Cybersecurity Settlement Details: Top Payouts and How to Claim

Cybersecurity settlements over the past few years have produced some of the largest consumer payouts in U.S. legal history, with Equifax at $425 million, T-Mobile at $350 million, Capital One at $190 million, and Comcast at $117.5 million leading the list. Alongside those class actions, federal regulators pulled more than $44 million from the major wireless carriers in a single year, and state attorneys general have added tens of millions more in enforcement penalties. If you received a data breach notice, the practical question is usually how much you can claim, how to file, and by when. The short answers are below, followed by the settlements themselves.

The Largest Consumer Data Breach Settlements

Equifax — $425 Million

The Equifax settlement, tied to the 2017 breach, remains the benchmark for consumer data breach resolutions. The fund was capped at up to $425 million, with roughly $70 million allocated for cash benefits covering out-of-pocket losses and time spent dealing with the breach.1Equifax. Equifax Statement on Final Payments in Data Breach Settlement The claims deadline passed on January 22, 2024, and final payments were distributed between November 7 and December 20, 2024, via prepaid debit cards to claimants who had already received an earlier disbursement.2CFPB. Equifax Settlement Per-person amounts varied with each claimant’s documented losses. Non-cash benefits are still in effect: free identity restoration services are available through January 2029, and eligible consumers can pull seven free Equifax credit reports per year through 2026.3FTC. Equifax Data Breach Settlement

T-Mobile — $350 Million

T-Mobile’s $350 million class action settlement resolved claims arising from a 2021 attack that exposed personal information for approximately 76.6 million people, including Social Security numbers, driver’s license numbers, and phone numbers.4Hausfeld. Final Approval of $350 Million Settlement in Data Breach Class Action Against T-Mobile Under the terms, class members with documented out-of-pocket losses could recover up to $25,000. Those without documented losses received $25, or $100 if they were in the California subclass, along with two years of identity monitoring and restoration services.5FindLaw. In re T-Mobile Customer Data Security Breach Litigation T-Mobile separately committed to spending $150 million over two years on data security. All court proceedings and payment distributions are now complete, though claimants with unresolved payment issues can request reissues through March 31, 2026.6T-Mobile Settlement. T-Mobile Data Breach Settlement

Capital One — $190 Million

Capital One’s 2019 breach exposed data on roughly 98 million Americans through the bank’s Amazon Web Services cloud environment. Stolen information included names, addresses, dates of birth, credit scores, Social Security numbers for about 140,000 people, and bank account numbers for roughly 80,000.7U.S. District Court. Final Approval Order, Capital One Data Breach Settlement The court granted final approval on September 13, 2022. Initial payments went out in September 2023, with a second round in September 2024, and all payment activity is complete. Settlement class members remain eligible for identity defense and restoration services through February 2028.8Capital One Settlement. Capital One Data Breach Settlement

Comcast/Xfinity — $117.5 Million

This one is still open for claims. A criminal cyberattack on Comcast’s systems between October 16 and 19, 2023, exposed usernames, passwords, contact details, dates of birth, and partial Social Security numbers.9USA Today. Comcast Xfinity Settlement Over 2023 Data Breach Under Hasson v. Comcast Cable Communications LLC, Comcast agreed to a $117.5 million settlement fund. Eligible class members are those who received a breach notification from Comcast around December 2023. Documented out-of-pocket losses and lost time (paid at $30 per hour for up to five hours) are reimbursable up to a combined $10,000. Claimants who prefer not to document losses can take an alternative cash payment estimated at $50, subject to adjustment based on claim volume. All class members also get three years of identity defense services, including $1 million in identity theft insurance.10Comcast Breach Settlement. Hasson v. Comcast Cable Communications LLC FAQ The claims deadline is September 14, 2026, with a final approval hearing scheduled for August 5, 2026. Comcast has denied wrongdoing.

How to Claim Money If You Got a Breach Notice

The process is fairly consistent across cases. After a breach is disclosed, lawsuits are filed and consolidated. Investigation, discovery, and mediation typically run one to three years before a settlement is reached. Once a proposed settlement is negotiated, it goes to a judge for preliminary and then final approval. A court-appointed claims administrator then sends notice to class members and opens a filing window.10Comcast Breach Settlement. Hasson v. Comcast Cable Communications LLC FAQ

Filing a claim usually means visiting the official settlement website and providing basic contact and account information. If you’re seeking more than a flat payment, you’ll need documentation: receipts, account statements, breach notification emails, and records of any financial losses or time spent dealing with the breach. Deadlines are set by court order and typically fall 60 to 120 days after final approval. Payments go out by direct deposit, prepaid debit card, digital wallet, or check, generally 60 to 90 days after claims are approved and any appeals resolved.10Comcast Breach Settlement. Hasson v. Comcast Cable Communications LLC FAQ

Payouts vary. Flat payments for class members who do not document specific losses commonly land between $25 and $100, as the T-Mobile and Comcast terms show. Claimants who can document harm receive more, with caps typically in the $10,000 to $25,000 range. Credit monitoring and identity restoration services are standard, and in most cases you can enroll regardless of whether you filed for cash.

Shareholder Settlements Over Cybersecurity Failures

Investors have also driven major settlements when companies concealed security problems. Three of the ten largest data breach securities class action settlements in history were reached in 2024, totaling $560 million.11Harvard Law School Forum on Corporate Governance. Data Breach Securities Class Actions: Record Settlements and Investor Claims on the Rise

Alphabet paid $350 million to resolve allegations that Google concealed a years-long software bug in its Google+ platform that gave third-party developers access to private user data. Judge Trina Thompson in the Northern District of California granted final approval on September 30, 2024.12Law360. Google Investors Attys Snag $66.5M in $350M Privacy Deal Zoom Video Communications settled for $150 million over allegations that it made false claims about its platform’s encryption and privacy measures, with final approval on October 29, 2025 and pro rata distribution among class members who filed valid claims by September 2025.13Kessler Topaz Meltzer & Check. Zoom Video Communications Securities Fraud Class Action Okta, the identity management company, settled for $60 million after investors alleged the company downplayed a 2022 cyberattack that affected 366 clients, with Judge Susan Illston finalizing the settlement on November 19, 2024. The estimated per-share recovery was roughly $0.90 after deductions.14Okta Securities Litigation. In re Okta Inc. Securities Litigation Notice of Settlement

Regulator Settlements: Money You Won’t See but Rules You’ll Feel

When a federal or state agency settles with a company, the penalty goes to the government, not to affected consumers. What you get instead is the compliance overhaul the company has to accept, which shapes how your data is handled going forward.

FCC Actions Against Wireless Carriers

In 2024 the FCC reached consent decrees with all four major wireless carriers. T-Mobile paid a $15.75 million civil penalty and committed to invest another $15.75 million over two years in cybersecurity upgrades, resolving investigations into breaches in 2021, 2022, and 2023. Required improvements included zero-trust architecture, network segmentation, multi-factor authentication, and board-level reporting from the CISO.15FCC. T-Mobile Required to Change Business Practices After Data Breaches AT&T paid $13 million over a January 2023 breach in which hackers exfiltrated data on nearly 8.9 million customers from a third-party vendor. AT&T admitted the underlying facts and agreed to overhaul vendor oversight and implement an information security program aligned with the NIST Cybersecurity Framework.16FCC. AT&T Consent Decree Verizon’s subsidiary TracFone Wireless paid $16 million in July 2024 over three separate breaches involving insecure APIs.17FCC. Privacy and Data Protection Consent Decrees

State Attorneys General

In November 2024, the New York Attorney General and Department of Financial Services secured $11.3 million from GEICO ($9.75 million) and Travelers ($1.55 million). Starting in 2020, hackers exploited GEICO’s public quoting tools to steal driver’s license numbers from about 116,000 New Yorkers. At Travelers, hackers used compromised agent credentials to reach a portal that lacked multi-factor authentication, exposing data on roughly 4,000 residents, undetected for more than seven months. Stolen data was used to file fraudulent pandemic unemployment claims.18NY Attorney General. Attorney General James and DFS Superintendent Harris Secure $11.3 Million From Auto Insurance Companies By October 2025, the New York AG had secured $14.2 million more from eight additional auto insurance companies over similar quoting-tool failures affecting over 825,000 New Yorkers.19NY Attorney General. Attorney General James Secures $14.2 Million From Car Insurance Companies Over Data Breaches

A November 2025 multistate settlement with Illuminate Education totaled $5.1 million over a December 2021 breach exposing millions of student records. Hackers used credentials belonging to a former employee whose access had never been deactivated. California received $3.25 million (3 million students impacted), New York $1.7 million (1.7 million students), and Connecticut $150,000 (about 28,600 students). It was Connecticut’s first enforcement under its Student Data Privacy Law.20Connecticut Attorney General. Attorney General Tong Enters Into Settlement in First Action Under Student Data Privacy Law

In April 2026, the New York Department of Financial Services finalized a $2.25 million settlement with Delta Dental Insurance Company and Delta Dental of New York for violations of the state’s cybersecurity regulation, 23 NYCRR Part 500. The companies failed to maintain adequate incident response plans, failed to implement proper data disposal policies, and failed to notify regulators of a 2023 MOVEit-related breach within the required 72-hour window. The consent order also prohibited seeking insurance reimbursement or tax deductions for the penalty and affirmed that regulated entities cannot delegate cybersecurity compliance to third-party vendors.21NYDFS. DFS Announces Settlement With Delta Dental

FTC and HHS Settlements

Notable FTC actions in 2025 included a court-approved order requiring Disney to pay $10 million for enabling the unlawful collection of children’s personal data, and a $5.7 million resolution with Dun & Bradstreet for violating a 2022 FTC order. Of the Dun & Bradstreet total, roughly $2.06 million was a civil penalty, with the remainder going to customer refunds.22DOJ. Dun & Bradstreet to Pay $5.7M to Resolve Alleged Violations of Federal Trade Commission Order

The HHS Office for Civil Rights continued HIPAA enforcement in healthcare. In January 2025, OCR announced a $3 million settlement with Solara Medical Supplies over a phishing attack that compromised the health information of over 114,000 individuals; Solara had also sent breach notification letters to incorrect addresses.23Nixon Peabody. OCR Continues Busy Start to 2025 With Three More HIPAA Settlements In August 2025, OCR settled with BST & Co. CPAs for $175,000 over a ransomware infection affecting a healthcare client’s data.24HHS. HHS OCR BST HIPAA Settlement

What’s Driving the Surge

The volume tells the story. Data breach class action filings increased by more than 1,265% between 2018 (108 filings) and 2024 (1,488 filings), and climbed past 1,800 in 2025.25Duane Morris LLP. Duane Morris Class Action Review 2026 The cost of U.S. data breaches also leads the world, averaging $10.2 million per incident against a $4.4 million global average, and 32% of organizations worldwide faced breach-related fines in 2025.26Infosecurity Magazine. Top 10 Data Breach Fines 2025

Certain failures show up again and again across these cases: missing multi-factor authentication (Travelers, TracFone), poor vendor oversight (AT&T, Delta Dental), failure to deactivate former employees’ credentials (Illuminate Education), inadequate patch management, and weak incident response planning. Courts have been granting motions to dismiss at higher rates, which has pushed many cases to settle before class certification. Plaintiffs’ lawyers have also begun pairing tools like session replay software, chatbots, and tracking pixels with older per-violation statutes to pursue larger damages.25Duane Morris LLP. Duane Morris Class Action Review 2026 If you keep receiving breach notices, the pattern is the point: check each one for a settlement website, note the claims deadline, and save any documentation of harm before it becomes hard to reconstruct.