Pacific Trial and Swigart Law: How Plaintiff Firms Are Scanning Your Website Right Now
CIPA demand letters don't start with a wronged customer. They start with an automated scan that detects the trackers on your site. Here's how the two best-known plaintiff firms actually operate — and how to get ahead of the scan instead of reacting to the letter.
In this article
There's a persistent misconception about CIPA lawsuits: that somewhere, a real consumer felt genuinely violated, hired a lawyer, and brought a claim. That's almost never how these begin. The modern CIPA case starts with software — an automated scan of your website that detects which third-party trackers are present and firing. The "plaintiff" and the demand letter come after.
Understanding that order is the whole point, because it tells you exactly where your exposure lives and how to remove it before anyone targets you. Defense and industry sources are blunt about the mechanics: the plaintiffs' bar targets businesses based on automated scans of what tracking technology is detectable on a site. This article walks through how the two most-cited firms in this space operate, what their scans look for, what a demand letter actually contains, and the concrete steps that take you off the target list.
If your site fires third-party trackers before a visitor consents, you don't need to do anything else to become a target. The detectable presence of those trackers is the trigger. The scan doesn't care whether you're a household name or a small Shopify store.
The scan comes before the lawsuit
The reason CIPA has produced an estimated tens of thousands of claims since 2022 isn't that website tracking suddenly became more invasive. It's that the process became industrialized. A relatively small group of plaintiff firms and repeat "tester" plaintiffs run automated detection across large numbers of consumer-facing sites, flag the ones using common trackers without proper consent gating, and then route those targets into a near-identical demand-and-settlement pipeline.
This is why the same plaintiff names recur across dozens of nearly identical complaints filed by the same firm. The bottleneck was never finding aggrieved individuals — it was finding vulnerable websites at scale, and automated scanning solved that. The legal theory rides on top: that common trackers function as illegal "pen registers" or "trap and trace devices" under California Penal Code § 638.51, capturing routing and addressing information (like IP addresses) without the consent the statute requires.
Pacific Trial Attorneys (Scott Ferrell)
Pacific Trial Attorneys is a Newport Beach firm led by attorney Scott Ferrell, and it's one of the highest-volume privacy plaintiff firms in the country. The firm is known for a high-volume, systematic model: filing large numbers of structurally similar complaints in California state and federal courts, built around documented technical evidence such as screenshots of chat interfaces, network logs showing third-party data transmission, and tracker data.
A few characteristics come up repeatedly in defense-side write-ups. The firm is associated with "courtesy" demand letters frequently sent by Federal Express, threatening litigation if a settlement isn't reached. Reported individual demand amounts commonly fall in the $10,000 to $75,000 range depending on estimated class size and site traffic, with class filings capable of escalating much higher. And the firm's early CIPA work leaned heavily on third-party live-chat and session-replay tools — arguing that a website using a third-party chat vendor was effectively enabling "eavesdropping" on its own visitors — before broadening into the pen-register theory as courts grew skeptical of the chat-based wiretapping claims.
If your site runs a third-party live-chat widget that logs and stores conversations, that single feature has historically been one of the most-targeted elements in this firm's filings. It's worth auditing specifically.
Swigart Law Group (Joshua Swigart)
Swigart Law Group is a San Diego firm led by attorney Joshua Swigart. Compared with the high-volume model, defense sources describe Swigart's approach as more methodical in case selection — tending to file where the technology evidence is well-documented and the statutory theory is developed, rather than casting the widest possible net.
The firm's signature is the pen-register theory: the argument that when website analytics tools like Google Analytics or the Meta Pixel record a visitor's IP address, browser characteristics, page URLs, and behavioral data, they function as a modern-day pen register or trap-and-trace device under § 638.51 — making each non-consented visit a potential $5,000 statutory-damages claim. Swigart's work also extends into the Video Privacy Protection Act (VPPA) where a site offers video content alongside tracking pixels that transmit viewing data tied to identifiable users. The firm is documented as actively sending demand letters and initiating arbitration proceedings, not only filing court complaints.
How the two firms differ
They share the same core theory but occupy noticeably different lanes. The distinction is useful because it tells you that no business is too big or too small to be in scope — the two approaches between them cover the whole market.
| Pacific Trial Attorneys | Swigart Law Group | |
|---|---|---|
| Lead attorney | Scott Ferrell | Joshua Swigart |
| Base | Newport Beach, CA | San Diego, CA |
| Volume profile | High-volume, systematic filings | Methodical, well-documented case selection |
| Frequent early focus | Third-party chat & session replay | Analytics/pixel pen-register theory |
| Commonly cited target | Larger consumer-facing businesses | SMB/SME market (per industry commentary) |
| Other theories | Pen register § 638.51, aiding-and-abetting | Pen register § 638.51, VPPA (video) |
| Common channel | FedEx "courtesy" demand letters | Demand letters & arbitration demands |
Note the bottom-line implication of that "commonly cited target" row: between a firm associated with larger businesses and one frequently described as focused on the SMB and SME market, the practical coverage is essentially every consumer-facing website. Being small is not protection.
What the scans actually look for
The detection step is technical and consistent. These are the elements most commonly named in CIPA tracking complaints, which is to say the things a scan is built to surface:
- The Meta (Facebook) Pixel — sends IP address, device data, URL paths, and event data to Meta, sometimes tied to identifiers via advanced matching.
- Google Analytics — logs IP address, device/browser details, page paths, and referrers.
- TikTok Pixel and Microsoft (Bing UET / Clarity) — track clicks, page flows, and in Clarity's case session replay.
- Third-party live-chat widgets — where conversations are logged and stored by an outside vendor.
- Session-replay tools — which record user interactions, keystrokes, and navigation.
- The LinkedIn Insight Tag and other cross-site advertising identifiers.
The common thread is that all of these can fire on page load, before a visitor has made any choice — and that pre-consent firing is precisely what the pen-register and wiretapping theories hang on. A scan that sees these tags executing before a consent interaction has found a candidate.
Anatomy of a CIPA demand letter
Knowing what these letters contain takes some of the fear out of receiving one and clarifies why prevention is so much cheaper. Based on publicly described examples, a typical demand follows a recognizable structure:
- A notice-of-dispute framing, often invoking the arbitration clause in your own terms and conditions, so the matter can be pushed into individual arbitration.
- The statutory hook — CIPA's $5,000-per-violation figure, with each detected interception or third-party transmission counted as a separate violation. A handful of tracker requests can be presented as a five-figure tally.
- Technical "evidence" — a description (sometimes a screenshot) of the trackers detected and the data they transmitted to third parties.
- An opening settlement demand, typically calibrated to sit below the cost of mounting a defense, which is what makes settling tempting even when the claim is weak.
That last point is the engine of the whole model. Reported demand amounts are tactically sized so that paying to make the matter go away looks cheaper than fighting — even though, as defense firms note, settling one claim doesn't immunize you and can mark you as a willing payer for the next one.
This article is informational, not legal advice, and it isn't a characterization of the merits of any firm's claims — courts have ruled both ways on these theories. If you receive a demand letter, engage qualified privacy counsel promptly rather than responding on your own or ignoring it.
How to get ahead of the scan
Here's the encouraging part: because the trigger is technical and detectable, the fix is technical and within your control. The goal is simple to state — when an automated scan loads your site, it should find no non-essential tracker firing before the visitor has consented. Concretely:
- Block trackers before consent — genuinely. Pixels, analytics, session replay, and third-party chat should not execute until the visitor makes a choice. A banner that displays while tags fire in the background is exactly the gap the scan detects.
- Audit everything that loads. You can't block what you haven't inventoried. Scan your own site the way the plaintiff firms do, and list every cookie, pixel, tag, and third-party script.
- Pay special attention to chat and session replay. Third-party chat widgets and replay tools have been among the most-targeted features; confirm they're consent-gated.
- Align your privacy policy with reality. Disclosures that promise control you don't actually deliver compound exposure. Make the words match the behavior.
- Keep verifiable consent records. If challenged, you want evidence of what fired, when, and what each visitor chose.
None of this is "install a banner and forget it." The thing that removes you from the target list is the substance underneath: scripts that are actually blocked until consent exists. That's the difference between a cosmetic consent UI and genuine enforcement — and it's the difference a scan can see.
If you've already received a letter
If a demand has already landed, a few principles hold regardless of which firm sent it. Don't ignore it — these matters don't evaporate, and deadlines may be running. Don't rush to settle on your own, since an uncounseled payment can invite repeat demands. Preserve everything — the letter, your current site configuration, and your consent records as they exist now. And engage privacy counsel experienced specifically with CIPA, because the defenses (party exception, consent, whether the technology meets the statutory definition) are fact-specific and the case law is genuinely unsettled. Remediating your site is still worthwhile after a letter arrives, both to limit ongoing exposure and to demonstrate good-faith correction.
The bottom line
CIPA demand letters from firms like Pacific Trial Attorneys and Swigart Law don't begin with an injured consumer — they begin with an automated scan that detects trackers firing on your site before consent. The two firms cover different ends of the market between them, which means no business is too large or too small to be in scope. But the same fact that makes the model so scalable is what makes it defeatable: the trigger is purely technical. Block your trackers until a visitor genuinely consents, keep the records to prove it, and the scan that drives the whole pipeline finds nothing to flag. Get ahead of the scan, and the letter never comes.
See what the plaintiff firms' scanners see
ConsentPixel — Privacy · Verified blocks trackers before consent and keeps verifiable, page-scoped records — so an automated scan finds nothing firing pre-consent. Run the same scan on your own site, free.
Scan my site freeFrequently asked questions
Who are Pacific Trial Attorneys and Swigart Law Group?
Both are California plaintiff firms prominent in CIPA website-tracking litigation. Pacific Trial Attorneys, led by Scott Ferrell, is a Newport Beach high-volume filer often associated with third-party chat and session-replay claims and FedEx demand letters. Swigart Law Group, led by Joshua Swigart, is a San Diego firm known for the pen-register theory against analytics and pixels, and is frequently described as focused on the SMB/SME market.
How do these firms find websites to target?
Largely through automated scanning. Defense and industry sources state the plaintiffs' bar targets businesses based on automated detection of what tracking technology is present and firing on a site. When a scan finds common trackers executing before consent, that site becomes a candidate, and a demand letter typically follows.
What trackers are most commonly named in these CIPA claims?
The Meta (Facebook) Pixel, Google Analytics, TikTok Pixel, Microsoft Bing UET and Clarity, third-party live-chat widgets, session-replay tools, and the LinkedIn Insight Tag are among the most frequently cited. The common factor is that they transmit data like IP addresses and behavioral metadata to third parties, often before a visitor consents.
How much do CIPA demand letters typically ask for?
Reported individual demands commonly range from about $10,000 to $75,000, calibrated to sit below the cost of mounting a defense so that settling looks cheaper than fighting. CIPA's statutory damages of $5,000 per violation, with each detected interception counted separately, let a handful of tracker requests be presented as a large tally. Class filings can escalate much higher.
Is my small business too small to be targeted?
No. CIPA has no business-size threshold, and the two best-known firms cover different ends of the market — one often associated with larger businesses, one frequently described as focused on SMBs and SMEs. If your site fires third-party trackers before consent and a California resident can load it, you can be in scope regardless of size.
What should I do if I receive a CIPA demand letter?
Don't ignore it and don't rush to settle on your own. Preserve the letter, your current site configuration, and your consent records, then engage privacy counsel experienced with CIPA — the available defenses are fact-specific and the case law is unsettled. Remediating your site to block trackers before consent remains worthwhile to limit ongoing exposure. This is informational, not legal advice.