LexisNexis Lawsuits: FCRA Class Actions, Daniel’s Law, Breaches

LexisNexis Risk Solutions, the data analytics arm of the RELX Group, has been the target of a long line of lawsuits over inaccurate consumer reports, mishandled personal information, false claims tied to government contracts, and the sale of surveillance tools to federal immigration authorities. The LexisNexis lawsuits summarized below include multimillion-dollar class action settlements, appellate rulings on the Fair Credit Reporting Act, and pending or recently dismissed cases involving state privacy laws.

The $13.5 Million “Deceased” Class Action Settlement

One of the most recent settlements involves people who were falsely flagged as dead in LexisNexis databases. In Scroggins v. LexisNexis Risk Solutions FL Inc., filed in the U.S. District Court for the Eastern District of Virginia (Case No. 3:22-cv-00545-MHL-SLS), the plaintiff alleged that LexisNexis violated the Fair Credit Reporting Act by incorrectly reporting living consumers as deceased in its identity-verification and fraud-prevention products.

The proposed settlement, filed on October 3, 2025, created a $13.5 million fund covering two groups:

  • Contact Members, meaning people who reached out to LexisNexis between August 11, 2017, and November 4, 2025, to ask about a “deceased” notation on a company report. They receive payment automatically.
  • Product Members, meaning people whose identity-verification or fraud-prevention transactions returned a false deceased notation during the same period. They had to file a claim.

Preliminary approval came on November 4, 2025, with a final approval hearing set for March 16, 2026. The claim window for Product Members closed on May 16, 2026. Individual payments were estimated between $150 and $1,000 depending on claim volume, after up to $4.4 million in attorneys’ fees and a service award of up to $7,500 for the named plaintiff.

Background-Check Accuracy Lawsuits Under the FCRA

LexisNexis has been sued repeatedly over errors in the background-check reports it sells to employers, landlords, and other businesses. These cases turn on whether the company followed “reasonable procedures to assure maximum possible accuracy,” as the FCRA requires.

Smith v. LexisNexis Screening Solutions

David Alan Smith lost a job offer after LexisNexis attributed the criminal fraud conviction of another person with a similar name to his report. The company did not require middle names in its criminal-history searches, even when the requesting employer supplied one. A jury in the Eastern District of Michigan found LexisNexis negligent and reckless, awarding $75,000 in compensatory damages and $300,000 in punitive damages, which the trial court later reduced to $150,000.

On appeal in 2016, the Sixth Circuit affirmed that LexisNexis had failed to follow reasonable accuracy procedures and rejected the company’s argument that plaintiffs must show “reasonable alternatives” or prior notice of the specific error. The court reversed the punitive damages, holding that negligence alone does not meet the FCRA’s “willful” standard. It noted that LexisNexis maintained an overall accuracy rate of about 99.8 percent and corrected Smith’s report soon after he raised the issue.

The Esteem Retail Theft Database

In Goode, et al. v. LexisNexis Risk & Information Analytics Group Inc. (Case No. 2:11-cv-02950), plaintiffs challenged the company’s “Esteem” database, which tracked employees accused of theft or fraud and assigned them scores used in hiring. They alleged LexisNexis took adverse action before providing the notices and reports required by the FCRA, and that it withheld signed “admission statements” from consumers’ files.

A federal judge in Pennsylvania allowed the case to proceed, finding the withholding of admission statements could be “willful” and support punitive damages. The parties settled in August 2014. LexisNexis agreed to suspend the Esteem database and impose stricter safeguards if it were ever revived for employment screening. Roughly 3,000 class members received about $800 each.

Berry v. LexisNexis and the Accurint Reports

In Berry v. LexisNexis Risk Management, Inc. (Case No. 3:11-cv-00754-JRS, E.D. Virginia), plaintiffs alleged the company sold Accurint reports to debt collectors without treating them as “consumer reports” subject to FCRA protections. The case settled for $13.5 million, covering individuals who requested copies of their Accurint reports or disputed information between October 2006 and April 2013. LexisNexis agreed to change how it classified and handled those reports.

Telespectrum Background-Check Settlement

An earlier class action, tied to LexisNexis reports used by Telespectrum, a call center in Newport News, Virginia, produced a $20.7 million proposed settlement that received preliminary approval in April 2008. The case involved failures to give employees the required adverse-action notice and copies of their background reports before termination. The court also flagged a company policy requiring two forms of identification before it would investigate a dispute, describing it as a barrier to contesting inaccurate reports.

The Castellanos Lawsuit Over ICE Surveillance

LexisNexis holds a $22.1 million contract with U.S. Immigration and Customs Enforcement to provide access to personal data through its Accurint platform. The contract began in February 2021 at $16.8 million and expanded in June 2021 to include jail booking and incarceration data from the Appriss Insights “Justice Intelligence” database. Between March and September of that year, ICE agents ran more than 1.2 million searches through the system.

The complaint in the resulting lawsuit described Accurint as compiling “encyclopedic dossiers” from public and non-public sources, including Social Security numbers, addresses, court records, utility data, cell phone records, and license plate images. The database reportedly holds information on 276 million people in the United States.

In August 2022, three individuals and two advocacy organizations, Mijente Support Committee and Organized Communities Against Deportations, sued LexisNexis in Cook County, Illinois. They alleged that the mass collection and sale of personal data to ICE without consent violated the Illinois Consumer Fraud and Deceptive Business Practices Act and constituted intrusion upon seclusion and unjust enrichment. Plaintiffs argued the practice enabled warrantless surveillance and circumvented sanctuary protections such as the Illinois TRUST Act and Chicago’s Welcoming City Ordinance.

The case was removed to the U.S. District Court for the Northern District of Illinois (Case No. 22 C 5384). On April 8, 2024, Judge LaShonda A. Hunt granted LexisNexis’s motion to dismiss all counts, finding that the individual plaintiffs were not “consumers” of LexisNexis products under the state statute, that the information at issue (names, addresses) did not qualify as “private facts” for the intrusion claim, and that the unjust-enrichment count failed as derivative of the others. Plaintiffs were given until April 29, 2024, to amend. LexisNexis has maintained that its tools “promote public safety,” are “not used to prevent legal immigration,” and that the DHS contract complies with governing statutes and regulations.

Daniel’s Law Retaliation Case in New Jersey

New Jersey’s Daniel’s Law, enacted after the 2020 murder of federal Judge Esther Salas’s son by a gunman who found the judge’s home address online, lets judges, prosecutors, and law enforcement officers demand that data brokers stop disclosing their home addresses and unpublished phone numbers. In early 2024, an estimated 18,000 or more public servants who had submitted such requests to LexisNexis sued in federal court in Newark.

The complaint in Doe et al. v. LexisNexis Risk Data Management, LLC (Case No. 2:24-cv-04566, D.N.J.) alleged that instead of removing the protected information, LexisNexis imposed unauthorized security freezes on plaintiffs’ entire credit files, told third parties the individuals had suffered “identity theft,” and continued making their personal information available. Plaintiffs framed these steps as retaliation for exercising rights under the statute. The New Jersey State Policemen’s Benevolent Association backed the case.

In a January 2025 ruling, the court dismissed the amended complaint but allowed another attempt. The judge found the state-law claims under the New Jersey Identity Theft Protection Act were preempted by the federal FCRA, that the interference-with-contract claims lacked sufficient factual detail, and that one plaintiff’s freeze-removal claim failed because he had not alleged he provided the PIN required by statute. Plaintiffs were given until February 6, 2025, to file a second amended complaint under the FCRA.

Multistate False Claims Settlement Over Crash Reports

In July 2019, LexisNexis agreed to pay $5.8 million to resolve allegations by five states and the City of Baltimore that it had cheated law enforcement agencies out of fees owed on resold vehicle crash reports. The case began as a whistleblower complaint from a former LexisNexis employee.

According to the participating attorneys general, LexisNexis paid agencies a fee on the initial sale of a crash report but withheld the contractually required fee on every subsequent resale, and omitted those repeat sales from the reports it gave the agencies. The conduct ran from June 2012 through May 2019. The participating jurisdictions were New York (which recovered about $1.7 million), Tennessee ($1.12 million), Massachusetts ($750,000), Illinois, New Jersey, and Baltimore. The whistleblower received approximately $1.1 million. LexisNexis also agreed to stop withholding fees on resold reports.

Data Breach Litigation

In December 2024, LexisNexis Risk Solutions disclosed that an unauthorized party had accessed a third-party platform used for software development, compromising the personal data of 364,333 individuals. The exposed information included names, dates of birth, phone numbers, email addresses, Social Security numbers, and driver’s license numbers. The company said no financial or credit card data was affected. Plaintiffs’ attorneys investigated whether the breach could support a class action, and the company has faced litigation scrutiny in the aftermath. No final outcome of a breach-specific class action is established in the available record.

The 2024 incident was not the company’s first significant data compromise. In early 2005, Reed Elsevier, the corporate predecessor to RELX, disclosed that personal data for 310,000 individuals had been stolen through its Seisint unit, acquired in July 2004 for $775 million. The company originally reported 32,000 people affected before revising the figure tenfold. Unauthorized users obtained access through credentials belonging to former employees of Seisint customers, weak passwords, and a computer virus. Exposed data included Social Security numbers, driver’s license information, and home addresses. The incident prompted federal proposals to restrict the sale of Social Security numbers and tighten regulation of data brokers.