim for a data breach?
In general, data breach victims can seek compensation for lost time responding to the incident, out-of-pocket costs related to the breach and loss of privacy.
Depending on the specifics of the data breach, out-of-pocket costs may include some of the following: money spent on preventative measures, such as identity theft and/or credit monitoring; service fees to replace stolen cards; money spent on credit reports and/or credit freezes; the costs associated with obtaining background checks or medical records; increased health insurance costs; and money lost via fraudulent transactions, fraudulent medical bills or stolen tax refunds.
Further damages may become available depending on the type of information exposed. For instance, if a person’s health data is leaked, they may be able to recover money for reputational damage if they are denied medical care or insurance coverage. Likewise, a person whose Social Security number is exposed may be able to recover money for damage to their credit.
How much can I claim in a data breach settlement?
How much you can claim in any data breach settlement will depend on a number of factors, including the specifics of the settlement, the amount of time you spent responding to the incident, the type and total amount of your out-of-pocket expenses, and how many claims are filed. There are never any guarantees as to whether a data breach lawsuit will be successful or how much they could provide to consumers; however, some of the largest data breach settlements obtained via class action lawsuits include a $350 million deal with T-Mobile and a $190 million deal with Capital One.
I’m looking for data breach class action settlements. Where can I find those?
We post class action settlements, including those involving data breaches, over on this page.
How do I know if I was part of a data breach?
If you were affected by a data breach, you should receive a notice via email or regular mail about the incident and what information may have been exposed. All 50 states require that businesses and governments alert consumers if their personal information is breached.
How do I prevent a data breach?
While it may not be possible to completely secure your sensitive information, some steps you can take to protect yourself from a data breach and its fallout include:
- Using strong, complex passwords, preferably a different one for each account;
- Regularly changing passwords;
- Using multi-factor authentication (MFA) when available;
- Encrypting your data;
- Updating your devices’ software regularly;
- Shopping with a credit card, as you may incur less liability in the event of fraudulent charges or if your account is hacked; and
- Consistently monitoring your accounts for fraud, including by setting up account alerts.
It can also be helpful to have a response plan should your personally identifiable information become compromised in a data breach or cyberattack.
Always be wary of unsolicited correspondence from companies with whom you have no relationship, and never give anyone remote access to your devices.
What is the leading cause of data breaches?
According to InfoSec Institute, the leading cause of data breaches is human error, which may involve privilege misuse, stolen credentials or social engineering, a tactic whereby hackers can bypass having to create their own access points by goading individuals with legitimate access to grant it for them. Other common causes of data breaches and cyberattacks include weak credentials, software vulnerabilities, malware, ransomware, DNS attacks, improper API configuration and excessive permissions.
Anything else I should know?
If you’re interested in starting a class action lawsuit, you should know that those who elect to serve as a lead plaintiff are generally entitled to what’s known as a “service award” – that is, an additional payment for their help with the case. Typically, the lead plaintiff in a data breach case does not need to be involved as much as they would in other types of lawsuits. Depositions in these types of class actions are rare, and little documentation and information – aside from the initial data breach notice – is needed.
Plus, if you elect to serve as a lead plaintiff, you can feel good that you’re working to hold a company legally accountable for failing to protect the private information of potentially hundreds of thousands of individuals.
What if there’s a data breach settlement?
In the event of a data breach lawsuit settlement, ClassAction.org will have the complete details over on our class action settlements page.