More than 160,000 Fidelity Investments customers may be eligible for a slice of a $2.5 million class action settlement, but the clock is ticking. Claims must be filed by July 27, 2026, and the maximum individual payout tops out at $5,000 for those who can document real losses from a 2024 cyberattack the lawsuit calls entirely preventable.
The settlement resolves allegations that Fidelity and its subsidiary, Fidelity Brokerage Services, failed to put adequate cybersecurity protections in place before hackers breached the firm's systems over three days in August 2024. According to the suit, the company then waited nearly two months to tell customers their personal data, including Social Security numbers and driver's license information, had been compromised.
Fidelity denied wrongdoing. The company told CNBC Select it agreed to settle to avoid the cost and uncertainty of drawn-out litigation, not because it admitted fault. That framing will sound familiar to anyone who has watched major corporations write checks while insisting they did nothing wrong.
The class action complaint, as reported by The Sun, painted a picture of a financial giant that left the door open. Plaintiffs alleged Fidelity's "inadequately secured computer systems" gave hackers a way in during August 17, 19, 2024. The breach exposed more than 77,000 individuals whose "particularly sensitive and high-risk information" was compromised.
That category included Social Security numbers and driver's licenses, exactly the kind of data identity thieves prize most. The suit described the breach as preventable, a word that carries weight when applied to a firm entrusted with millions of Americans' retirement savings and brokerage accounts.
Perhaps more damaging than the breach itself was the alleged delay. Plaintiffs claimed Fidelity detected suspicious activity but waited roughly two months before notifying the affected customers. Two months is a long time for a thief to sit on a stolen Social Security number.
The settlement carves out two tiers of compensation. Customers who can provide documentation of out-of-pocket losses tied to the breach, fraudulent charges, credit repair costs, or similar expenses, may claim up to $5,000. Those without documented losses can still file for a pro-rata share of the fund, estimated at roughly $100 per person, though the final amount depends on how many class members submit claims.
California residents get an additional $50 on top of whatever they receive, though the settlement does not specify the statutory basis for that state-specific bump.
Every claimant, regardless of tier, also receives two years of free credit monitoring through CyEx, bundled with $1 million in identity theft and fraud insurance coverage. That credit monitoring may be the most practically valuable piece of the deal for customers who have no way to prove a direct financial hit but know their data is floating around in the wrong hands.
The pattern of modest individual payouts from large corporate breach settlements has become routine. Flagstar Bank customers recently became eligible for up to $599 each under a $31.5 million settlement stemming from a similar breach.
Eligible customers should have received a notice containing a Unique ID and PIN. Claims can be filed online at FidelityDataSettlement.com or mailed in before the July 27, 2026 deadline. Anyone who believes they are eligible but did not receive a notice can contact the Settlement Administrator at [email protected].
A final approval hearing for the settlement took place on July 9, which appears to have cleared the way for distributions once the claims window closes. The settlement website hosts the claim form directly.
Fidelity's public posture has been carefully measured. In a statement provided to CNBC Select, the company said:
"We remain fully committed to the security of our clients' accounts and personal information."
The company added that "litigation can involve a considerable amount of time and resources, a settlement is one way to avoid this for both parties." That language is standard corporate-litigation boilerplate. It acknowledges nothing, concedes nothing, and resolves everything with a check.
What it does not address is the core allegation: that Fidelity's systems were not adequately secured in the first place, and that the company sat on the breach for weeks before warning customers. Denying wrongdoing in a legal filing is one thing. Explaining to 77,000 people why their Social Security numbers were exposed, and why they weren't told for two months, is another.
The Fidelity settlement is far from the largest in the growing wave of data breach class actions. Comcast agreed to a $117.5 million settlement after a 2023 breach exposed millions of Xfinity customers, a figure that dwarfs Fidelity's $2.5 million fund.
The Fidelity case fits a now-familiar cycle. A major company suffers a breach. Customers learn months later that their most sensitive data was compromised. A class action follows. The company settles for a fraction of its annual revenue, denies fault, and promises to do better. Individual payouts land somewhere between a decent dinner and a modest car payment.
For the 77,000 people whose driver's licenses and Social Security numbers were allegedly exposed, the math is cold. Even the maximum $5,000 payout requires documented proof of losses, receipts, bank statements, credit reports, that many victims may not have kept or may not yet know they need.
The roughly $100 pro-rata payment available to everyone else is better than nothing, but it is not much consolation for the long tail of identity theft risk that follows a breach of this kind. Credit monitoring helps. It does not undo the exposure.
Smaller settlements have followed similar contours. Krispy Kreme settled a breach lawsuit for $1.6 million, with customers eligible for up to $3,500. The numbers change. The script does not.
And the deadlines keep coming. First Financial Security's breach settlement deadline recently approached, with affected consumers eligible for up to $500, another case where the window to act was narrow and the burden fell on the victim to file paperwork.
Several important questions hang over the Fidelity settlement. The lawsuit does not publicly identify the specific cybersecurity failures that allegedly allowed the breach. The attack vector, how the hackers actually got in, has not been disclosed in available filings. And the precise court handling the case, along with the named plaintiffs, remains unidentified in public reporting.
The gap between the 77,000 individuals whose sensitive data was allegedly compromised and the broader pool of more than 160,000 potentially eligible claimants also raises questions. Were the additional customers exposed to lesser categories of data loss? The settlement materials do not make that distinction clear.
Meanwhile, Cash App parent Block Inc. agreed to a $120 million fraud settlement covering consumers in 45 states, a reminder that the financial services industry's accountability problems extend well beyond any single company or breach.
For Fidelity customers who may be affected, the immediate task is simple: check for a notice, file a claim before July 27, and sign up for the credit monitoring. The broader question, whether $2.5 million is a meaningful deterrent for a firm of Fidelity's size, answers itself.
When the cost of a settlement is a rounding error on the quarterly balance sheet, it's hard to call it accountability.