Ready to Register?

MyLawCLE All-Access Pass

Best choice

Add the All-Access Pass and get this program —
plus 1,000+ live CLE programs every year.


All specialty & ethics credits included
38 practice areas
New sections: AI & the Law, Practice Management
100s of current and trending legal topics
Nationally recognized and highly experienced presenters

$395 / year — this program included
Register with the All-Access Pass

This program + 1,000+ CLE programs, all year

Or register for just this program

Live Video Broadcast

Live webinar of this one program.
$195 Register

On-Demand Video

Recorded access + self-study credit.
$195 Register

Dark Web Evidence in Data Breach Class Actions: The Multiple-Compromise Defense

A data breach plaintiff’s PII may already be circulating on the dark web before the breach you are litigating. Learn to build or rebut dark web forensic evidence, plead traceability under TransUnion, and attack standing and predominance through class certification.

2026-09-28 12:00:00

Program Details

2026-09-28 12:00:00

Program Details

2026-09-28 12:00:00

Over 1,000+ webinars

2026-09-28 12:00:00

Course Overview

The Breach You Are Litigating May Not Be the One That Exposed Your Plaintiff

2026-09-28 12:00:00

Article III traceability was once an afterthought in data breach class actions. Two decisions ended that. Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) identified the factual allegations a plaintiff must plead to establish traceability. Holmes v. Elephant Insurance Co. (4th Cir. 2025) separated plaintiffs who can show their data on the dark web from those who cannot.

Plead without prior-exposure facts, and a motion to dismiss ends the case. Ignore historical dark web scans, and defense counsel builds the causal break for you. Skip the FRE 901, FRE 802, and Daubert foundation, and your forensic expert never testifies. Leave individualized traceability inquiries standing, and Rule 23(b)(3) predominance fails at certification.

You leave with the five-element pleading framework and the evidentiary foundation your expert must lay. You also leave with a defense playbook: post-breach forensic engagement through class certification opposition. This is judgment about timing, forum, and proof — work no research tool performs for you.

Format

CLE Credit

2h CLE Credits

Level

Intermediate

Length

2

Key topics that will be covered

01
Traceability Under TransUnion
How the multiple-compromise problem turns Article III traceability into the threshold fight in every data breach class action, on both sides of the caption.
02
Five Pillars of Pleading
How the five-element pleading framework drawn from Santos-Pagán v. Bayamón Medical Center and Holmes v. Elephant Insurance Co. changes what your complaint must allege before filing.
03
Dark Web Forensic Proof
How historical dark web scans, investigative tooling, and expert framing change what defense counsel can put before the court at the motion-to-dismiss stage.
04
Admissibility and Daubert
How FRE 901, FRE 802, and Daubert change the authentication and chain-of-custody foundation a forensic expert must lay to be heard.
05
Multiple-Compromise Playbook
How the defense’s timing, named-plaintiff targeting, and forum selection change plaintiff-side strategy from the complaint through Rule 23(b)(3) predominance.
06
Live Q&A and Takeaways
How each faculty member’s closing Q&A and takeaways turn the session frameworks into the next step in your own pending matter.

Program schedule

clock 12:00 pm - 1:00 pm EST

Defeating Data Breach Class Actions with Dark Web Forensic Evidence

This session examines how defense counsel can deploy dark web forensic evidence to challenge Article III standing in data breach class actions, focusing on the traceability requirement as the primary pressure point. Attorneys will learn how to use historical dark web scans, expert forensic testimony, and prior-exposure evidence to break the causal chain between a defendant’s breach and a plaintiff’s alleged harm. Attendees leave with a litigation playbook—from immediate post-breach forensic engagement through class certification opposition—grounded in the latest circuit authority.

Tyler R. BrideganTyler R. Bridegan
Scott J. HymanScott J. Hyman
Matt BarrettMatt Barrett
clock 1:10 pm - 2:10 pm EST

Pleading and Proving Traceability for Multiply-Breached Data Breach Plaintiffs

This session examines the plaintiff-side challenge of establishing Article III traceability when a data breach plaintiff’s PII has been exposed in multiple prior incidents. Attorneys will learn the five-element pleading framework drawn from recent circuit and district court decisions, including Santos-Pagán v. Bayamón Medical Center (1st Cir. 2026) and Holmes v. Elephant Insurance Co. (4th Cir. 2025), and will understand how defendants deploy dark web forensic evidence to defeat standing. Attendees will leave with actionable pleading strategies, an understanding of the emerging circuit split on intangible-harm concreteness, and practical guidance on when to engage dark web intelligence experts.

Tyler R. BrideganTyler R. Bridegan
Scott J. HymanScott J. Hyman
Matt BarrettMatt Barrett
Tyler R. Bridegan

Tyler R. Bridegan

Womble Bond Dickinson (US) LLP

Scott J. Hyman

Scott J. Hyman

Womble Bond Dickinson (US) LLP

Matt Barrett

Matt Barrett

Cyber Engineering Services, Incorporated (CyberESI)

Tyler R. Bridegan

Tyler R. Bridegan

Womble Bond Dickinson (US) LLP

Tyler Bridegan is a Partner in the privacy and cybersecurity practice at the international law firm, Womble Bond Dickinson (US) LLP, and the former Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office. He provides clients with support through the full life cycle of issues related to technology, from compliance challenges to vigorously defending against government investigations and litigation.

Education & Credentials

He holds the CIPP/US, CIPP/E, and CIPM credentials from the International Association of Privacy Professionals and is a Registered Practitioner under the Cybersecurity Maturity Model Certification framework.

Recognition & Leadership

The American Lawyer named him Litigator of the Week in 2022, and the D.C. Bar Association placed him on its Capital Pro Bono Honor Roll, High Honors List, for 2020–2021. Since 2024 he has co-chaired the Computer and Technology Section of the Texas Bar and the Privacy and Data Security Committee of the Federal Communications Bar Association. He also sits on the Law360 Cybersecurity and Privacy Editorial Board and on the Board of Editors of The Global Regulatory Developments Journal.

Professional Involvement

He serves on the IAPP Privacy Bar Section Advisory Board and on the Board of Directors of the Cholangiocarcinoma Foundation, and participates in the Houston Bar Association’s LGBTQ+ Committee. From 2021 to 2023 he co-chaired the Federal Communications Bar Association’s Video Programming and Distribution Committee. His writing on privacy and cybersecurity has appeared in Law360, National Defense Magazine, HR Executive, and Federal News Network, and he has spoken recently for the ABA Consumer Financial Services Committee and at the ABA Mid-Year Meeting.

Experience

He previously served as Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office and as Acting Legal Advisor to Commissioner Simington at the Federal Communications Commission, and has conducted or defended hundreds of government investigations involving state attorneys general, the FTC, the CFPB, the FCC, and the NYDFS. Representative matters include closing an FTC investigation of an artificial intelligence startup without further action, resolving an FTC investigation through a ROSCA settlement, and obtaining closure of an NYDFS data breach investigation without further action.
Scott J. Hyman

Scott J. Hyman

Womble Bond Dickinson (US) LLP

Scott J. Hyman is a Partner at Womble Bond Dickinson (US) LLP in Irvine, California, where he has spent more than three decades representing financial institutions, national banks, automobile finance companies, and loan servicers. He counsels and defends clients on privacy and cybersecurity, licensing and regulatory matters, and individual and class actions under state and federal Truth-in-Lending laws, UDAP laws, the Telephone Consumer Protection Act, the Fair Credit Reporting Act, and the Fair Debt Collection Practices Act. He is the lead author of “Using the Dark Web to Defend Data Breach Class Actions,” published in The Conference on Consumer Finance Law Quarterly Report.

Education & Credentials

He earned his J.D. with distinction from the University of the Pacific, McGeorge School of Law in 1990, where he served as Articles Editor on the Pacific Law Review Board of Editors and was a member of the Traynor Society, and holds a B.A. from The Pennsylvania State University, 1987, through the Schreyer Honors College. He completed the Harvard VPAL certificate in Cybersecurity: Managing Risk in the Information Age in 2020 and carries the CIPP/US, CIPP/E, CIPT, and CIPM credentials. He is admitted in California and Texas, before the U.S. District Courts for the Southern District of Texas and the Southern, Central, Eastern, and Northern Districts of California, the Ninth and Eleventh Circuits, and the Supreme Court of the United States.

Recognition & Leadership

He serves as Vice President and a Governing Committee member of the Conference on Consumer Finance Law and was elected a Fellow of the American College of Consumer Financial Services Lawyers in 2023. He sat on the Debt Collection Advisory Committee of the California Department of Financial Protection and Innovation from 2021 to 2025.

Professional Involvement

He has been a member of the International Association of Privacy Professionals since 2018 and sits on the advisory board for the Certificate Program in Big Data at California State University, East Bay’s College of Extended Learning. He authors the Fair Debt Collection Practices Acts section of CEB’s Debt Collection Practice in California, co-writes the Consumer Finance + Privacy Counsel blog, and has published dozens of articles in The Conference on Consumer Finance Law Quarterly Report and other scholarly periodicals. Recent writing includes “Emerging Cybersecurity Issues for Boards” in Directors and Boards.

Experience

His practice centers on defending banks, automobile finance companies, and loan servicers in privacy and cybersecurity matters, licensing and regulatory work, and consumer class action litigation. He presented on cybersecurity trends and best practices at the Athena Event in June 2025.
Matt Barrett

Matt Barrett

Cyber Engineering Services, Incorporated (CyberESI)

Matt Barrett is Chief Operating Officer of Cyber Engineering Services, Incorporated (CyberESI, www.cyberesi.com) – an industry leading managed cybersecurity services and cybersecurity consulting company. Mr. Barrett oversees all facets of operation, including service oversight, client communications, employee well-being, and corporate operations.

For nearly fourteen years, CyberESI has focused on cybersecurity and cyber supply chain challenges of the telecommunications industry. CyberESI offers grant opportunities and supports clients with part-time Chief Information Security Officer support, vulnerability assessments & penetration testing, and managed detection & response.

Education & Credentials

B.S. Biochemistry, Virginia Tech, 1991-1995 · B.A. Chemistry, Virginia Tech, 1991-1995.

Recognition & Leadership

He received the Department of Commerce Gold Medal Award and was named to the 2007 Federal 100. At NIST he led the development and publication of Cybersecurity Framework Version 1.1 and ran the awareness campaign behind its adoption, which reached an estimated thirty percent of domestic organizations, and he previously led the agency’s Security Content Automation Protocol program.

Professional Involvement

His standards work at NIST placed him at the center of the community that built and maintains the Cybersecurity Framework, and he served as President of the Trusted Security Alliance. He speaks on cybersecurity framework measurement and on critical infrastructure security.

Experience

Mr. Barrett previously led the Framework for Improving Critical Infrastructure Cybersecurity (a.k.a., Cybersecurity Framework; https://www.nist.gov/cyberframework) program for the National Institute of Standards and Technology (NIST).

Before NIST he was President of G2, Inc., a cybersecurity and signals intelligence firm he grew from forty to one hundred employees between 2009 and 2014, and earlier a Director at Computer Sciences Corporation, where he expanded the cybersecurity unit from fifteen to two hundred personnel.
Tyler R. Bridegan

Tyler R. Bridegan

Womble Bond Dickinson (US) LLP

Tyler Bridegan is a Partner in the privacy and cybersecurity practice at the international law firm, Womble Bond Dickinson (US) LLP, and the former Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office. He provides clients with support through the full life cycle of issues related to technology, from compliance challenges to vigorously defending against government investigations and litigation.

Education & Credentials

He holds the CIPP/US, CIPP/E, and CIPM credentials from the International Association of Privacy Professionals and is a Registered Practitioner under the Cybersecurity Maturity Model Certification framework.

Recognition & Leadership

The American Lawyer named him Litigator of the Week in 2022, and the D.C. Bar Association placed him on its Capital Pro Bono Honor Roll, High Honors List, for 2020–2021. Since 2024 he has co-chaired the Computer and Technology Section of the Texas Bar and the Privacy and Data Security Committee of the Federal Communications Bar Association. He also sits on the Law360 Cybersecurity and Privacy Editorial Board and on the Board of Editors of The Global Regulatory Developments Journal.

Professional Involvement

He serves on the IAPP Privacy Bar Section Advisory Board and on the Board of Directors of the Cholangiocarcinoma Foundation, and participates in the Houston Bar Association’s LGBTQ+ Committee. From 2021 to 2023 he co-chaired the Federal Communications Bar Association’s Video Programming and Distribution Committee. His writing on privacy and cybersecurity has appeared in Law360, National Defense Magazine, HR Executive, and Federal News Network, and he has spoken recently for the ABA Consumer Financial Services Committee and at the ABA Mid-Year Meeting.

Experience

He previously served as Director of Privacy and Technology Enforcement for the Texas Attorney General’s Office and as Acting Legal Advisor to Commissioner Simington at the Federal Communications Commission, and has conducted or defended hundreds of government investigations involving state attorneys general, the FTC, the CFPB, the FCC, and the NYDFS. Representative matters include closing an FTC investigation of an artificial intelligence startup without further action, resolving an FTC investigation through a ROSCA settlement, and obtaining closure of an NYDFS data breach investigation without further action.
Scott J. Hyman

Scott J. Hyman

Womble Bond Dickinson (US) LLP

Scott J. Hyman is a Partner at Womble Bond Dickinson (US) LLP in Irvine, California, where he has spent more than three decades representing financial institutions, national banks, automobile finance companies, and loan servicers. He counsels and defends clients on privacy and cybersecurity, licensing and regulatory matters, and individual and class actions under state and federal Truth-in-Lending laws, UDAP laws, the Telephone Consumer Protection Act, the Fair Credit Reporting Act, and the Fair Debt Collection Practices Act. He is the lead author of “Using the Dark Web to Defend Data Breach Class Actions,” published in The Conference on Consumer Finance Law Quarterly Report.

Education & Credentials

He earned his J.D. with distinction from the University of the Pacific, McGeorge School of Law in 1990, where he served as Articles Editor on the Pacific Law Review Board of Editors and was a member of the Traynor Society, and holds a B.A. from The Pennsylvania State University, 1987, through the Schreyer Honors College. He completed the Harvard VPAL certificate in Cybersecurity: Managing Risk in the Information Age in 2020 and carries the CIPP/US, CIPP/E, CIPT, and CIPM credentials. He is admitted in California and Texas, before the U.S. District Courts for the Southern District of Texas and the Southern, Central, Eastern, and Northern Districts of California, the Ninth and Eleventh Circuits, and the Supreme Court of the United States.

Recognition & Leadership

He serves as Vice President and a Governing Committee member of the Conference on Consumer Finance Law and was elected a Fellow of the American College of Consumer Financial Services Lawyers in 2023. He sat on the Debt Collection Advisory Committee of the California Department of Financial Protection and Innovation from 2021 to 2025.

Professional Involvement

He has been a member of the International Association of Privacy Professionals since 2018 and sits on the advisory board for the Certificate Program in Big Data at California State University, East Bay’s College of Extended Learning. He authors the Fair Debt Collection Practices Acts section of CEB’s Debt Collection Practice in California, co-writes the Consumer Finance + Privacy Counsel blog, and has published dozens of articles in The Conference on Consumer Finance Law Quarterly Report and other scholarly periodicals. Recent writing includes “Emerging Cybersecurity Issues for Boards” in Directors and Boards.

Experience

His practice centers on defending banks, automobile finance companies, and loan servicers in privacy and cybersecurity matters, licensing and regulatory work, and consumer class action litigation. He presented on cybersecurity trends and best practices at the Athena Event in June 2025.
Matt Barrett

Matt Barrett

Cyber Engineering Services, Incorporated (CyberESI)

Matt Barrett is Chief Operating Officer of Cyber Engineering Services, Incorporated (CyberESI, www.cyberesi.com) – an industry leading managed cybersecurity services and cybersecurity consulting company. Mr. Barrett oversees all facets of operation, including service oversight, client communications, employee well-being, and corporate operations.

For nearly fourteen years, CyberESI has focused on cybersecurity and cyber supply chain challenges of the telecommunications industry. CyberESI offers grant opportunities and supports clients with part-time Chief Information Security Officer support, vulnerability assessments & penetration testing, and managed detection & response.

Education & Credentials

B.S. Biochemistry, Virginia Tech, 1991-1995 · B.A. Chemistry, Virginia Tech, 1991-1995.

Recognition & Leadership

He received the Department of Commerce Gold Medal Award and was named to the 2007 Federal 100. At NIST he led the development and publication of Cybersecurity Framework Version 1.1 and ran the awareness campaign behind its adoption, which reached an estimated thirty percent of domestic organizations, and he previously led the agency’s Security Content Automation Protocol program.

Professional Involvement

His standards work at NIST placed him at the center of the community that built and maintains the Cybersecurity Framework, and he served as President of the Trusted Security Alliance. He speaks on cybersecurity framework measurement and on critical infrastructure security.

Experience

Mr. Barrett previously led the Framework for Improving Critical Infrastructure Cybersecurity (a.k.a., Cybersecurity Framework; https://www.nist.gov/cyberframework) program for the National Institute of Standards and Technology (NIST).

Before NIST he was President of G2, Inc., a cybersecurity and signals intelligence firm he grew from forty to one hundred employees between 2009 and 2014, and earlier a Director at Computer Sciences Corporation, where he expanded the cybersecurity unit from fifteen to two hundred personnel.

Credits by state

AK2.0
AL2.0
AR2.0
AZ2.0
CA2.0
CO2.0
CT2.0
DC2.0
DE2.0
FL2.0
GA2.0
HI2.0
IA2.0
ID2.0
IL2.0
IN2.0
KS2.0
KY2.0
LA2.0
MA2.0
MD2.0
ME2.0
MI2.0
MN2.0
MO2.4
MS2.0
MT2.0
NC2.0
ND2.0
NE2.0
NH120.0
NJ2.0
NM2.0
NV2.0
NY2.0
OH2.0
OK2.5
OR2.0
PA2.0
RI2.5
SC2.0
SD2.0
TN2.0
TX2.0
UT2.0
VA2.0
VT2.0
WA2.0
WI2.0
WV2.4
WY2.0

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

10,000+

Trusted by Legal Professionals

1000+

Live stream programs

24/7

Access to live webinars & recordings

70,000+

Trusted by Legal Professionals

MCLE Credits

Alabama
Pending
Alaska
Approved
Arizona
Approved
Arkansas
Approved
California
Approved
Colorado
Pending
Connecticut
Approved
Delaware
Pending
District of Columbia
No Required
Florida
Approved
Georgia
Pending
Hawaii
Approved
Idaho
Pending
Illinois
Pending
Indiana
Pending
Iowa
Pending
Kansas
Pending
Kentucky
Pending
Louisiana
Pending
Maine
Pending
Maryland
No Required
Massachusetts
No Required
Michigan
No Required
Minnesota
Pending
Mississippi
Pending
Missouri
Approved
Montana
Pending
Nebraska
Pending
Nevada
Pending
New Hampshire
Approved
New Jersey
Approved
New Mexico
Approved
New York
Approved
North Carolina
Pending
North Dakota
Approved
Ohio
Pending
Oklahoma
Pending
Oregon
Pending
Pennsylvania
Approved
Rhode Island
Pending
South Carolina
Pending
South Dakota
No Required
Tennessee
Pending
Texas
Approved
Utah
Pending
Vermont
Approved
Virginia
Not Eligible
Washington
Approved
West Virginia
Pending
Wisconsin
Pending
Wyoming
Pending

Alabama

Requirements

The Alabama State Bar MCLE Commission requires attorneys to complete 12 credits, including 1 ethics, by December 31 of each year. All credits must be reported by February 15 of the following year. A maximum of 12 credits, including 1 ethics credit, may be carried over for 1 year only.  

Formats

  • Attorneys can earn unlimited “live” credit through live seminars, live webcasts, and co-sponsored locations with MyLAWCLE-Alabama approved programs
  • Attorneys are limited to 6 credits per compliance period of “online” programs through MyLAwCLE On-Demand programs