Three unknown numbers buzz your phone before lunch. A collection text lands while you're in a meeting. That night, an email tells you your data showed up in a breach dump, and a week later your credit score drops for a card you never opened.
The Robocall and Spam Text Case
This is the one almost everyone encounters. A number you don't recognize, a prerecorded voice, a text pitching solar panels or a car warranty you never asked about. The volume is staggering: according to YouMail, U.S. consumers received 52.5 billion robocalls in 2025, with unwanted telemarketing and scam calls making up more than half the total.
The Telephone Consumer Protection Act treats each unwanted automated call or text as its own violation, not the campaign as a whole. That matters. A single company that blasts you with fifty texts after you've told them to stop isn't looking at one problem; it's looking at fifty. What makes a case here isn't annoyance. It's the pattern:
* No consent, or revoked consent. You never gave the company your number, or you told them to stop and they kept going anyway.
* Automated systems. The messages carry the fingerprints of a dialer or a prerecorded voice, not a real person calling.
* Documentation you actually kept. Screenshots, call logs, voicemails, and the exact date you said stop. Without these, the strongest claim gets thin fast.
The Debt Collector Who Won't Verify the Debt
A different flavor of harassment. Someone contacts you about a balance you don't recognize, or one you already paid, or one that belongs to a person with a similar name. You ask for verification; they keep calling.
The Fair Debt Collection Practices Act draws a hard line around this behavior. Collectors can't misrepresent what you owe, can't threaten action they don't intend to take, and can't keep contacting you after you've sent a written cease request. The moment they ignore a verification demand and keep dialing, the case shifts from a billing dispute to a statutory one.
Two details tend to decide these cases. Whether you asked for validation in writing, and whether the collector reported the disputed debt to a credit bureau without noting the dispute. The second one is often where the real damage happens.
The Credit Report Error That Won't Die
Credit reporting mistakes read like a paperwork nuisance until you try to buy a car or refinance a mortgage. Maybe it's a late payment that isn't yours, or a collection account for a bill you disputed years ago. Sometimes it's an old repossession that should have dropped off long ago and hasn't.
You file a dispute. The bureau confirms the item. The item stays.
The Fair Credit Reporting Act was built for this exact moment. Both the credit bureau and the company that furnished the bad information owe you a real investigation, not a coin flip. If they rubber-stamp the furnisher's response without looking at your evidence, they've likely broken the statute. A consumer rights law firm can pursue these cases on contingency, which matters, because the harm from a bad credit file is rarely the kind you can quantify on a receipt.
Save the dispute letters, the tracking numbers, and every reply the bureau sends back. The paper trail is the case.
The Data Breach Fallout Case
A retailer, a health insurer, a payroll processor. Somebody's system gets breached, your email lands on a list, and now you're getting phishing texts, fraud alerts, and password reset attempts you didn't initiate. The breach itself might feel abstract, but the consequences don't.
Breach response has its own playbook. The FTC's identity theft resources walk you through the immediate steps: freeze your credit, pull your reports, and generate an Identity Theft Report if fraudulent accounts appear. That report does real work later, both for disputing charges and for any claim against the company that lost your data.
A few habits that pay off if a breach touches you:
* Freeze first, monitor second. A credit freeze blocks new accounts. Monitoring only tells you after the fact.
* Keep the notification letter. The company's own disclosure is often the cleanest proof that your data was in the affected set.
* Track your losses. Time spent on the phone with banks, fees paid, replacement documents. These add up and they're recoverable in the right cases.
The Privacy Statute You Didn't Know Applied
This one surprises people. Some of the strongest consumer protections sit inside statutes with narrow names and wide reach.
The Video Privacy Protection Act covers streaming and video platforms sharing your viewing data with advertisers. State biometric privacy laws reach facial recognition and voiceprints. Wiretap statutes govern the session-replay scripts that record every keystroke on a checkout page.
The pattern here isn't a harassing phone or a ruined credit file. It's a company monetizing something about you that a specific statute says they can't. These cases move as class actions more often than not, because the same script runs on millions of visitors at once.
Reading Your Own Situation
The through-line across all of these is that the tech feels modern, but the legal frameworks are older and sturdier than most people assume. The TCPA dates back to 1991, the FCRA to 1970, and the FDCPA to 1977.
They've been amended and stretched to cover autodialers, AI voices, furnisher databases, and breach-driven identity theft, and courts keep applying them to whatever's new. What changes case to case is which statute fits, and what you can prove. Screenshots beat memory. Written disputes beat phone calls. A single saved voicemail can be worth more than a month of frustration.
If the pattern in your inbox or your credit file looks like one of the cases above, treat the documentation as the priority. The legal question sorts itself out from there.
