What did the Supreme Court actually hold in TransUnion v. Ramirez?
In TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), decided June 25, 2021, the Supreme Court held that a plaintiff suing for damages in federal court must show a concrete harm, and that a statutory violation alone does not supply one. The case was brought under the Fair Credit Reporting Act by a class of 8,185 people whose internal TransUnion credit files carried alerts flagging them as potential matches to a government list of terrorists and serious criminals. For 1,853 of them, including the named plaintiff Sergio Ramirez, TransUnion had provided the misleading reports to third-party businesses. For the other 6,332, it had not.
The Court split the class along exactly that line. The 1,853 class members whose reports were disseminated “have demonstrated concrete reputational harm and thus have Article III standing to sue on the reasonable-procedures claim.” The 6,332 whose reports stayed internal “have not demonstrated concrete harm and thus lack Article III standing” on that claim. On two further claims about the format of TransUnion’s mailings, no class member other than Ramirez himself had standing. The Court summarized the whole holding in five words: “No concrete harm, no standing.”
Two further points in the opinion do a great deal of work in later breach litigation. The first is that “Every class member must have Article III standing in order to recover individual damages.” The second is that standing must be shown “with the manner and degree of evidence required at the successive stages of the litigation,” so allegations that suffice on a motion to dismiss must be proved at trial. TransUnion is not a data breach case, but it is the framework every data breach standing decision since has had to work within.
Does the risk of future identity theft after a breach count as an injury?
Not on its own in a suit for damages, under TransUnion, and that is the sentence the whole area turns on. The Court described as persuasive TransUnion’s argument “that in a suit for damages, the mere risk of future harm, standing alone, cannot qualify as a concrete harm — at least unless the exposure to the risk of future harm itself causes a separate concrete harm.” The Court distinguished Clapper v. Amnesty International USA, 568 U.S. 398 (2013), on the ground that Clapper involved injunctive relief: a person exposed to a sufficiently imminent and substantial risk may seek forward-looking relief, but “a plaintiff’s standing to seek injunctive relief does not necessarily mean that the plaintiff has standing to seek retrospective damages.”
The Court added a second, independent ground. Even setting aside that problem, the 6,332 plaintiffs “did not factually establish a sufficient risk of future harm to support Article III standing,” because the risk they identified — that TransUnion might disseminate the alerts at any moment — was too speculative on the trial record. The Court also noted that those plaintiffs had not shown they even knew the alerts were in their files, remarking that it is “difficult to see how a risk of future harm could supply the basis for a plaintiff’s standing when the plaintiff did not even know that there was a risk of future harm.”
What TransUnion left open matters as much as what it closed. In footnote 7 the Court observed that a plaintiff’s knowledge of exposure to a risk of future harm “could cause its own current emotional or psychological harm,” and expressly took no position on whether or how such a harm could suffice for Article III purposes. That footnote is the doorway through which most post-2021 data breach standing arguments have been run.
Which federal circuits accept a risk of future misuse as an injury, and which do not?
The Third Circuit accepts it where the risk has produced present harms, and the Fourth Circuit, most recently, does not. In Clemens v. ExecuPharm, Inc., 48 F.4th 146 (3d Cir. 2022), decided September 2, 2022, a former employee’s Social Security number and financial account information were taken in a phishing attack and posted on the dark web. The Third Circuit held “that in the data breach context, where the asserted theory of injury is a substantial risk of identity theft or fraud, a plaintiff suing for damages can satisfy concreteness as long as he alleges that the exposure to that substantial risk caused additional, currently felt concrete harms,” giving emotional distress and mitigation spending as examples. It also set out non-exhaustive factors bearing on imminence, among them whether the breach was intentional.
In Holmes v. Elephant Insurance Co., No. 23-1782 (4th Cir. Oct. 14, 2025), a published opinion by Judge Richardson, the Fourth Circuit took a different route. It held that the common-law tort of public disclosure of private information supplies the concrete analogue, so the information “must be accessible to many.” Two named plaintiffs who alleged finding their driver’s license numbers listed on the dark web had a concrete injury. Two others, whose numbers were held by the hackers but not published, did not: the Fourth Circuit called them “materially indistinguishable from the 6,332 plaintiffs in TransUnion.” It also held that even for the two whose data was published, future fraudulent impersonation was not imminent, relying on its earlier decision in Beck v. McDonald, 848 F.3d 262 (4th Cir. 2017).
The Holmes opinion is useful precisely because it maps the disagreement rather than eliding it. The Fourth Circuit acknowledged that “our sister circuits have found imminent injury to plaintiffs in similar circumstances,” citing Bohnak v. Marsh & McLennan Cos., 79 F.4th 276, 289 (2d Cir. 2023), Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365, 375-76 (1st Cir. 2023), Attias v. CareFirst, Inc., 865 F.3d 620, 628-29 (D.C. Cir. 2017), and Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688, 693-94 (7th Cir. 2015), along with McMorris v. Carlos Lopez & Associates, 995 F.3d 295, 301 (2d Cir. 2021), Clemens, and Green-Cooper v. Brinker International, Inc., 73 F.4th 883, 889-90 (11th Cir. 2023), for the proposition that a targeted attack and a dark web listing weigh in favor of standing. Its objection was that those courts “have not explained how a data breach presents a substantial risk that any one piece of personal information will be misused in the future.” Those characterizations belong to the Fourth Circuit: they are how Holmes described its sister circuits, and the decisions of the First, Second, Seventh, Eleventh and D.C. Circuits are not restated here from their own opinions.
Can credit monitoring costs or time spent responding to a breach create standing by themselves?
Not where the underlying future harm is speculative, and the Fourth Circuit extended that rule to time in 2025. Holmes v. Elephant Insurance Co. held that the two named plaintiffs whose driver’s license numbers were never published “cannot furnish standing for damages solely through expenditures of time and allegations of emotional distress,” resting on Clapper v. Amnesty International USA, 568 U.S. 398, 402 (2013), that plaintiffs “cannot manufacture standing by choosing to make expenditures based on hypothetical future harm that is not [imminent].” The court reasoned that the worry about mitigation costs — “anyone can pay to mitigate anything, however unlikely” — applies equally to hours: “rather than spend a dollar, plaintiffs could spend a minute.”
The Fourth Circuit was candid that the doctrinal home of this rule is unsettled. In a footnote it observed that it is unclear whether the bar on freestanding mitigation costs goes to injury in fact or to traceability, and cited its own Hutton v. National Board of Examiners in Optometry, 892 F.3d 613, 622 (4th Cir. 2018), and the Seventh Circuit’s Remijas for the proposition that mitigation expenses do not qualify where the harm is not imminent. “Either way,” it concluded, “the result is the same — mitigation costs cannot furnish standing on their own.”
That is not the same as saying mitigation spending is irrelevant. The Third Circuit’s Clemens treats mitigation spending and emotional distress as the currently felt harms that convert a substantial risk into a concrete injury. The two courts are not applying the same sequence: Clemens asks whether a substantial risk produced present harm, and Holmes asks first whether the risk is imminent at all, treating mitigation as incapable of supplying what is missing. A practitioner reading only one of them will badly misjudge the other forum.
What does evidence of actual misuse do to the standing analysis?
It largely removes the argument, which is why the technical record about misuse carries weight far beyond its size. TransUnion itself illustrates the mechanism: the 1,853 class members won on standing not because the risk to them was greater but because something had already happened — their reports had gone to third parties, which the Court treated as concrete reputational harm with a common-law analogue in defamation. Where a plaintiff can show a fraudulent account, a fraudulent filing, or an unauthorized charge traceable to the exposed data, the court is no longer being asked to price a probability.
Publication does similar work in the circuits that have accepted it. In Holmes, the injury the Fourth Circuit recognized was not future fraud but the present fact of the driver’s license numbers being listed on the dark web “against their justifiable wishes,” which the court held analogous to public disclosure of private information and therefore sufficient for retrospective relief. In Clemens, the dark web posting was central to the Third Circuit’s conclusion that the risk was substantial rather than hypothetical.
The difficulty is that establishing misuse traceable to a particular breach is frequently impossible, and no amount of legal argument changes that. Records from many incidents are aggregated and resold before use, so identifiers like name, address and Social Security number rarely carry a fingerprint back to one source. The Institute covers what the technical record does and does not support in exposure is not misuse and in more depth at exposure versus misuse.
What does the standing question mean for the evidence a breach case needs?
It moves several technical questions forward in the schedule, because they now bear on jurisdiction rather than only on damages. Whether data was exfiltrated as opposed to merely reachable, whether the specific dataset has surfaced in circulation and is identifiable as this one, whether the attack was targeted, and which fields were involved are all facts that the decisions above treat as material to standing. They are also facts that depend on evidence with short lifespans — egress telemetry, firewall and proxy records, staging artifacts — which is why the Institute treats preservation in what disappears first after a breach as the first question on the site.
TransUnion’s instruction that every class member must have standing to recover individual damages, and that standing must be supported by the evidence appropriate to each stage, also means the question does not go away after the pleadings. What is enough on a motion to dismiss is not enough at certification or trial, and an analysis built for the first will not survive the third.
Two boundaries are worth stating plainly. Whether a given plaintiff has standing in a given forum is a question of law that varies by circuit and is genuinely unsettled; counsel decides it, and any technical expert offering a confident general answer has stepped outside their evidence. And what a claim is worth, once standing is established, belongs to the Economic Damages Institute at economicdamagesinstitute.com. This Institute covers whether the technical chain holds, link by link, in breach causation.