People whose email addresses turn up in dark web monitoring scans are receiving alerts naming a “Disney Internal 37M (Slack)” breach, which traces to the July 2024 leak of Disney’s internal Slack data rather than a new hack. A proposed employee class action over that leak settled and was dismissed in Los Angeles without a public claim process, so there is nothing to claim.
This article describes a class action complaint. The claims in it are unproven allegations. The Walt Disney Company was never found liable, no class was certified, the case was dismissed after a settlement whose terms are not public, and there is nothing to claim. This page is informational and is not legal advice.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
No new Disney breach has been reported. The name matches the July 2024 leak of Disney’s internal Slack data, which was posted on a hacking forum under the title “DISNEY INTERNAL SLACK.” The “date found” on an alert is when the monitoring service came across a copy of the files, not when the data was taken.
Neither Disney nor federal prosecutors have published a 37 million figure. Prosecutors described about 1.1 terabytes of data from thousands of Slack channels, and press reports counted more than 44 million messages. The 37M label appears to be the monitoring service’s own count of records in the copy it found; OCA could not match it to any official number.
No. A proposed class action, Margel v. The Walt Disney Company, was filed in Los Angeles County Superior Court in October 2024 on behalf of people who gave Disney personal information in connection with their employment. A notice of settlement was filed in September 2025 and the case was dismissed in February 2026, but no class was certified, no settlement terms were made public and no class notice or claim form was issued, so there is nothing to claim.
Ryan Mitchell Kramer of Santa Clarita, California, who posed as a hacktivist group called NullBulge. He pleaded guilty in federal court in Los Angeles to accessing a computer and obtaining information and to threatening to damage a protected computer, and in May 2026 he was sentenced to 15 months in prison.
Not necessarily. An alert means the monitoring service found the email address somewhere in the leaked files. The Slack data was internal workplace messages and documents, so an outside email address could appear in a message, a spreadsheet or a shared file without any password attached. The alert service’s own breach details list which kinds of data it found.