Recent cybersecurity settlements in mid-2026 span three separate tracks: consumer class actions with active claims windows, Federal Trade Commission consent orders against companies that mishandled personal data, and Department of Justice False Claims Act recoveries against federal contractors that misrepresented their security. The single largest consumer fund still open is Comcast’s $117.5 million settlement, which accepts claims through September 14, 2026. Several smaller class actions closed their claims windows in June 2026, and the FTC finalized its order against ed-tech company Illuminate Education on June 5, 2026.
Consumer Claims You Can Still File
Comcast — $117.5 Million
The largest open consumer settlement is Hasson v. Comcast Cable Communications, LLC (Case No. 2:23-cv-05039, Eastern District of Pennsylvania), which resolves claims arising from an October 2023 breach affecting roughly 31.6 million current and former Comcast customers. Attackers exploited the “Citrix Bleed” vulnerability in Citrix NetScaler products between October 16 and 19, 2023, taking usernames, hashed passwords, names, contact information, dates of birth, the last four digits of Social Security numbers, and security question answers.
Key dates for class members:
- Opt-out and objection deadline: July 1, 2026
- Final approval hearing: August 5, 2026
- Claims deadline: September 14, 2026
Eligible class members can claim up to $10,000 for documented out-of-pocket losses, $150 for lost time spent dealing with the breach, or a flat alternative cash payment of up to $50. The settlement also provides two years of identity-defense and restoration services.
Capital Health Systems — $4.5 Million (Pending Final Approval)
Capital Health Systems is awaiting final approval of a $4.5 million settlement covering a November 2023 breach, with the approval hearing set for July 14, 2026. Claim details follow final approval.
Settlements That Recently Closed or Began Paying
Several class actions moved past their claim deadlines in June 2026. If you received notice for one of these and missed the window, the deadlines have passed:
- Complete Payroll Solutions ($2.6 million, March 2024 breach exposing Social Security numbers and insurance information): claims due June 18, 2026.
- Avis Rent A Car (August 2024 breach affecting approximately 300,000 customers, exposing names, driver’s license numbers, and credit card information): claims deadline June 21, 2026, with a final hearing July 28, 2026. Eligible claimants could seek up to $5,000 in documented losses or a pro rata cash payment.
- Krispy Kreme ($1.6 million, breach discovered November 29, 2024, involving payment card data and Social Security numbers): claims due June 22, 2026.
- Lakeview Loan Servicing ($26 million, 2021 breach involving Social Security and loan numbers): claims due June 22, 2026.
Payments are already going out in In Re: Yale New Haven Health Services Corp. Data Breach Litigation (Case No. 3:25-cv-00609-SRU, District of Connecticut), an $18 million settlement covering more than 5.5 million individuals affected by a breach reported in April 2025. The court granted final approval on March 3, 2026, and the settlement administrator began issuing payments to approved claimants on May 27, 2026. Class members were eligible for up to $5,000 in documented losses, an estimated $100 alternative cash payment, or two years of free medical data monitoring.
Other recent healthcare-sector resolutions include Veradigm ($10.5 million over a breach affecting 2.67 million people), Medusind ($5 million over a breach affecting more than 700,000 individuals), and the Gunster law firm ($8.5 million after a 2022 hack that compromised information belonging to approximately 746,000 people).
FTC Consent Orders: Regulatory Action Without Consumer Payouts
FTC consent orders address company conduct but generally don’t put money in consumers’ pockets. Two recent orders are worth knowing about.
Illuminate Education
On June 5, 2026, the FTC finalized a consent order against Illuminate Education, Inc. by a 2-0 vote after a public comment period. The underlying breach happened in late December 2021, when a hacker used login credentials belonging to an employee who had left the company three and a half years earlier and accessed cloud-based databases holding health-related information, dates of birth, and email and mailing addresses for more than 10 million students. The FTC alleged that Illuminate stored student data in plain text until at least January 2022, ignored warnings from a third-party vendor about security vulnerabilities starting as early as January 2020, and delayed notifying some school districts for nearly two years.
The order requires Illuminate to build a comprehensive information security program, delete personal information it no longer needs, publish a public data retention schedule, and stop misrepresenting its security and privacy practices. It also requires the company to notify the FTC whenever it alerts another government entity about a future breach. The Electronic Privacy Information Center pushed the agency to tighten the data-deletion and retention-schedule provisions before the order was finalized. The order carries no upfront civil penalty, but each future violation could carry fines of up to $51,744. Separately, Illuminate had already paid $5.1 million to state attorneys general over the same breach.
General Motors and OnStar
In January 2026, the FTC finalized a 20-year consent order against GM and OnStar for secretly collecting and selling drivers’ precise geolocation and driving behavior data without informed consent. GM must now obtain affirmative express consent before collecting connected vehicle data, give consumers ways to access and delete their data, and allow them to disable geolocation tracking. The company is banned for five years from sharing geolocation and driver behavior data with consumer reporting agencies. The order carried no financial penalty; the FTC called the conduct an “egregious betrayal of consumers’ trust.”
The FTC also secured a $10 million court-approved settlement with Disney in December 2025 over allegations of enabling the unlawful collection of children’s personal data, and a $5.7 million payment from Dun & Bradstreet in September 2025 for alleged violations of a prior FTC order.
DOJ False Claims Act Recoveries From Federal Contractors
The Department of Justice is running a separate enforcement track against federal contractors that lied about their cybersecurity compliance. In fiscal year 2025, DOJ recovered more than $52 million across nine cybersecurity-related False Claims Act settlements under the Civil Cyber-Fraud Initiative launched in October 2021. Liability here doesn’t require an actual breach. As Deputy Assistant Attorney General Brenna E. Jenny put it, the cases are “premised on misrepresentations” about cybersecurity compliance, so a contractor can face penalties for lying about its security posture even if no attacker ever exploited the gap.
Notable 2025 settlements:
- Health Net Federal Services and parent Centene Corporation paid $11.25 million in February 2025 over allegations that Health Net falsely certified compliance with cybersecurity requirements under its TRICARE military health contract, letting deficiencies in access controls, patch management, and firewall configuration persist from 2015 through 2018.
- Illumina, Inc. paid $9.8 million in July 2025 over allegations that it sold sequencing systems to federal agencies with known software vulnerabilities while falsely certifying compliance with NIST and ISO cybersecurity standards. Former Illumina director Erica Lenore, who brought the whistleblower case, received $1.9 million.
- Raytheon, RTX Corporation, and Nightwing Group paid $8.4 million over allegations of failing to implement required cybersecurity controls on an internal system used for unclassified Defense Department work across 29 contracts and subcontracts from 2015 to 2021. Former Raytheon engineering director Branson Kenneth Fowler, Sr. received $1.512 million as the whistleblower.
- MORSECORP Inc. paid $4.6 million over allegations that it submitted a self-assessed cybersecurity score of 104 to the Supplier Performance Risk System in 2021, when a later third-party assessment found only 22 percent of required controls in place, yielding a score of negative 142. MORSE did not update its score until it received a government subpoena.
- Aero Turbine Inc. and Gallant Capital Partners paid $1.75 million, the first FCA cyber settlement naming a private equity firm. The defendants received a reduced damages multiplier for voluntary disclosure and cooperation.
- Swiss Automation Inc. paid $421,234 in December 2025 over allegations that the Illinois precision machining company failed to protect technical parts drawings supplied to Defense Department prime contractors. A former quality-control manager brought the suit.
Whistleblowers drove much of this activity, with 1,297 False Claims Act lawsuits filed in fiscal year 2025, a record. The Defense Department’s Cybersecurity Maturity Model Certification program took effect for new contract solicitations on November 10, 2025, meaning false certification of CMMC compliance now carries direct FCA exposure.
SEC: SolarWinds Case Dismissed
One high-profile track ended quietly. The SEC’s enforcement action against SolarWinds Corp. and its former chief information security officer Timothy Brown, filed in October 2023 over alleged misrepresentations to investors about cybersecurity before and after the 2020 supply-chain attack, did not produce a settlement. A federal judge dismissed most of the SEC’s claims in July 2024, finding they relied on “hindsight and speculation.” After announcing a settlement in principle in July 2025, the SEC reversed course and filed a joint stipulation to dismiss the remaining claims with prejudice on November 20, 2025, with no financial penalty and no admission of wrongdoing. As of September 2025, no enforcement actions had been publicly initiated under the SEC’s 2023 cybersecurity incident disclosure rule.