Data Breach Lawsuits & Investigations
Every year, hundreds of millions of people are affected by data breaches that can leave them vulnerable to identity theft, credit damage, reputational harm and more.
Class action lawsuits remain one of the strongest ways to hold companies accountable for leaving consumers’, employees’ and patients’ private information unprotected. Indeed, some have resulted in multi-million-dollar settlements on behalf of those who – through no fault of their own – had their information stolen and, in the worst cases, even published on the dark web.
When a data breach lawsuit is successful, it can also require the company at fault to implement new security protocols to ensure the information it is entrusted with – medical, financial and otherwise – stays safe.
Got a data breach notice?
Scroll down to see the list of data breaches attorneys working with ClassAction.org are currently investigating. If you see one that looks familiar, click through to learn more about the breach and what you can do to potentially help get a class action lawsuit started.
And remember – don’t throw your notice away! It essentially serves as proof that you were affected by a specific security incident and can be vital if you choose to take legal action for the harm you suffered.
We update this page often with new data breach investigations, so make sure to bookmark it and come back regularly. You can also sign up for our free newsletter, which is sent on a weekly basis and includes our latest data breach alerts.
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Featured Data Breaches
Park Dental Partners Data Breach
September 2026Park Dental Partners, a resource and support organization, has reported an August 2026 data breach that may have compromised patient information.
Allied Digestive Health Data Breach
August 2026
The service provider for New Jersey-based Allied Digestive Health has reported a data breach involving sensitive information.
McKesson Corporation Data Breach
August 2026McKesson Corporation, a medical supplies and pharmaceuticals company, has reported an August 2026 data breach that exposed certain customers' data.
Nutex Health Data Breach
August 2026Nutex Health, a physician-led healthcare management company, has reported a data breach that may have exposed private information.
Attorneys are investigating claims from ransomware group Interlock that Southeastern Oklahoma State University was breached in July 2026.
Kiewit Corporation Data Breach
August 2026Kiewit Corporation, a major construction and engineering firm, has reported a data breach impacting the information of its employees and contractors.
Recent Data Breaches
Received a notice but don’t see the breach listed here? Tell us about it using this form.
Proliance Surgeons Data Breach
September 2026
Attorneys are investigating claims from ransomware group Payouts King that Washington's Proliance Surgeons was breached in August 2026.
Mountain Laurel Medical Center Data Breach
September 2026Mountain Laurel Medical Center, a multispecialty healthcare group in Maryland, has reported a data breach involving sensitive information.
Park Dental Partners Data Breach
September 2026Park Dental Partners, a resource and support organization, has reported an August 2026 data breach that may have compromised patient information.
About Women OB-Gyn Data Breach
August 2026Virginia's About Women OB-Gyn has reported a December 2025 data breach that may have exposed sensitive personal information.
Bennett College Data Breach
August 2026North Carolina's Bennett College has reported a late 2025 data breach that may have exposed sensitive personal information.
Comprehensive Care Services Data Breach
August 2026Attorneys are investigating claims from hacker group Brain Cipher that Comprehensive Care Services was breached in August 2026.
Neogen Corporation Data Breach
August 2026
Attorneys are investigating claims from hacker group ShinyHunters that Neogen Corporation, a food and animal safety company, was breached in August 2026.
McKesson Corporation Data Breach
August 2026McKesson Corporation, a medical supplies and pharmaceuticals company, has reported an August 2026 data breach that exposed certain customers' data.
Amzur Technologies Data Breach
August 2026Attorneys are investigating claims from hacker group Unsafe that Amzur Technologies, a Florida-based IT support company, was breached in August 2026.
Caduceus Medical Group Data Breach
August 2026Attorneys are investigating claims from ransomware group Anubis that California's Caduceus Medical Group was breached in August 2026.
Our Hospice of South Central Indiana Data Breach
August 2026Attorneys are investigating claims from ransomware group Storm that Our Hospice of South Central Indiana was breached in August 2026.
Tennessee Medical Association Data Breach
August 2026Attorneys are investigating claims from hacker group Lockbit 5 that Tennessee Medical Association was breached in August 2026.
Rockwood Retirement Communities Data Breach
August 2026Washington's Rockwood Retirement Communities has reported a data breach that may have exposed personal and protected health information.
Murfreesboro Medical Clinic Data Breach
August 2026
Murfreesboro Medical Clinic, a Tennessee healthcare center, has reported a data breach involving sensitive information.
Next Level Urgent Care Data Breach
August 2026Attorneys are investigating claims from ransomware group PEAR that Next Level Urgent Care, a Texas healthcare chain, was breached in August 2026.
Integrex Health Data Breach
August 2026Attorneys are investigating claims from ransomware group Qilin that Integrex, a healthcare support company, was breached in August 2026.
Hamilton Company Data Breach
August 2026Attorneys are investigating claims from hacker group AiLock that Hamilton Company, a laboratory technology company, was breached in August 2026.
Ocean Edge Resort & Golf Club Data Breach
August 2026
Ocean Edge Resort & Golf Club, a Cape Cod vacation resort, has reported a July 2025 data breach involving sensitive information.
National Kidney Registry Data Breach
August 2026Attorneys are investigating claims from ransomware group Dire Wolf that National Kidney Registry was breached in August 2026.
Central Ohio Primary Care Physicians Data Breach
August 2026Attorneys are investigating claims from ransomware group Chaos that Central Ohio Primary Care Physicians was breached in August 2026.
Allied Digestive Health Data Breach
August 2026
The service provider for New Jersey-based Allied Digestive Health has reported a data breach involving sensitive information.
University Surgical Associates Data Breach
August 2026University Surgical Associates, an affiliate of the University of Tennessee, has reported a data breach that impacted sensitive information.
Ascent Global Logistics Data Breach
August 2026Ascent Global Logistics, a North American end-to-end logistics services company, has reported a data breach involving sensitive information.
Life Bridges Data Breach
August 2026Life Bridges, a residential and support company serving people with disabilities, has reported a data breach involving sensitive information.
Kiewit Corporation Data Breach
August 2026Kiewit Corporation, a major construction and engineering firm, has reported a data breach impacting the information of its employees and contractors.
Nutex Health Data Breach
August 2026Nutex Health, a physician-led healthcare management company, has reported a data breach that may have exposed private information.
Country-Wide Insurance Data Breach
August 2026Attorneys are investigating claims from ransomware group Booba Project that New York's Country-Wide Insurance was breached in August 2026.
Longhorn Investments Data Breach
August 2026Attorneys are investigating claims from hacker group Coinbase Cartel that Texas-based Longhorn Investments was breached in August 2026.
Attorneys are investigating claims from ransomware group Interlock that Southeastern Oklahoma State University was breached in July 2026.
Integrated Health Systems Data Breach
August 2026Attorneys are investigating claims from hacker group Coinbase Cartel that Integrated Health Systems, an IT support company, was breached in August 2026.
Psychiatric Wellness Center Data Breach
August 2026Psychiatric Wellness Center, a psychiatry practice serving two counties in Southern California, has reported a data breach impacting sensitive information.
Surgeons Choice Medical Center Data Breach
August 2026Michigan's Surgeons Choice Medical Center has disclosed a data breach involving sensitive personal information.
Forrestall CPAs Data Breach
August 2026Forrestall CPAs, a Georgia accounting firm, has reported a December 2025 data breach that exposed sensitive information.
Interim HealthCare Data Breach
August 2026Attorneys are investigating claims from ransomware group Anubis that Interim HealthCare, a hospice and elderly care provider, was breached in August 2026.
Apollo Global Management Data Breach
August 2026Asset management and investment firm Apollo Global Management has reported a July 2026 data breach that exposed sensitive information.
Legacy Bank and Trust Data Breach
August 2026Legacy Bank and Trust, a Missouri-based financial institution, has reported a May 2026 data breach involving sensitive information.
Medical Arts Chemists and Surgicals Data Breach
August 2026Attorneys are investigating claims from hacker group PEAR that New York's Medical Arts Chemists and Surgicals was breached in August 2026.
Austin Plastic Surgery Institute Data Breach
August 2026
Attorneys are investigating claims from ransomware group PEAR that Austin Plastic Surgery Institute was breached in August 2026.
Williams Brothers Construction, a large civil engineering firm based in Texas, has reported a January 2026 data breach involving sensitive information.
Delek US Data Breach
August 2026Attorneys are investigating claims from hacker group Helix that Delek US, an energy and fuel refinery company, was breached in August 2026.
Data Exchange Corporation Data Breach
April 2026Attorneys are investigating claims from ransomware group Payout Kings that DEX, a technology services provider, was breached in April 2026.
Alphanumeric Systems Data Breach
August 2026Attorneys are investigating claims from hacker group Settra that Alphanumeric Systems, a healthcare communications company, was breached in August 2026.
Heart Vascular & Leg Center Data Breach
August 2026
California's Heart Vascular & Leg Center has disclosed a third-party data breach involving sensitive patient information.
Rood & Riddle Equine Hospital Data Breach
August 2026Attorneys are investigating claims from ransomware group Storm that Rood & Riddle Equine Hospital was breached in August 2026.
American Contractors Insurance Group Data Breach
August 2026Attorneys are investigating claims from hacker group Storm that American Contractors Insurance Group was breached in August 2026.
Heights Finance Data Breach
August 2026
Heights Finance, a personal loan provider based in South Carolina, has reported a May 2026 data breach involving sensitive customer information.
Midwest Spine and Brain Institute Data Breach
August 2026Midwest Spine and Brain Institute, a Minnesota-based surgical practice, has reported a third-party breach impacting sensitive information in its care.
Cook Medical Data Breach
August 2026Attorneys are investigating claims from hacker group ShinyHunters that Cook Medical, a large medical device manufacturer, was breached in August 2026.
Arizona State University Data Breach
August 2026Attorneys are investigating claims from ransomware group Dire Wolf that Arizona State University was breached in August 2026.
River City Data Data Breach
June 2026River City Data, a document digitization company, has disclosed a data breach involving the sensitive information of its clients' patients.
Lansing Urgent Care Data Breach
August 2026Attorneys are investigating claims from hacker group INC Ransom that Lansing Urgent Care, an eight-clinic healthcare group, was breached in August 2026.
Carhartt Data Breach
August 2026Attorneys are investigating claims from hacker group ShinyHunters that Michigan-based apparel brand Carhartt was breached in August 2026.
Lennar Mortgage Data Breach
August 2026Lennar Mortgage, a subsidiary of major nationwide homebuilder Lennar Corporation, has disclosed a data breach impacting sensitive personal information.
NFI North Data Breach
August 2026NFI North, an individual and family services organization serving Maine and New Hampshire, has disclosed a September 2025 data breach impacting sensitive information.
Corporation Service Company Data Breach
August 2026Corporation Service Company, a multinational business services firm, has disclosed an August 2025 data breach affecting sensitive information.
United Group of Companies Data Breach
August 2026Attorneys are investigating claims from ransomware group Storm that United Group of Companies, a real estate developer, was breached in August 2026.
Cornelius Data Breach
August 2026Attorneys are investigating claims from ransomware group Cl0p that Cornelius, a nationwide beverage equipment vendor, was breached in August 2026.
Minnesota ENT Data Breach
August 2026Minnesota ENT, a group of ear, nose and throat specialists, has disclosed a data breach affecting personal and protected health information.
Universal Plant Services Data Breach
August 2026Universal Plant Services, an industrial maintenance and engineering services provider, has reported a data breach involving sensitive information.
Flowco Data Breach
August 2026Attorneys are investigating claims from hacker group Settra that Flowco, an oil and gas technology company, was breached in June 2026.
Health Carousel Data Breach
August 2026Attorneys are investigating claims from ransomware group Dire Wolf that Health Carousel, a healthcare staffing company, was breached in August 2026.
AngMar Data Breach
August 2026Attorneys are investigating claims from hacker group Interlock that Angmar, a home healthcare management company, was breached in August 2026.
Cleaver-Brooks Data Breach
August 2026Attorneys are investigating claims from hacker group Anubis that Cleaver-Brooks, a boiler and thermal solutions company, was breached in August 2026.
Attorneys are investigating claims from ransomware group Genesis that Consolidated Medical Practices of Memphis was breached in August 2026.
Kovack Financial Data Breach
August 2026Kovack Financial, an investment advisory firm in Florida, has reported an August 2025 data breach affecting sensitive information.
Minidoka Memorial Hospital Data Breach
August 2026Idaho's Minidoka Memorial Hospital has reported an April 2026 data breach impacting sensitive patient information.
USA DeBusk Data Breach
August 2026
USA DeBusk, an industrial services provider based in Texas, has reported a data breach involving sensitive information.
Indiana University Health Data Breach
August 2026Attorneys are investigating claims from hacker group Storm that Indiana University Health was breached in August 2026.
Eva Care Group Data Breach
August 2026
Attorneys are investigating claims from ransomware group The Gentlemen that California-based Eva Care Group was breached in August 2026.
Oculus Pathology Data Breach
August 2026Texas-based Oculus Pathology has reported a data breach that may have exposed personally identifiable and protected health information.
ABC Supply Data Breach
August 2026ABC Supply, a nationwide roofing supplies wholesaler, has reported a data breach involving sensitive information.
Liberty Healthcare Data Breach
August 2026Attorneys are investigating claims from ransomware group Storm that Pennsylvania-based Liberty Healthcare was breached in August 2026.
LabPharma Data Breach
August 2026Attorneys are investigating claims from ransomware group Dark Project that LabPharma, a Florida clinical laboratory, was breached in mid-2026.
Pioneer Bank Data Breach
August 2026Attorneys are investigating claims from ransomware group Storm that New York-based Pioneer Bank was breached in August 2026.
Park Place Behavioral Health Care Data Breach
August 2026Attorneys are investigating claims from ransomware group Insomnia that Florida-based Park Place Behavioral Health Care was breached in July 2026.
Heart of America Medical Center Data Breach
August 2026Heart of America Medical Center, a North Dakota medical provider, has reported a data breach involving sensitive patient information.
Pavillon Data Breach
August 2026Attorneys are investigating claims from hacker group Global Secret Group that Pavillon, a North Carolina addiction treatment center, was breached in August 2026.
Leviton Data Breach
August 2026Attorneys are investigating claims from hacker group Dark Project that electronics manufacturer Leviton was breached in July 2026.
Mile Bluff Medical Center Data Breach
August 2026Wisconsin's Mile Bluff Medical Center has reported a data breach impacting sensitive patient and employee information.
Atlantic Tomorrow's Office Data Breach
August 2026Attorneys are investigating claims from ransomware group Chaos that New York-based Atlantic, Tomorrow's Office was breached in August 2026.
Attorneys are investigating claims from ransomware group Qilin that Texas-based Community Management Associates was breached in July 2026.
Lantis Enterprises Data Breach
August 2026Attorneys are investigating claims from hacker group INC Ransom that South Dakota-based Lantis Enterprises was breached in August 2026.
First Tek Data Breach
August 2026Attorneys are investigating claims from ransomware group Play that IT support company First Tek was breached in August 2026.
Healthcare Highways Data Breach
August 2026Attorneys are investigating claims from hacker group Chaos that Healthcare Highways, a medical provider network company, was breached in August 2026.
Blackburn's Physicians Pharmacy Data Breach
August 2026Attorneys are investigating claims from ransomware group Anubis that Pennsylvania-based Blackburn's Physicians Pharmacy was breached in August 2026.
Miles Partnership Data Breach
July 2026Miles Partnership, a global tourism marketing agency, has reported a data breach involving sensitive information.
Cameron Regional Medical Center Data Breach
August 2026Missouri-based Cameron Regional Medical Center has reported a June 2026 data breach involving personal and protected health information.
Winn-Dixie Data Breach
August 2026Attorneys are investigating claims from hacker group Anubis that grocery chain Winn-Dixie was breached in August 2026.
Valley Kidney Specialists Data Breach
July 2026Pennsylvania-based Valley Kidney Specialists has disclosed a June 2026 data breach involving sensitive patient information.
Peachtree Group Data Breach
July 2026Attorneys are investigating claims from hacker group The Gentlemen that Peachtree Group, a Georgia-based investment firm, was breached in July 2026.
Cambridge Management Data Breach
August 2026Attorneys are investigating claims from ransomware group Play that Cambridge Management, an affordable housing management company, was breached in August 2026.
Amgen Data Breach
July 2026Biopharmaceutical manufacturing company Amgen has reported a July 2026 data breach affecting sensitive information.
Cardiovascular Institute of New England, a Rhode Island-based healthcare provider, has reported a data breach involving sensitive patient and employee information.
Sonitor Technologies Data Breach
July 2026Attorneys are investigating claims from ransomware group PEAR that healthcare support company Sonitor Technologies was breached in July 2026.
Hawaii Family Dental Data Breach
July 2026Attorneys are investigating claims from ransomware group Qilin that Hawaii Family Dental, a 12-location dental practice, was breached in July 2026.
Kansas City, Missouri-based Nephrology Associates has reported a January-to-April 2026 data breach involving sensitive information.
Analog Devices Data Breach
July 2026Analog Devices, a multibillion-dollar semiconductor and electrical manufacturing company, has reported a data breach detected in June 2026.
HealthStream Data Breach
July 2026HealthStream, a software solutions company, has disclosed a data breach impacting employee and certain customers' information.
Sunrise Company Data Breach
July 2026Sunrise Company, a real estate developer based in California, has disclosed a data breach potentially affecting sensitive information.
Join the Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Data Breach FAQs
What is a data breach?
A data breach is a cybersecurity incident whereby an unauthorized party or parties gain access to sensitive, protected and/or confidential information belonging to an individual or organization.
The information stolen or compromised in a data breach can include, but may not be limited to, names, email addresses, physical addresses, passwords, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, credit card numbers, debit card numbers, CVV numbers, medical information, diagnoses, health insurance information, biometric data, and taxpayer ID numbers. Data breaches also may involve sensitive business information, trade secrets or national security matters.
The causes of a data breach, sometimes called a cyberattack, can include software vulnerabilities, email-based phishing attempts, ransomware, accidental disclosure, access improperly given to computer systems, a lack of encryption, or hacking perpetrated by cybercriminals.
I got a data breach notification. Does this definitely mean my info is being used fraudulently?
Not necessarily. When a company experiences a data breach, state law requires that it notify affected individuals. Receiving a letter does not automatically mean that your personal information is being used fraudulently – it just means your information was exposed in a data security incident and has the potential for being misused.
If your Social Security number is involved in a data breach, you’ll want to monitor and check your credit report and financial accounts for any signs of identity theft. Warning signs of identity theft can include withdrawals from your bank account that you can’t explain, missing bills or other mail, contact from debt collectors you don’t recognize, unfamiliar charges on your debit/credit cards, and unfamiliar accounts or charges on your credit report.
If your identity is in fact stolen from a data breach, report it to the Federal Trade Commission on IdentityTheft.gov and receive a personalized recovery plan.
To help protect yourself from identity theft, you can contact each of the three major credit bureaus—Equifax, Experian and TransUnion—to place a credit freeze on your credit report. A credit freeze will restrict access to your credit information and prevent anyone from opening a new credit account in your name.
Freezing your credit in the event of a data breach does not harm your credit score and will stay in place on your credit report until you decide to lift it.
In addition, you can also place a fraud alert on your credit reports, which alerts businesses to check with you before any new account is opened in your name. However, unlike a credit freeze, a fraud alert does not prevent businesses from seeing your credit report data, the FTC says.
Anyone who is concerned about identity theft can place an initial fraud alert on their credit report for free. To do this online, visit the Equifax, Experian or TransUnion website; you don’t have to contact all three. An initial fraud alert typically lasts for one year and can be renewed should a consumer opt to do so.
Another, more serious form of identity theft protection in the event of a data breach is an extended fraud alert, which, like an initial fraud alert, requires a business to contact you before any new credit is issued in your name. To create an extended fraud alert, you must have experienced identity theft and completed an FTC identity theft report or filed a police report.
An extended fraud alert will exist on your credit report for seven years, after which it can be renewed so long as an FTC identity theft or police report is resubmitted. An extended fraud alert can also be set up online through Equifax, Experian or TransUnion.
What should I do if I get a data breach letter?
If you get a data breach notice, make sure to read it closely. It should contain information on what happened, what information was involved, what the company is doing about it, steps you can take to protect yourself, and how you can get more information.
Some companies may offer free credit and/or identity theft monitoring for a period of time following a data breach, and the notice should include instructions on how to sign up. If you’re offered free monitoring, take advantage of it; signing up should not affect any legal claim you may have against the company.
Importantly, if you get a data breach letter, don’t throw it out! If you are interested in helping any of the investigations listed on this page, attorneys will want to see the letter you received.
Why do attorneys need to see my data breach notice?
Attorneys working with ClassAction.org are specifically looking to hear from people with a data breach notice because it essentially serves as proof that the individual was a victim of the incident and makes for a stronger legal claim.
So, I can sue over a data breach?
Yes. If your data was exposed in a security incident, you may be able to sue the company or companies responsible. Dozens of data breach class action lawsuits are filed each month, and this number only continues to increase. You can check out the proposed data breach class actions we’ve covered recently over on our newswire.
How do I know if a data breach letter is legitimate?
To verify whether a data breach notice letter you received is real, the first step is to Google the company name, along with the words “data breach.” More often than not, the search results, which may include news articles, will reveal whether the data breach letter in your possession stems from a real-world cyberattack.
You can also check ClassAction.org directly to see if we’ve reported on the data breach, though it’s important to note that we do not cover every incident.
If you are unsure of whether a data breach notice is legit, contact the company directly through a verified channel to confirm the data breach. Many times, companies post data breach notices on their websites.
Generally, a data breach notice you receive via email will come from a company or organization’s official email address and will usually address you by name.
Do not click on any links in the notice that may look suspicious or don’t match the company’s official website. Lastly, keep an eye out for spelling and grammar mistakes in a data breach notice, as they might indicate that the message is fake.
Can you give me an example of a data breach notification letter?
Absolutely. Here is an example of one sent to Forever 21 employees following a massive data breach that occurred in March 2023. This is the letter sent to consumers affected by the MAPFRE insurance data breach in late August 2023. In some cases, notices may be sent via email.
What if I never heard of the company that sent me a data breach notice?
It’s important to note that, in rare cases, you may not recognize the company sending the letter, but this does not mean it was sent in error.
For instance, a May 2023 data incident affecting a popular file transfer tool caused millions of individuals to have their information exposed. In this instance, many of the data breach letters were sent by a third-party vendor of the affected companies. For example, PBI Research Services sent this letter to customers of Corebridge Financial.
What if I threw my data breach notice out?
It’s important that, if you receive any data breach notice, you do not throw it out. If you’ve already done so, you may want to check the company’s website for their official notice of the breach – it should include the same information that was in your notice. You may also want to check the post for a dedicated number consumers can call with questions about the security incident. It’s worth a call to see if they can resend your notice, but this may not be possible.
What if I think I’m affected but haven’t received a notice?
Notices aren’t always sent immediately after a breach hits the news, so you may just have to be patient. Otherwise, you can check the company’s website to see if they’ve posted a notice about the breach – it may contain a number you can call with questions. They should, at the very least, be able to answer when notices are expected to go out and may also be able to confirm whether you were affected.
Be sure to bookmark our page and come back to it if you believe you’ve been affected by a data breach listed below but haven’t received a notice yet.
What kind of damages can I claim for a data breach?
In general, data breach victims can seek compensation for lost time responding to the incident, out-of-pocket costs related to the breach and loss of privacy.
Depending on the specifics of the data breach, out-of-pocket costs may include some of the following: money spent on preventative measures, such as identity theft and/or credit monitoring; service fees to replace stolen cards; money spent on credit reports and/or credit freezes; the costs associated with obtaining background checks or medical records; increased health insurance costs; and money lost via fraudulent transactions, fraudulent medical bills or stolen tax refunds.
Further damages may become available depending on the type of information exposed. For instance, if a person’s health data is leaked, they may be able to recover money for reputational damage if they are denied medical care or insurance coverage. Likewise, a person whose Social Security number is exposed may be able to recover money for damage to their credit.
How much can I claim in a data breach settlement?
How much you can claim in any data breach settlement will depend on a number of factors, including the specifics of the settlement, the amount of time you spent responding to the incident, the type and total amount of your out-of-pocket expenses, and how many claims are filed. There are never any guarantees as to whether a data breach lawsuit will be successful or how much they could provide to consumers; however, some of the largest data breach settlements obtained via class action lawsuits include a $350 million deal with T-Mobile and a $190 million deal with Capital One.
I’m looking for data breach class action settlements. Where can I find those?
We post class action settlements, including those involving data breaches, over on this page.
How do I know if I was part of a data breach?
If you were affected by a data breach, you should receive a notice via email or regular mail about the incident and what information may have been exposed. All 50 states require that businesses and governments alert consumers if their personal information is breached.
How do I prevent a data breach?
While it may not be possible to completely secure your sensitive information, some steps you can take to protect yourself from a data breach and its fallout include:
- Using strong, complex passwords, preferably a different one for each account;
- Regularly changing passwords;
- Using multi-factor authentication (MFA) when available;
- Encrypting your data;
- Updating your devices’ software regularly;
- Shopping with a credit card, as you may incur less liability in the event of fraudulent charges or if your account is hacked; and
- Consistently monitoring your accounts for fraud, including by setting up account alerts.
It can also be helpful to have a response plan should your personally identifiable information become compromised in a data breach or cyberattack.
Always be wary of unsolicited correspondence from companies with whom you have no relationship, and never give anyone remote access to your devices.
What is the leading cause of data breaches?
According to InfoSec Institute, the leading cause of data breaches is human error, which may involve privilege misuse, stolen credentials or social engineering, a tactic whereby hackers can bypass having to create their own access points by goading individuals with legitimate access to grant it for them. Other common causes of data breaches and cyberattacks include weak credentials, software vulnerabilities, malware, ransomware, DNS attacks, improper API configuration and excessive permissions.
Anything else I should know?
If you’re interested in starting a class action lawsuit, you should know that those who elect to serve as a lead plaintiff are generally entitled to what’s known as a “service award” – that is, an additional payment for their help with the case. Typically, the lead plaintiff in a data breach case does not need to be involved as much as they would in other types of lawsuits. Depositions in these types of class actions are rare, and little documentation and information – aside from the initial data breach notice – is needed.
Plus, if you elect to serve as a lead plaintiff, you can feel good that you’re working to hold a company legally accountable for failing to protect the private information of potentially hundreds of thousands of individuals.
What if there’s a data breach settlement?
In the event of a data breach lawsuit settlement, ClassAction.org will have the complete details over on our class action settlements page.