Now more than ever, companies face an onslaught of cyberattacks and potential data breaches. While the core steps of incident response (containment, investigation, remediation, and recovery) remain consistent, the legal and regulatory landscape continues to evolve. Organizations must now navigate overlapping notification requirements, compressed timelines, and increased demands for precise information from multiple stakeholders.
In many cases, class action lawsuits are filed within days of a breach becoming public, often seeking substantial damages. Filings have increased dramatically from roughly 100 in 2018 to more than 150 per month in 2025.[i] Some early decisions that allowed plaintiffs to survive motions to dismiss helped fuel this growth.
Recent appellate decisions, particularly from the Fourth and Ninth Circuits, have also signaled a meaningful shift. Many data breach cases now rise or fall not simply on the existence of an incident, but on the record created after the breach. Judges are examining what the company said in its notice letters; whether data was actually accessed, exfiltrated, or misused; whether contractual defenses were preserved; and what internal records show about the incident. As a result, appellate courts are narrowing claims based on speculative harm and placing greater weight on documented facts.
This shift impacts far more than legal departments. CISOs, risk managers, development teams, and public-sector technology officials now help create the record that Courts of Appeal will scrutinize.
What Is Standing?
When the class actions inevitably hit, companies naturally ask reflexive questions: How do we know anyone was actually harmed? Won’t plaintiffs have to prove causation? Isn’t this data already exposed elsewhere?
These questions target a concept known as “standing,” which speaks to whether plaintiffs have a sufficient legal basis to bring a suit in federal court. To establish standing, plaintiffs must show a concrete injury that is traceable to the company’s conduct and can be addressed by a court decision.
In data breach cases, plaintiffs typically point to: (1) an increased risk of future identity theft; (2) the time and money spent on mitigation like credit monitoring; (3) the diminished value of their personal data; and (4) the loss of benefit of their bargain with the company (arguing they would not have shared data if security risks were disclosed).
The Supreme Court’s 2021 decision in TransUnion LLC v. Ramirez clarified that plaintiffs cannot rely on speculative injury but must show an “imminent and substantial” risk of future harm. Even so, courts remain divided on whether these common breach allegations meet the standard. For years, plaintiffs treated the mere fact of a breach as sufficient, but recent appellate rulings show otherwise.
Appellate Decisions Are Curbing Pro Forma Allegations.
In Greenstein v. Noblr Reciprocal Exchange[ii], plaintiffs relied on a breach notice stating their driver’s license numbers “may have been accessed.” The Ninth Circuit held this language was insufficient to show their data had actually been stolen, and without that foundation, their future-harm theory failed. The court also rejected the plaintiffs’ attempted workaround of alleging mitigation expenses, finding they too were speculative. The takeaway: breach notifications are not just compliance documents; they can become key litigation exhibits.
The distinction between data being merely accessed and being publicly disseminated is also becoming increasingly central to the standing analysis. The Fourth Circuit reached a similar result in Holmes v. Elephant Insurance,[iii] holding that only the plaintiffs whose driver’s license numbers were actually listed on the dark web had standing to seek damages. Those who alleged only that hackers possessed their information were dismissed as too speculative, along with their claims for mitigation costs, emotional distress, and fear of future theft. The takeaway: the distinction between hacker possession (exfiltration) and public dissemination (posting/leaking) can make or break whether a class action will survive.
In yet another recent example, the Ninth Circuit affirmed dismissal of a lawsuit in Kisil v. Illuminate Education,[iv] because Illuminate had informed the parents of impacted students that Social Security numbers and financial information were not at risk, none of the breached information had been released, and more than three years had passed without any identifiable fraud. The Ninth Circuit found that based on this record the plaintiffs failed to demonstrate an “imminent and substantial” risk of identity theft. The takeaway: even large-scale breaches involving sensitive data may fail to support standing if the factual record shows no exposure of the data and no evidence of misuse.
Standing Turns on the Quality of the Post-Breach Record.
These decisions share a clear theme that standing can turn on the quality of the post-breach record. Courts of Appeal are asking practical questions: Was data actually taken? What categories were involved? Was it publicly exposed? Has misuse occurred? What did the company tell affected individuals?
A company’s incident response activities carry weight. In Greenstein, notice language conveying possibility rather than confirmed theft was central to dismissal. In Kisil, the company’s representations about what data was not at risk shaped the standing analysis. In Holmes, the difference between dark-web publication and mere possession determined who could proceed.
These are not purely legal issues—they are incident response decisions with downstream consequences. Diligent forensics determines what data was actually accessed or exfiltrated. Thorough data review establishes what data elements were actually impacted. Prompt response limits damage and can prevent leaks. Thoughtful notification strategy offers precise information that curtails generalized allegations. In tandem, decisions about privilege (especially over forensic reports and internal communications) can influence how that record is later used in litigation.
Appellate Courts Are Also Shaping Whether Data Breach Cases Proceed as Class Actions.
The tightening of data breach class actions is not limited simply to standing. The Fourth Circuit’s decision in Maldini v. Marriott International[v] shows appellate courts are also deciding whether breach cases can proceed as class actions. The Fourth Circuit court reversed class certification, holding Marriott had not waived the class-action waiver provisions in its guest contracts and that those waivers applied broadly to negligence and consumer-protection claims tied to the loyalty program. The takeaway: customer agreements, online terms, and program conditions can determine whether a class action proceeds. When properly drafted and preserved, these provisions may eliminate class action exposure entirely.
The Decision to Litigate or Settle Remains a Business Judgment.
Recent appellate decisions have raised the bar for plaintiffs, particularly where the exposed data is limited or low-risk, misuse has not occurred, or the data was already publicly available. But litigation is not always the optimal path.

