Data breach class action settlements
Class action settlements from data breaches and security incidents that exposed consumers' personal information.
Data breach settlements by the numbers
A settlement fund is the total a defendant agreed to pay, not what any one claimant receives — most funds are divided among everyone who files. Settlements are negotiated agreements, and defendants typically deny wrongdoing rather than being found liable.
The 113 settlements in this category that publish a fund, grouped by size. Most cluster low and a few are very large — which is why the headline figure above is a median rather than an average.
| Fund size | Settlements | Share | |
|---|---|---|---|
| Under $1M | 36 | 32% | |
| $1M – $5M | 50 | 44% | |
| $5M – $25M | 21 | 19% | |
| $25M – $100M | 5 | 4% | |
| $100M and up | 1 | 1% |
A fund is the total a defendant agreed to pay, not an individual payout.
Get new claim opportunities by email
Free alerts for new settlements and deadlines. Unsubscribe anytime.
Accepting claims now
FMC Services Data Breach Settlement
FMC Services, LLC experienced a data incident on or about July 26, 2022, in which an unauthorized third party compromised personally identifiable information and personal health information of class members. The company denies that any information had been acquired.
Urban One Data Breach Settlement
Urban One's computer systems were targeted in a cyberattack in March 2025, resulting in unauthorized access to files containing personal information such as identifying information or information that could be used to identify, locate, or contact individuals. Urban One denies any wrongdoing.
AOD Federal Credit Union Data Breach Settlement
AOD Federal Credit Union experienced unauthorized access to its network from August 8-9, 2024, resulting in potential exposure of members' personally identifiable information including names, Social Security numbers, dates of birth, bank account numbers, credit card numbers, government IDs, health insurance information, and tax identification numbers. The defendant denies any wrongdoing.
$75–$5,000
Kaplan v. Crimson Wine Group Data Breach Settlement
Crimson Wine Group, Ltd. suffered a targeted cyberattack on its computer systems in or about June 2024. Certain files containing private information were accessed, potentially including names, Social Security numbers, and financial account information. The company denies wrongdoing.
Serviceaide Data Breach Settlement
Serviceaide, Inc. experienced unauthorized access to its computer systems and network between September 19, 2024, and November 5, 2024, which exposed the private information of current and former patients of Catholic Health. The lawsuit alleges negligence, breach of implied contract, unjust enrichment, and invasion of privacy. The defendant denies all wrongdoing.
Abbott Laboratories Employees Credit Union Data Breach Settlement
Abbott Laboratories Employees Credit Union ("ALEC") experienced a targeted cyberattack on its computer systems in August 2024. Files containing private information such as names, financial account information, and Social Security numbers were accessed. ALEC denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of ongoing litigation.
Circle K (Gas Express) Data Breach Settlement
Circle K experienced a targeted cyberattack on its computer systems in May 2024 in which certain files containing private information were accessed. These files may have contained personal information such as names and Social Security numbers. Circle K denies that it did anything wrong, and the parties agreed to settle to avoid ongoing litigation costs and uncertainties.
Labcorp Data Breach Settlement
Labcorp allegedly suffered a data breach involving customer diagnostic services information through American Medical Collection Agency. The company has agreed to settle for $35 million related to this alleged security breach.
MOVEit Data Breach Settlement - GRIPA
In May 2023, Greater Rochester Independent Practice Association suffered a data breach involving MOVEit Transfer file transfer software. The breach exposed personally identifiable information and protected healthcare information of individuals, including names, dates of birth, Social Security numbers, health information, and insurance details. GRIPA is settling claims related to this breach, though litigation against Progress Software Corporation (the MOVEit software licensor) continues.
$100–$12,500
Okanogan Behavioral Healthcare Data Breach Settlement
Okanogan Behavioral Healthcare (OBHC) experienced an unauthorized data incident discovered in May 2024 that exposed sensitive patient information including names, addresses, dates of birth, Social Security numbers, driver's license numbers, identification numbers, and medical and health insurance information. OBHC denies any wrongdoing.
$50–$5,350
Omni Healthcare Data Breach Settlement
In January 2024, an unauthorized third party conducted a cyberattack on Omni Healthcare's network and accessed certain files containing personal and medical information. The accessed files may have contained names, dates of birth, medical information, Social Security numbers, health insurance information, and financial account information. Omni Healthcare denies wrongdoing, and the parties agreed to settle to avoid the costs and uncertainties of continued litigation.
Banner Health Data Breach Settlement
Banner Health allegedly disclosed patients' personally identifiable information and protected health information to third parties including Meta (Facebook) and Google through tracking technologies on its website and patient portal. This allegedly violated patients' privacy rights and applicable laws. Banner denies all wrongdoing.
Up to $20
Lucent Health Solutions Data Breach Settlement
Lucent Health Solutions experienced a targeted cyberattack in October 2023 that compromised computer systems and may have exposed personal information including names, dates of birth, and health/dental/vision policy numbers and member IDs. The defendant denies wrongdoing, but has agreed to settle to avoid ongoing litigation costs and risks.
Allina Pixel Settlement
Allina Health System allegedly disclosed certain personal or health-related information to third parties. The defendant denies these allegations but agreed to settle the class action lawsuit.
Lemonade Data Disclosure Settlement
Lemonade, Inc. and Lemonade Insurance Agency, LLC experienced an unauthorized data exposure involving their online insurance quote platform between April 2023 and September 18, 2024. Personal information such as driver's license numbers was compromised, and affected individuals were notified in April and June 2025.
Parks Heritage Federal Credit Union Data Breach Settlement
A targeted cyberattack on Parks Heritage Federal Credit Union's computer systems occurred in July 2024, during which certain files containing private information were accessed. The files may have contained personal information such as names, Social Security numbers, financial information, credit card numbers, and debit card numbers. Parks Heritage denies wrongdoing.
Pineland Community Service Board Data Breach Settlement
Pineland Community Service Board experienced a cybersecurity incident from November 2024 to January 2025 that resulted in potential unauthorized access to or acquisition of individuals' private information including names, dates of birth, Social Security numbers, medical billing information, and medical treatment information. The defendant denies any wrongdoing or liability, but agreed to settle to avoid the risk, cost, and time of continuing the lawsuits.
STIIIZY Data Breach Settlement
In October 2024, STIIIZY, Inc. suffered a data breach where certain personal information was stolen from their servers. The company announced the breach on January 7, 2025. STIIIZY denies all allegations and liability.
Comcast Data Breach Settlement
In October 2023, a third-party gained unauthorized access to Comcast customers' personal information in a cybersecurity incident. Comcast denies that it engaged in any wrongdoing or violated any law.
Cash payments to Settlement Class Members, reimbursement for documented out-of-pocket losses and lost time, and Identity Defense Services and Restoration Services
Schuster Company Data Breach Settlement
Schuster Company experienced a January 2024 cybersecurity incident involving its computer systems where certain files containing personal information may have been accessed, including names, Social Security numbers, dates of birth, and driver's license numbers or state identification information. Schuster denies wrongdoing, but the parties agreed to settle to avoid the costs, risks, and uncertainties of continued litigation.
Murphy v. Western Montana Clinic Data Breach Settlement
Western Montana Clinic experienced a data breach between March 11, 2025, and April 15, 2025, in which an unauthorized third party accessed a company employee email account containing personal health information. The clinic has proposed a settlement agreement to resolve the resulting class action lawsuit.
American Consumer Credit Counseling, Inc. Data Breach Settlement
In January 2025, a criminal third party gained unauthorized access to certain of ACCC's employee email accounts in a cybersecurity incident. Personal information of certain individuals may have been impacted, including name, Social Security number, driver's license number, financial account number, and/or payment card information. ACCC denies wrongdoing and all claims of liability.
Aspire Health Alliance Data Breach Settlement
Aspire Health Alliance experienced a targeted cyberattack on its computer systems in September 2023. Files containing private information including names, dates of birth, medical services dates, health insurance policy numbers, physician information, medical condition or treatment information, and Medicare/Medicaid numbers were potentially accessed. Aspire denies wrongdoing, but has agreed to settle the lawsuit to avoid costs, risks, and uncertainties of continued litigation.
Cash Payment A (documented losses) or Cash Payment B (pro rata cash) plus Medical Data Monitoring
Naper Grove Vision Care Data Breach Settlement
Naper Grove Vision Care, P.C. experienced a targeted cyberattack on its computer systems in May 2025 (the "Data Incident") in which certain files containing private information were accessed. The files may have contained personal information such as names combined with Social Security numbers and other non-public personally identifiable information. Naper Grove denies wrongdoing.
Columbus Regional Health Data Breach Settlement
Columbus Regional Health allegedly disclosed confidential personally identifiable information (PII) and protected health information (PHI) to third-party technologies without patient consent. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid litigation costs and uncertainties.
Up to $25.50
Amy Crull v. University of St. Thomas Data Breach Settlement
University of St. Thomas experienced unauthorized access to its network between July 25, 2025 and August 12, 2025. Personal information including credit card numbers, bank account numbers, Social Security numbers, passports, licenses, work account login credentials, home addresses, email addresses, phone numbers, and other sensitive documents were potentially compromised. UST denies any wrongdoing.
$50–$5,100
Atrium Health Pixel Technology Settlement
Atrium Health improperly used pixel technology in connection with its MyAtriumHealth and MyCarolinas patient portal accounts. The health system has agreed to settle a class action lawsuit over this use of tracking technology without admitting wrongdoing.
Central Valley Meat Co. Data Breach Settlement
Central Valley Meat Co.'s computer systems were compromised in May 2024, and certain files containing private information including names and Social Security numbers may have been accessed. The defendant denies wrongdoing.
Mount Sinai Data Breach Settlement
Mount Sinai Medical Center of Florida disclosed protected health information and personally identifying information of patients through tracking, analytics, and advertising technologies on its website and patient portal to third parties. The disclosure occurred between June 10, 2021 and September 18, 2025.
Up to $20
Physicians' Primary Care Data Incident Settlement
Physicians' Primary Care of Southwest Florida experienced a targeted cyberattack on its computer systems in September 2024 that compromised personal information including names, Social Security numbers, and private health information. Physicians' Primary Care denies wrongdoing, but has agreed to settle the lawsuit to avoid further litigation costs and uncertainties.
ApolloMD Data Breach Settlement
A data security incident at ApolloMD on or around May 22, 2025, may have allowed an unauthorized third party to access files containing private information of patients treated by ApolloMD's affiliated physicians and practices. ApolloMD denies these claims and maintains it did nothing wrong.
Healthcare Services Group Data Breach Settlement
Healthcare Services Group, Inc. suffered a cybersecurity data breach on or around September 27, 2024, which exposed employee personally identifiable information including names, Social Security numbers, driver's license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information. HCSG denies any wrongdoing.
Up to $5,000
Total Vision Data Breach Settlement
Total Vision experienced a data security incident on October 30, 2020, in which patient and customer information was compromised. Plaintiffs claim Total Vision did not adequately protect personal information, though Total Vision denies any wrongdoing.
Up to $1,000
Period Tracker Data Privacy Settlement (Flo, Google, Flurry)
Between November 2016 and February 2019, the Flo period and ovulation tracker app allegedly incorporated code from third-party software development kits (from Flurry, Meta, and Google) through which user information related to menstruation and pregnancy was allegedly shared without proper legal authorization. Google agreed to pay $48 million, Flo agreed to pay $8 million, and Flurry agreed to pay $3.5 million to settle. All defendants deny wrongdoing and assert they did nothing wrong.
Not stated
Lands' End Data Breach Settlement
Lands' End experienced a data security incident in December 2024 that compromised personal information on a portion of its computer systems. Certain files containing information such as names, dates of birth, Social Security numbers, driver's license/passport information, and in some cases medical information were accessed. Lands' End denies wrongdoing, and the parties agreed to settle to avoid litigation costs and uncertainties.
Data breach cases in litigation
Filed and being fought in court. These are allegations — there is no settlement, no claim form and no payout yet.
Aarons v. NextRoll Data Privacy Class Action
A proposed class action against NextRoll, Inc. apparently concerning privacy or data-related claims affecting consumers or users of the company's services or platforms. Without access to the complaint details, the specific allegations cannot be determined from the docket information provided.
Doe v. X.AI Corp.
A proposed class action has been filed against X.AI Corp. and related entities by multiple plaintiffs using pseudonyms (John Doe I and Jane Does). The nature of suit code suggests statutory claims, and the use of anonymized plaintiff names indicates the case may involve sensitive personal matters such as privacy violations, data breaches, or similar concerns affecting ordinary individuals.
Wright v. McCormick & Company Data Breach Class Action
This proposed class action alleges that McCormick & Company, Inc. engaged in fraud or violations of truth-in-lending laws. Based on the nature of suit code, the complaint apparently concerns alleged misrepresentations or deceptive practices that may have affected consumer transactions or data handling by the defendant.
Kennedy v. PowerSchool Group Class Action
A proposed class action has been filed against PowerSchool Group LLC, a company that provides student information and school management software to educational institutions. The complaint alleges unspecified claims that could plausibly affect students, parents, or other individuals whose data is processed through PowerSchool's systems. The specific allegations cannot be determined from the docket caption and initial filing information alone.
Cada v. Amazon.com Data Breach Class Action
This proposed class action alleges that Amazon.com, Inc. failed to adequately protect consumer personal data, resulting in unauthorized access or breach. The complaint seeks relief on behalf of affected consumers and is being pursued by a well-known class-action attorney.
Yellow Corporation Data Breach Class Action
A proposed class action has been filed in bankruptcy court alleging that Yellow Corporation and related entities suffered a data breach affecting ordinary people. The complaint, brought by individual named plaintiffs, seeks recovery of money and property, injunctive relief, and declaratory judgment related to the alleged unauthorized access to personal information.
Funk v. Collectors Universe Data Breach Class Action
A proposed class action against Collectors Universe, Inc. and Collectors Holdings, Inc. alleges racketeering and corrupt practices under RICO. Based on the nature of suit code and filing structure, the case apparently concerns alleged misconduct affecting consumers, though the specific allegations are not detailed in the available docket metadata.
Sanchez v. Exact Sciences Corporation Class Action
A proposed class action has been filed against Exact Sciences Corporation, a company known for genetic testing and cancer screening products. Based on the docket entry, the complaint alleges claims characterized as "Other" personal injury matters, though the specific allegations are not detailed in the available docket metadata. Ordinary consumers who may have purchased or used Exact Sciences' products or services could plausibly be class members if the claims involve product defects, privacy violations, or similar consumer-facing issues.
Hayes v. Welldynerx Data Breach Class Action
A proposed class action filed by Rochelle Hayes against Welldynerx, LLC, apparently concerning a contractual or consumer-related dispute. Based on the case caption and nature of suit, the lawsuit likely involves allegations affecting ordinary consumers or account holders, though the specific claims cannot be determined from the docket entry alone.
Life Line Screening Data Breach Class Action
A proposed class action against Life Line Screening of America Ltd., apparently concerning a data breach or privacy violation affecting consumers who used the company's screening services. The case was filed as a class action complaint with jury demand in the Northern District of Georgia.
Closed to new claims
Past the filing deadline — kept so you can look up what a case was about and what it paid.
Berman & Rabin Data Breach Settlement
Berman & Rabin, P.A. experienced a cyberattack on its computer systems in July 2024 (the "Data Incident"). Certain files containing private information were potentially accessed, including names, Social Security numbers, drivers' license numbers, financial information, medical information, and health insurance information. Berman & Rabin denies any wrongdoing, but the parties agreed to settle to avoid costs and risks of continued litigation.
Henderson & Walton Women's Center Data Breach Settlement
Unauthorized actors accessed Henderson & Walton Women's Center's computer systems containing personal information and protected health information between February 11 and February 14, 2022. Henderson has agreed to provide settlement benefits to affected individuals as a result of this cybersecurity incident.
Backchecked Data Breach Settlement
Backchecked, LLC suffered a targeted cyberattack on its computer systems in September 2024. Files containing private information including names, addresses, dates of birth, Social Security numbers, and driver's license numbers may have been accessed. Backchecked denies any wrongdoing.
Hillcrest Convalescent Center Data Breach Settlement
Hillcrest Convalescent Center, Inc. experienced a cyberattack on its computer systems in June 2024 that may have resulted in unauthorized access to and acquisition of sensitive personal information including names, addresses, financial account information, dates of birth, driver's license numbers, Social Security numbers, government ID numbers, medical treatment records, health insurance information, and provider information. Hillcrest denies wrongdoing and the court has not decided the merits; the parties settled to avoid litigation costs and uncertainties.
KYB Americas Corporation Data Incident Settlement
In February 2025, KYB Americas Corporation experienced a targeted data security incident on its computer systems. Certain files containing personal information were potentially accessed. KYB denies doing anything wrong, and the court has not decided who is right.
Advanced Recovery Data Settlement
Advanced Recovery Equipment & Supplies, LLC experienced unauthorized access to its systems in or around October 2024, compromising files containing personal identifiable information (PII). The defendant denies any wrongdoing in connection with the incident.
Paid $50–$4,250
CR&R Data Breach Settlement
CR&R Incorporated experienced a targeted cyberattack on its computer systems on or about December 13, 2022, in which certain files containing private information were accessed. These files may have contained personal information including names, Social Security numbers, financial account information, and health insurance information. CR&R denies wrongdoing.
McKenzie Memorial Hospital Data Breach Settlement
McKenzie Memorial Hospital suffered a targeted cyberattack on its computer systems in April 2025 that compromised certain files containing private information such as names, addresses, dates of birth, Social Security numbers, patient account numbers, medical record numbers, and treatment information. McKenzie denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continuing litigation.
Skov et al. v. Lakeview Health Systems Data Breach Settlement
Lakeview Health Systems suffered a targeted cyberattack on its computer systems in January 2024. The attack compromised files containing private information including names, addresses, dates of birth, Social Security numbers, driver's license numbers, financial account numbers, patient IDs, medical treatment information, diagnoses, prescriptions, and health insurance information. Lakeview Health denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continued litigation.
Marlboro-Chesterfield Pathology Data Breach Settlement
Marlboro-Chesterfield Pathology's computer systems were compromised in a data breach announced on or around May 22, 2025. The settlement alleges that MCP failed to properly secure and safeguard sensitive personal and health information (names, dates of birth, Social Security numbers, and protected health information) of its current and former patients. MCP denies any wrongdoing.
Paid $10–$1,000
Valladolid v. Memorial Health Services - Meta Pixel Data Privacy Settlement
Memorial Health Services disclosed patients' personally identifiable information to third parties through the Meta Pixel and other tracking, analytics, and advertising technologies without consent in violation of the California Invasion of Privacy Act. The defendant denies all claims and maintains it did nothing wrong but agreed to the settlement to avoid ongoing litigation expenses and uncertainties.
OBI Seafoods Data Incident Settlement
OBI Seafoods experienced a targeted cyberattack on its computer systems in August 2024 that compromised certain files containing private information such as names, social security numbers, addresses, medical information, and financial data. The defendant denies wrongdoing, but has agreed to settle the class action lawsuit to avoid ongoing litigation costs and risks.
Wyssta Services, Inc. Data Privacy Settlement
Wyssta Services allegedly violated the Electronic Communications Privacy Act and Illinois Eavesdropping Statute by installing and implementing advertising and analytics tracking technologies, such as cookies and pixels, on the Delta Dental member portal (my.deltadentalcoversme.com) without users' knowledge or consent. The defendant denies all allegations and liability.
Compex Legal Services Data Breach Settlement
An unauthorized user gained access to Compex Legal Services' systems in a cyber incident that was discovered in April 2024. The incident impacted personally identifiable information (PII) and protected health information (PHI) of class members. Compex has agreed to settle the claims without admitting wrongdoing.
Paid $100–$5,200
Legends Hospitality Data Breach Settlement
Legends Hospitality suffered targeted cyberattacks on its computer systems in November 2024, December 2024, and January 2025. Certain files containing Private Information including names, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, financial information, medical information, and health insurance information were accessed. Legends Hospitality denies wrongdoing, and the parties agreed to settle to avoid the costs and risks of continued litigation.
Mt. Baker Imaging Data Security Incident Settlement
Mt. Baker Imaging and Northwest Radiologists experienced a ransomware attack between January 20-25, 2025, in which cybercriminals accessed and stole personally identifiable information and protected health information belonging to approximately 340,184 people. Plaintiffs allege the companies failed to implement adequate data security safeguards, though Defendants deny wrongdoing but agreed to settle to avoid litigation costs and uncertainty.
Paid Up to $5,000
WaterStreet Company Data Breach Settlement
WaterStreet Company experienced a data breach on March 17, 2025, resulting in unauthorized access to files containing private information including names, taxpayer identification numbers, bank account information, and Social Security numbers. WaterStreet denies wrongdoing, but has agreed to settle the lawsuit to avoid further costs and risks.
Ciuni & Panichi Data Breach Settlement
Ciuni & Panichi, Inc. experienced a data breach in November 2024 when unauthorized individuals accessed a database containing personal information including names, Social Security numbers, and dates of birth. The defendant denies wrongdoing, but a settlement has been reached to compromise and end the lawsuit.
Paid $125–$5,000
Datavant Data Security Incident Settlement
A phishing email attack allowed unauthorized access to a company email account at Ciox Health, LLC d/b/a Datavant Group between May 8, 2024 and May 9, 2024, potentially exposing certain personal information. The defendant denies any wrongdoing.
Mason v. Wright Brothers Construction Company Data Breach Settlement
Wright Brothers Construction Company suffered a targeted cyberattack on its computer systems in April 2024 in which certain files containing private information, including names and Social Security numbers, were accessed. The defendant denies wrongdoing.
Alta Resources Corp. Data Breach Settlement
A targeted cyberattack on Alta Resources Corp.'s computer systems occurred in November 2023, which compromised files containing private information including names, Social Security numbers, financial account information, taxpayer identification numbers, government-issued identification, and health insurance/medical information. Alta denies wrongdoing, but has agreed to settle the lawsuit to avoid litigation costs and risks.
Bradford Health Data Incident Settlement
Bradford Health Partners, LLC and Bradford Health Services, LLC experienced a cybersecurity incident in November 2023 that resulted in unauthorized access to or acquisition of customers' private information, including names, dates of birth, identification numbers, Social Security numbers, medical information, health insurance information, and financial information. The company has agreed to pay $900,000 and implement additional security measures to resolve the class action lawsuit.
Paid $150–$5,000
EMM Loans Data Breach Settlement
EMM Loans was the target of a cyberattack on its computer systems in February 2024. The attack resulted in unauthorized access to files containing personal information including names, Social Security numbers, driver's license numbers, and passport numbers. EMM Loans denies it did anything wrong.
GeoLogics Corporation Data Breach Settlement
GeoLogics Corporation experienced a targeted cyberattack on its computer systems in December 2023 that compromised private information. Files containing personal data such as names, addresses, phone numbers, dates of birth, photo identification, driver's licenses, and Social Security numbers were accessed. GeoLogics denies wrongdoing, and the court has not decided the merits of the case.