SettleSignal
Settlements Data breachConsumer refundsPrivacy & biometricsEmployment How we verify Guides Help center For business Log in See what you may be owed →

Research report · updated September 12, 2026

U.S. Data-Breach Settlements: What 102 Verified Cases Reveal

A data breach rarely ends when the notification email lands. Months or years later, many become class-action settlements with real money for affected consumers. This report analyzes the 102 published U.S. data-breach settlement records in the SettleSignal catalog, with evidence status shown separately, to show what that afterlife actually looks like. Free to cite with attribution.

102 published data-breach settlements — 12% of the entire catalog
2%
accept a claim with no proof (2)
60
open for claims right now
22
closing this month
6
require documentation (out-of-pocket losses)

Key findings

Key findings

The headline numbers from the published data-breach catalog, each computed live and free to cite.

  • 102 published data-breach settlements — 12% of the entire published catalog
  • 2% accept a claim with no proof of purchase (2) — usually a short attestation for the flat cash payment
  • 6 require documentation — the track for reimbursing out-of-pocket losses (receipts, bank statements)
  • 60 open for claims right now Open
  • 22 close this month Closing
  • 12 named companies with a published data-breach settlement record (largest below)

Finding

The afterlife of a breach

Data breaches are the single largest settlement category we track. When a breach produces a settlement, consumers are typically offered two tracks: a flat cash payment — often claimable with no documentation — and reimbursement of documented out-of-pocket losses (the time and money spent on fraud, credit freezes, and monitoring). The notice usually also includes a period of free credit monitoring. The practical takeaway: a large share of this money can be claimed in minutes, because 2% of published data-breach settlements accept the flat-cash claim with no proof — but the deadlines are real, and a claim that is never filed is money no one receives.

By company

Companies with published data-breach settlements

The most-tracked companies in the published data-breach catalog, by settlement count:

Method

How this data is verified

This report covers published data-breach settlement records and reports evidence status separately. Accepted fields are checked against an official court, administrator, or government document and retain the named authority and check date. Link-only and review-stage records stay labeled while evidence is refreshed. Full method: how we verify.

Open data

Download the data

The underlying public dataset is free to reuse with attribution:

Cite this report

Free to quote and republish with attribution and a link to SettleSignal. Suggested citation:

SettleSignal, "U.S. Data-Breach Settlements: What the Data Reveals," settlesignal.com (updated September 12, 2026).

Every figure in this report is computed from SettleSignal's published catalog. Accepted official evidence and field citations are identified separately from link-only records. SettleSignal is an independent information service, not a law firm, and does not provide legal advice.