← All Articles

The Leaker You Cannot Find: Privacy Litigation and the Attribution Problem

When confidential material escapes, the instinct is to sue. But privacy and leak litigation contains a structural paradox that most plaintiffs discover only after they have paid to learn it: the law's primary remedy for a leak runs against the person who leaked, and the person who leaked is almost always the one party the plaintiff cannot identify. Everything downstream of that fact, every motion, every subpoena, every settlement posture, is shaped by whether the plaintiff can put a name on the source. Most cannot.

The Remedy Runs Against the Leaker

The clearest statement of this comes from the Supreme Court. In Bartnicki v. Vopper, 532 US 514 (2001), an unknown person intercepted a private phone call during a labor dispute and left the recording in a third party's mailbox. A radio commentator who had no part in the interception broadcast it. The Court held, six to three, that the First Amendment protected the broadcaster: a stranger's illegal act does not strip constitutional protection from someone who lawfully received the material and published truthful information on a matter of public concern.

The reasoning is the part that matters for anyone holding sensitive material. The Court explained that "the normal method of deterring unlawful conduct is to impose an appropriate punishment on the person who engages in it." Translated into practice, the Constitution points the remedy at the leaker, not at the megaphone. The person who took the material is liable. The person who amplified it, if they came by it lawfully and it bears on a public issue, often is not.

Bartnicki's shield is strongest when the leaked material is a matter of public concern and truthful. Purely private material, an intimate image or a medical record, is a weaker candidate for that protection. But the structural point survives regardless of the material's character: the party a plaintiff most wants to reach is the original source, and the doctrine assumes that source can be identified and punished. When the source is anonymous, the assumption fails and the remedy fails with it.

Why the Downstream Targets Fail

A plaintiff who cannot find the leaker will look for someone closer at hand. Three familiar substitutes exist, and each collapses for a predictable reason.

The publisher cannot reliably be enjoined. An order forbidding publication is a prior restraint, the single most disfavored remedy in American constitutional law. From Near v. Minnesota, 283 US 697 (1931), through the Pentagon Papers decision in New York Times Co. v. United States, 403 US 713 (1971), and Nebraska Press Assn v. Stuart, 427 US 539 (1976), courts have refused all but the narrowest injunctions against speech. A plaintiff who asks a court to order a website to take down leaked material is asking for the relief the First Amendment most resists.

The platform cannot be sued for hosting. Section 230 of the Communications Decency Act, 47 USC § 230, immunizes online services from liability for content posted by their users. The site that hosts the leak is generally beyond reach. The recent exception is narrow: the federal TAKE IT DOWN Act, signed in May 2025 and enforceable against platforms as of May 2026, requires covered platforms to remove non-consensual intimate imagery within 48 hours of a valid request, on pain of Federal Trade Commission enforcement. That is a removal mechanism for one category of content, not a damages remedy, and it does nothing to identify who posted the material in the first place.

The distribution cannot be recalled. Even a plaintiff who wins an order against one host achieves little. A file that has been copied is not retrievable. No injunction reaches the drives it already sits on. The practical futility of chasing distributed material is why the fight, if it is winnable at all, has to be won before the material moves, not after.

So Everything Turns on Attribution

Strip away the substitutes and the case comes back to a single question: who released this. That question is often unanswerable. A plaintiff who suspects an anonymous online poster must file a John Doe action and seek to unmask the account through subpoena, and courts require a threshold evidentiary showing before they will compel a platform to reveal an identity, under the standards developed in cases such as Dendrite International, Inc. v. Doe No. 3 (NJ App Div 2001) and Doe v. Cahill (Del 2005). Even a plaintiff who clears that bar frequently finds nothing at the end of the subpoena: a VPN, a burner account, a dead trail.

The harder version of the problem is internal. Confidential material rarely leaks from a stranger. It leaks from someone who was authorized to see it: an employee, a contractor, a co-party in litigation, a vendor. A document that passed through a dozen authorized hands, each holding an identical copy, ordinarily carries no marking that distinguishes which hand released it. The plaintiff knows the leak came from inside a defined group and still cannot say which member did it. Suspicion is not proof, and a misidentified defendant is its own liability.

Where This Bites

The attribution bottleneck runs through every category of leak litigation. In non-consensual intimate imagery cases, Oregon supplies both a criminal offense, ORS 163.472, and a civil action, ORS 30.833, which authorizes injunctive relief, damages, punitive damages, and attorney fees. The remedies are real, but each requires a named defendant. In trade secret cases, the Defend Trade Secrets Act, 18 USC § 1836, and Oregon's Uniform Trade Secrets Act give a misappropriation claim, but a misappropriation claim needs a misappropriator. In litigation itself, materials produced under a protective order leak with some regularity, and a motion for sanctions goes nowhere without evidence of the source. In the public-disclosure-of-private-facts tort, recognized in the Restatement (Second) of Torts § 652D and in Oregon privacy law, the same gap appears: the tort is available, the defendant is unknown.

The Leverage Moved Upstream

Because the remedies that follow a leak are weak, disfavored, or futile, the effective center of gravity has moved to the moment before the leak. If after-the-fact litigation cannot reliably reach the source, the alternative is to make the source identifiable in advance: to bind sensitive material to the identity of each authorized recipient so that any copy that surfaces testifies to its own origin. This is the logic behind forensic watermarking and content-binding, and it is the problem a growing set of tools, including PrivateBond, is built to address under the heading of content privacy and protection.

Traceable attribution does not stop a determined insider from leaking. What it changes is the evidentiary posture. It converts the unanswerable question, who released this, into a fact that a chart and an expert can establish. That conversion is decisive, because every doctrine surveyed above, from Bartnicki forward, rewards the plaintiff who can name the source and strands the plaintiff who cannot.

The privacy plaintiff who can prove attribution has a case. The one who cannot has a grievance. The tools that move a matter from the second column to the first are, increasingly, not the legal ones. They are the ones that make a leaked document reveal who let it go.

David Brunk is a civil litigation attorney. newmanbrunk.com  ·  david@newmanbrunk.com

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

Questions about this topic: david@newmanbrunk.com

Practice areas