<img height="1" width="1" src="https://www.facebook.com/tr?id=1858256345574652&amp;ev=PageView &amp;noscript=1"> Data Breach Glossary: Plain-Language Definitions
Data Breach Class Actions
Console & Associates, P.C.
1011001011010110100110101100101010101100111000101001011011010010 01101001110100101011001011010110100110101100101010101100 1011001011010110100110101100101010101100111000101001011011010010 01101001110100101011001011010110100110101100101010101100 1011001011010110100110101100101010101100111000101001011011010010 01101001110100101011001011010110100110101100101010101100

Data Breach Terms Explained.

Breach notices are full of words most people have never needed before. This glossary defines the 35 terms that come up most often, covering the breach itself, the letter you received, the steps you can take to protect yourself, and how a class action works.

A data breach notice is written for lawyers and regulators, not for the person who opens the envelope. This glossary explains 35 terms you are likely to run into, in plain language, so you can work out what actually happened and what you can do about it.

Quick Answer
  • A data breach means someone reached information they were not authorized to see.
  • A breach notification letter is the company telling you that you were affected. Keep it.
  • A credit freeze is free and is the strongest step you can take today.
  • A class action lets many affected people seek compensation together.
  • There is never a cost to you. The attorneys are paid only if the case wins.

The Breach Itself

These are the words used to describe what happened to the company that held your information.

Data Breach

An incident where someone gains access to information they were not authorized to see. It can happen through a cyberattack, a stolen laptop, a misconfigured server, or an employee mistake. A breach does not require that anyone actually used the information.

Personally Identifiable Information

Often shortened to PII. Any information that can identify a specific person, including your name, Social Security number, date of birth, address, and financial account details.

Protected Health Information

Often shortened to PHI. Health information tied to an identifiable person and protected under federal law. It covers diagnoses, treatment records, prescriptions, and insurance details.

Threat Actor

The person or group behind an attack. Breach reports often name a specific group, such as a ransomware gang. Naming a group does not mean anyone has been identified or charged.

Ransomware

Software that locks an organization out of its own systems until a payment is made. Many groups now steal a copy of the data first, so they can threaten to publish it even if systems are restored.

Exfiltration

Copying data out of a system and moving it somewhere the attacker controls. This is the step that turns an intrusion into a data breach, because the information has left the organization's hands.

Dark Web

Parts of the internet that require special software to reach and are not indexed by search engines. Stolen data is often posted, traded, or sold there.

Leak Site

A site run by a ransomware group where it publishes the names of organizations it has attacked, often with samples of stolen data. These postings are sometimes the first public sign of a breach.

Phishing

A message designed to trick you into giving up information or clicking something harmful. After a breach, phishing attempts often reference the breach itself, because attackers know you are expecting news.

Credential Stuffing

An attack that takes usernames and passwords stolen in one breach and tries them on other sites. It works because many people reuse passwords, which turns one breach into several.

Encryption

Scrambling data so it cannot be read without a key. Companies sometimes report that breached data was encrypted, which lowers the risk. It does not remove it, since attackers occasionally obtain keys too.

Protecting Yourself

These are the tools available to you right now, most of them free, whether or not a lawsuit is ever filed.

Credit Freeze

A lock you place on your credit file that stops new accounts from being opened in your name. It is free, you place it with each of the three credit bureaus separately, and you can lift it whenever you need to.

Fraud Alert

A flag on your credit file telling lenders to take extra steps to confirm your identity before opening an account. It is free and easier to manage than a freeze, but it is a weaker protection.

Credit Report

A record of your credit accounts and payment history kept by Equifax, Experian, and TransUnion. You are entitled to free copies, and reviewing them is the most direct way to spot accounts you did not open.

Identity Theft

Using someone else's personal information to commit fraud, such as opening accounts, filing tax returns, or claiming benefits. It is the harm most people worry about after a breach notice.

Medical Identity Theft

Using someone else's information to obtain medical care, prescriptions, or insurance benefits. It is especially damaging because it can put false information into your actual medical records.

Two-Factor Authentication

A second step beyond your password, usually a code sent to your phone or generated by an app. It is among the most effective protections available, because a stolen password alone is no longer enough.

How a Class Action Works

If a case is filed over the breach that affected you, these are the terms that will shape it from filing through payment.

Class Action

A lawsuit where one or a few people sue on behalf of a large group harmed in the same way. It exists because individual losses are often too small to justify separate lawsuits, even when total harm is large.

Class Representative

The named person who brings the case on behalf of everyone else affected. Also called the named plaintiff. They take a more active role than other class members.

Class Member

Anyone who falls within the group the lawsuit covers. In a data breach case that usually means everyone whose information was involved. You are typically a class member without doing anything.

Putative Class

The proposed group in a case a court has not yet approved as a class action. The word signals that the case is early and certification has not happened yet.

Class Certification

The court's decision on whether a case can proceed as a class action. The court looks at whether the group is clearly defined and whether the claims are similar enough to decide together.

Standing

Whether a person has suffered enough harm to bring a case at all. This is heavily contested in data breach cases, because courts disagree on whether exposure alone is enough or actual misuse is required.

Discovery

The stage where each side must hand over relevant documents and answer questions under oath. In breach cases this is often where details about a company's security practices first come to light.

Settlement

An agreement to resolve a case without a trial. Most data breach class actions end this way. A judge must approve the settlement and find it fair to the people it covers.

Claims Administrator

The company a court appoints to run a settlement. It sends notices, processes claims, and distributes payments. Settlement mail usually comes from the administrator rather than from a law firm.

Opt Out

Choosing to remove yourself from a class action so you can pursue your own case. There is a deadline, and opting out means giving up any share of the class settlement.

Contingency Fee

A fee arrangement where the attorneys are paid only if the case wins, taken as a share of the recovery. It is why there is never a cost to you to pursue a claim.

Statute of Limitations

The deadline for filing a lawsuit. It varies by state and by type of claim, and it generally starts running when the harm occurs or when you reasonably should have discovered it.

Multidistrict Litigation

Often shortened to MDL. A process that groups similar federal cases from around the country before a single judge for pretrial handling. Common when one breach produces lawsuits in many states.

Attorney Advertising Disclosure

This is a paid advertisement by Attorney Richard P. Console Jr., Esq. and the law firm of Console & Associates P.C., not a referral service. Prior results do not guarantee a similar outcome. Testimonials are not necessarily representative of results obtained by all clients. Console & Associates, P.C.'s primary office is located at 1 Executive Drive, Suite #100, Marlton, NJ 08053 · (866) 778-5500. The information on this site is for general informational purposes only and does not constitute legal advice or form an attorney-client relationship. Submitting information through this site does not create an attorney-client relationship. Results may vary. In certain instances we may refer matters to co-counsel if in the client's best interest. New Jersey Residents: You may report concerns about this advertisement to the Committee on Attorney Advertising, Hughes Justice Complex, CN 037, Trenton, NJ 08625. No aspect of this advertisement has been approved by the Supreme Court of New Jersey. Privacy: We do not sell, trade, or rent your personal information to third parties.