A run of high-profile cybersecurity lawsuits filed between 2024 and 2026 is redrawing the lines of who pays when a breach happens. Clorox is chasing its IT help desk vendor for $380 million. Delta is pursuing CrowdStrike for a botched software update. Google has sued a China-based phishing network. Shareholders have started invoking the SEC’s new cyber disclosure rules against companies like Coupang and F5. And the SEC’s own signature enforcement case against SolarWinds ended in dismissal. The through-line is that liability is spreading outward from the breached company itself to vendors, executives, and the criminals running the infrastructure.
Clorox v. Cognizant: Can a Help Desk Be Liable for $380 Million
On July 22, 2025, Clorox sued Cognizant in Alameda County Superior Court in California, seeking $380 million tied to an August 11, 2023 cyberattack. The complaint pleads breach of contract, breach of good faith and fair dealing, gross negligence, and intentional misrepresentation, and demands a jury trial.1CSO Online. Clorox Sues Cognizant for $380M Over Alleged Helpdesk Failures in Cyberattack2CRN. Clorox Sues Cognizant for Providing Network Credentials Without Authentication
The alleged failure is remarkably simple. Members of the hacking group Scattered Spider called Cognizant’s help desk pretending to be Clorox employees. According to Clorox, agents reset passwords, disabled multi-factor authentication, and changed phone numbers on security accounts without asking for employee ID numbers, manager names, or any other identity check. Transcripts cited in the complaint reportedly show agents reading passwords aloud to the attackers.1CSO Online. Clorox Sues Cognizant for $380M Over Alleged Helpdesk Failures in Cyberattack
Clorox also blames Cognizant for a slow response. The complaint claims Cognizant staff took over an hour to reinstall a critical security tool that should have taken fifteen minutes and handed over incorrect IP address lists that delayed containment by eight hours. Outside counsel Mary Rose Alexander said: “Cognizant didn’t just drop the ball. They handed over the keys to Clorox’s corporate network to a notorious cybercriminal group.”3Cybersecurity Dive. Clorox Files $380 Million Suit Against Cognizant Over Cyberattack
Cognizant denies the framing. A spokesperson said the company was hired for a “narrow scope of help desk services” and did not manage cybersecurity for Clorox, adding: “It is shocking that a corporation the size of Clorox had such an inept internal cybersecurity system to mitigate this attack.”2CRN. Clorox Sues Cognizant for Providing Network Credentials Without Authentication
The damages number is grounded in real disruption. Ransomware encrypted key servers, severed manufacturing and distribution systems, and forced Clorox to process orders manually. Net sales dropped 20% to $1.4 billion in the first quarter after the attack, with roughly $24 million in direct costs and projected full-year incremental costs of $40 to $50 million.4Clorox SEC Filing. Clorox Form 8-K, November 2023 The lawsuit remains in active litigation as of mid-2026, with no settlement or ruling reported.5SCL. Why Is the Clorox Lawsuit Against Cognizant a Wake-Up Call for Third-Party Cyber Risk
Delta v. CrowdStrike: A Software Update, 7,000 Canceled Flights
Delta Air Lines sued CrowdStrike in Fulton County Superior Court in Georgia after a faulty CrowdStrike update in July 2024 triggered a global IT outage. Delta canceled roughly 7,000 flights and initially claimed more than $500 million in out-of-pocket losses.6CRN. 5 Things to Watch in Delta’s Lawsuit Against CrowdStrike
On May 16, 2025, Judge Kelly Lee Ellerbe issued a mixed ruling. She dismissed Delta’s claims for intentional misrepresentation and fraud by omission but let gross negligence and computer trespass claims proceed. Delta had earlier withdrawn its product liability and Georgia Fair Business Practices Act claims.6CRN. 5 Things to Watch in Delta’s Lawsuit Against CrowdStrike7John Bandler. Delta v. CrowdStrike and 2024 Outage
The remaining fight is about money and contract language. CrowdStrike argues its June 2022 subscription agreement caps liabilities “in the single-digit-millions of dollars” and excludes consequential damages. Delta disagrees. On the shareholder side, a consolidated derivative suit against CrowdStrike’s board and executives was dropped after a federal judge in Texas dismissed a related securities class action and no appeal was filed.8Bloomberg Law. CrowdStrike Shareholders Drop Board Suit Over Massive IT Outage
Google v. Outsider Enterprise: Suing the Phishing Ring Itself
On June 12, 2026, Google filed suit against a China-based cybercrime network called “Outsider Enterprise” in the U.S. District Court for the Southern District of New York. It was Google’s first civil action against parties for allegedly misusing its Gemini AI platform to run consumer scams.9Washington Examiner. Google AI Phishing Lawsuit Gemini Scams
Google says the group ran a “phishing-as-a-service” platform coordinated through Telegram, renting AI-powered kits for as little as $88 per week. The kits included more than 290 templates mimicking Google, YouTube, the U.S. Postal Service, the New York E-ZPass system, brokerage firms, and mobile carriers. In a two-week stretch in May 2026 alone, the network allegedly pushed 2.5 million messages to Android users tied to 9,000 fake websites and over a million fraudulent URLs.10New York Times. Google Lawsuit China AI Scams
The suit runs alongside a federal takedown called “Operation Ghost Hook,” coordinated with the FBI, Lumen Technologies, and AT&T, T-Mobile, and Verizon. Authorities seized core admin server domains, a Shopify storefront, roughly $100,000 in payment wallets, and thousands of domains registered through U.S.-based providers.11Cyberscoop. Outsider Cybercrime Network Takedown China FBI Google Lumen The FBI estimates losses linked to the group at $1.9 billion and 3.9 million stolen credit cards since July 2023.12OCCRP. Experts Say That Google’s Recent Scam Lawsuit May Have Limited Impact
Chester Wisniewski of Sophos said the suit would “increase the friction for fraudsters” and give Google a legal basis to seize reachable infrastructure, but was “unlikely to have a massive impact overall” given the ecosystem’s international scope. Brett Leatherman, assistant director of the FBI’s Cyber Division, said: “Criminals increasingly use A.I. to make fraud like this more convincing and harder to detect.”12OCCRP. Experts Say That Google’s Recent Scam Lawsuit May Have Limited Impact
Shareholder Suits Under the SEC’s New Disclosure Rules
Two securities class actions filed in December 2025 broke new ground by invoking the SEC’s cybersecurity disclosure rules, which took effect in late 2023. Those rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of a materiality determination.
Coupang: The First Suit Citing the New Rules
On December 18, 2025, shareholders sued South Korean e-commerce company Coupang in the Northern District of California, the first securities class action to include allegations tied specifically to the SEC’s cyber disclosure guidelines. The suit centers on a data breach discovered on November 18, 2025, that compromised personal information of more than 33 million customers and was allegedly carried out by a former employee who kept login credentials and exploited a system vulnerability.13D&O Diary. Two Tech Companies Hit With Data Breach-Related Securities Suits
The complaint, brought under Sections 10(b) and 20(a) of the Securities Exchange Act, alleges Coupang misrepresented its cybersecurity protocols and failed to report the breach in required SEC filings. A related action against Coupang and Chairman Bom Kim, filed in the Eastern District of New York, seeks $5 million in damages. An initial conference was scheduled for June 17, 2026, with a July 6, 2026 deadline for the defendant to answer.14UPI. Coupang Personal Data Breach Lawsuit
F5: A Nation-State Breach and a DOJ-Approved Delay
One day later, on December 19, 2025, shareholders sued cybersecurity firm F5 in the Western District of Washington. F5 had disclosed on October 15, 2025 that a “highly sophisticated nation-state threat actor” had persistent access to its systems, compromising BIG-IP source code and information about undisclosed vulnerabilities. The breach reportedly exposed more than 260,000 F5 BIG-IP systems globally.15DiCello Levitt. DiCello Levitt Named Lead Counsel in F5 Securities Class Action16Levi & Korsinsky. F5, Inc. Securities Class Action Lawsuit Update
F5 learned of the intrusion in August 2025 but delayed disclosure until October after the Department of Justice determined on September 12, 2025 that immediate disclosure would pose a “substantial risk to national security or public safety,” triggering the SEC’s Item 1.05(c) exemption.13D&O Diary. Two Tech Companies Hit With Data Breach-Related Securities Suits Shareholders argue that even with the government-approved delay, F5 was misleading investors by touting its security capabilities while the breach continued. F5’s stock fell nearly 14% after disclosure and another 11% after the company lowered its fiscal 2026 guidance. DiCello Levitt was appointed lead counsel in March 2026.15DiCello Levitt. DiCello Levitt Named Lead Counsel in F5 Securities Class Action
The SEC’s Own Retreat: SolarWinds Dismissed
Whether the SEC will actually enforce those rules is a separate question. In October 2023, the SEC sued SolarWinds and its chief information security officer, Timothy Brown, alleging the company misled investors about its cybersecurity posture and concealed vulnerabilities tied to the 2020 Orion breach. It was the first time the SEC brought a cyber enforcement action against an individual CISO.17Harvard Law School Forum on Corporate Governance. SolarWinds Dismissed: What the SEC’s U-Turn Signals for Cyber Enforcement
In July 2024, U.S. District Judge Paul Engelmayer dismissed most of the SEC’s claims, letting only limited claims about the company’s public “Security Statement” proceed. A July 2, 2025 settlement in principle fell apart, and on November 20, 2025 the SEC filed a joint stipulation dismissing all remaining claims with prejudice. The only condition was that SolarWinds and Brown waived any right to seek reimbursement for legal fees.18Hunton Andrews Kurth. SEC Dismisses Remainder of SolarWinds Case
Under Acting Chair Mark Uyeda, the SEC has shifted away from negligence-based cybersecurity claims toward “traditional scienter-based fraud” involving “egregious misstatements.” Form 8-K cybersecurity incident filings dropped from 19 in the first half of 2024 to just seven in the same period of 2025. The House Financial Services Committee urged the SEC to repeal the disclosure rules in March 2025, and the SEC withdrew proposed cyber rules for investment advisers and broker-dealers in June 2025.19Baker & Hostetler. A Deeper Dive: The SEC Cybersecurity Rule Enforcement Landscape
Where the Settlement Dollars Are Landing
Comcast: $117.5 Million
A proposed $117.5 million settlement in Hasson v. Comcast Cable Communications, LLC received preliminary approval on January 22, 2026. The case stems from an October 2023 breach exploiting a Citrix software vulnerability to access Xfinity customer data, affecting roughly 35 to 36 million customers. Compromised information included usernames, hashed passwords, partial Social Security numbers, dates of birth, and security questions. Final approval is set for August 5, 2026 in the Eastern District of Pennsylvania.20Classaction.org. Comcast Cable Communications LLC Data Breach Lawsuits21Comcast Breach Settlement. Comcast Breach Settlement
MGM Resorts: $45 Million
MGM Resorts International agreed to a $45 million settlement, preliminarily approved in January 2025, in a consolidated class action in the U.S. District Court of Nevada. The deal covers two incidents: a 2019 breach exposing driver’s license and passport numbers, and the September 2023 ransomware attack that disabled hotel room access and gaming machines and cost MGM roughly $100 million. About 37 million people were affected across both events.22Cohen Milstein. MGM Agrees to Pay $45 Million to Settle Data Breach Lawsuit
T-Mobile: $31.5 Million to the FCC
In September 2024, the FCC reached a $31.5 million consent decree with T-Mobile over breaches in 2021, 2022, and 2023. Half went to the U.S. Treasury as a civil penalty; the other half was earmarked for cybersecurity investments over two years. The FCC required T-Mobile to implement zero-trust architecture, deploy phishing-resistant multi-factor authentication, and have its CISO report regularly to the board on cyber risks.23Cybersecurity Dive. FCC Settlement T-Mobile Data Breaches24FCC. FCC Consent Decree, T-Mobile US, Inc. That was on top of a 2022 class action settlement of $500 million tied to a 2021 breach affecting more than 76 million people, split between $350 million for the class and $150 million in security investments.
Change Healthcare: The Biggest One Still Pending
The February 2024 ransomware attack on Change Healthcare, a UnitedHealth Group subsidiary that processes a large share of U.S. medical claims, may produce the most consequential cybersecurity litigation of all. Dozens of class actions from patients and healthcare providers have been consolidated into a multidistrict litigation in the District of Minnesota. As of mid-2026 the cases remain pretrial, with no global settlement approved. In May 2025, the presiding judge encouraged coordination between federal and state courts to move settlement talks forward.25Security.org. Change Healthcare Data Breach
A separate suit filed by the Nebraska Attorney General in December 2024, alleging consumer protection and data privacy violations, survived a motion to dismiss and is proceeding on its own track. The U.S. Department of Health and Human Services also opened a HIPAA investigation into whether Change Healthcare and UnitedHealth Group followed proper breach notification requirements.25Security.org. Change Healthcare Data Breach26Panorays. Change Healthcare Data Breach
Read together, these cases test the same question from different angles: when a breach or outage causes hundreds of millions in damages, who is on the hook? Clorox and Delta are trying to push liability onto vendors. Coupang and F5 shareholders are trying to push it onto executives and boards under new disclosure rules. Google is trying to push it onto the criminals themselves. And SolarWinds shows the limits of pushing it through federal enforcement. How each of these plays out will shape whether cybersecurity risk stays with the breached company or migrates across the contract, up to the C-suite, or out to the attackers.