University of St. Thomas Data Breach Settlement Offers Up to $4,500

The University of St. Thomas Data Breach Settlement Offers Up to $4,500 settlement, with individual payouts of $4.50K to eligible claimants who reside in the united states. The deadline to file is September 28, 2026. Proof of purchase is required.
Deadline: September 28, 2026
Total amount allocated for all claims
Estimated amount per eligible claim
Claimants must submit information required by the settlement notice and provide documentation tailored to the type of payment. Online claims require the loginID and PIN from the notice; mail claims require the loginID. Ordinary losses (up to $500) require supporting documents such as receipts, invoices, and/or third-party documentation of out-of-pocket expenses. Extraordinary losses (up to $4,500) require proof of unreimbursed monetary fraud/identity theft losses, documentation tying losses to the breach, and evidence that available insurance or reimbursement options were exhausted. Claims for losses involving sensitive personal information (e.g., employment files/disciplinary records) require third-party documentation showing the disclosure was more likely than not caused by the data breach. Credit monitoring eligibility/payment is tied to election of the benefit option; supporting proof requirements are not detailed beyond the required claim information.
Settlement Summary
In late summer 2025, the University of St. Thomas disclosed a ransomware incident that potentially exposed sensitive personal data for more than 26,000 people. Individuals who received a notice—because they live in the United States and were affected by the breach occurring between July 25, 2025 and Aug. 12, 2025—can submit a claim for money under a class action settlement. The data described in the notice includes Social Security numbers, bank and credit card information, government IDs, login credentials, and contact and home address information, among other confidential records—types of details that can make victims vulnerable to fraud, identity theft, and persistent account-related problems. The lawsuit was filed after the breach, alleging the university failed to take adequate steps to protect private information, and the settlement is intended to compensate people for certain losses tied to the incident. While the university denies wrongdoing, it agreed to settle to avoid the cost and uncertainty of continuing the legal fight. Claimants may seek reimbursement for documented out-of-pocket “ordinary losses” (up to $500), pursue higher “extraordinary losses” tied to fraud or identity theft (up to $4,500) if they can show the losses were more likely than not caused by the breach and not covered by other remedies, and/or receive a smaller cash payment for verified disclosures of sensitive information; many can also choose multi-year credit monitoring and identity theft protection. This type of outcome reflects a broader pattern in the education and technology sectors, where cyber incidents repeatedly trigger claims that organizations did not meet reasonable cybersecurity expectations, and where regulations such as the FTC Act’s “unfair or deceptive” practices standard, state data-breach laws, and sector expectations for safeguards help shape what counts as adequate protection.
Entities Involved
Related Topics
Eligibility Requirements
- Reside in the United States
- Received a notice from the University of St. Thomas regarding a data breach
- Notice must state that personal information was potentially compromised due to the ransomware incident occurring between July 25, 2025 and Aug. 12, 2025
- Submit a claim by the deadline (Sept. 28, 2026)
- For higher-tier losses (up to $4,500): show unreimbursed fraud/identity theft losses after the incident, not covered by other claims, and that available credit monitoring/identity theft insurance was exhausted
Featured Investigations
Important Notice About Filing Claims
Submitting false information in a settlement claim is considered perjury and will result in your claim being rejected. Fraudulent claims harm legitimate class members and may result in legal consequences.
If you are unsure about your eligibility for this settlement, please visit the official settlement administrator’s website using the link provided above. Review the eligibility criteria carefully before submitting a claim.
Class Action Champion is an independent information resource and is not affiliated with any settlement administrator, law firm, or court. We provide settlement information as a service to help connect eligible class members with legitimate settlements.
