Open data breach settlements you can still claim

6 breach settlements are taking claims right now. Each one below was read off the claim site the court authorized — the deadline, who qualifies, and what a valid claim actually pays.

ByNikita Silianov· Founder & CEO ·LinkedIn
Quick answer

As of August 5, 2026, 6 US data breach settlements are still accepting claims, and the next one to close is Flagstar Bank on August 11, 2026. You file free, on the settlement administrator’s own site, without a lawyer. Most funds pay for documented losses, add a flat cash payment for people with nothing to document, and include a period of credit monitoring.

Taking claims now

Flagstar Bank

$31.5M fund

Two breaches at the bank, one in January 2021 and one in December 2021.

Who is covered

About 2.19 million people in the US whose information was in either incident, including roughly 364,000 California residents.

What a valid claim gets you
  • Up to $25,000 for documented losses
  • A residual cash payment estimated around $60 (capped at $599)
  • Three years of three-bureau credit monitoring
  • Up to $100 more for California residents
File by: · 6 days leftFinal approval hearing: October 1, 2026

Exclusion deadline June 29, 2026 — already passed, so filing a claim is the remaining option.

Onsite Mammography (Onsite Women’s Health)

An employee email account was accessed by someone outside the company in October 2024.

Who is covered

People in the US whose private information was caught up in the October 2024 incident, whether or not a notice reached them.

What a valid claim gets you
  • Up to $5,000 for documented out-of-pocket losses, plus a pro rata cash payment
  • Or credit monitoring together with medical-data monitoring instead of the cash
File by: · 6 days leftFinal approval hearing: September 9, 2026

Exclusion deadline July 13, 2026 — already passed, so filing a claim is the remaining option.

ZOLL Medical

$3.5M fund

A breach of the cardiac-device maker’s network between 22 and 24 January 2023.

Who is covered

US residents who got a notice from ZOLL about the January 2023 incident. The class splits in two: people whose Social Security number was involved, and people whose was not.

What a valid claim gets you
  • Up to $5,000 per person for documented out-of-pocket losses
  • A pro rata cash payment, doubled if your Social Security number was involved
File by: · 28 days leftFinal approval hearing: September 10, 2026

Exclusion deadline August 3, 2026 — already passed, so filing a claim is the remaining option.

STIIIZY

$2.95M fund

A breach at the cannabis retailer in October 2024, disclosed on 7 January 2025.

Who is covered

People whose personal information may have been taken in the incident STIIIZY announced in January 2025 — the ID-scan data collected at checkout makes this one worth reading closely.

What a valid claim gets you
  • Up to $7,500 for documented losses
  • A pro rata cash payment, with double shares for California class members
  • Two years of three-bureau credit monitoring with $1,000,000 of identity-theft insurance
File by: · 36 days leftFinal approval hearing: October 19, 2026

Exclusion deadline August 26, 2026 — the last day to keep your own right to sue.

Payactiv

A data incident at the earned-wage-access provider in April 2025.

Who is covered

People whose information was compromised in the April 2025 incident. The exposed fields included names, dates of birth, financial account numbers and Social Security numbers.

What a valid claim gets you
  • Reimbursement for documented out-of-pocket losses — the claim form states the cap
  • A cash payment and credit monitoring
File by: · 38 days leftFinal approval hearing: October 12, 2026

Exclusion deadline September 12, 2026 — the last day to keep your own right to sue.

Comcast (Xfinity)

$117.5M fund

The October 2023 attack on Xfinity, with notices going out around 18 December 2023.

Who is covered

Xfinity customers who were told their personal information was involved — including people who have since cancelled the service.

What a valid claim gets you
  • Reimbursement for documented out-of-pocket losses and for time you lost dealing with it
  • Or an alternative cash payment with nothing to document
  • Identity-defence and restoration services through an enrolment code
File by: · 40 days leftFinal approval hearing: August 5, 2026

Exclusion deadline July 1, 2026 — already passed, so filing a claim is the remaining option.

General information, not legal advice. Caps, class definitions and dates come from the administrator’s site and can change by court order — the notice and that site govern. We are not affiliated with any settlement, take no cut of any payout, and link only to court-authorized claim sites.

Recently closed

The claim window has shut on these. They stay listed because people keep searching for them, and because the steps that still help after a missed deadline are the same ones as before it.

Fidelity Investments

$2.5M fund

An August 2024 incident in which two customer accounts were used to pull files on other customers.

Who is covered

The 77,099 people Fidelity notified. Names, Social Security numbers, financial account details and driver’s licence numbers were in the files.

What a valid claim gets you
  • $100 cash, with another $50 for California residents
  • Up to $5,000 for documented losses
  • Two years of credit monitoring and identity protection
Claims closed:

Before you fill in a claim form

Work out which route you are taking first, because most forms make you pick. The documented-loss route needs paperwork — a statement showing the fraudulent charge, the bank letter, the credit-repair invoice — and pays properly. The flat cash option needs nothing and pays what is left after everyone else has filed. Claiming for time spent is normally self-attested at a set hourly rate, signed under penalty of perjury, so describe honestly what you actually did. Our guide to claiming a breach settlement walks through the whole process, including opting out.

The fake claim sites arrive first

Big settlements draw copies within days, and they are built around what the breach already leaked: the page knows the company, sometimes your name, and asks for the Social Security number or bank details to “verify” you. A genuine administrator wants your contact details, usually the ID from your notice, and at most the last four digits of an SSN. Nobody charges you to file. If a text or email pushes you to a claim page, close it and go to the address printed in the notice instead — the same reflex as checking a breach letter is real.

Most people qualify for more than one

Settlements only cover breaches you know about. PersProtect shows which known breaches hold your email, then finds and removes your profile across 499 broker and people-search sites — the exposure a payout never touches. Free scan, about a minute.

Check which breaches involve me →
Common questions

Filing a settlement claim, answered

How do I know a settlement claim site is the real one?

Every settlement has one website set up by the administrator the court appointed, and the address is printed in the notice and in the court filings. That site never asks for a payment, a full Social Security number, a card number or a banking login. Anything that arrives by text or unsolicited email offering to "release" your award is a copy built to harvest exactly what the breach exposed. Type the address in yourself instead of tapping the link.

I never received a notice. Can I still file?

Usually yes. Notices go to whatever address the company had on file, which is often years out of date, so most administrators let you file without a class-member ID by confirming your details and attesting that you were affected. Claims do get checked against the class list, so filing on a breach you were not part of goes nowhere.

What if the deadline has already passed?

Then that fund is closed to you, and no lawyer or service can reopen it. What is still worth doing is the part a payout never covered: freeze your credit at all three bureaus, kill any password you reused, and check which other breaches hold your details, because most people who qualified for one settlement qualify for another they have not heard about yet.

How long until the money arrives?

Longer than anyone expects. After the claim deadline comes the final approval hearing, then an appeal window, then the administrator works out how far the fund stretches across valid claims. A year between filing and a payment is ordinary, and the amounts get trimmed pro rata when more people file than the estimate assumed.

Does filing a claim stop me suing the company?

Yes, and that is the trade. Filing keeps you in the class and releases your right to sue over that incident. Opting out by the exclusion deadline keeps that right and gives up the fund, which only makes sense with substantial documented losses and legal advice. Doing nothing is the worst of both: the release still binds you and you get nothing.

Why are there so few settlements on this list?

Because we only list ones we have checked on the administrator’s own site this month. Aggregator lists run to dozens of entries, many of them expired, mislabelled, or repeating a claim deadline that moved. A short list you can trust beats a long one you have to re-verify.

A cheque closes the case. It does not close the exposure.

See which breaches hold your data and where your details are still listed for sale — free, in about a minute.

Run my free exposure scan →