▼
Allegations Only · No Settlement Yet
This article describes two class action complaints. The statements below are unproven
allegations. BuzzFeed Media Enterprises, Inc. has not been found liable, there is no certified
class, and nothing to claim at this time. This page is informational and is not legal advice.
BuzzFeed Media Enterprises, Inc. began mailing data breach notices on September 14, 2026. According to the
company’s sample letter, filed with the Massachusetts Office of Consumer Affairs and Business Regulation,
BuzzFeed learned on August 19, 2026 that a misconfiguration in two BuzzFeed-controlled Google Groups
allowed unauthorized viewing of sensitive data. BuzzFeed said it secured the groups by August 20, 2026 and
had no evidence that any information had been misused.
Two former employees have since filed proposed class actions in the U.S. District Court for the Southern
District of New York: Bronstein v. BuzzFeed Media Enterprises, Inc., No. 1:26-cv-08153, filed
September 18, 2026, and Todd v. BuzzFeed Media Enterprises, Inc., No. 1:26-cv-08185, filed
September 21, 2026. Both allege BuzzFeed failed to safeguard information employees gave it as part of
their employment. No court has ruled on any of the allegations.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Status
Two Complaints Filed
September 18 and 21, 2026 · S.D.N.Y. · no class certified
Data Exposed (per BuzzFeed’s notice)
Social Security numbers, bank account numbers, driver’s license or passport numbers
Also names, dates of birth, phone numbers, email and home addresses · number affected not disclosed
Free Credit Monitoring
24 months of Experian IdentityWorks
Offered in BuzzFeed’s notice · enrollment deadline December 31, 2026
Can I Claim?
No — nothing to claim yet
The notice describes the exposed information as possibly including a person’s full name, date of birth,
Social Security number, bank account number, driver’s license or passport number, telephone number, email
address and physical address. It says BuzzFeed investigated with its internal IT team and corrected the
access settings on the Google Groups by August 20, 2026, one day after the report.
The letter offers 24 months of Experian IdentityWorks credit monitoring and identity restoration at no
cost, with enrollment open through December 31, 2026 at 11:59 p.m. UTC using a code printed in the letter.
Neither the sample notice nor either complaint says how many people were affected or who made the report
to BuzzFeed.
The two complaints are nearly identical in their factual allegations. Each named plaintiff says they are a
former BuzzFeed employee who provided personal information to the company in connection with their
employment and received the breach notice. The complaints allege that:
- BuzzFeed had a duty to keep employees’ information secure and failed to use reasonable safeguards,
including controls over who could view sensitive data
- The notice is incomplete because it does not say exactly how the breach occurred, the dates the
exposure took place, or whether the threat was fully contained
- Two years of credit monitoring is inadequate because the risk from a stolen Social Security number
lasts far longer
Both plaintiffs say the breach has left them at a continuing risk of identity theft and will cost them time
spent monitoring their accounts and credit. These are allegations; BuzzFeed has not yet responded in court.
Both complaints propose a nationwide class of all persons in the United States whose information was
impacted by the data breach, including everyone who received BuzzFeed’s notice. The Todd complaint
adds a California Subclass of California residents whose information was compromised. BuzzFeed, its
affiliates and the judge are excluded. These are proposed definitions; a court would have to certify a
class before anyone is formally part of the case.
Both complaints bring claims for negligence, negligence per se, breach of implied contract and unjust
enrichment on behalf of the nationwide class. The Todd complaint adds two California claims for the
California Subclass: violation of the Unfair Competition Law and violation of the California Consumer
Privacy Act’s data breach provision, Cal. Civ. Code § 1798.150.
The lawsuits ask the court to certify the classes and seek damages, statutory damages or penalties where
available, restitution, interest and other relief. Those are requests, not amounts anyone has been awarded.
When several suits are filed over the same breach in the same court, they are commonly consolidated into a
single case with one set of lead lawyers. BuzzFeed will then respond, often with a motion to dismiss. The
case could also settle; data breach settlements typically pay for documented losses and sometimes a flat
cash amount, and require a claim form.
There is nothing to file in the lawsuits now. The Experian enrollment offer in BuzzFeed’s letter is a
separate, company-run program with its own December 31, 2026 deadline. If a settlement is reached, notice
recipients would normally be told how to file a claim.
Can I get money from the BuzzFeed data breach lawsuits?
Not now. Both cases were filed in September 2026 and are at the complaint stage. No class has been certified, there is no settlement, and there is no claim form. BuzzFeed has not been found liable. Money would only become available if a case settles or the plaintiffs win.
Who was affected by the BuzzFeed data breach?
BuzzFeed sent notice letters starting September 14, 2026 to people whose information was in two misconfigured Google Groups. Both named plaintiffs in the lawsuits are former BuzzFeed employees who say they gave the company their information as part of their employment. Neither BuzzFeed’s sample notice nor the complaints state how many people were affected.
What information was exposed in the BuzzFeed breach?
According to BuzzFeed’s notice letter, the information may have included full names, dates of birth, Social Security numbers, bank account numbers, driver’s license or passport numbers, telephone numbers, email addresses and physical addresses. BuzzFeed said it had no evidence the information had been misused.
What is BuzzFeed offering people who got a notice?
BuzzFeed’s notice offers 24 months of Experian IdentityWorks credit monitoring and identity restoration at no cost. The letter says the activation code must be used to enroll by December 31, 2026 at 11:59 p.m. UTC. The credit monitoring offer is separate from the lawsuits.
Is this related to the BuzzFeed video privacy settlement?
No. BuzzFeed’s earlier $9 million settlement involved a different claim about video viewing data. The 2026 lawsuits are about the August 2026 Google Groups data exposure and involve different people.
• Class Action Complaint, Todd v. BuzzFeed Media Enterprises, Inc., No. 1:26-cv-08185 (S.D.N.Y., filed September 21, 2026):
Todd complaint (PDF).
• Class Action Complaint, Bronstein v. BuzzFeed Media Enterprises, Inc., No. 1:26-cv-08153 (S.D.N.Y., filed September 18, 2026):
Bronstein complaint (PDF)
and docket on CourtListener.
• BuzzFeed Media Enterprises, Inc., “Important Security Notification” sample letter (September 14, 2026), filed with the Massachusetts Office of Consumer Affairs and Business Regulation:
BuzzFeed breach notice (PDF).
For more class actions keep scrolling below.
Status
Complaints Filed — No Class Certified
Cases
Bronstein v. BuzzFeed Media Enterprises, Inc. · Todd v. BuzzFeed Media Enterprises, Inc.
Case Numbers
1:26-cv-08153 · 1:26-cv-08185
Court
U.S. District Court, Southern District of New York
Dates Filed
September 18 and September 21, 2026
Breach Reported to BuzzFeed
August 19, 2026
Notices Sent
Beginning September 14, 2026