Several major cybersecurity settlements are open for claims in 2026, with the largest being Comcast’s $117.5 million agreement covering roughly 31.6 million people whose data was exposed in an October 2023 cyberattack. Other active consumer settlements include Lakeview Loan Servicing, Avis, Krispy Kreme, and a handful of smaller data breach resolutions with mid-year deadlines. On the enforcement side, the Department of Justice recovered more than $52 million from government contractors under the False Claims Act in fiscal year 2025, and federal healthcare regulators continued a string of HIPAA penalties into 2026.
Consumer Data Breach Settlements You Can Claim in 2026
If you received a breach notice from any of the companies below, you may be eligible for a payment. Deadlines run through much of 2026, and most settlements offer either a documented-loss payment or a flat cash alternative.
Comcast: $117.5 Million
Comcast agreed to pay $117.5 million to resolve a class action alleging it failed to implement reasonable cybersecurity measures before an attack between October 16 and October 19, 2023. The class covers an estimated 31.6 million people who received breach notification letters.1Comcast Breach Settlement. Hasson v. Comcast Cable Communications LLC Settlement FAQ Class members can claim up to $10,000 for documented out-of-pocket losses and lost time, or take an alternative cash payment estimated at $50. Three years of identity defense services are also included. The claim deadline is September 14, 2026, and the final approval hearing is scheduled for August 5, 2026.2Comcast Breach Settlement. Hasson v. Comcast Cable Communications LLC Settlement
Lakeview Loan Servicing: $26 Million
Lakeview reached a $26 million settlement over an intrusion between October 27 and December 7, 2021, that exposed names, addresses, loan numbers, and Social Security numbers for roughly 5.8 million customers.3ClassAction.org. $26M Lakeview Loan Servicing Settlement Ends Class Action Over October 2021 Data Breach Class members can claim up to $5,000 for documented losses, a pro-rated cash payment, and one year of credit monitoring. California residents are eligible for an additional statutory payment under the California Consumer Privacy Act. Claims are due June 22, 2026.4Greenwich Time. Lakeview Loan Servicing Settlement
Smaller Settlements With Mid-2026 Deadlines
- Avis: $1.02 million over an August 2024 breach affecting nearly 300,000 customers, with names, driver’s license numbers, credit card information, and dates of birth exposed. Claims due June 21, 2026.5ClassAction.org. Avis Rent A Car System Data Breach Settlement
- Krispy Kreme: $1.6 million over a breach discovered on November 29, 2024. Payments run up to $3,500 for documented losses or a $75 flat payment. Claims due June 22, 2026.6Top Class Actions. 10 Class Action Settlements You Can Claim in June 2026
- Essen Medical Associates: $4 million over a March 2023 breach. Claims due June 1, 2026.6Top Class Actions. 10 Class Action Settlements You Can Claim in June 2026
- Complete Payroll Solutions: $2.6 million over a March 2024 breach, with three years of credit monitoring. Claims due June 18, 2026.6Top Class Actions. 10 Class Action Settlements You Can Claim in June 2026
Several other settlements have already closed to new claims but are worth knowing about if you were notified: Frontier Communications ($5.64 million over an April 2024 breach, finalized in late 2025), City of Hope ($8.5 million over a 2023 healthcare data breach affecting more than 774,000 individuals), and Sutter Health ($21.5 million over allegations it shared user data through third-party tracking tools).7Frontier Data Settlement. Wilson v. Frontier Communications Settlement8ClassAction.org. $8.5M City of Hope Settlement Ends Class Action Over 2023 Data Breach9Top Class Actions. 10 Class Action Settlements You Can Claim in April 2026
T-Mobile Payments Began in 2025
The T-Mobile settlement is the largest resolved cybersecurity class action to date. A 2021 breach exposed personal information for more than 76 million current, former, and prospective customers. T-Mobile agreed in 2022 to pay $500 million: $350 million to class members and $150 million toward improving its data security infrastructure. Payments began in May 2025 after the Eighth Circuit affirmed the settlement in part but sent it back on attorneys’ fees. A revised fee order was entered in January 2025.10Keller Rohrback. T-Mobile 2021 Data Breach
A separate FCC settlement in October 2024 required T-Mobile to pay $31.5 million covering breaches from 2021 through 2023. Half went to the Treasury; the rest funds internal cybersecurity work, including phishing-resistant multifactor authentication and a zero-trust network architecture. The consent decree also requires the company’s chief information security officer to give regular reports to the board.11Cybersecurity Dive. FCC Settlement With T-Mobile Over Data Breaches
Change Healthcare: Still Unresolved
The Change Healthcare breach affected approximately 192.7 million people and is the largest healthcare data breach ever recorded. Hackers accessed Change Healthcare’s systems on February 12, 2024, through a remote access portal that lacked multifactor authentication, and deployed ransomware nine days later.12HIPAA Journal. Change Healthcare Responding to Cyberattack
Patient and provider lawsuits have been consolidated into multidistrict litigation in the U.S. District Court for the District of Minnesota. As of early 2026, no global settlement has been approved. Any resolution is expected to address consumer relief (credit monitoring, identity restoration, and documented losses) separately from provider relief covering financial disruption from the months-long outage.13Panorays. Change Healthcare Data Breach The Department of Health and Human Services’ Office for Civil Rights has an open investigation but has not announced enforcement findings.14Nixon Peabody. Change Healthcare Cybersecurity Breach Impact on Healthcare Providers If you received a notice from Change Healthcare or your provider, there is nothing to file yet.
DOJ Cybersecurity Enforcement Against Contractors
The Department of Justice recovered more than $52 million across nine cybersecurity-related settlements in fiscal year 2025, part of $6.8 billion in total False Claims Act recoveries.15Data Protection Report. The DOJ’s Civil Cyber-Fraud Initiative Lives On Since launching its Civil Cyber-Fraud Initiative in October 2021, the DOJ has settled fifteen civil cyber-fraud cases, more than half of them in FY2025. These cases target government contractors and grant recipients who falsely certify compliance with federal cybersecurity requirements, whether or not a breach occurred. The DOJ has said these actions are “premised on misrepresentations” of compliance with technical standards.16Mayer Brown. False Claims Act Enforcement Record-Breaking Year Signals Continued Attention to Cybersecurity
The largest FY2025 settlement was an $11.2 million payment by a military health benefits contractor in February 2025 to resolve allegations it falsely certified compliance with TRICARE cybersecurity requirements.16Mayer Brown. False Claims Act Enforcement Record-Breaking Year Signals Continued Attention to Cybersecurity
Illumina paid $9.8 million in July 2025 over allegations that between 2016 and 2023 it sold genomic sequencing equipment with known software vulnerabilities while falsely certifying compliance with NIST and ISO cybersecurity standards. Former employee Erica Lenore, who brought the case as a whistleblower, received $1.9 million.17U.S. Department of Justice. Illumina Inc. to Pay $9.8M to Resolve False Claims Act Allegations Arising From Cybersecurity The DOJ called it the first False Claims Act cybersecurity settlement involving a medical device manufacturer.
Raytheon and successor entity Nightwing Group paid $8.4 million in May 2025 over allegations the companies failed to implement required cybersecurity controls on unclassified systems used for 29 Department of Defense contracts. The DOJ named Nightwing, which acquired Raytheon’s cybersecurity business in 2024, as a successor in liability. Former Raytheon engineering director Branson Kenneth Fowler received $1.5 million as the whistleblower.18U.S. Department of Justice. Raytheon Companies and Nightwing Group Pay $8.4M to Resolve False Claims Act Allegations
Additional FY2025 settlements included MORSE Corp ($4.6 million for failure to implement NIST SP 800-171 controls), Aero Turbine and Gallant Capital Partners ($1.75 million, reduced for voluntary self-disclosure), and Georgia Tech Research Corporation ($875,000 over an allegedly false cybersecurity assessment score and a failure to run anti-malware tools on systems handling sensitive Defense research).19U.S. Department of Justice. Georgia Tech Research Corporation Agrees to Pay $875,000 to Resolve Civil Cyber-Fraud Litigation
Healthcare HIPAA Settlements
The HHS Office for Civil Rights continued its Risk Analysis Initiative, targeting hacking incidents where organizations may have skipped required HIPAA Security Rule assessments. As of January 2026, OCR had closed 11 investigations with financial penalties under the initiative, and hacking accounted for more than 80 percent of large healthcare data breaches in 2025.20HIPAA Journal. Healthcare Data Breach Statistics
Solara Medical Supplies paid $3 million to resolve a 2019 phishing attack that compromised 114,007 people’s health information. Investigators found inadequate risk analysis, insufficient security measures, and late breach notifications. Solara also mailed more than 1,500 notification letters to the wrong addresses, causing a second breach. The company must follow a two-year corrective action plan monitored by OCR.21U.S. Department of Health and Human Services. Solara Medical Supplies Resolution Agreement and Corrective Action Plan
OCR imposed a $1.5 million civil money penalty on Warby Parker in February 2025 following a 2018 credential stuffing attack (in which hackers used credentials stolen elsewhere to log into customer accounts) and further attacks in 2020 and 2022 affecting nearly 198,000 people. OCR found the company had not conducted a proper risk analysis, not put adequate safeguards in place, and not regularly reviewed system logs that could have flagged the unusual login patterns earlier.22U.S. Department of Health and Human Services. Penalty Against Warby Parker
In March 2026, OCR settled with dental software company MMG Fusion over a December 2020 breach that exposed the health information of about 15 million people. Despite the scale, the settlement was just $10,000; OCR cited the company’s limited financial resources.23U.S. Department of Health and Human Services. OCR MMG Fusion HIPAA Agreement
FTC and SEC Actions
A court approved a $10 million FTC order against Disney in December 2025 over allegations the company enabled unlawful collection of children’s personal data. The FTC finalized an order against General Motors and OnStar in January 2026 over allegations they collected and sold consumer geolocation data without informed consent, and took action against crypto bridge Nomad for security failures that led to consumer losses. Other 2025 FTC targets included Illuminate Education, Dun & Bradstreet ($5.7 million for violating a prior order), and Snap.24Federal Trade Commission. Privacy and Security Enforcement
The SEC has pulled back on cybersecurity disclosure cases. In October 2024, it charged four companies with materially misleading disclosures related to the SolarWinds Orion compromise, with penalties from $990,000 to $4 million.25White & Case. SEC Enforcement Heats Up on Key Public Company Topics But its case against SolarWinds and its CISO Timothy Brown ended with a voluntary dismissal in November 2025, after a federal judge threw out most of the SEC’s claims in July 2024. The dismissal was with prejudice and carried no settlement conditions.26Harvard Law School Forum on Corporate Governance. SolarWinds Dismissed: What the SEC’s U-Turn Signals for Cyber Enforcement The SEC launched a Cyber and Emerging Technologies Unit in February 2025 and has signaled a focus on cases involving clear investor harm rather than disclosure-based theories.27U.S. Securities and Exchange Commission. SEC Announces Fiscal Year 2025 Enforcement Results
How to File a Claim
If you got a breach notification letter, keep it. It usually contains a unique claim ID you’ll need to file. For the settlements above, file through the official settlement website (the links in the citations go to the administrator’s site or a news account with the correct URL). You’ll generally have a choice between submitting documentation of actual losses and taking a flat cash payment. Documented-loss claims can be much larger but require receipts, statements, or other proof; flat payments require little more than confirming you were notified. If you’re a California resident, check whether the settlement includes a separate California Consumer Privacy Act payment, since Lakeview and some other settlements do.