Americans whose personal data was compromised in the October 2023 breach at First Financial Security have less than a month to file claims under a $1.2 million class action settlement. Eligible customers can recover up to $500 in out-of-pocket losses, plus two years of free credit and medical monitoring, but the window closes on July 20.
The breach, which occurred on October 17, 2023, exposed sensitive customer information including Social Security numbers. A class action lawsuit followed, alleging the financial services company failed to implement sufficient cybersecurity measures, failures that, plaintiffs argued, stronger protections could have prevented.
First Financial Security has not admitted wrongdoing. But the company agreed to the seven-figure settlement to resolve the litigation, and settlement administrators have already distributed notices to affected customers. A final approval hearing is set for November 9.
Class members can claim up to $500 to cover documented out-of-pocket losses tied to the breach. Qualifying expenses include bank fees, credit-related costs, communication charges, and expenses for obtaining credit reports, all of which must be supported by evidence such as bank statements, receipts, or other financial documents.
Beyond direct financial losses, claimants can also recover for up to three hours of lost time at a rate of $20 per hour, a maximum of $60 for time spent dealing with the fallout of having their personal information exposed.
The settlement also provides two years of free medical and credit monitoring through CyEx Medical Shield Complete. Claimants must use the code included on their settlement notice to activate the monitoring services, as The Sun reported.
The claim form submission deadline is July 20. Forms can be submitted online. Those who received a settlement notice should have the information needed to file.
Customers who want to object to the settlement terms, or opt out of the automatic payment structure, must do so by September 18. After the November 9 final approval hearing, payments will be distributed to eligible claimants.
The settlement follows a pattern that has become all too familiar for American consumers. Data breaches at financial institutions continue to pile up, and the companies responsible rarely face consequences beyond writing a check, often without even acknowledging fault.
This is far from the only active settlement where Americans may be leaving money on the table. Flagstar Bank customers could collect up to $599 each under a separate $31.5 million data breach settlement.
The lawsuit against First Financial Security centered on a straightforward allegation: the company did not do enough to protect customer data. Social Security numbers, the skeleton key to identity theft, were among the information compromised.
For the customers affected, the breach created real costs and real headaches. Freezing credit, monitoring accounts, replacing cards, sitting on hold with banks, none of it is free, and none of it is quick. The settlement's $20-per-hour lost-time provision at least acknowledges that reality, even if the cap is modest.
The broader picture is grimmer. Major companies across industries have faced similar litigation in recent years. Comcast agreed to a $117.5 million settlement after a 2023 breach exposed millions of Xfinity customers. The scale varies, but the underlying problem does not: companies collect vast amounts of sensitive personal data and too often treat cybersecurity as an afterthought.
The $1.2 million total in the First Financial Security case is small compared to some of these headline-grabbing settlements. But for individual claimants, especially those who incurred real expenses, $500 and two years of monitoring represent meaningful relief.
What remains unclear is how many customers are actually part of the class. The settlement notice was distributed by administrators, but the total number of affected individuals has not been disclosed publicly. The court overseeing the case, the specific jurisdiction, and the named plaintiffs are also not identified in available reporting.
Class action settlements routinely go unclaimed. People toss the notices, assume the payout will be trivial, or simply forget. In this case, eligible customers who do nothing will miss the July 20 deadline entirely.
That pattern benefits the companies that caused the problem. Lower claim rates mean less money paid out, and less incentive to fix the underlying security failures. Meanwhile, similar breaches keep happening at institutions across the financial sector. Union Bank and Trust customers recently faced a tight deadline to claim up to $12,500 from their own data breach settlement.
The lesson is simple: if you received a notice from the First Financial Security settlement administrators, act before July 20. Gather your bank statements and receipts. File the claim form online. Activate the free credit monitoring.
Retail and financial companies are not the only ones caught in this cycle. Lands' End is offering up to $5,000 to customers affected by its own data breach settlement, another reminder that consumers across industries need to stay vigilant about their personal information.
The September 18 objection deadline and the November 9 final approval hearing will determine whether the settlement moves forward on its current terms. Until then, the clock is ticking for affected customers to file.
First Financial Security's refusal to admit wrongdoing is standard corporate legal strategy. It protects the company from future liability. But it also means the underlying cybersecurity failures that led to the breach may never be fully examined in court.
For consumers, the takeaway is blunt: companies that hold your Social Security number have a duty to protect it. When they fail, the least they can do is pay for the damage. The most you can do is make sure you collect.