Data breaches are so common in the U.S. and around the world that many Americans never follow through with claiming their share of a settlement when it happens to them. The reasoning comes back to several factors, including that how it affects individuals is usually delayed and the harm feels almost invisible – until it isn’t.
Then there’s the fact that there were 3,322 confirmed data compromises in the U.S. in 2025, as reported by the Identify Theft Resource Center. The sheer number of breaches have made people somewhat immune, if not desensitized, to headlines about cyberattacks and stolen data.
But the risks and impact of having your private information stolen, anything from your name, address, and login details to Social Security numbers and financial details, is significant.
The damage data breaches cause is extensive. Globally, the average cost of a data breach was $4.99 million in 2025, but the average cost per breach in the U.S. was far higher. It reached a record-high of $10.22 million last year.
Understanding data breach notices, how settlements work and how much they pay, what can be enforced, and what to do if your personal data is taken is important.
Recent Data Breaches, Third-Party Vendors, and State Laws
The companies targeted in cyberattacks are frequently third-party vendors, so if you’ve gotten a data breach notice this year from a company you don’t recognize, you’re not alone. A growing share of 2026 data breach settlements trace back not to the company that mailed the notice, but to a vendor working behind the scenes that most consumers haven’t heard of.
Take Serviceaide, an AI-powered digital solutions provider that partners with hospital systems like Catholic Health, as an example. A breach on Serviceaide’s systems in late 2024 led to a $1.8 million class action settlement, even though those affected never signed up to the provider directly. They just happened to be patients of a hospital that used a third-party’s system.
Another case, this one involving SitusAMC, a mortgage-industry services vendor, recently reached a $5.3 million settlement. The case was brought forward after a SitusAMC data breach in November 2025 exposed information belonging to customers of the banks and lenders it serves.
There was also a $3 million settlement with Modernizing Medicine after a cyberattack exposed patient data. The list goes on.
None of these companies are household names. That’s the point; much of your personal information doesn’t stay with the businesses you chose to disclose it to or receive products or services from.
Your data moves through a web of processors, software platforms, and administrative vendors that the majority of consumers never see and can’t opt out of. This means the usual advice of “be careful which companies you trust with your data” only goes so far.
All 50 states require companies to notify consumers when their personal data is exposed, but the notice comes from whoever held the data at the time of the breach. If your hospital, employer, insurer, or bank outsources billing, IT, or record-keeping to a third-party and that vendor gets breached, you’ll hear from that company.
It's a process that leaves people confused, skeptical of the notice, and unsure whether they should be concerned.
Some states are taking action to better address data privacy. California's Delete Act allows residents to make a single request to every registered data broker in the state.
How Much Do Data Breach Settlements Pay?
Settlement notices tend to highlight the total funds, which are often worth millions or tens of millions of dollars. But that number is the ceiling, not the payout consumers actually receive.
A meaningful share of that total is set aside before anyone gets paid. Court-approved attorneys’ fees, which is usually substantial (think: 25% or more), settlement administration costs, and notice expenses all come out first. What’s left is paid to those who file a claim.
Most data breach settlements use a tiered structure. Consumers who can document actual losses, like fraudulent charges, credit monitoring they paid for out of pocket, and/ or time spent resolving the breach, can typically claim reimbursement up to a stated cap. In the Labcorp data breach settlement, those with documented losses and who filed by September 3 could receive up to a $5,000 payout.
Consumers who don’t have documented losses are usually offered a smaller flat payment or a “pro rata” share of whatever remains in the fund.
That pro rata piece is where expectations can go wrong. The per-person amount isn’t fixed; it depends entirely on how many people file claims. If 5% of eligible class members file a data breach claim, each member’s share is meaningful higher than if the majority of those affected take part.
The key takeaway for consumers is that there’s no way to know the final payout when filing a data breach settlement claim until the claims window closes, but notices frequently advertise top payouts. A good example of this is the recent Fidelity financial data settlement, which noted those eligible could receive up to $5,000.
What a Data Breach Settlement Doesn’t Do
Unfortunately, while data breach settlements put money into the pockets of those whose data was stolen, it doesn’t mean that the company fixed the problem or is forced to do so.
Most private class action settlements are structured as a cash payment in exchange for releasing the company from further liability over a specific breach. They also typically include no admission of wrongdoing and, more importantly, have no enforceable requirement that the company change its security practices.
Compared to regulatory enforcement, such as when the Federal Trade Commission settles a data security case, the resulting order can require years of independent, third-party security audits. This ensures the company better protects the data it stores, which may involve new security measures, standards, and protocols. State attorneys general can bring similar cases with ongoing compliance obligations attached.
Those regulatory settlements are aimed at preventing the next breach, whereas private class action settlements are aimed at compensating consumers for a breach that already happened.
Both a private and regulatory settlement can happen for the same incident, and both matter in their own ways. But they’re not doing the same job, and in many cases, a private settlement does nothing to fix what caused the data breach in the first place.
What to Do If You Received a Data Breach Settlement Notice
If you received a data breach settlement notice, file the claim. It’s free, and even a modest payout is better than leaving money on the table.
Follow these other steps when your personal data is stolen:
- Keep documentation of any out-of-pocket losses tied to the breach (that’s what typically qualifies you for the higher payout).
- Enroll in free credit monitoring if offered, which is typically for one or two years. But don’t treat it as a permanent fix because a stolen Social Security number carries risks indefinitely.
- Verify a data breach settlement notice is legitimate by checking the court docket online or the official settlement administrator’s site before entering personal information.
While false class action notices and phishing attempts have become increasingly common, take them seriously.
As the world becomes even more dependent on technology and AI is further integrated into business operations and everyday life, data breaches will continue to put Americans at risk of real financial and personal losses.
Upcoming data breach settlement claims deadlines:
- American Income Life/ Globe Life Data Breach: October 19, 2026
- Palomar Health Data Breach: October 22, 2026
- Brevard Skin & Cancer Center Data Breach: November 16, 2026