Breach notices are full of words most people have never needed before. This glossary defines the 35 terms that come up most often, covering the breach itself, the letter you received, the steps you can take to protect yourself, and how a class action works.
A data breach notice is written for lawyers and regulators, not for the person who opens the envelope. This glossary explains 35 terms you are likely to run into, in plain language, so you can work out what actually happened and what you can do about it.
These are the words used to describe what happened to the company that held your information.
An incident where someone gains access to information they were not authorized to see. It can happen through a cyberattack, a stolen laptop, a misconfigured server, or an employee mistake. A breach does not require that anyone actually used the information.
Often shortened to PII. Any information that can identify a specific person, including your name, Social Security number, date of birth, address, and financial account details.
Often shortened to PHI. Health information tied to an identifiable person and protected under federal law. It covers diagnoses, treatment records, prescriptions, and insurance details.
The person or group behind an attack. Breach reports often name a specific group, such as a ransomware gang. Naming a group does not mean anyone has been identified or charged.
Software that locks an organization out of its own systems until a payment is made. Many groups now steal a copy of the data first, so they can threaten to publish it even if systems are restored.
Copying data out of a system and moving it somewhere the attacker controls. This is the step that turns an intrusion into a data breach, because the information has left the organization's hands.
Parts of the internet that require special software to reach and are not indexed by search engines. Stolen data is often posted, traded, or sold there.
A site run by a ransomware group where it publishes the names of organizations it has attacked, often with samples of stolen data. These postings are sometimes the first public sign of a breach.
A message designed to trick you into giving up information or clicking something harmful. After a breach, phishing attempts often reference the breach itself, because attackers know you are expecting news.
An attack that takes usernames and passwords stolen in one breach and tries them on other sites. It works because many people reuse passwords, which turns one breach into several.
Scrambling data so it cannot be read without a key. Companies sometimes report that breached data was encrypted, which lowers the risk. It does not remove it, since attackers occasionally obtain keys too.
If a letter or email arrived telling you your information was exposed, these are the terms it is most likely to use.
The written notice a company sends when it believes your information was involved in a breach. Most states require these by law. Keep yours. It is the clearest proof that you were affected.
Many states require companies to report breaches to the state Attorney General, not only to affected people. Several states publish these reports, which is often how a breach becomes public.
A public federal database where healthcare organizations must report breaches affecting 500 or more people. It is a primary public source for confirmed healthcare breaches in the United States.
A service that watches your credit file and alerts you to new activity. Breached companies often offer it free for a set period. It tells you after something happens rather than preventing it.
A broader service that may include credit monitoring, dark web scanning, and help restoring your identity if it is misused. Also commonly offered free for a limited time after a breach.
These are the tools available to you right now, most of them free, whether or not a lawsuit is ever filed.
A lock you place on your credit file that stops new accounts from being opened in your name. It is free, you place it with each of the three credit bureaus separately, and you can lift it whenever you need to.
A flag on your credit file telling lenders to take extra steps to confirm your identity before opening an account. It is free and easier to manage than a freeze, but it is a weaker protection.
A record of your credit accounts and payment history kept by Equifax, Experian, and TransUnion. You are entitled to free copies, and reviewing them is the most direct way to spot accounts you did not open.
Using someone else's personal information to commit fraud, such as opening accounts, filing tax returns, or claiming benefits. It is the harm most people worry about after a breach notice.
Using someone else's information to obtain medical care, prescriptions, or insurance benefits. It is especially damaging because it can put false information into your actual medical records.
A second step beyond your password, usually a code sent to your phone or generated by an app. It is among the most effective protections available, because a stolen password alone is no longer enough.
If a case is filed over the breach that affected you, these are the terms that will shape it from filing through payment.
A lawsuit where one or a few people sue on behalf of a large group harmed in the same way. It exists because individual losses are often too small to justify separate lawsuits, even when total harm is large.
The named person who brings the case on behalf of everyone else affected. Also called the named plaintiff. They take a more active role than other class members.
Anyone who falls within the group the lawsuit covers. In a data breach case that usually means everyone whose information was involved. You are typically a class member without doing anything.
The proposed group in a case a court has not yet approved as a class action. The word signals that the case is early and certification has not happened yet.
The court's decision on whether a case can proceed as a class action. The court looks at whether the group is clearly defined and whether the claims are similar enough to decide together.
Whether a person has suffered enough harm to bring a case at all. This is heavily contested in data breach cases, because courts disagree on whether exposure alone is enough or actual misuse is required.
The stage where each side must hand over relevant documents and answer questions under oath. In breach cases this is often where details about a company's security practices first come to light.
An agreement to resolve a case without a trial. Most data breach class actions end this way. A judge must approve the settlement and find it fair to the people it covers.
The company a court appoints to run a settlement. It sends notices, processes claims, and distributes payments. Settlement mail usually comes from the administrator rather than from a law firm.
Choosing to remove yourself from a class action so you can pursue your own case. There is a deadline, and opting out means giving up any share of the class settlement.
A fee arrangement where the attorneys are paid only if the case wins, taken as a share of the recovery. It is why there is never a cost to you to pursue a claim.
The deadline for filing a lawsuit. It varies by state and by type of claim, and it generally starts running when the harm occurs or when you reasonably should have discovered it.
Often shortened to MDL. A process that groups similar federal cases from around the country before a single judge for pretrial handling. Common when one breach produces lawsuits in many states.
Knowing the words is a start. Whether you have a claim depends on what was exposed, who exposed it, and where you live.
Read our full guide to data breach lawsuits explained, browse the active data breach investigations to see if your company is listed, or start a free case review.