Dark Web Evidence in Data Breach Class Actions: The Multiple-Compromise Defense

Tyler R. Bridegan
Scott J. Hyman
Matt Barrett
Tyler R. Bridegan | Womble Bond Dickinson (US) LLP
Scott J. Hyman | Womble Bond Dickinson (US) LLP
Matt Barrett | Cyber Engineering Services, Incorporated (CyberESI)

Live Video-Broadcast: September 28, 2026

2 hour CLE

Tuition: $195.00
Subscribe to Federal Bar Association CLE Pass...
Co-Sponsored by myLawCLE
Get this course, plus over 1,000+ of live webinars.
Learn More
Training 5 or more people?

Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs

Program Summary

 

The Breach You Are Litigating May Not Be the One That Exposed Your Plaintiff

Article III traceability was once an afterthought in data breach class actions. Two decisions ended that. Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) identified the factual allegations a plaintiff must plead to establish traceability. Holmes v. Elephant Insurance Co. (4th Cir. 2025) separated plaintiffs who can show their data on the dark web from those who cannot.

Plead without prior-exposure facts, and a motion to dismiss ends the case. Ignore historical dark web scans, and defense counsel builds the causal break for you. Skip the FRE 901, FRE 802, and Daubert foundation, and your forensic expert never testifies. Leave individualized traceability inquiries standing, and Rule 23(b)(3) predominance fails at certification.

You leave with the five-element pleading framework and the evidentiary foundation your expert must lay. You also leave with a defense playbook: post-breach forensic engagement through class certification opposition. This is judgment about timing, forum, and proof — work no research tool performs for you.

Key topics to be discussed:

  • ETraceability Under TransUnion
    How the multiple-compromise problem turns Article III traceability into the threshold fight in every data breach class action, on both sides of the caption.
  • Five Pillars of Pleading
    How the five-element pleading framework drawn from Santos-Pagán v. Bayamón Medical Center and Holmes v. Elephant Insurance Co. changes what your complaint must allege before filing.
  • Dark Web Forensic Proof
    How historical dark web scans, investigative tooling, and expert framing change what defense counsel can put before the court at the motion-to-dismiss stage.
  • Admissibility and Daubert
    How FRE 901, FRE 802, and Daubert change the authentication and chain-of-custody foundation a forensic expert must lay to be heard.
  • Multiple-Compromise Playbook
    How the defense’s timing, named-plaintiff targeting, and forum selection change plaintiff-side strategy from the complaint through Rule 23(b)(3) predominance.
  • Live Q&A and Takeaways
    How each faculty member’s closing Q&A and takeaways turn the session frameworks into the next step in your own pending matter

This course is co-sponsored with myLawCLE.

Date / Time: September 28, 2026

  • 12:00 pm – 2:10 pm Eastern
  • 11:00 am – 1:10 pm Central
  • 10:00 am – 12:10 pm Mountain
  • 9:00 am – 11:10 am Pacific

Closed-captioning available

Speakers

Tyler R. Bridegan, Partner | Womble Bond Dickinson (US) LLP

Tyler Bridegan is a Partner in the privacy and cybersecurity practice at the international law firm, Womble Bond Dickinson (US) LLP, and the former Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office. He provides clients with support through the full life cycle of issues related to technology, from compliance challenges to vigorously defending against government investigations and litigation.

  • Education & Credentials

He holds the CIPP/US, CIPP/E, and CIPM credentials from the International Association of Privacy Professionals and is a Registered Practitioner under the Cybersecurity Maturity Model Certification framework.

  • Recognition & Leadership

The American Lawyer named him Litigator of the Week in 2022, and the D.C. Bar Association placed him on its Capital Pro Bono Honor Roll, High Honors List, for 2020–2021. Since 2024 he has co-chaired the Computer and Technology Section of the Texas Bar and the Privacy and Data Security Committee of the Federal Communications Bar Association. He also sits on the Law360 Cybersecurity and Privacy Editorial Board and on the Board of Editors of The Global Regulatory Developments Journal.

  • Professional Involvement

He serves on the IAPP Privacy Bar Section Advisory Board and on the Board of Directors of the Cholangiocarcinoma Foundation, and participates in the Houston Bar Association’s LGBTQ+ Committee. From 2021 to 2023 he co-chaired the Federal Communications Bar Association’s Video Programming and Distribution Committee. His writing on privacy and cybersecurity has appeared in Law360, National Defense Magazine, HR Executive, and Federal News Network, and he has spoken recently for the ABA Consumer Financial Services Committee and at the ABA Mid-Year Meeting.

  • Experience

He previously served as Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office and as Acting Legal Advisor to Commissioner Simington at the Federal Communications Commission, and has conducted or defended hundreds of government investigations involving state attorneys general, the FTC, the CFPB, the FCC, and the NYDFS. Representative matters include closing an FTC investigation of an artificial intelligence startup without further action, resolving an FTC investigation through a ROSCA settlement, and obtaining closure of an NYDFS data breach investigation without further action.

 

Scott J. Hyman, Partner | Womble Bond Dickinson (US) LLP

Scott J. Hyman is a Partner at Womble Bond Dickinson (US) LLP in Irvine, California, where he has spent more than three decades representing financial institutions, national banks, automobile finance companies, and loan servicers. He counsels and defends clients on privacy and cybersecurity, licensing and regulatory matters, and individual and class actions under state and federal Truth-in-Lending laws, UDAP laws, the Telephone Consumer Protection Act, the Fair Credit Reporting Act, and the Fair Debt Collection Practices Act. He is the lead author of “Using the Dark Web to Defend Data Breach Class Actions,” published in The Conference on Consumer Finance Law Quarterly Report.

  • Education & Credentials

He earned his J.D. with distinction from the University of the Pacific, McGeorge School of Law in 1990, where he served as Articles Editor on the Pacific Law Review Board of Editors and was a member of the Traynor Society, and holds a B.A. from The Pennsylvania State University, 1987, through the Schreyer Honors College. He completed the Harvard VPAL certificate in Cybersecurity: Managing Risk in the Information Age in 2020 and carries the CIPP/US, CIPP/E, CIPT, and CIPM credentials. He is admitted in California and Texas, before the U.S. District Courts for the Southern District of Texas and the Southern, Central, Eastern, and Northern Districts of California, the Ninth and Eleventh Circuits, and the Supreme Court of the United States.

  • Recognition & Leadership

He serves as Vice President and a Governing Committee member of the Conference on Consumer Finance Law and was elected a Fellow of the American College of Consumer Financial Services Lawyers in 2023. He sat on the Debt Collection Advisory Committee of the California Department of Financial Protection and Innovation from 2021 to 2025.

  • Professional Involvement

He has been a member of the International Association of Privacy Professionals since 2018 and sits on the advisory board for the Certificate Program in Big Data at California State University, East Bay’s College of Extended Learning. He authors the Fair Debt Collection Practices Acts section of CEB’s Debt Collection Practice in California, co-writes the Consumer Finance + Privacy Counsel blog, and has published dozens of articles in The Conference on Consumer Finance Law Quarterly Report and other scholarly periodicals. Recent writing includes “Emerging Cybersecurity Issues for Boards” in Directors and Boards.

  • Experience

His practice centers on defending banks, automobile finance companies, and loan servicers in privacy and cybersecurity matters, licensing and regulatory work, and consumer class action litigation. He presented on cybersecurity trends and best practices at the Athena Event in June 2025.

 

Matt Barrett, Chief Operating Officer | Cyber Engineering Services, Incorporated (CyberESI)

Matt Barrett is Chief Operating Officer of Cyber Engineering Services, Incorporated (CyberESI, www.cyberesi.com) – an industry leading managed cybersecurity services and cybersecurity consulting company. Mr. Barrett oversees all facets of operation, including service oversight, client communications, employee well-being, and corporate operations.

For nearly fourteen years, CyberESI has focused on cybersecurity and cyber supply chain challenges of the telecommunications industry. CyberESI offers grant opportunities and supports clients with part-time Chief Information Security Officer support, vulnerability assessments & penetration testing, and managed detection & response.

  • Education & Credentials

B.S. Biochemistry, Virginia Tech, 1991-1995 · B.A. Chemistry, Virginia Tech, 1991-1995.

  • Recognition & Leadership

He received the Department of Commerce Gold Medal Award and was named to the 2007 Federal 100. At NIST he led the development and publication of Cybersecurity Framework Version 1.1 and ran the awareness campaign behind its adoption, which reached an estimated thirty percent of domestic organizations, and he previously led the agency’s Security Content Automation Protocol program.

  • Professional Involvement

His standards work at NIST placed him at the center of the community that built and maintains the Cybersecurity Framework, and he served as President of the Trusted Security Alliance. He speaks on cybersecurity framework measurement and on critical infrastructure security.

  • Experience

Mr. Barrett previously led the Framework for Improving Critical Infrastructure Cybersecurity (a.k.a., Cybersecurity Framework; https://www.nist.gov/cyberframework) program for the National Institute of Standards and Technology (NIST).

Before NIST he was President of G2, Inc., a cybersecurity and signals intelligence firm he grew from forty to one hundred employees between 2009 and 2014, and earlier a Director at Computer Sciences Corporation, where he expanded the cybersecurity unit from fifteen to two hundred personnel.

Agenda

SESSION 1 – Defeating Data Breach Class Actions with Dark Web Forensic Evidence | 12:00pm – 1:00pm

This session examines how defense counsel can deploy dark web forensic evidence to challenge Article III standing in data breach class actions, focusing on the traceability requirement as the primary pressure point. Attorneys will learn how to use historical dark web scans, expert forensic testimony, and prior-exposure evidence to break the causal chain between a defendant’s breach and a plaintiff’s alleged harm. Attendees leave with a litigation playbook—from immediate post-breach forensic engagement through class certification opposition—grounded in the latest circuit authority.

BREAK | 1:00pm – 1:10pm

SESSION 2 – Pleading and Proving Traceability for Multiply-Breached Data Breach Plaintiffs | 1:10pm – 2:10pm

This session examines the plaintiff-side challenge of establishing Article III traceability when a data breach plaintiff’s PII has been exposed in multiple prior incidents. Attorneys will learn the five-element pleading framework drawn from recent circuit and district court decisions, including Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) and Holmes v. Elephant Insurance Co. (4th Cir. 2025), and will understand how defendants deploy dark web forensic evidence to defeat standing. Attendees will leave with actionable pleading strategies, an understanding of the emerging circuit split on intangible-harm concreteness, and practical guidance on when to engage dark web intelligence experts.

Credits

Alaska

Approved for CLE Credits
2 General

Our programs are CLE-eligible through Alaska’s recognition of multi-jurisdictional reciprocity.
Alabama

Pending CLE Approval
2 General

Arkansas

Approved for CLE Credits
2 General

Arizona

Approved for CLE Credits
2 General

California

Approved for CLE Credits
2 General

Colorado

Pending CLE Approval
2 General

Connecticut

Approved for CLE Credits
2 General

District of Columbia

No MCLE Required
2 CLE Hour(s)

Delaware

Pending CLE Approval
2 General

Florida

Approved via Attorney Submission
2 General

Georgia

Pending CLE Approval
2 General

Hawaii

Approved for CLE Credits
2 General

Iowa

Pending CLE Approval
2 General

Idaho

Pending CLE Approval
2 General

Illinois

Pending CLE Approval
2 General

Indiana

Pending CLE Approval
2 General

Kansas

Pending CLE Approval
2 Substantive

Kentucky

Pending CLE Approval
2 General

Louisiana

Pending CLE Approval
2 General

Massachusetts

No MCLE Required
2 CLE Hour(s)

Maryland

No MCLE Required
2 CLE Hour(s)

Maine

Pending CLE Approval
2 General

Michigan

No MCLE Required
2 CLE Hour(s)

Minnesota

Pending CLE Approval
2 General

Missouri

Approved for CLE Credits
2.4 General

Mississippi

Pending CLE Approval
2 General

Montana

Pending CLE Approval
2 General

North Carolina

Pending CLE Approval
2 General

North Dakota

Approved for CLE Credits
2 General

Our programs are CLE-eligible through North Dakota’s recognition of multi-jurisdictional reciprocity. Section 1, Policy 1.14
Nebraska

Pending CLE Approval
2 General

myLawCLE reports attendance to Nebraska on each attorney’s behalf for all programs. Please do not self-report.
New Hampshire

Approved for CLE Credits
120 General minutes

As of July 1, 2014, the NHMCLE Board no longer provides pre- or post-approval of courses. Attendees must self-determine whether a program is eligible for credit, and self-report their attendance online at www.nhbar.org, based on qualification provisions of Rule 53.
New Jersey

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New Jersey’s recognition of multi-jurisdictional reciprocity, except for the courses required under BCLE Reg. 201:2
New Mexico

Approved for CLE Credits
2 General

Nevada

Pending CLE Approval
2 General

New York

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New York’s Approved Jurisdiction Group “B”.
Ohio

Pending CLE Approval
2 General

Oklahoma

Pending CLE Approval
2.5 General

Oregon

Pending CLE Approval
2 General

Pennsylvania

Approved for CLE Credits
2 General

Rhode Island

Pending CLE Approval
2.5 General

South Carolina

Pending CLE Approval
2 General

South Dakota

No MCLE Required
2 CLE Hour(s)

Tennessee

Pending CLE Approval
2 General

Texas

Approved for CLE Credits
2 General

Utah

Pending CLE Approval
2 General

Virginia

Not Eligible
2 General Hours

Vermont

Approved for CLE Credits
2 General

Washington

Approved via Attorney Submission
2 Law & Legal Hours

Receive CLE credit in Washington via attorney submission.
Wisconsin

Pending CLE Approval
2 General

West Virginia

Pending CLE Approval
2.4 General

Wyoming

Pending CLE Approval
2 General

More CLE Webinars
Upcoming CLE Webinars
Derivatives, Digital Assets, and AI in Financial Markets
Derivatives, Digital Assets, and AI in Financial Markets Fri, September 11, 2026
Live Webcast