Live Video-Broadcast: September 28, 2026
Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs
The Breach You Are Litigating May Not Be the One That Exposed Your Plaintiff
Article III traceability was once an afterthought in data breach class actions. Two decisions ended that. Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) identified the factual allegations a plaintiff must plead to establish traceability. Holmes v. Elephant Insurance Co. (4th Cir. 2025) separated plaintiffs who can show their data on the dark web from those who cannot.
Plead without prior-exposure facts, and a motion to dismiss ends the case. Ignore historical dark web scans, and defense counsel builds the causal break for you. Skip the FRE 901, FRE 802, and Daubert foundation, and your forensic expert never testifies. Leave individualized traceability inquiries standing, and Rule 23(b)(3) predominance fails at certification.
You leave with the five-element pleading framework and the evidentiary foundation your expert must lay. You also leave with a defense playbook: post-breach forensic engagement through class certification opposition. This is judgment about timing, forum, and proof — work no research tool performs for you.
Key topics to be discussed:
This course is co-sponsored with myLawCLE.
Date / Time: September 28, 2026
Closed-captioning available
Tyler R. Bridegan, Partner | Womble Bond Dickinson (US) LLP
Tyler Bridegan is a Partner in the privacy and cybersecurity practice at the international law firm, Womble Bond Dickinson (US) LLP, and the former Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office. He provides clients with support through the full life cycle of issues related to technology, from compliance challenges to vigorously defending against government investigations and litigation.
He holds the CIPP/US, CIPP/E, and CIPM credentials from the International Association of Privacy Professionals and is a Registered Practitioner under the Cybersecurity Maturity Model Certification framework.
The American Lawyer named him Litigator of the Week in 2022, and the D.C. Bar Association placed him on its Capital Pro Bono Honor Roll, High Honors List, for 2020–2021. Since 2024 he has co-chaired the Computer and Technology Section of the Texas Bar and the Privacy and Data Security Committee of the Federal Communications Bar Association. He also sits on the Law360 Cybersecurity and Privacy Editorial Board and on the Board of Editors of The Global Regulatory Developments Journal.
He serves on the IAPP Privacy Bar Section Advisory Board and on the Board of Directors of the Cholangiocarcinoma Foundation, and participates in the Houston Bar Association’s LGBTQ+ Committee. From 2021 to 2023 he co-chaired the Federal Communications Bar Association’s Video Programming and Distribution Committee. His writing on privacy and cybersecurity has appeared in Law360, National Defense Magazine, HR Executive, and Federal News Network, and he has spoken recently for the ABA Consumer Financial Services Committee and at the ABA Mid-Year Meeting.
He previously served as Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office and as Acting Legal Advisor to Commissioner Simington at the Federal Communications Commission, and has conducted or defended hundreds of government investigations involving state attorneys general, the FTC, the CFPB, the FCC, and the NYDFS. Representative matters include closing an FTC investigation of an artificial intelligence startup without further action, resolving an FTC investigation through a ROSCA settlement, and obtaining closure of an NYDFS data breach investigation without further action.
Scott J. Hyman, Partner | Womble Bond Dickinson (US) LLP
Scott J. Hyman is a Partner at Womble Bond Dickinson (US) LLP in Irvine, California, where he has spent more than three decades representing financial institutions, national banks, automobile finance companies, and loan servicers. He counsels and defends clients on privacy and cybersecurity, licensing and regulatory matters, and individual and class actions under state and federal Truth-in-Lending laws, UDAP laws, the Telephone Consumer Protection Act, the Fair Credit Reporting Act, and the Fair Debt Collection Practices Act. He is the lead author of “Using the Dark Web to Defend Data Breach Class Actions,” published in The Conference on Consumer Finance Law Quarterly Report.
He earned his J.D. with distinction from the University of the Pacific, McGeorge School of Law in 1990, where he served as Articles Editor on the Pacific Law Review Board of Editors and was a member of the Traynor Society, and holds a B.A. from The Pennsylvania State University, 1987, through the Schreyer Honors College. He completed the Harvard VPAL certificate in Cybersecurity: Managing Risk in the Information Age in 2020 and carries the CIPP/US, CIPP/E, CIPT, and CIPM credentials. He is admitted in California and Texas, before the U.S. District Courts for the Southern District of Texas and the Southern, Central, Eastern, and Northern Districts of California, the Ninth and Eleventh Circuits, and the Supreme Court of the United States.
He serves as Vice President and a Governing Committee member of the Conference on Consumer Finance Law and was elected a Fellow of the American College of Consumer Financial Services Lawyers in 2023. He sat on the Debt Collection Advisory Committee of the California Department of Financial Protection and Innovation from 2021 to 2025.
He has been a member of the International Association of Privacy Professionals since 2018 and sits on the advisory board for the Certificate Program in Big Data at California State University, East Bay’s College of Extended Learning. He authors the Fair Debt Collection Practices Acts section of CEB’s Debt Collection Practice in California, co-writes the Consumer Finance + Privacy Counsel blog, and has published dozens of articles in The Conference on Consumer Finance Law Quarterly Report and other scholarly periodicals. Recent writing includes “Emerging Cybersecurity Issues for Boards” in Directors and Boards.
His practice centers on defending banks, automobile finance companies, and loan servicers in privacy and cybersecurity matters, licensing and regulatory work, and consumer class action litigation. He presented on cybersecurity trends and best practices at the Athena Event in June 2025.
Matt Barrett, Chief Operating Officer | Cyber Engineering Services, Incorporated (CyberESI)
Matt Barrett is Chief Operating Officer of Cyber Engineering Services, Incorporated (CyberESI, www.cyberesi.com) – an industry leading managed cybersecurity services and cybersecurity consulting company. Mr. Barrett oversees all facets of operation, including service oversight, client communications, employee well-being, and corporate operations.
For nearly fourteen years, CyberESI has focused on cybersecurity and cyber supply chain challenges of the telecommunications industry. CyberESI offers grant opportunities and supports clients with part-time Chief Information Security Officer support, vulnerability assessments & penetration testing, and managed detection & response.
B.S. Biochemistry, Virginia Tech, 1991-1995 · B.A. Chemistry, Virginia Tech, 1991-1995.
He received the Department of Commerce Gold Medal Award and was named to the 2007 Federal 100. At NIST he led the development and publication of Cybersecurity Framework Version 1.1 and ran the awareness campaign behind its adoption, which reached an estimated thirty percent of domestic organizations, and he previously led the agency’s Security Content Automation Protocol program.
His standards work at NIST placed him at the center of the community that built and maintains the Cybersecurity Framework, and he served as President of the Trusted Security Alliance. He speaks on cybersecurity framework measurement and on critical infrastructure security.
Mr. Barrett previously led the Framework for Improving Critical Infrastructure Cybersecurity (a.k.a., Cybersecurity Framework; https://www.nist.gov/cyberframework) program for the National Institute of Standards and Technology (NIST).
Before NIST he was President of G2, Inc., a cybersecurity and signals intelligence firm he grew from forty to one hundred employees between 2009 and 2014, and earlier a Director at Computer Sciences Corporation, where he expanded the cybersecurity unit from fifteen to two hundred personnel.
SESSION 1 – Defeating Data Breach Class Actions with Dark Web Forensic Evidence | 12:00pm – 1:00pm
This session examines how defense counsel can deploy dark web forensic evidence to challenge Article III standing in data breach class actions, focusing on the traceability requirement as the primary pressure point. Attorneys will learn how to use historical dark web scans, expert forensic testimony, and prior-exposure evidence to break the causal chain between a defendant’s breach and a plaintiff’s alleged harm. Attendees leave with a litigation playbook—from immediate post-breach forensic engagement through class certification opposition—grounded in the latest circuit authority.
BREAK | 1:00pm – 1:10pm
SESSION 2 – Pleading and Proving Traceability for Multiply-Breached Data Breach Plaintiffs | 1:10pm – 2:10pm
This session examines the plaintiff-side challenge of establishing Article III traceability when a data breach plaintiff’s PII has been exposed in multiple prior incidents. Attorneys will learn the five-element pleading framework drawn from recent circuit and district court decisions, including Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) and Holmes v. Elephant Insurance Co. (4th Cir. 2025), and will understand how defendants deploy dark web forensic evidence to defeat standing. Attendees will leave with actionable pleading strategies, an understanding of the emerging circuit split on intangible-harm concreteness, and practical guidance on when to engage dark web intelligence experts.
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Approved for CLE Credits
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
No MCLE Required
2 CLE Hour(s)
Pending CLE Approval
2 General
Approved via Attorney Submission
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2 Substantive
Pending CLE Approval
2 General
Pending CLE Approval
2 General
No MCLE Required
2 CLE Hour(s)
No MCLE Required
2 CLE Hour(s)
Pending CLE Approval
2 General
No MCLE Required
2 CLE Hour(s)
Pending CLE Approval
2 General
Approved for CLE Credits
2.4 General
Pending CLE Approval
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
120 General minutes
Approved for CLE Credits
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Pending CLE Approval
2.5 General
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2.5 General
Pending CLE Approval
2 General
No MCLE Required
2 CLE Hour(s)
Pending CLE Approval
2 General
Approved for CLE Credits
2 General
Pending CLE Approval
2 General
Not Eligible
2 General Hours
Approved for CLE Credits
2 General
Approved via Attorney Submission
2 Law & Legal Hours
Pending CLE Approval
2 General
Pending CLE Approval
2.4 General
Pending CLE Approval
2 General