A settlement notice reaching bank and credit-union customers this summer asks recipients to make a decision: accept a quick, modest cash payment, or take the time to document actual losses in exchange for a potentially larger sum. The notices stem from a $5.5 million settlement over a data breach at Doxim, a financial-software company most consumers have never heard of but whose systems carry sensitive account information for the institutions they bank with. Claims are due October 13, 2026.
What the Doxim breach exposed
Doxim is a Michigan-based technology provider that supplies statement, communication, and processing software to banks and credit unions. Because of that role, the company held records belonging to the customers of its client institutions rather than its own retail customers. A breach in late 2023 exposed a combination of names, mailing addresses, financial account numbers, and Social Security numbers, the kind of data that fuels identity theft and account fraud long after the original incident.
The lawsuit that followed alleged Doxim failed to adequately protect that information, and the company agreed to a $5.5 million fund to resolve the claims. The official Doxim data-security settlement site spells out who is covered, people whose information was compromised and who received a notice, and lays out the two ways an affected person can file.
The indirect nature of the exposure is part of what makes the settlement notable. A single vendor breach can ripple across dozens of unrelated banks and credit unions at once, which is why a person may receive a Doxim notice without ever having heard of the company or knowingly done business with it. The compromised mix of a name, address, account number, and Social Security number is especially valuable to fraudsters, because that combination is enough to open new credit lines or take over existing accounts, and it does not expire the way a stolen card number does once the card is replaced.
Free retirement updates: Every year, billions in settlements and unclaimed money go unclaimed. Our free Retirement Shield newsletter sends the real ones — with deadlines — a couple times a week. Get the free newsletter.
Choosing between $100 and up to $5,000
The settlement offers two paths, and they suit very different situations. The first is an estimated $100 cash payment that requires no proof of harm; a class member confirms eligibility and selects it. The second reimburses documented out-of-pocket losses traceable to the breach, such as fraudulent charges, fees, or the cost of resolving identity theft, up to a ceiling of $5,000, but only with supporting records.
Reporting on the deal by ClassAction.org notes the breach dates to late 2023, meaning claimants pursuing the larger amount may have to reconstruct expenses from more than two years ago to support the claim. For many, the flat payment will be the practical choice; for those who suffered concrete, well-documented losses, the reimbursement route can be worth considerably more.
The two options require a single choice at the moment of filing. A claimant who takes the estimated $100 receives it without further scrutiny, while one who pursues the documented route trades that speed and certainty for the chance at a larger recovery and must be ready for the administrator to review the proof. Statements showing fraudulent charges, records of fees paid to resolve identity theft, and correspondence with creditors are the kind of evidence that substantiates a loss traceable to the breach; a documented claim submitted without them is likely to be reduced to the flat amount.
The October 13 claim deadline and the monitoring option
Every valid claimant is also entitled to one year of free credit monitoring, a benefit separate from the cash payment and worth electing regardless of which payment path a person selects. Federal resources such as the FTC’s IdentityTheft.gov outline the steps breach victims can take on their own, including placing credit freezes, but the settlement’s bundled monitoring adds a layer at no cost.
The claim deadline is October 13, 2026, and it is open now. A final approval hearing is scheduled for October 28, 2026, at which the court will decide whether to authorize payments, which are typically distributed only after that approval and after any appeals are resolved. Filing by the October cutoff preserves a claimant’s right to a payment even though the money itself arrives later.
Class members who want no part of the deal have their own choices to make. Objecting to the terms, or opting out to preserve the right to sue Doxim separately, must be done before the cutoffs the administrator sets, and opting out forfeits both the cash payment and the free monitoring. For most people whose data was exposed but who have seen no concrete misuse, the flat payment paired with a year of monitoring is the practical result the settlement was designed to deliver.
For customers who never chose Doxim as a vendor and may not recognize the name on a notice, the settlement underscores how exposure often happens a step removed from the institutions people actually deal with. The settlement administrator’s site remains the definitive place to confirm eligibility, weigh the $100 flat payment against a documented claim, and track the two October dates that govern both.
This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.
More Financial Reading