Capital One Loses Bid to Shield Post-Breach Report from Consumer Plaintiffs
Insights for Insurers Alert | 2 min read
Jun 29, 2020
On June 25, a Federal District Court in Virginia (Anthony J. Trenga, U.S.D.J.) affirmed a Magistrate Judge's Order requiring Capital One to produce a vendor's post-breach forensic report to plaintiffs in a consumer class action. In doing so, it rejected the bank's argument that the report was protected attorney work product.
Capital One had a forensic vendor, Mandiant, on a retainer to generally assist with cybersecurity matters, including any potential incident responses, prior to the 2019 data breach at issue. After the breach, Capital One and its outside counsel formally engaged Mandiant to conduct an investigation of the 2019 breach and prepare a written report. Capital One sought to have the Order set aside on various legal grounds, along with arguing the Order was "unworkable" and incentivized companies to (1) forego keeping an incident response vendor on retainer, or (2) hire a new, unfamiliar vendor to investigate incidents that are expected to result in litigation.
To set the Order aside, the district court said Capital One was required to prove that the post-breach report (1) was created when the litigation was a real likelihood and not when it was a mere possibility; and (2) would not have been created in essentially the same form in the absence of the litigation. Because there was no dispute concerning the first prong of the test, the court's analysis focused on the second prong, also known as the "but for" or "driving force" test. Capital One was required to demonstrate that the report would not have been prepared in substantially similar form but for the prospect of litigation.
Capital One asserted that Mandiant changed the nature of its investigation, the scope of work, and its purpose in anticipation of litigation. The bank further contended that Mandiant's investigation and report would have been very different if Mandiant had been engaged to investigate the breach for business purposes; a report prepared for business purposes would have focused on remediation, while a report prepared at the direction of counsel would focus on causation issues, according to Capital One.
That contention, the court stated, appeared "hollow" in light of the "identical" services covered under Mandiant's pre-breach agreement with Capital One and its post-breach engagement letter. The court said the primary difference between those two documents concerned the role that Capital One's outside counsel would play, and that Capital One failed to prove that the report would have been substantively different if it had been produced in the ordinary course of business absent the involvement of outside counsel.
The court also rejected Capital One's assertion that the Magistrate Judge should not have relied on the distribution of the post-breach report to approximately 50 employees, Capital One's board of directors, and regulators when deciding that the report was not entitled to work product protection, stating that "post-production disclosures are appropriately probative of the purposes for which the work product was initially produced."
The court then noted that Capital One's argument that the Order was unworkable "ignores the alternatives available to produce and protect work product, either through different vendors, different scopes of work and/or different investigation teams."
Related Content
In our prior post on this case, we discuss practical steps companies can take to protect post-breach reports from disclosure in light of the Capital One decision.
Related Capabilities
Featured Insights

Press Release
Aug 7, 2026
Daniel McGrath Re-Elected Senior Director of the Federation of Defense & Corporate Counsel

Insights for Insurers Alert
Aug 7, 2026
California Supreme Court Clarifies Pleading Standards for Excess Policy Claims

Press Release
Aug 6, 2026
Charles Townsend Named a Best Mentor Finalist in the 2026 ALM Texas Legal Awards

Webinar
Aug 5, 2026
April Toy Moderates HNBA Webinar on AI in the Practice of Law

Privacy, Cyber & AI Decoded Alert
Aug 5, 2026
2026 AI Compliance: Upcoming Laws Every Organization Needs to Know

Press Release
July 21, 2026 | Updated on August 4, 2026
Three Hinshaw Attorneys Named to the 2026 National Black Lawyers’ Top 40 Under 40 List

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

In The News
Jul 29, 2026
Hinshaw Authors Contribute Two Articles in Latest Edition of the CCFL Quarterly Report

Webinar
Jul 28, 2026
Cathy Mulrow-Peattie and Sabrina Janeiro Present on Legal AI Technology
