Super Lawyers - Michael Nourmand
Best Lawyers
Super Lawyers - James A. De Sario
Consumer Attorneys
Lawyers of Distinction
Consumer Attorneys of California
Daily Journal
Los Angeles County Bar Association
Newsweek Showcase
Newsweek Top Attorneys

Identity Theft After a California Data Breach

Data Breach Identity Theft in California At a Glance

When information exposed in a data breach is used to commit fraud, California lets the victim pursue both statutory damages under Cal. Civ. Code § 1798.150 and the actual losses the theft caused.

  • What the theft looks like: New-account fraud, tax-refund fraud, medical identity theft, and unemployment fraud committed with breached data.
  • Governing law: The private right of action under § 1798.150, the Confidentiality of Medical Information Act for medical identity theft, and the Unfair Competition Law.
  • What you can recover: Statutory damages of $100 to $750 per incident under § 1798.150, plus documented fraud losses, credit-repair costs, and time spent.
  • The link that matters: Connecting the specific breach to the fraud that followed is the core of the case.
  • Free steps to act: A credit freeze and fraud alerts cost nothing and block most new-account fraud.
  • Where to report it: The Federal Trade Commission’s recovery site and a police report create the record a claim relies on.

The Nourmand Law Firm helps California consumers whose stolen data was used against them, in Fresno, Bakersfield, Riverside, and communities across the state.

A data breach exposes information; identity theft is what happens when someone puts that information to use. The gap between the two can be days or years, and the fraud often surfaces long after the breach that made it possible has faded from the news. California treats that later harm as compensable, and it lets a victim reach back to the business whose security failure started the chain. The firm’s California data breach practice covers the underlying claim, and this page focuses on what happens once exposure turns into actual theft.

For 20 years the Nourmand Law Firm has represented Californians against companies far larger than they are, and an identity theft claim built on a corporate breach is the same kind of fight. The person harmed did nothing wrong, and the business that failed to protect their information is the one that should answer for it.

What Is Identity Theft After a Data Breach?

Identity theft after a breach is the fraudulent use of personal information that a business exposed through a security failure. It takes several forms. New-account fraud opens credit cards or loans in the victim’s name. Tax-refund fraud files a return using a stolen Social Security number to claim a refund. Medical identity theft obtains care or prescriptions in someone else’s name, and unemployment fraud claims benefits using stolen identities. Each begins with data that was supposed to be secure.

The legal thread connecting the breach to the theft is Cal. Civ. Code § 1798.150, which lets a consumer sue when nonencrypted personal information is exposed because a business failed to maintain reasonable security. The statute does not require that fraud already occurred, but where it has, that fraud becomes recoverable actual damages, and it strengthens the account of how the exposure caused real harm. The firm approaches these matters the way it approaches its broader consumer and employment practice, by pinning responsibility on the company that created the risk.

How Do These Cases Begin?

Most identity theft claims start with a discovery, not a notice. A credit application is denied for no reason the person recognizes. The IRS rejects a tax return because one was already filed under that Social Security number. A collection agency calls about an account the person never opened, or a medical bill arrives for treatment they never received. Each of those is a symptom of data already in the wrong hands.

Working backward from the fraud to the breach is what turns a frustrating personal ordeal into a claim. Many victims received a breach notice months earlier and set it aside, and matching the exposed data to the fraud that followed is often what reveals which company’s failure is responsible.

What Can You Recover After Identity Theft?

The recovery in an identity theft case comes from two directions at once. Under Cal. Civ. Code § 1798.150, a consumer may recover statutory damages of $100 to $750 per incident even without proving a loss, and the actual losses the fraud caused are recoverable on top. Those losses can include fraudulent charges, the cost of credit repair and monitoring, and the documented time spent untangling accounts.

Medical identity theft carries an added remedy. Where medical information was exposed and misused, the Confidentiality of Medical Information Act allows nominal damages of $1,000 per violation under Cal. Civ. Code § 56.36, without proof of an actual loss. Unfair competition claims under Bus. & Prof. Code § 17200 can add restitution where a business profited from cutting corners on security.

Source of recoveryWhat it coversAuthority
Statutory damages$100 to $750 per incident, no proof of loss requiredCiv. Code § 1798.150
Actual damagesFraud losses, credit repair, monitoring, time spentCommon law and statute
Medical identity theft$1,000 nominal damages per violationCMIA, Civ. Code § 56.36
Unfair business practicesRestitution and injunctive reliefBus. & Prof. Code § 17200

How Do You Prove a Breach Caused the Theft?

Causation is the heart of an identity theft claim, and it is built from records rather than assumption. The case matches the type of data used in the fraud to the data a particular breach exposed, and it uses the timing between the exposure and the misuse to connect them. Where several breaches could be responsible, the analysis narrows to the one whose exposed fields line up with the fraud.

These claims frequently proceed as class actions, because a breach that produced fraud for one person usually produced it for thousands. The firm’s reported case results include class recoveries between $1.35 million and $7.25 million, the scale a single security failure that caused widespread theft can reach.

What Evidence Does an Identity Theft Case Turn On?

An identity theft claim is won on documentation, and the strongest cases are the ones where the victim captured the fraud as it happened. The records below carry these matters.

  • The identity theft report: A report filed with the Federal Trade Commission and a police report create the official record that fraud occurred and when it was discovered.
  • Credit reports and fraud alerts: Reports from all three bureaus show the fraudulent accounts and inquiries that trace back to the exposed data.
  • The breach notice: The letter from the responsible business fixes what was exposed and helps connect the exposure to the fraud.
  • Financial and tax records: Statements, IRS notices, and collection letters document the fraudulent activity and the losses it caused.
  • A resolution log: A record of the calls, disputes, and hours spent fixing the damage supports a claim for actual damages.

How the Firm Traces Identity Theft to Its Source

Building an identity theft claim starts by finding the breach behind the fraud. The Nourmand Law Firm investigates which exposure put the data in circulation, establishes the link between that exposure and the fraud, and pursues the business responsible for both. It represents the people who were defrauded, never the companies whose security failed, and works in English and Spanish. Cases proceed on a no recovery, no fee basis, so a victim already spending money to recover their identity does not spend more to assert their rights.

What Should You Do if Your Identity Was Stolen?

Acting quickly both limits the damage and preserves the record a claim depends on. Take these steps as soon as you spot the fraud.

  • Report it officially. File a report at the Federal Trade Commission’s IdentityTheft.gov and with local police, which creates the record you will need to dispute fraudulent accounts.
  • Freeze and alert. Place a free security freeze and fraud alerts with all three credit bureaus to stop further accounts from being opened.
  • Dispute the fraud. Notify each bank, card issuer, and creditor of the fraudulent accounts in writing, and keep copies of everything you send.
  • Address tax and medical fraud. Contact the IRS if a fraudulent return was filed, and your insurer if care was billed in your name.
  • Preserve the trail. Keep every notice, statement, and report together, because they are the evidence that ties the theft to the breach.

Frequently Asked Questions About Data Breach Identity Theft

Can I Sue if a Data Breach Led to Identity Theft?

Yes, where the breach resulted from a business’s failure to maintain reasonable security. Cal. Civ. Code § 1798.150 allows a claim when nonencrypted personal information is exposed, and any fraud that follows is recoverable as actual damages in addition to the statutory amount. Connecting the theft to the specific breach is part of building the case.

How Do You Prove the Breach Caused the Fraud?

Causation is shown by matching the data used in the fraud to the data the breach exposed, and by the timing between the two. Breach notices, dark-web exposure reports, credit records, and the fraudulent accounts themselves are compared to establish that the misuse traces to that specific exposure.

What Is Medical Identity Theft?

Medical identity theft is the use of stolen information to obtain care, prescriptions, or insurance in another person’s name. Where medical information was exposed, Cal. Civ. Code § 56.36 allows nominal damages of $1,000 per violation, separate from other data breach remedies.

What Does It Cost to Hire the Firm for an Identity Theft Claim?

Nothing to start. These claims are taken on contingency, so the fee comes out of any recovery and there is none if the case does not succeed. The first consultation is free.

Related Practice Areas

Identity theft is the business’s failure made into your problem, and California law lets you hand it back. The Nourmand Law Firm takes these cases across California on contingency, charges no fee unless it recovers money, and reviews them for free in English or Spanish. Call 800-700-9243 or use the firm’s contact page to have a lawyer look at what happened.

Client Reviews

When I was fired, my employer failed to pay me all the wages that I earned. I hired The Nourmand Law Firm, they did the best and resolved my case very fast. I highly recommend them, they know what they are doing.

A.G.

I am very grateful to the attorneys because they helped me quickly and always kept me informed in every aspect of my case. I would recommend them to other people.

E.S.

Thank you very much for getting me a great settlement. You guys are the best. I will give your number out to anyone who ask me if I know any good lawyers. G-D bless you and have a merry Christmas and a bless new year.

T.W.

Contact Us

  1. 1 Free Consultation
  2. 2 No Recovery, No Fee
  3. 3 Se Habla Español
Fill out the contact form or call us at 800-700-WAGE (9243)  to schedule your free consultation.

Get In Touch