home  /  insights  /  standing-in-data-breach-cases
Causation & Exposure

What injury does a data breach plaintiff have to show to get into federal court?

A concrete harm, and since TransUnion LLC v. Ramirez the mere risk of future harm will not by itself supply one in a damages suit. What counts as concrete after that is where the circuits have gone different ways.

September 15, 2026 · 11 min read

The short answer

A concrete injury, and under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), the risk that harm might arrive later is generally not one. The Court called persuasive the argument “that in a suit for damages, the mere risk of future harm, standing alone, cannot qualify as a concrete harm — at least unless the exposure to the risk of future harm itself causes a separate concrete harm,” held that the risk of future harm could not supply the basis for the standing of the class members whose reports were never disseminated, and held that “[e]very class member must have Article III standing in order to recover individual damages.” The federal courts of appeals have since divided over what satisfies that test after a data breach — the Third Circuit accepts a substantial risk of identity theft where it has produced present harms, while the Fourth Circuit in 2025 required that the information actually have been made public. Whether a particular plaintiff clears the bar in a particular forum is a question of law for counsel, not a technical finding, and the Institute describes the landscape rather than resolving it.

What this article establishes

  • In TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), the Supreme Court held that 1,853 class members whose misleading credit reports were sent to third parties had standing and the 6,332 whose reports were not disseminated did not — summarized in the opinion as “No concrete harm, no standing.”
  • TransUnion described as persuasive the argument that “in a suit for damages, the mere risk of future harm, standing alone, cannot qualify as a concrete harm — at least unless the exposure to the risk of future harm itself causes a separate concrete harm.”
  • The Third Circuit in Clemens v. ExecuPharm, Inc., 48 F.4th 146 (3d Cir. 2022), held that a plaintiff facing a substantial risk of identity theft satisfies concreteness where the exposure to that risk caused additional, currently felt harms such as mitigation spending or emotional distress.
  • The Fourth Circuit in Holmes v. Elephant Insurance Co., No. 23-1782 (4th Cir. Oct. 14, 2025), held that two plaintiffs who found their driver’s license numbers listed on the dark web had a concrete injury analogous to public disclosure of private information, while two whose numbers were held only by the hackers did not.
  • Holmes also held that the two plaintiffs whose driver’s license numbers were never published “cannot furnish standing for damages solely through expenditures of time and allegations of emotional distress,” relying on Clapper v. Amnesty International USA, 568 U.S. 398, 402 (2013), that plaintiffs “cannot manufacture standing by choosing to make expenditures based on hypothetical future harm that is not [imminent].”

What did the Supreme Court actually hold in TransUnion v. Ramirez?

In TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), decided June 25, 2021, the Supreme Court held that a plaintiff suing for damages in federal court must show a concrete harm, and that a statutory violation alone does not supply one. The case was brought under the Fair Credit Reporting Act by a class of 8,185 people whose internal TransUnion credit files carried alerts flagging them as potential matches to a government list of terrorists and serious criminals. For 1,853 of them, including the named plaintiff Sergio Ramirez, TransUnion had provided the misleading reports to third-party businesses. For the other 6,332, it had not.

The Court split the class along exactly that line. The 1,853 class members whose reports were disseminated “have demonstrated concrete reputational harm and thus have Article III standing to sue on the reasonable-procedures claim.” The 6,332 whose reports stayed internal “have not demonstrated concrete harm and thus lack Article III standing” on that claim. On two further claims about the format of TransUnion’s mailings, no class member other than Ramirez himself had standing. The Court summarized the whole holding in five words: “No concrete harm, no standing.”

Two further points in the opinion do a great deal of work in later breach litigation. The first is that “Every class member must have Article III standing in order to recover individual damages.” The second is that standing must be shown “with the manner and degree of evidence required at the successive stages of the litigation,” so allegations that suffice on a motion to dismiss must be proved at trial. TransUnion is not a data breach case, but it is the framework every data breach standing decision since has had to work within.

Does the risk of future identity theft after a breach count as an injury?

Not on its own in a suit for damages, under TransUnion, and that is the sentence the whole area turns on. The Court described as persuasive TransUnion’s argument “that in a suit for damages, the mere risk of future harm, standing alone, cannot qualify as a concrete harm — at least unless the exposure to the risk of future harm itself causes a separate concrete harm.” The Court distinguished Clapper v. Amnesty International USA, 568 U.S. 398 (2013), on the ground that Clapper involved injunctive relief: a person exposed to a sufficiently imminent and substantial risk may seek forward-looking relief, but “a plaintiff’s standing to seek injunctive relief does not necessarily mean that the plaintiff has standing to seek retrospective damages.”

The Court added a second, independent ground. Even setting aside that problem, the 6,332 plaintiffs “did not factually establish a sufficient risk of future harm to support Article III standing,” because the risk they identified — that TransUnion might disseminate the alerts at any moment — was too speculative on the trial record. The Court also noted that those plaintiffs had not shown they even knew the alerts were in their files, remarking that it is “difficult to see how a risk of future harm could supply the basis for a plaintiff’s standing when the plaintiff did not even know that there was a risk of future harm.”

What TransUnion left open matters as much as what it closed. In footnote 7 the Court observed that a plaintiff’s knowledge of exposure to a risk of future harm “could cause its own current emotional or psychological harm,” and expressly took no position on whether or how such a harm could suffice for Article III purposes. That footnote is the doorway through which most post-2021 data breach standing arguments have been run.

Which federal circuits accept a risk of future misuse as an injury, and which do not?

The Third Circuit accepts it where the risk has produced present harms, and the Fourth Circuit, most recently, does not. In Clemens v. ExecuPharm, Inc., 48 F.4th 146 (3d Cir. 2022), decided September 2, 2022, a former employee’s Social Security number and financial account information were taken in a phishing attack and posted on the dark web. The Third Circuit held “that in the data breach context, where the asserted theory of injury is a substantial risk of identity theft or fraud, a plaintiff suing for damages can satisfy concreteness as long as he alleges that the exposure to that substantial risk caused additional, currently felt concrete harms,” giving emotional distress and mitigation spending as examples. It also set out non-exhaustive factors bearing on imminence, among them whether the breach was intentional.

In Holmes v. Elephant Insurance Co., No. 23-1782 (4th Cir. Oct. 14, 2025), a published opinion by Judge Richardson, the Fourth Circuit took a different route. It held that the common-law tort of public disclosure of private information supplies the concrete analogue, so the information “must be accessible to many.” Two named plaintiffs who alleged finding their driver’s license numbers listed on the dark web had a concrete injury. Two others, whose numbers were held by the hackers but not published, did not: the Fourth Circuit called them “materially indistinguishable from the 6,332 plaintiffs in TransUnion.” It also held that even for the two whose data was published, future fraudulent impersonation was not imminent, relying on its earlier decision in Beck v. McDonald, 848 F.3d 262 (4th Cir. 2017).

The Holmes opinion is useful precisely because it maps the disagreement rather than eliding it. The Fourth Circuit acknowledged that “our sister circuits have found imminent injury to plaintiffs in similar circumstances,” citing Bohnak v. Marsh & McLennan Cos., 79 F.4th 276, 289 (2d Cir. 2023), Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365, 375-76 (1st Cir. 2023), Attias v. CareFirst, Inc., 865 F.3d 620, 628-29 (D.C. Cir. 2017), and Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688, 693-94 (7th Cir. 2015), along with McMorris v. Carlos Lopez & Associates, 995 F.3d 295, 301 (2d Cir. 2021), Clemens, and Green-Cooper v. Brinker International, Inc., 73 F.4th 883, 889-90 (11th Cir. 2023), for the proposition that a targeted attack and a dark web listing weigh in favor of standing. Its objection was that those courts “have not explained how a data breach presents a substantial risk that any one piece of personal information will be misused in the future.” Those characterizations belong to the Fourth Circuit: they are how Holmes described its sister circuits, and the decisions of the First, Second, Seventh, Eleventh and D.C. Circuits are not restated here from their own opinions.

Can credit monitoring costs or time spent responding to a breach create standing by themselves?

Not where the underlying future harm is speculative, and the Fourth Circuit extended that rule to time in 2025. Holmes v. Elephant Insurance Co. held that the two named plaintiffs whose driver’s license numbers were never published “cannot furnish standing for damages solely through expenditures of time and allegations of emotional distress,” resting on Clapper v. Amnesty International USA, 568 U.S. 398, 402 (2013), that plaintiffs “cannot manufacture standing by choosing to make expenditures based on hypothetical future harm that is not [imminent].” The court reasoned that the worry about mitigation costs — “anyone can pay to mitigate anything, however unlikely” — applies equally to hours: “rather than spend a dollar, plaintiffs could spend a minute.”

The Fourth Circuit was candid that the doctrinal home of this rule is unsettled. In a footnote it observed that it is unclear whether the bar on freestanding mitigation costs goes to injury in fact or to traceability, and cited its own Hutton v. National Board of Examiners in Optometry, 892 F.3d 613, 622 (4th Cir. 2018), and the Seventh Circuit’s Remijas for the proposition that mitigation expenses do not qualify where the harm is not imminent. “Either way,” it concluded, “the result is the same — mitigation costs cannot furnish standing on their own.”

That is not the same as saying mitigation spending is irrelevant. The Third Circuit’s Clemens treats mitigation spending and emotional distress as the currently felt harms that convert a substantial risk into a concrete injury. The two courts are not applying the same sequence: Clemens asks whether a substantial risk produced present harm, and Holmes asks first whether the risk is imminent at all, treating mitigation as incapable of supplying what is missing. A practitioner reading only one of them will badly misjudge the other forum.

What does evidence of actual misuse do to the standing analysis?

It largely removes the argument, which is why the technical record about misuse carries weight far beyond its size. TransUnion itself illustrates the mechanism: the 1,853 class members won on standing not because the risk to them was greater but because something had already happened — their reports had gone to third parties, which the Court treated as concrete reputational harm with a common-law analogue in defamation. Where a plaintiff can show a fraudulent account, a fraudulent filing, or an unauthorized charge traceable to the exposed data, the court is no longer being asked to price a probability.

Publication does similar work in the circuits that have accepted it. In Holmes, the injury the Fourth Circuit recognized was not future fraud but the present fact of the driver’s license numbers being listed on the dark web “against their justifiable wishes,” which the court held analogous to public disclosure of private information and therefore sufficient for retrospective relief. In Clemens, the dark web posting was central to the Third Circuit’s conclusion that the risk was substantial rather than hypothetical.

The difficulty is that establishing misuse traceable to a particular breach is frequently impossible, and no amount of legal argument changes that. Records from many incidents are aggregated and resold before use, so identifiers like name, address and Social Security number rarely carry a fingerprint back to one source. The Institute covers what the technical record does and does not support in exposure is not misuse and in more depth at exposure versus misuse.

What does the standing question mean for the evidence a breach case needs?

It moves several technical questions forward in the schedule, because they now bear on jurisdiction rather than only on damages. Whether data was exfiltrated as opposed to merely reachable, whether the specific dataset has surfaced in circulation and is identifiable as this one, whether the attack was targeted, and which fields were involved are all facts that the decisions above treat as material to standing. They are also facts that depend on evidence with short lifespans — egress telemetry, firewall and proxy records, staging artifacts — which is why the Institute treats preservation in what disappears first after a breach as the first question on the site.

TransUnion’s instruction that every class member must have standing to recover individual damages, and that standing must be supported by the evidence appropriate to each stage, also means the question does not go away after the pleadings. What is enough on a motion to dismiss is not enough at certification or trial, and an analysis built for the first will not survive the third.

Two boundaries are worth stating plainly. Whether a given plaintiff has standing in a given forum is a question of law that varies by circuit and is genuinely unsettled; counsel decides it, and any technical expert offering a confident general answer has stepped outside their evidence. And what a claim is worth, once standing is established, belongs to the Economic Damages Institute at economicdamagesinstitute.com. This Institute covers whether the technical chain holds, link by link, in breach causation.

For informational purposes only. Not legal advice, not a security assessment, and not an opinion on whether any organization’s security was reasonable.

Related

The practice area

incident conciergeorientation · not a security opinion
Happy to. Tell me roughly what happened and when it was discovered — and whether anything has been rebooted, reimaged or restored since. That last answer decides what evidence is still recoverable, so it is worth establishing before anything else.