Connect with us

Security

Navigating the Legal Landscape of Data Breach Appeals: A New Battleground for Cybersecurity Cases

Published

on

Now more than ever, companies face an onslaught of cyberattacks and potential data breaches. While the core steps of incident response (containment, investigation, remediation, and recovery) remain consistent, the legal and regulatory landscape continues to evolve. Organizations must now navigate overlapping notification requirements, compressed timelines, and increased demands for precise information from multiple stakeholders.

In many cases, class action lawsuits are filed within days of a breach becoming public, often seeking substantial damages. Filings have increased dramatically from roughly 100 in 2018 to more than 150 per month in 2025.[i] Some early decisions that allowed plaintiffs to survive motions to dismiss helped fuel this growth.

Recent appellate decisions, particularly from the Fourth and Ninth Circuits, have also signaled a meaningful shift. Many data breach cases now rise or fall not simply on the existence of an incident, but on the record created after the breach. Judges are examining what the company said in its notice letters; whether data was actually accessed, exfiltrated, or misused; whether contractual defenses were preserved; and what internal records show about the incident. As a result, appellate courts are narrowing claims based on speculative harm and placing greater weight on documented facts.

This shift impacts far more than legal departments. CISOs, risk managers, development teams, and public-sector technology officials now help create the record that Courts of Appeal will scrutinize.

What Is Standing?

When the class actions inevitably hit, companies naturally ask reflexive questions: How do we know anyone was actually harmed? Won’t plaintiffs have to prove causation? Isn’t this data already exposed elsewhere?

These questions target a concept known as “standing,” which speaks to whether plaintiffs have a sufficient legal basis to bring a suit in federal court. To establish standing, plaintiffs must show a concrete injury that is traceable to the company’s conduct and can be addressed by a court decision.

In data breach cases, plaintiffs typically point to: (1) an increased risk of future identity theft; (2) the time and money spent on mitigation like credit monitoring; (3) the diminished value of their personal data; and (4) the loss of benefit of their bargain with the company (arguing they would not have shared data if security risks were disclosed).

See also  Canvas Owner Strikes Deal with Hackers to Safeguard Stolen Data

The Supreme Court’s 2021 decision in TransUnion LLC v. Ramirez clarified that plaintiffs cannot rely on speculative injury but must show an “imminent and substantial” risk of future harm. Even so, courts remain divided on whether these common breach allegations meet the standard. For years, plaintiffs treated the mere fact of a breach as sufficient, but recent appellate rulings show otherwise.

Appellate Decisions Are Curbing Pro Forma Allegations.

In Greenstein v. Noblr Reciprocal Exchange[ii], plaintiffs relied on a breach notice stating their driver’s license numbers “may have been accessed.” The Ninth Circuit held this language was insufficient to show their data had actually been stolen, and without that foundation, their future-harm theory failed. The court also rejected the plaintiffs’ attempted workaround of alleging mitigation expenses, finding they too were speculative. The takeaway: breach notifications are not just compliance documents; they can become key litigation exhibits.

The distinction between data being merely accessed and being publicly disseminated is also becoming increasingly central to the standing analysis. The Fourth Circuit reached a similar result in Holmes v. Elephant Insurance,[iii] holding that only the plaintiffs whose driver’s license numbers were actually listed on the dark web had standing to seek damages. Those who alleged only that hackers possessed their information were dismissed as too speculative, along with their claims for mitigation costs, emotional distress, and fear of future theft. The takeaway: the distinction between hacker possession (exfiltration) and public dissemination (posting/leaking) can make or break whether a class action will survive.

In yet another recent example, the Ninth Circuit affirmed dismissal of a lawsuit in Kisil v. Illuminate Education,[iv] because Illuminate had informed the parents of impacted students that Social Security numbers and financial information were not at risk, none of the breached information had been released, and more than three years had passed without any identifiable fraud. The Ninth Circuit found that based on this record the plaintiffs failed to demonstrate an “imminent and substantial” risk of identity theft. The takeaway: even large-scale breaches involving sensitive data may fail to support standing if the factual record shows no exposure of the data and no evidence of misuse.

See also  Apple's Legal Battle: The $634M Masimo Patent Appeal Loss

Standing Turns on the Quality of the Post-Breach Record.

These decisions share a clear theme that standing can turn on the quality of the post-breach record. Courts of Appeal are asking practical questions: Was data actually taken? What categories were involved? Was it publicly exposed? Has misuse occurred? What did the company tell affected individuals?

A company’s incident response activities carry weight. In Greenstein, notice language conveying possibility rather than confirmed theft was central to dismissal. In Kisil, the company’s representations about what data was not at risk shaped the standing analysis. In Holmes, the difference between dark-web publication and mere possession determined who could proceed.

These are not purely legal issues—they are incident response decisions with downstream consequences. Diligent forensics determines what data was actually accessed or exfiltrated. Thorough data review establishes what data elements were actually impacted. Prompt response limits damage and can prevent leaks. Thoughtful notification strategy offers precise information that curtails generalized allegations. In tandem, decisions about privilege (especially over forensic reports and internal communications) can influence how that record is later used in litigation.

Appellate Courts Are Also Shaping Whether Data Breach Cases Proceed as Class Actions.

The tightening of data breach class actions is not limited simply to standing. The Fourth Circuit’s decision in Maldini v. Marriott International[v] shows appellate courts are also deciding whether breach cases can proceed as class actions. The Fourth Circuit court reversed class certification, holding Marriott had not waived the class-action waiver provisions in its guest contracts and that those waivers applied broadly to negligence and consumer-protection claims tied to the loyalty program. The takeaway: customer agreements, online terms, and program conditions can determine whether a class action proceeds. When properly drafted and preserved, these provisions may eliminate class action exposure entirely.

See also  Massive Data Breach at Retail Titan Coupang Affects 33.7 Million Customers

The Decision to Litigate or Settle Remains a Business Judgment.

Recent appellate decisions have raised the bar for plaintiffs, particularly where the exposed data is limited or low-risk, misuse has not occurred, or the data was already publicly available. But litigation is not always the optimal path.

Enhancing Cyber Defense Through Strategic Litigation Planning

When it comes to data breach litigation, the aftermath of the incident is where the real battle lies. Companies need to focus on response communications, contractual structures, and maintaining a strong evidentiary foundation to navigate through legal challenges effectively. This approach ensures that organizations are well-prepared when faced with litigation.

For Chief Information Security Officers (CISOs), risk management leaders, and technical teams, there may be a need for a cultural shift. While technical containment remains crucial, crafting a compelling litigation narrative concurrently is essential. How incidents are portrayed, documented, and communicated to customers can significantly impact the outcome in court.

Based on recent legal precedents, here are some practical recommendations:

  • Early collaboration between legal, technical, and communications teams.
  • Integrating incident communications into the overall litigation strategy.
  • Consistent and intentional preservation of privilege.
  • Drafting notification letters based on verified facts, not assumptions.
  • Avoiding language that suggests misuse certainty without evidence.
  • Reviewing contractual defenses proactively before a breach occurs.

Taylor Sample is a legal expert at Bass, Berry & Sims, specializing in complex data privacy and security cases. With a certification as a Certified Information Privacy Professional (CIPP/US) from the International Association of Privacy Professionals (IAPP), he assists companies in managing breach responses, complying with notification requirements, and defending against regulatory actions and class action lawsuits.

Contact Taylor at [email protected] or visit https://www.bassberry.com for more information.

[i] Data Privacy Filings Continued to Grow As the Playbook Became More Refined, Gerald Maatman, Jr. and Jennifer Riley (https://blogs.duanemorris.com/classactiondefense/2026/01/21/video-dmcar-trend-6-data-privacy-filings-continued-to-grow-as-the-playbook-became-more-refined/)

[ii] No. 22-17023, 2024 WL 3886977 (9th Cir. Aug. 21, 2024)

[iii] No. 23-1782, 156 F.4th 413 (4th Cir. 2025).

[iv] No. 23-4114, 2025 WL 2589000 (9th Cir. Sept. 8, 2025)

[v] No. 24-1064, 2025 WL 1560372 (4th Cir. June 3, 2025)

Trending