Skip to main content
Back
Jul 28, 2026
171

Bank of America MOVEit Breach Settlement Up to 12500 for Alleged Identity Theft

Settlement Image

The Bank of America MOVEit Breach Settlement Up to 12500 for Alleged Identity Theft settlement offers $2.50M in total, with individual payouts of $100 to $12.50K to eligible claimants who be a current or former bank of america customer, residing in the united states. The deadline to file is October 8, 2026. Proof of purchase is required.

Deadline
48 days remaining

Deadline: October 8, 2026

Total Settlement Amount
$2.50M

Total amount allocated for all claims

Individual Payout Range
$100 to $12.50K

Estimated amount per eligible claim

Proof of Purchase
Required

To submit a claim, the claimant must provide the claimant ID from the settlement notice; online filers must also provide the PIN from the notice. Claims for ordinary and extraordinary losses require supporting documentation such as receipts, invoices, bank/credit card statements showing unreimbursed fees or fraudulent charges, invoices for professional services, and police reports and other proof of identity theft or fraud. Extraordinary losses generally cover unreimbursed monetary losses occurring between May 31, 2023 and Oct. 8, 2026.

Settlement Summary

In 2023, a widely used file-transfer platform called MOVEit was hit by a cyberattack that let criminals exploit a vulnerability and steal sensitive personal information. Bank of America had shared customer data with Ernst & Young (EY) for services, and both firms later notified certain customers that their personally identifying information may have been accessed during the May 27–May 31, 2023 incident. With the impact reported as affecting more than 198,667 people, the alleged harm ranged from out-of-pocket costs and time spent addressing fraud-related fallout to potential longer-term recovery needs such as credit monitoring and restoration. The lawsuit was filed as a class action to challenge the companies’ data security practices—specifically, claims that EY’s use of MOVEit exposed Bank of America’s data and that the parties failed to adequately protect it. Its significance is that it provides a structured path for affected people to seek reimbursement without proving individual fault in court, with settlement amounts up to $12,500 depending on documented “ordinary,” “lost time,” and “extraordinary” losses (and an alternative pro rata cash option for those who don’t submit those expense categories). This reflects broader trends in the cybersecurity legal landscape: under U.S. consumer protection expectations and state privacy laws, including often-cited duties around “reasonable” data security, class actions increasingly test whether companies met that standard when third-party vendors or software vulnerabilities are involved. Beyond this case, the MOVEit incident has produced multiple lawsuits and settlements across industries because it highlights how vendor-managed systems can become a weak link—even when the victim is not the direct software operator. Similar claims commonly focus on whether organizations had appropriate safeguards, monitoring, and risk management for third-party tools, and on whether they responded promptly after suspicious activity. In this settlement, EY and Bank of America agreed to resolve the dispute by paying $2.5 million (including administration, attorneys’ fees, and credit monitoring), and eligible U.S. class members can file claims online or by mail by Oct. 8, 2026

Entities Involved

Bank of America Corp.
Ernst & Young LLP (EY)
MOVEit Transfer
EY and BOA Settlement
RG/2 Claims Administration
United States District Court (final approval referenced)
Delaware Attorney General (referenced source link)
PayPal
Venmo

Related Topics

MOVEit data breach settlement
Bank of America MOVEit class action
Ernst & Young data breach lawsuit settlement
cybersecurity negligence class action
data breach claims payment
up to 12500 payout
credit monitoring 2 years three-bureau
identity theft insurance up to 1 million
claim deadline October 8 2026
FREE MOVEit settlement claim form
claim online or mail claim form
documented out of pocket expenses
lost time reimbursement 25 per hour
dark web monitoring identity theft protection
PII compromise notice

Eligibility Requirements

  • Be a current or former Bank of America customer, residing in the United States
  • Receive a notice indicating that your PII may have been impacted by the May 2023 MOVEit data breach
  • Your PII must be the type potentially affected as it relates to services Ernst & Young provided to Bank of America
  • Provide the claimant ID from the settlement notice (and PIN for online submissions)

Important Notice About Filing Claims

Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.

If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.

Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.