Data brokers like LexisNexis and Experian collect and sell massive amounts of personal data, but what happens when that data is mishandled or exposed? In recent years, there’s been a growing trend: class action lawsuits targeting these companies over alleged data breaches and privacy violations. These cases are testing the limits of data protection law in the U.S. and raising big questions about consumer rights.
At Mason LLP, our data breach attorneys closely track these cases and represent consumers harmed by data broker misconduct. Here’s what you need to know about current class action trends and where courts are starting to draw the line.

LexisNexis and Experian data breaches: What happened?
Several major data brokers are currently facing class action litigation. While data breach lawsuits have existed for years, the current wave is broader and focused on how data brokers collect, sell, and use personal data without customer consent.
LexisNexis data breach
In 2024, LexisNexis faced legal action over allegations that it improperly sold sensitive data to law enforcement without a warrant. Plaintiffs argued this violated privacy laws and constituted unlawful surveillance. The court’s early decisions in the case focused on whether individuals have a private right of action under state and federal privacy statutes, which is a recurring issue in data breach litigation.
Then, in December 2024, LexisNexis disclosed a separate breach affecting over 364,000 people after a hacker accessed personal information, including Social Security numbers and driver’s license data, through a third-party software platform.
Experian data breach
Experian, too, has been in the spotlight for failing to secure millions of users’ personal information. In 2015, Experian’s data breach exposed the personal information of over 15 million people, including T-Mobile customers who had applied for credit checks. The compromised data included names, addresses, Social Security numbers, and driver’s license details.
Although Experian offered credit monitoring and denied that its core systems were affected, the breach sparked investigations by multiple attorneys general, and eventually, the court ruled in a $16 million multistate settlement in 2022.
Legal trends in class action litigation against data brokers
As class action data breach cases evolve, a few key legal trends have started to shape how courts and companies respond.
Courts are split on whether future harm counts as injury
One growing trend is the disagreement among courts over what counts as a valid injury. Some courts are beginning to treat the risk of future identity theft as enough to establish standing, especially if the breach involves leaked sensitive data like Social Security numbers or driver’s license information. Other courts still require proof of actual, out-of-pocket losses before allowing a lawsuit to proceed. This inconsistency means that similar cases can have very different outcomes depending on the jurisdiction.
Lack of a federal private right of action creates legal uncertainty
Another trend is the increasing reliance on state laws and privacy policies to move class action filings forward. Since there’s no comprehensive federal law giving consumers a clear right to sue over data breaches, plaintiffs can cite state consumer protection statutes or breach notification laws. Courts then examine if companies violated their own terms of service or failed to meet state-specific data protection standards. This patchwork approach creates confusion and makes it harder to predict the outcome of class actions across states.
State attorneys general are playing a larger role in breach enforcement
With little progress on federal privacy laws, state attorneys general are stepping up to protect consumer data. They’re enforcing existing laws, pushing for new regulations, and warning the public about growing threats like AI scams and data broker abuse.
In one case, the Illinois attorney general helped secure a multi-state settlement after a hospital data breach exposed information from over 6 million people. In another, California’s attorney general took early action against a fertility tracking app with weak data protections, even before a breach occurred.
What to do after a data broker breach
If you’ve been affected by a data broker breach, you may feel powerless. But you have rights after a breach, especially if your personal information was exposed, sold, or used without your consent.
- Monitor your credit and report fraud immediately.
- Save any breach notices you receive and file a report with the FTC at IdentityTheft.gov.
- Remove leaked data
- Speak with a data breach attorney to find out if you may qualify for inclusion in a class action lawsuit.
Mason LLP has recovered millions for victims of data breaches and can help you understand your legal options. Even if you haven’t seen direct financial harm yet, you may still have a valid claim.
Mason LLP holds data brokers accountable
At Mason LLP, we’re committed to protecting your personal information from misuse. If your private data has been compromised due to a LexisNexis data breach, Experian data breach, or similar data broker breach, we may be able to help.
We represent clients nationwide in data breach class actions and other complex privacy litigation. To learn more about your rights and whether you qualify to join a class action, submit a claim, use our online form to contact Mason LLP, or call us at (202) 429-2290.
Toronto, Canada – June 1, 2018: LexisNexis Office building in Toronto, Canada. LexisNexis is a corporation providing computer-assisted legal research as well as business research.