Data left the building. Proving what happened to it afterward, for any particular person, is a different order of difficulty.
Start a conversation with the Incident Concierge, already scoped to exposure vs misuse. Pick a starting point, or describe the incident directly.
Most consumer breach litigation turns on a gap that technical evidence cannot close. That data was exfiltrated is often provable. That a particular individual's data was among it is usually provable. What happened next — whether it was sold, to whom, whether it was used, and whether any specific harm followed — generally is not. Stolen records are aggregated across many breaches, resold repeatedly, and combined before use, so tracing one person's fraudulent charge back to one incident is rarely possible even when it genuinely originated there. That evidentiary reality is why the legal question of whether exposure alone constitutes injury carries such weight, and why the same facts produce different outcomes in different forums. The Institute's role is to be clear about what the evidence supports, not to resolve the legal question.
Provable at the top, progressively harder downward.
Often provable from egress telemetry, attacker infrastructure, or the data appearing elsewhere.
Usually provable from the affected records themselves.
Sometimes, where records surface on known forums and can be matched.
Rarely tied to this breach rather than to any of the others in circulation.
Very rarely provable at the individual level.
The standard defense, and frequently true given how much data is already circulating.
How the gap is analyzed.
Frequently whether there is a viable claim at all, and for whom.
After years of large breaches, most people's basic identifiers are already circulating. That makes "this breach caused this fraud" genuinely hard to establish — and it is the defense argument that most often survives contact with the evidence.
Occasionally, and the exceptions are instructive. Tracing works best where the exposed field is unusual enough to be a fingerprint — a distinctive account identifier, a unique combination that existed only in this dataset, or credentials specific to this service. It also works where timing is tight and distinctive: fraud appearing across many affected individuals shortly after exfiltration, in a pattern matching the exposed fields. What almost never works is tracing generic identifiers like name, address and Social Security number, because those are already in circulation from elsewhere.
More than it supports at the individual level, which is why so much of this litigation is brought collectively. Statistical arguments about elevated fraud rates within an affected population against a comparable baseline can be made, and where the data has been found in circulation the inference across the group strengthens considerably. Whether that group-level evidence satisfies the legal requirement for any particular plaintiff is a different question, and it is one of the reasons certification is so heavily contested in these matters.
They are the most concrete category and they still carry a causation question. Mitigation costs are actual out-of-pocket expenditure, which makes them easier to evidence than speculative future harm. The contested point is whether incurring them was reasonable and attributable to this breach, particularly where the organization offered monitoring at its own cost or where the individual was already affected by other incidents. Whether they are recoverable is a legal question; what they are worth is a damages question, and the Economic Damages Institute covers the measurement.
By naming it explicitly and refusing to bridge it by inference. An expert who states clearly what the evidence establishes — exfiltration, dataset membership, circulation if shown — and then says plainly that individual misuse cannot be established from the technical record is credible and difficult to attack. One who reasons from exposure to harm because harm is plausible has produced the most fragile opinion in the case, and it will not survive a competent cross-examination.
Describe the exposure and the harm alleged. The Institute will help you see where the record stops.