Data Breach Lawsuits & Investigations
Every year, hundreds of millions of people are affected by data breaches that can leave them vulnerable to identity theft, credit damage, reputational harm and more.
Class action lawsuits remain one of the strongest ways to hold companies accountable for leaving consumers’, employees’ and patients’ private information unprotected. Indeed, some have resulted in multi-million-dollar settlements on behalf of those who – through no fault of their own – had their information stolen and, in the worst cases, even published on the dark web.
When a data breach lawsuit is successful, it can also require the company at fault to implement new security protocols to ensure the information it is entrusted with – medical, financial and otherwise – stays safe.
Got a data breach notice?
Scroll down to see the list of data breaches attorneys working with ClassAction.org are currently investigating. If you see one that looks familiar, click through to learn more about the breach and what you can do to potentially help get a class action lawsuit started.
And remember – don’t throw your notice away! It essentially serves as proof that you were affected by a specific security incident and can be vital if you choose to take legal action for the harm you suffered.
We update this page often with new data breach investigations, so make sure to bookmark it and come back regularly. You can also sign up for our free newsletter, which is sent on a weekly basis and includes our latest data breach alerts.
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Featured Data Breaches
AppFolio, Inc. Data Breach
October 2025
AppFolio, a cloud-based software provider, is notifying individuals about an August 2025 data breach impacting Social Security numbers and other personal information.
Brightstar Global Solutions Corporation Data Breach
October 2025
IGT Group and Brightstar Lottery Group have reported that over 103,000 people may have been impacted by a November 2024 data breach.
Motility Software Solutions Data Breach
September 2025
Motility Software Solutions, which provides software to specialty dealerships, experienced a data breach that reportedly exposed personal information of 760,000 people.
Anchorage Neighborhood Health Center Data Breach
September 2025
Anchorage Neighborhood Health Center in Alaska has reportedly been the victim of a data breach, with hackers claiming to have stolen 60,000 patient records.
ClaimPix Data Breach
September 2025
A cybersecurity researcher reported discovering an exposed database containing sensitive information belonging to users of ClaimPix, a platform used in the insurance claims process.
Huron Regional Medical Center Data Breach
September 2025
Huron Regional Medical Center, a hospital in Huron, South Dakota, has reported a May 2025 data breach that exposed patient data, including personal, medical and financial information.
University of Iowa Community HomeCare, a home infusion and medical equipment services provider affiliated with University of Iowa Health Care, is notifying the public of a July 2025 data breach affecting its systems.
Tufts Medicine, Inc. Data Breach
August 2025
Massachusetts-based Tufts Medicine, Inc. has reported a data breach that potentially exposed personal and financial data.
Fairmont Federal Credit Union Data Breach
September 2025
Fairmont Federal Credit Union in West Virginia has reported that a slew of personal, financial and medical information was exposed in a late 2023 data breach.
Recent Data Breaches
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Care N’ Care Health Plan Data Breach
October 2025
Care N’ Care Health Plan, a Texas-based Medicare Advantage plan, has reported that a data breach may have exposed Social Security numbers and other personal information.
Sierra Vista Hospital & Clinics Data Breach
October 2025
Sierra Vista Hospital & Clinics, located in Truth or Consequences, New Mexico, has reported that personal and health information may have been compromised in a January 2025 data breach.
Space Coast Vascular Data Breach
October 2025
Space Coast Vascular, a Florida-based vascular lab and treatment center, has reported a data breach that may have affected personal and health information.
AppFolio, Inc. Data Breach
October 2025
AppFolio, a cloud-based software provider, is notifying individuals about an August 2025 data breach impacting Social Security numbers and other personal information.
Fort Wayne Medical Education Program Data Breach
October 2025
Fort Wayne Medical Education Program, a medical training program based in Indiana, has announced a December 2024 data breach impacting over 29,000 people.
Brightstar Global Solutions Corporation Data Breach
October 2025
IGT Group and Brightstar Lottery Group have reported that over 103,000 people may have been impacted by a November 2024 data breach.
Superior Vision Services, Inc. Data Breach
September 2025
Superior Vision, a subsidiary of insurer Versant Health, has reported that a July 2025 data breach may have compromised Social Security numbers and other sensitive information.
The Moinian Group Data Breach
September 2025
The Moinian Group, a real estate investment company, reportedly fell victim to a ransomware attack during which 4.7 TB of data was compromised.
ClaimPix Data Breach
September 2025
A cybersecurity researcher reported discovering an exposed database containing sensitive information belonging to users of ClaimPix, a platform used in the insurance claims process.
Red Coats, Inc. Data Breach
September 2025
Commercial cleaning company Red Coats, Inc. has reported a data breach that may have exposed Social Security numbers and other personal information.
Miami Management Data Breach
September 2025
Reports have surfaced that Miami Management, a property management company in South Florida, may have fallen victim to a ransomware attack that potentially affects employees and clients.
Pollard & Associates Data Breach
September 2025
Pollard & Associates, a third-party administration firm in the Greater Baltimore area that administers retirement plans for employer groups, has announced that an April 2025 data breach may have exposed personal and financial information.
Anchorage Neighborhood Health Center Data Breach
September 2025
Anchorage Neighborhood Health Center in Alaska has reportedly been the victim of a data breach, with hackers claiming to have stolen 60,000 patient records.
Integrity Testing & Safety Administrators Data Breach
September 2025
Integrity Testing & Safety Administrators Inc., a Michigan-based provider of workplace drug and alcohol testing, has announced a data breach involving unauthorized network access that occurred around March 27, 2025.
Trusteed Plans Service Corporation Data Breach
September 2025
Trusteed Plans Service Corporation, a custom healthcare benefit solutions provider, has reported that nearly 19,800 people were affected by a data breach discovered in December 2024.
Hampton Regional Medical Center Data Breach
September 2025
Hampton Regional Medical Center, a general acute care hospital in Varnville, South Carolina, is notifying the public of a June/July 2025 data breach that may have exposed personal and medical information.
HIPP Workforce Solutions Data Breach
September 2025
HIPP Workforce Solutions has reported a data breach affecting employees of the Raleigh, North Carolina-based staffing firm.
Radiology Associates of San Luis Obispo Data Breach
September 2025
Radiology Associates of San Luis Obispo, a medical imaging service provider based in California, has reported a data breach discovered in March 2025.
Fairmont Federal Credit Union Data Breach
September 2025
Fairmont Federal Credit Union in West Virginia has reported that a slew of personal, financial and medical information was exposed in a late 2023 data breach.
OB-GYN Associates Data Breach
September 2025
OB-GYN Associates, a healthcare practice in Reno, Nevada, has reported a data breach impacting Social Security numbers and other personal information.
Huron Regional Medical Center Data Breach
September 2025
Huron Regional Medical Center, a hospital in Huron, South Dakota, has reported a May 2025 data breach that exposed patient data, including personal, medical and financial information.
Twin Cities Pain Clinic Data Breach
September 2025
Twin Cities Pain Clinic has reported a July 2025 data breach involving unauthorized access to an employee's email account.
Genesis Billing Services Data Breach
September 2025
Keys Pathology Associates in Marathon, Florida is notifying individuals affected by a May 2025 data breach at its vendor, Genesis Billing Services.
Pediatric Otolaryngology Head & Neck Surgery Associates has reported that a February 2025 data breach may have exposed personal and health information.
Toast Data Breach
July 2025
In early September 2025, payroll services provider Toast, Inc. began notifying individuals whose personal information may have been exposed in a data breach first reported in July.
University of Iowa Community HomeCare, a home infusion and medical equipment services provider affiliated with University of Iowa Health Care, is notifying the public of a July 2025 data breach affecting its systems.
The health plan for Teamsters Union Local 25 members has reported an August 2025 data breach that exposed personal and health information.
Woodlawn Hospital Data Breach
August 2025
Woodlawn Hospital, an Indiana-based medical facility, has reported a data breach exposing Social Security numbers and other personal info.
SGS & Co. Data Breach
August 2025
SGS & Co., a global marketing services company, has reported a data breach exposing personal information, including Social Security numbers.
Tufts Medicine, Inc. Data Breach
August 2025
Massachusetts-based Tufts Medicine, Inc. has reported a data breach that potentially exposed personal and financial data.
Louis Vuitton Data Breach
August 2025
Louis Vuitton North America, Inc., the U.S. subsidiary of the French luxury fashion house, has reported a mid-2025 data breach involving unauthorized access to a database containing client information.
Risk Management Services Data Breach
September 2025
Risk Management Services, which provides claims administration services, has reported a data breach affecting information associated with LCTA Workers' Comp.
Carter Federal Credit Union Data Breach
August 2025
Louisiana-based Carter Federal Credit Union has reported that nearly 69,000 individuals had their information exposed in a mid-2025 data breach.
National Integrity Title Agency Data Breach
August 2025
National Integrity Title Agency, which serves the Delaware Valley and Florida, has reported a data breach that potentially exposed sensitive personal information.
Legacy Treatment Services Data Breach
August 2025
An October 2024 data breach reportedly exposed the personal and health information of those who received services from New Jersey-based Legacy Treatment Services and Community Treatment Solutions.
MPOWERHealth Data Breach
August 2025
Reports have surfaced that MPOWERHealth, a digital health system based in Addison, Texas, fell victim to a cyberattack that may have exposed protected health information.
Northwest Dental Data Breach
July 2025
Northwest Dental and Denture, which has four offices in Washington, has reported that a May 2025 data breach may have exposed the personal and medical information of current and former patients.
Ohio Marijuana Card Data Breach
August 2025
A security researcher recently reported that databases containing sensitive personal and medical information belonging to patients of Ohio Marijuana Card were publicly accessible online.
Inotiv Data Breach
August 2025
Contract research organization Inotiv, Inc. reported a cyberattack in early August 2025 during which a threat actor accessed and encrypted some of its systems.
Openforce Data Breach
August 2025
Contractor Management Services, LLC, which does business as Openforce and provides solutions for independent contractors and contracting companies, has reported a data breach involving personal information.
Commonwealth Business Bank Data Breach
August 2025
Commonwealth Business Bank, which has branches in California, Texas and Hawaii, has reported an early 2025 data breach exposing personal information, including financial data.
CEI Vision Partners Data Breach
August 2025
CEI Vision Partners, which operates a network of eye care practices, reported a data breach that may have exposed personal, financial and clinical information.
Seasons Living Data Breach
August 2025
Senior care provider Seasons Living is notifying those affected by an early 2025 data breach, which potentially impacted rental applicants, tenants, and employees, among others.
Langdon & Company Data Breach
August 2025
Langdon & Company, which provides accounting services to Easterseals PORT Health, is notifying patients of a data breach that may have exposed their information.
Community Realty Management Data Breach
August 2025
Community Realty Management, Inc., now known as CRM Residential, is notifying the public of a 2024 data breach involving its email system.
Kokomo Solutions Data Breach
August 2025
Kokomo Solutions, Inc., operating as Kokomo24/7, has reported a December 2024 data breach potentially involving personal information maintained on behalf of the Los Angeles Unified School District.
32 Pearls Data Breach
July 2025
32 Pearls, a dental practice in Seattle and Tacoma, experienced a data breach in May 2025 that may have exposed patients' personal and medical information.
Mid America Health Data Breach
August 2025
Mid America Health (MAH), which provides dental and healthcare services to state and federal governments, has reported a data breach potentially exposing individuals' SSNs and other personal information.
Altos Data Breach
August 2025
Altos, Inc., which provides billing services for healthcare providers in California, has reported that personal and health information were exposed in a June 2025 data breach.
Highlands Oncology Group Data Breach
August 2025
Highlands Oncology Group PA, specializing in radiation therapy and chemotherapy in Arkansas, reported a data breach that affected 113,575 individuals and involved unauthorized access to personal and medical information.
Infinite Services Data Breach
July 2025
New York-based therapy services provider Infinite Services is notifying patients and employees potentially affected by a May 2025 data breach.
BYU-Pathway Worldwide Data Breach
July 2025
BYU-Pathway Worldwide, an online education program affiliated with BYU-Idaho and Ensign College, has reported a data breach affecting over 25,000 students.
CRC Insurance Services, LLC Data Breach
June 2025
CRC Insurance Services, LLC, a wholesale and specialty insurance distributor, has reported that a February 2025 data breach may have exposed personal information.
Curium Pharma Data Breach
June 2025
Curium Pharma is notifying affected individuals about an October 2024 data breach that may have exposed personal information.
Smile Solutions of Goodlettsville has announced that it was affected by a data breach involving its former debt collection vendor, Nationwide Recovery Services.
Jacksonville, Florida-based Gateway Community Services, Inc. is informing certain current and former patients of an April 2025 data breach that may have compromised their personal and medical information.
Next Step Healthcare Data Breach
May 2025
Next Step Healthcare, which operates nursing and rehab facilities in Massachusetts, has reported that a data breach discovered in June 2024 may have exposed personal data.
Lemonade Data Breach
April 2025
Lemonade reported that roughly 190,000 driver's license numbers may have been exposed due to an issue with the company's online car insurance application.
Bradford Health Services Data Breach
May 2025
Personal, financial and medical information belonging to patients and employees of Bradford Health Services was reportedly exposed in a December 2023 data breach.
California water utility El Dorado Irrigation District is notifying individuals affected by a data breach at third-party vendor Nationwide Recovery Services.
New Jersey-based law firm Hardin, Kundla, McKeon & Poletto has reported a data breach caused by a malicious encryption attack that led to unauthorized copying of files from its network around January 2024.
Lanigan Ryan Data Breach
May 2025
Accounting and advisory firm Lanigan Ryan is notifying individuals whose personal information was exposed in a December 2024 data breach.
The Cooper Health System Data Breach
May 2025
The Cooper Health System, which operates hospitals, urgent care centers and outpatient offices in New Jersey, has reported a data breach impacting over 50,000 people.
North Carolina-based Pinehurst Radiology Associates has reported that a data breach may have exposed patient data, including treatment details and diagnoses.
Branhaven Motors Inc. Data Breach
May 2025
Branhaven Motors Inc., which operates the Branhaven Chrysler Dodge Jeep Ram dealership in Branford, Connecticut, has reported a data breach involving unauthorized access to its computer systems between September 9 and September 10, 2024.
Radiology Chartered Data Breach
May 2025
Radiology Chartered of Green Bay, Wisconsin has reported that personal information was affected by a data breach at vendor Nationwide Recovery Services.
Balance Autism Data Breach
May 2025
Iowa-based Balance Autism is providing notice of a 2025 data breach that may have exposed personal information.
Communications Data Group, a billing vendor for Kentucky internet and phone service provider Duo Broadband, is notifying Duo customers affected by a data breach.
Coinbase Data Breach
May 2025
Crypto giant Coinbase recently reported that cybercriminals gained access to customers' personal information by bribing overseas support employees to copy data.
EB Archbald & Associates, Inc., which specializes in energy production accounting services for oil and gas producers, has reported a ransomware attack that potentially exposed personal information.
GeoLogics Corporation Data Breach
May 2025
GeoLogics Corporation is sending notice of a December 2023 data breach that may have compromised the personal information of nearly 12,000 people.
Financial Plus Credit Union Data Breach
April 2025
Financial Plus Credit Union members are receiving notice of a December 2023 data breach that targeted account statement provider Doxim and may have impacted their private information.
Intealth Data Breach
April 2025
Intealth, which provides services to support the training and education of healthcare professionals, is notifying individuals affected by an April 2024 data breach.
The Hertz Corporation Data Breach
April 2025
Hertz is notifying individuals associated with its car rental brands, which include Dollar and Thrifty, about a data breach involving a third-party file transfer platform.
Qmatic Data Breach
April 2025
A December 2024 data breach at Qmatic may have compromised individuals’ personal information, including Social Security numbers.
CIO Partners Data Breach
April 2025
Recruiting firms CIO Partners and Talentric have reported a data breach that may have compromised Social Security numbers and more.
Business Insurance Services, Inc Data Breach
April 2025
Hawaii-based Business Insurance Services, Inc. has reported that an unauthorized individual gained access to its systems twice and potentially acquired the personal information of certain customers.
Unity National Bank of Houston Data Breach
April 2025
Unity National Bank of Houston has reported that a July 2024 data beach may have exposed customer data.
ProSearch Strategies Data Breach
April 2025
A data breach detected by ProSearch on January 27, 2025 may have compromised Social Security numbers, financial account information and more.
Tempel Steel Company Data Breach
April 2025
Tempel Steel Company, LLC has announced that a February 2025 data breach may have exposed information belonging to participants of its health and welfare plan.
Davenport & Company LLC Data Breach
April 2025
Davenport & Company LLC, which offers wealth management and financial advisory services, has reported a data breach involving sensitive personal information.
Salus Group Data Breach
April 2025
Benefits Partner, LLC, an insurance agency doing business as Salus Group, has reported an October 2024 data breach involving an employee email account.
Harcourts Prime Properties Data Breach
April 2025
Real estate company Harcourts Prime Properties is sending notice of a data breach that may have impacted agents’ private information.
Special Tree Data Breach
March 2025
Special Tree, a neurorehabilitation provider in Romulus, Michigan, has reported a data breach that may have compromised personal information, including Social Security numbers.
St. Joseph’s College of Maine Data Breach
March 2025
St. Joseph's College of Maine has reported a data breach that occurred from December 2023 to January 2024 and affected over 126,000 people.
Cottrill’s Specialty Pharmacy Data Breach
March 2025
Cottrill’s Specialty Pharmacy is notifying customers about the potential exposure of their personal information in a January 2025 data breach.
iTP Partners Data Breach
February 2025
Financial advisory firm iTP Partners is notifying individuals of an email phishing incident, reportedly linked to Osaic Wealth, Inc., that may have exposed Social Security numbers and financial account numbers.
Linn-Benton Community College Data Breach
February 2025
Linn-Benton Community College is notifying employees whose information may have been compromised in a data breach at retirement plan administrator Carruth Compliance Consulting.
Restorix Health Data Breach
February 2025
Restorix Health, which provides wound care management services to hospitals, has reported that over 38,000 people were affected by a May 2024 data breach.
Stock Development Data Breach
January 2025
Florida real estate developer Stock Development has reported a nearly year-long data breach that may have exposed personal and financial information of over 13,000 people from April 2023 to March 2024.
North Los Angeles County Regional Center Data Breach
January 2025
North Los Angeles County Regional Center (NLACRC), which assists individuals with disabilities, has reported that a suspected ransomware attack from late 2024 has led to the exposure of personal, medical and financial information.
Sadiant Health Data Breach
January 2025
The healthcare staffing company has reported a data breach exposing personal, financial and medical information.
Kotz Sangster Wysocki Data Breach
January 2025
Kotz Sangster has reportedly experienced a data breach, and the law firm is now sending notice to those whose private information may have been impacted.
Inszone Insurance Services Data Breach
November 2024
Inszone Insurance Services was reportedly the victim of a ransomware attack that may have exposed the personal data of more than 20,000 people.
Wonder CPA Firm Data Breach
December 2024
Wonder CPA Firm, which provides tax, accounting and payroll services, is notifying individuals whose information may have been exposed as part of a 2024 data breach.
Covaris Data Breach
December 2024
Covaris is notifying individuals of a February 2024 data breach that involved unauthorized access to its computer system, exposing individuals’ personal, financial and health information.
Arixa Capital Advisors Data Breach
December 2024
The private real estate lender is notifying individuals of a data breach that may have exposed their personal information.
Delmar International Data Breach
December 2024
Delmar is notifying U.S. employees that their personal information may have been stolen in an attack reported to be a ransomware event.
Newman Ferrara Data Breach
December 2024
The New York City law firm is notifying individuals of a data breach that may have compromised their Social Security numbers, financial information and more.
Praedicat, Inc Data Breach
December 2024
Employees of the risk analytics company may have had their personal data exposed in a November 2024 data breach.


Join the Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Data Breach FAQs
What is a data breach?
A data breach is a cybersecurity incident whereby an unauthorized party or parties gain access to sensitive, protected and/or confidential information belonging to an individual or organization.
The information stolen or compromised in a data breach can include, but may not be limited to, names, email addresses, physical addresses, passwords, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, credit card numbers, debit card numbers, CVV numbers, medical information, diagnoses, health insurance information, biometric data, and taxpayer ID numbers. Data breaches also may involve sensitive business information, trade secrets or national security matters.
The causes of a data breach, sometimes called a cyberattack, can include software vulnerabilities, email-based phishing attempts, ransomware, accidental disclosure, access improperly given to computer systems, a lack of encryption, or hacking perpetrated by cybercriminals.
I got a data breach notification. Does this definitely mean my info is being used fraudulently?
Not necessarily. When a company experiences a data breach, state law requires that it notify affected individuals. Receiving a letter does not automatically mean that your personal information is being used fraudulently – it just means your information was exposed in a data security incident and has the potential for being misused.
If your Social Security number is involved in a data breach, you’ll want to monitor and check your credit report and financial accounts for any signs of identity theft. Warning signs of identity theft can include withdrawals from your bank account that you can’t explain, missing bills or other mail, contact from debt collectors you don’t recognize, unfamiliar charges on your debit/credit cards, and unfamiliar accounts or charges on your credit report.
If your identity is in fact stolen from a data breach, report it to the Federal Trade Commission on IdentityTheft.gov and receive a personalized recovery plan.
To help protect yourself from identity theft, you can contact each of the three major credit bureaus—Equifax, Experian and TransUnion—to place a credit freeze on your credit report. A credit freeze will restrict access to your credit information and prevent anyone from opening a new credit account in your name.
Freezing your credit in the event of a data breach does not harm your credit score and will stay in place on your credit report until you decide to lift it.
In addition, you can also place a fraud alert on your credit reports, which alerts businesses to check with you before any new account is opened in your name. However, unlike a credit freeze, a fraud alert does not prevent businesses from seeing your credit report data, the FTC says.
Anyone who is concerned about identity theft can place an initial fraud alert on their credit report for free. To do this online, visit the Equifax, Experian or TransUnion website; you don’t have to contact all three. An initial fraud alert typically lasts for one year and can be renewed should a consumer opt to do so.
Another, more serious form of identity theft protection in the event of a data breach is an extended fraud alert, which, like an initial fraud alert, requires a business to contact you before any new credit is issued in your name. To create an extended fraud alert, you must have experienced identity theft and completed an FTC identity theft report or filed a police report.
An extended fraud alert will exist on your credit report for seven years, after which it can be renewed so long as an FTC identity theft or police report is resubmitted. An extended fraud alert can also be set up online through Equifax, Experian or TransUnion.
What should I do if I get a data breach letter?
If you get a data breach notice, make sure to read it closely. It should contain information on what happened, what information was involved, what the company is doing about it, steps you can take to protect yourself, and how you can get more information.
Some companies may offer free credit and/or identity theft monitoring for a period of time following a data breach, and the notice should include instructions on how to sign up. If you’re offered free monitoring, take advantage of it; signing up should not affect any legal claim you may have against the company.
Importantly, if you get a data breach letter, don’t throw it out! If you are interested in helping any of the investigations listed on this page, attorneys will want to see the letter you received.
Why do attorneys need to see my data breach notice?
Attorneys working with ClassAction.org are specifically looking to hear from people with a data breach notice because it essentially serves as proof that the individual was a victim of the incident and makes for a stronger legal claim.
So, I can sue over a data breach?
Yes. If your data was exposed in a security incident, you may be able to sue the company or companies responsible. Dozens of data breach class action lawsuits are filed each month, and this number only continues to increase. You can check out the proposed data breach class actions we’ve covered recently over on our newswire.
How do I know if a data breach letter is legitimate?
To verify whether a data breach notice letter you received is real, the first step is to Google the company name, along with the words “data breach.” More often than not, the search results, which may include news articles, will reveal whether the data breach letter in your possession stems from a real-world cyberattack.
You can also check ClassAction.org directly to see if we’ve reported on the data breach, though it’s important to note that we do not cover every incident.
If you are unsure of whether a data breach notice is legit, contact the company directly through a verified channel to confirm the data breach. Many times, companies post data breach notices on their websites.
Generally, a data breach notice you receive via email will come from a company or organization’s official email address and will usually address you by name.
Do not click on any links in the notice that may look suspicious or don’t match the company’s official website. Lastly, keep an eye out for spelling and grammar mistakes in a data breach notice, as they might indicate that the message is fake.
Can you give me an example of a data breach notification letter?
Absolutely. Here is an example of one sent to Forever 21 employees following a massive data breach that occurred in March 2023. This is the letter sent to consumers affected by the MAPFRE insurance data breach in late August 2023. In some cases, notices may be sent via email.
What if I never heard of the company that sent me a data breach notice?
It’s important to note that, in rare cases, you may not recognize the company sending the letter, but this does not mean it was sent in error.
For instance, a May 2023 data incident affecting a popular file transfer tool caused millions of individuals to have their information exposed. In this instance, many of the data breach letters were sent by a third-party vendor of the affected companies. For example, PBI Research Services sent this letter to customers of Corebridge Financial.
What if I threw my data breach notice out?
It’s important that, if you receive any data breach notice, you do not throw it out. If you’ve already done so, you may want to check the company’s website for their official notice of the breach – it should include the same information that was in your notice. You may also want to check the post for a dedicated number consumers can call with questions about the security incident. It’s worth a call to see if they can resend your notice, but this may not be possible.
What if I think I’m affected but haven’t received a notice?
Notices aren’t always sent immediately after a breach hits the news, so you may just have to be patient. Otherwise, you can check the company’s website to see if they’ve posted a notice about the breach – it may contain a number you can call with questions. They should, at the very least, be able to answer when notices are expected to go out and may also be able to confirm whether you were affected.
Be sure to bookmark our page and come back to it if you believe you’ve been affected by a data breach listed below but haven’t received a notice yet.
What kind of damages can I claim for a data breach?
In general, data breach victims can seek compensation for lost time responding to the incident, out-of-pocket costs related to the breach and loss of privacy.
Depending on the specifics of the data breach, out-of-pocket costs may include some of the following: money spent on preventative measures, such as identity theft and/or credit monitoring; service fees to replace stolen cards; money spent on credit reports and/or credit freezes; the costs associated with obtaining background checks or medical records; increased health insurance costs; and money lost via fraudulent transactions, fraudulent medical bills or stolen tax refunds.
Further damages may become available depending on the type of information exposed. For instance, if a person’s health data is leaked, they may be able to recover money for reputational damage if they are denied medical care or insurance coverage. Likewise, a person whose Social Security number is exposed may be able to recover money for damage to their credit.
How much can I claim in a data breach settlement?
How much you can claim in any data breach settlement will depend on a number of factors, including the specifics of the settlement, the amount of time you spent responding to the incident, the type and total amount of your out-of-pocket expenses, and how many claims are filed. There are never any guarantees as to whether a data breach lawsuit will be successful or how much they could provide to consumers; however, some of the largest data breach settlements obtained via class action lawsuits include a $350 million deal with T-Mobile and a $190 million deal with Capital One.
I’m looking for data breach class action settlements. Where can I find those?
We post class action settlements, including those involving data breaches, over on this page.
How do I know if I was part of a data breach?
If you were affected by a data breach, you should receive a notice via email or regular mail about the incident and what information may have been exposed. All 50 states require that businesses and governments alert consumers if their personal information is breached.
How do I prevent a data breach?
While it may not be possible to completely secure your sensitive information, some steps you can take to protect yourself from a data breach and its fallout include:
- Using strong, complex passwords, preferably a different one for each account;
- Regularly changing passwords;
- Using multi-factor authentication (MFA) when available;
- Encrypting your data;
- Updating your devices’ software regularly;
- Shopping with a credit card, as you may incur less liability in the event of fraudulent charges or if your account is hacked; and
- Consistently monitoring your accounts for fraud, including by setting up account alerts.
It can also be helpful to have a response plan should your personally identifiable information become compromised in a data breach or cyberattack.
Always be wary of unsolicited correspondence from companies with whom you have no relationship, and never give anyone remote access to your devices.
What is the leading cause of data breaches?
According to InfoSec Institute, the leading cause of data breaches is human error, which may involve privilege misuse, stolen credentials or social engineering, a tactic whereby hackers can bypass having to create their own access points by goading individuals with legitimate access to grant it for them. Other common causes of data breaches and cyberattacks include weak credentials, software vulnerabilities, malware, ransomware, DNS attacks, improper API configuration and excessive permissions.
Anything else I should know?
If you’re interested in starting a class action lawsuit, you should know that those who elect to serve as a lead plaintiff are generally entitled to what’s known as a “service award” – that is, an additional payment for their help with the case. Typically, the lead plaintiff in a data breach case does not need to be involved as much as they would in other types of lawsuits. Depositions in these types of class actions are rare, and little documentation and information – aside from the initial data breach notice – is needed.
Plus, if you elect to serve as a lead plaintiff, you can feel good that you’re working to hold a company legally accountable for failing to protect the private information of potentially hundreds of thousands of individuals.
What if there’s a data breach settlement?
In the event of a data breach lawsuit settlement, ClassAction.org will have the complete details over on our class action settlements page.