Latest Update — As of July 12, 2026, the original Birdsall wiretap case against PNC remains pending in federal court, with no class certified and no settlement reached. But PNC’s legal exposure over website tracking has widened: on April 6, 2026, a separate case, Erakat v. PNC Bank, National Association (Case No. 2:26-at-00581), was filed in the U.S. District Court for the Eastern District of California. That suit alleges PNC embedded pixel trackers from Pinterest, LinkedIn, and X on its personal finance pages and shared visitors’ browsing data with those third parties without a consent mechanism in place. It was filed alongside similar pixel-tracking suits against Wells Fargo, Hilton, and LinkedIn itself. The Erakat case is in early litigation, with no class certified and no settlement reached.
Last updated: July 2026
PNC Bank is facing a class action lawsuit that claims it secretly tracked everything you did on its website, and sent that data to LinkedIn, without ever asking your permission. Plaintiff Leslie Birdsall claims in the PNC bank website communications lawsuit that PNC intercepts and records the electronic communications of visitors to its website through tracking technology provided by LinkedIn.
That’s not a data breach in the traditional sense. No hacker broke in. The bank itself is accused of doing it.
The case was initiated in September 2025 and claims that PNC used third-party tracking tools from LinkedIn to intercept and record users’ electronic communications without consent, potentially violating state privacy laws.
This guide covers what happened, who is affected, what the law says, and what you should know about potential eligibility.
What Is the PNC Bank Website Communications Lawsuit?
The PNC bank website communications lawsuit is a proposed class action alleging that PNC Bank secretly embedded tracking code on its website that captured visitors’ online behavior and transmitted that data to LinkedIn without user knowledge or consent.
The lawsuit accuses the financial services company of wiretapping the electronic communications of visitors to its website without their knowledge or consent.
This is not a case about hacking or a data breach from the outside. The allegations are about code that PNC allegedly chose to install on its own website.
The complaint argues that this technology captured user communications without clear consent. The case centers on how the PNC website handled customer interactions.
| Key Detail | Information |
|---|---|
| Lawsuit Type | Proposed class action |
| Filed | September 15, 2025 |
| Court | Court of Common Pleas, Allegheny County, PA |
| Case Number | GD-25-009654 |
| Plaintiff | Leslie Birdsall |
| Defendant | The PNC Financial Services Group Inc. |
| Law Firm | Lynch Carpenter LLP |
PNC Bank Lawsuit 2025: How It Started and Why It Matters
The lawsuit was born out of a wave of digital privacy litigation that swept through U.S. courts in 2024 and 2025. Consumers and their attorneys started looking hard at what tracking code banks were running on their websites.
Privacy lawsuits related to website tracking have increased across the United States. Courts now examine how companies use analytics tools and advertising technologies. Financial institutions face higher expectations because customers trust banks with sensitive information.
PNC became a target because of its use of LinkedIn’s tracking pixel. The timing matters. Courts in 2025 were actively expanding their interpretation of what counts as illegal interception of communications.

Recent rulings in 2024 and 2025 expanded the definition of “communication” to include the transmission of data between a user’s browser and a server.
That legal shift is exactly what makes this lawsuit viable. What used to be dismissed as “just analytics” is now being treated as potential wiretapping under state law.
Key stat: The case targets a class potentially numbering in the thousands, covering any Pennsylvania resident who visited the PNC website while the LinkedIn tracking code was active.
Birdsall v. PNC Financial Services: Inside the Core Case
Birdsall v. The PNC Financial Services Group Inc. is the central legal filing at the heart of this story. It is the case that started the conversation.
PNC Financial Services Group was hit with a digital privacy class action on September 15 in Pennsylvania Court of Common Pleas for Allegheny County over alleged unauthorized wiretapping of website visitors through LinkedIn’s tracking code. The suit, brought by Lynch Carpenter on behalf of Pennsylvania residents who visited PNC’s website, accuses the bank of embedding LinkedIn’s Insight Tag code to intercept and record visitors’ communications, mouse movements and other interactions, which are then matched to LinkedIn member profiles without user consent.
Read that last part again. Not just page views. Mouse movements. Keystrokes. All of it matched back to your LinkedIn profile.
Birdsall demands a jury trial and requests declaratory and injunctive relief and an award of actual, statutory, compensatory, consequential, punitive and nominal damages for herself and all class members.
The case was later removed to federal court from state court, where it continued to move through the pre-trial process.
| Case Element | Detail |
|---|---|
| Original Court | Allegheny County Court of Common Pleas |
| Removed To | Federal Court (E.D. Pennsylvania) |
| Plaintiff’s Attorney | Nicholas A. Colella, Lynch Carpenter LLP |
| Relief Sought | Damages, injunction, jury trial |
| Status (as of early 2026) | Pending, no settlement announced |
Key Takeaway: Birdsall v. PNC Financial Services Group is a live federal lawsuit alleging LinkedIn’s tracking code on PNC’s website violated Pennsylvania wiretap law.
PNC Bank LinkedIn Tracking Lawsuit: What the Insight Tag Actually Does
Think of LinkedIn’s Insight Tag like a tiny invisible observer sitting on every page of a website. You never see it. You never agreed to let it watch. But it’s watching.
The tracking technology in question, LinkedIn’s Insight Tag or similar pixels, embeds code on PNC’s website that sends user data back to LinkedIn servers. This allows for targeted advertising but, according to the suit, intercepts communications without users’ knowledge.
When you visit a website with the Insight Tag installed, LinkedIn can identify you if you have a LinkedIn account and track your browsing behavior across participating sites.
Legal responsibilities under the act require explicit consent, often through clear privacy policies or opt-in mechanisms, which the plaintiff claims were absent.
For a regular retailer, this might be a gray area. For a bank, where you type account information and financial data, the stakes are completely different.
- The tag captures page visits, clicks, and time-on-page
- Data is matched to LinkedIn member profiles in real time
- Advertisers (and LinkedIn) can use this to target users with ads
- Users are not notified before tracking begins
PNC Bank Wiretap Lawsuit: Is Recording Your Clicks Really Illegal?
Yes, under the right circumstances, recording someone’s website activity without consent is illegal. That is the entire legal foundation of this case.
The PNC Bank website communications lawsuit alleges that by allowing third-party vendors to “listen in” and record these sessions to help the bank analyze user experience, PNC is essentially allowing a digital wiretap. Plaintiffs argue that because these vendors are third parties, they are “eavesdroppers” under the law if the user hasn’t provided explicit, prior consent.
The word “wiretap” might make you picture a phone line with a clip attached to it. In digital law, it means something broader. It means intercepting a communication in real time without consent.
The Pennsylvania Wiretap Act defines “electronic communication” broadly to include data transmissions, and courts have interpreted it to cover website interactions where third-party scripts capture real-time data.
The crux of the legal argument is timing. If the tracking starts before a user clicks any consent banner, plaintiffs argue the interception was unauthorized.
Bold fact: Pennsylvania is an “all-party consent” state for communications, meaning all parties must agree before a communication is recorded or intercepted.
Pennsylvania Wiretap Act and the PNC Bank Lawsuit
The Pennsylvania Wiretapping and Electronic Surveillance Control Act, known as WESCA, is the primary law at the center of this case. It was originally passed in 1978 but has been applied by courts to digital communications in recent years.
The Pennsylvania Wiretap Act (18 Pa. Cons. Stat. § 5701 et seq.) prohibits the unauthorized interception of electronic communications, including those occurring on websites. This act requires consent from all parties for such interceptions, reflecting legislative intent to protect against unauthorized surveillance in an era of advancing technology.
Courts interpreting WESCA have been inconsistent, which is part of why cases like this one are still being argued. Some rulings have dismissed similar claims for lack of standing, while others have allowed them to proceed.
A Pennsylvania federal court remanded to state court a putative class action under WESCA due to a lack of Article III standing, explaining that the plaintiff’s “searches for drink flavors” allegedly collected on defendant’s website “is not the type of private information that, when disclosed, creates a harm sufficient to establish standing.”
PNC’s case involves a bank, not a beverage company. Financial data carries far more weight in privacy harm arguments.
The Third Circuit Court of Appeals clarified that there is no broad direct-party exception to civil liability under WESCA, strengthening plaintiffs’ ability to pursue claims against companies that use third-party tracking tools.
| WESCA Element | Application to PNC Case |
|---|---|
| Statute | 18 Pa. Cons. Stat. § 5701 et seq. |
| Consent Requirement | All-party consent required |
| Tracking Covered | Third-party script interception |
| Standing Threshold | Financial data likely qualifies |
| Key Precedent | Third Circuit: no broad direct-party exception |
Key Takeaway: Pennsylvania’s wiretap law covers digital tracking, and the Third Circuit has ruled that banks cannot hide behind a “direct-party exception” to avoid liability for third-party code they embed on their own websites.
PNC Bank Session Replay Tracking: The Technology at the Center of This Case
Session replay is a category of software that records your entire visit to a website like a video, capturing every click, scroll, pause, and keystroke. It’s used by thousands of companies for website analytics.
Unlike simple cookies that track which pages you visit, Session Replay software provided by vendors like FullStory, Quantum Metric, or Glassbox allows a company to record a video-like recreation of a user’s session.
Some versions of this technology go beyond what a security camera would capture. They record what you typed into form fields, including fields you deleted before submitting.
On a banking website, that could include partial account numbers, password attempts, or financial search queries.
These tools help companies understand customer behavior. Businesses use this information to improve website design and marketing strategy. However, privacy concerns arise when companies share collected data with third parties.
The lawsuit’s key allegation is that this data was shared with LinkedIn, a third party with no banking relationship with the consumer.
- Session replay captures mouse movements, clicks, and scrolling
- Keystroke logging may capture partially entered information
- Vendor servers store this data outside the bank’s own systems
- Users typically receive no real-time notice when recording begins
PNC Bank Data Collection Lawsuit: What Information Was Allegedly Captured?
According to the lawsuit, it wasn’t just which pages you clicked. The alleged data collection was detailed enough to reconstruct your activity on the site.
The suit accuses the bank of embedding LinkedIn’s Insight Tag code to intercept and record visitors’ communications, mouse movements and other interactions, which are then matched to LinkedIn member profiles without user consent.
This is significant because matching browsing data to a named LinkedIn profile is not anonymous. It identifies specific individuals.
The complaint also states that third-party services may have received the collected information. Plaintiffs argue that such data transmission occurred without proper notice.
For regular consumers, this creates a concrete concern: private financial browsing activity may have been shared with a tech platform for advertising purposes.
| Alleged Data Type | Why It Matters |
|---|---|
| Page visits on pnc.com | Maps financial interests and needs |
| Mouse movements and clicks | Reveals browsing intent in detail |
| Interactions matched to LinkedIn profiles | Removes anonymity from the data |
| Subpage visits (loans, savings, etc.) | Exposes financial planning activity |
Key Takeaway: The alleged data collection was not passive. The LinkedIn Insight Tag reportedly matched individual browsing behavior to named LinkedIn accounts, eliminating anonymity.
PNC Bank Invasion of Privacy Lawsuit: What the Plaintiffs Are Claiming
Alongside the wiretap claim, the lawsuit also includes an invasion of privacy count. These two theories reinforce each other.
The PNC class action lawsuit alleges the financial services company violated the Pennsylvania Wiretap Act and is guilty of invasion of privacy.
Invasion of privacy as a legal theory requires showing that the intrusion would be objectionable to a reasonable person. Courts have increasingly found that secret digital surveillance, especially by a financial institution, meets that bar.
The complaint states: “Defendant knowingly, willfully and intentionally procured the interception of, and used, the electronic communications at issue without the knowledge or prior consent of Plaintiff or the Class Members.”
That language is deliberate. “Knowingly, willfully, and intentionally” is the standard for proving conduct serious enough to justify punitive damages.
- Wiretap claim: illegal interception of communications
- Invasion of privacy claim: unreasonable intrusion into private activity
- Combined, both claims support a request for punitive damages
- Declaratory relief is also sought, which could force PNC to change its practices
PNC Bank Privacy Lawsuit: How This Fits a National Pattern
PNC is not alone in this situation. It is one piece of a nationwide wave of digital privacy litigation targeting financial institutions and major websites.
PNC is not alone in this legal storm. The rise of privacy-centric laws like CIPA in California and WESCA in Pennsylvania has triggered a wave of “digital wiretap” suits against almost every major financial institution.
Think of it like the class action wave against banks over overdraft fees a decade ago. The legal theory was new. Courts were skeptical at first. Then settlements started happening.
Legal experts note that privacy litigation has expanded as digital tracking becomes more common. Banking websites receive extra attention because they handle financial and personal data.
California has its own version of this battle under CIPA. Pennsylvania has WESCA. Other states have their own privacy statutes. The result is a multi-state legal battleground where every major bank faces potential exposure.
Key stat: Similar session replay and pixel tracking lawsuits have been filed against major retailers, healthcare systems, and financial institutions across more than 30 states since 2022.
PNC Class Action Lawsuit: Why This Case Matters Beyond One Plaintiff
Leslie Birdsall filed this case as an individual, but the goal is to make it a class action representing thousands of people. That process requires court certification.
Birdsall wants to represent a Pennsylvania class of consumers who had their electronic communications intercepted through the use of LinkedIn’s tracking technology embedded on PNC’s website.
Class certification is the pivotal step. A judge must find that the claims are common enough, that the class is large enough, and that Birdsall’s claims are typical of the class. If certified, everyone in the class gets a shot at compensation.
The case is currently pending in federal court after removal from state court, with no settlement announced as of February 2026.
Class action cases against banks over digital practices have a mixed track record. Some settle quickly. Others drag through the courts for years before reaching resolution.
| Stage | What Happens |
|---|---|
| Filing | Individual lawsuit filed, seeking class status |
| Removal | PNC moved case to federal court |
| Class Certification | Judge decides if a class can be formed |
| Discovery | Both sides gather evidence |
| Settlement Talks | Negotiations, potentially before trial |
| Trial or Settlement | Final resolution |
Key Takeaway: Class certification is the single most important milestone ahead. If granted, this case could deliver compensation to tens of thousands of PNC website visitors.
PNC Bank Class Action Settlement: Has Anything Been Resolved?
As of early 2026, no settlement has been reached in the Birdsall case. The lawsuit is still in its early stages.
The case is pending in federal court after removal from state court, with no settlement announced as of February 2026.
That is not unusual. Large class action cases against financial institutions typically take two to four years from filing to final resolution. Motions, discovery, class certification battles, and negotiations all take time.
It’s also worth knowing what NOT to confuse this with. A separate PNC data breach lawsuit, filed by plaintiff Madonna Blunt, was dismissed in September 2025.
The case was voluntarily dismissed on September 28, 2025, after PNC’s investigation determined that the claims were “bogus.” PNC confirmed that no malicious attack occurred.
That dismissed case involved fabricated dark web claims. The Birdsall wiretap case is entirely separate and remains active.
- Birdsall wiretap case: ACTIVE as of early 2026
- Blunt data breach case: DISMISSED September 28, 2025
- No settlement amount announced in either case
- No claims portal is open yet for the Birdsall case
PNC Bank Lawsuit Settlement Amount: What Could Claimants Receive?
No official settlement figure exists yet for the Birdsall case. But comparable digital wiretap settlements offer a realistic range for context.
Under WESCA, statutory damages can reach $100 per day of violation or $1,000 per violation, whichever is greater, plus punitive damages and attorney’s fees. For a class action covering thousands of people, aggregate exposure for PNC could run into the millions.
Similar pixel tracking and session replay class action settlements nationally have ranged from $50 to $400 per individual claimant after attorney fees, depending on class size and strength of the claims.
Legal responsibilities under the act require explicit consent, often through clear privacy policies or opt-in mechanisms, which the plaintiff claims were absent.
The absence of any consent mechanism is a factor courts look at when assessing damages. The stronger the evidence that tracking started before any consent was possible, the higher the potential payout per class member.
| Settlement Context | Estimated Range |
|---|---|
| WESCA statutory damages | $100/day or $1,000/violation |
| Comparable digital wiretap settlements | $50 to $400 per individual |
| Punitive damages | Possible, based on willful conduct |
| Attorney fees | Typically 25 to 33% of total fund |
| Timeline to payout | Likely 2027 or later |
Who Qualifies for the PNC Bank Lawsuit?
No formal class has been certified yet, so no official eligibility criteria have been court-approved. But based on the complaint, here is what the proposed class covers.
Birdsall wants to represent a Pennsylvania class of consumers who had their electronic communications intercepted through the use of LinkedIn’s tracking technology embedded on PNC’s website.
In plain terms: if you live in Pennsylvania and visited pnc.com at any point while the LinkedIn Insight Tag was active on the site, you may fall within the proposed class.
Visitors who browsed without a LinkedIn account may also qualify. The tracking code can still capture device data and browsing behavior even without a profile match.
Likely class members include:
- Pennsylvania residents who visited pnc.com
- People who browsed PNC’s website without signing in to an account
- Active PNC customers who used the website for banking tasks
- Individuals who never consented to LinkedIn tracking of their session
Not yet determined by the court:
- Whether the class extends to non-Pennsylvania states
- The exact timeframe during which the tracking occurred
- Whether out-of-state visitors under Pennsylvania jurisdiction qualify
PNC Bank Lawsuit Eligibility: The Specific Requirements
Eligibility for this lawsuit depends on a combination of factors that the court will define once class certification is addressed.
The complaint specifically targets Pennsylvania residents, but the legal questions raised here have national implications. Courts in other states with similar privacy laws could see parallel filings.
If the class is certified and a settlement is reached, eligibility may include Pennsylvania residents who visited PNC’s website and had their interactions tracked via the alleged technology. However, no class has been certified yet, and eligibility would be determined by court approval.
At this stage, the best thing you can do is document your history with the PNC website. Note approximate dates, the type of device you used, and whether you ever saw a consent banner before any tracking began.
| Eligibility Factor | Current Status |
|---|---|
| State of Residence | Pennsylvania (proposed) |
| Activity Required | Visited pnc.com |
| Account Status | Not required; website visitors qualify |
| Consent Banner Seen? | Relevant to individual claims |
| Class Certification | Pending court approval |
| LinkedIn Account Needed? | No, device data still captured |
Key Takeaway: Eligibility will ultimately be defined by the court, but any Pennsylvania resident who visited PNC’s website while the LinkedIn tracking code was active is a potential class member.
PNC Bank Lawsuit Update 2026: Where Does the Case Stand Now?
As of early 2026, the Birdsall case is actively moving through the federal court system in the Eastern District of Pennsylvania. Key procedural steps are still ahead.
As of February 2026, a series of legal challenges collectively referred to as the PNC Bank website communications lawsuit have put the spotlight on how financial institutions track user behavior and protect, or fail to protect, sensitive data during online sessions.
The case was removed from Pennsylvania state court to federal court, which is standard practice for large defendants in class action cases. A motion to remand back to state court may still be pending.
The dismissal of the Adair v. Cigna case in February 2026 is a significant precedent for PNC. In that case, the judge ruled that because the plaintiffs had eventually clicked through a “Terms of Use” that mentioned tracking, they had legally consented to the communication being recorded.
That ruling could influence how the PNC case is argued. If PNC can show that users clicked through any consent mechanism, the case gets harder for plaintiffs.
2026 Case Status Snapshot:
- Case removed to federal court (Eastern District of Pennsylvania)
- No class certification granted yet
- No settlement negotiations publicly disclosed
- Relevant precedent cases from 2025 and 2026 are shaping legal strategy
- Next milestone: class certification motion and briefing
How to Join the PNC Bank Class Action
Right now, there is no open claims portal because no settlement has been reached and no class has been certified. You cannot officially “sign up” yet.
Many consumers now search for answers about the PNC Bank website communications lawsuit. People want to know what the case involves and whether they may qualify for a potential class action.
When a settlement is eventually reached and the class is certified, a formal notice process begins. Class members typically receive mail or email notices with instructions for filing a claim.
Here is what you can do right now:
- Document your history: Note when you visited pnc.com, what device you used, and what you did on the site.
- Monitor official case records: The case docket (GD-25-009654) is publicly accessible through Pennsylvania and federal court records.
- Watch for class notice: If a settlement is reached, class members receive notice with claim filing instructions.
- Contact Lynch Carpenter LLP: The plaintiff’s law firm is Lynch Carpenter LLP. You can contact them to express interest in being added to the class or to get information about your specific situation.
- Avoid third-party sign-up sites: Any website claiming to enroll you in the PNC settlement right now is not using official court-approved channels.
Key Takeaway: You cannot officially join this class action yet, but you can prepare by documenting your PNC website activity and tracking the case through official court records.
Frequently Asked Questions
What is the PNC bank website communications lawsuit about?
The PNC bank website communications lawsuit is a proposed class action alleging that PNC Bank embedded LinkedIn’s tracking code on its website and used it to intercept and record visitors’ electronic communications without consent. The lawsuit claims this violated the Pennsylvania Wiretap Act and constitutes an invasion of privacy. The case, Birdsall v. The PNC Financial Services Group Inc., was filed on September 15, 2025, in Allegheny County, Pennsylvania.
Did PNC Bank get sued for spying on website visitors?
Yes. A class action lawsuit filed in September 2025 specifically accuses PNC of using LinkedIn’s Insight Tag to track and record the behavior of website visitors without their knowledge. The tracking allegedly captured mouse movements, clicks, and browsing activity, which were then matched to individual LinkedIn profiles. PNC has not publicly admitted wrongdoing, and the case remains active in federal court.
How much could I receive from the PNC Bank class action settlement?
No settlement has been announced yet, so no official payout amount exists. Comparable digital wiretap class action settlements have paid individual claimants between $50 and $400 after legal fees, depending on class size and claim strength. Pennsylvania’s wiretap law also allows for statutory damages of $100 per day or $1,000 per violation, which could increase the total settlement fund significantly.
Who qualifies for the PNC Bank website tracking lawsuit?
The proposed class targets Pennsylvania residents who visited the PNC Bank website while LinkedIn’s tracking technology was active on the site. No LinkedIn account is required to be affected, since device data and browsing behavior can be captured regardless. Final eligibility criteria will be determined by the court once class certification is decided.
What is the current status of the PNC Bank website lawsuit in 2026?
As of early 2026, the case is pending in the Eastern District of Pennsylvania federal court after being removed from state court. No class has been certified, no settlement has been announced, and both sides are still in early procedural stages. The case is expected to proceed through class certification briefing before any settlement discussions become public.
Stay Ahead of This Case
The PNC bank website communications lawsuit is one of the most significant digital privacy cases against a major U.S. bank right now. If you visited pnc.com in Pennsylvania before consenting to any tracking, you may be part of the proposed class.
No action is required immediately. But preparation matters.
Document your PNC website history. Watch for official class notices in your mail and email. Check the public court docket under case number GD-25-009654 for updates. When the class is certified and a settlement opens, you’ll want to be ready to file.









