Skip to main content

The Money Overview

Doxim data-breach victims can take a no-proof $100 payment, or up to $5,000 for documented losses, before October 13

People whose personal information was exposed in the 2023 Doxim data breach have until October 13 to claim a piece of a $5.5 million settlement, and the easiest option pays about $100 with no paperwork at all. Those who can document fraud or identity theft traced to the breach may instead claim up to $5,000. The money comes from a financial-software company whose files, including names, account numbers, and Social Security numbers, were accessed by an unauthorized party, and the window to file is open now but closes in the fall. For anyone who received a notice, the decision is worth a few minutes before the deadline passes.

Who qualifies and what the breach exposed

Doxim is a behind-the-scenes vendor that provides software to credit unions and banks, which is why many of the people affected had never heard its name until a settlement notice arrived. The company detected suspicious activity in late December 2023 in the part of its network supporting credit-union services and later determined that files had been removed. Those files included names, mailing addresses, account numbers, and in some cases Social Security numbers, the exact combination that fuels identity theft.

The settlement class covers living U.S. residents who were identified by Doxim, or by the credit unions and banks it serves, and sent notice that their information was involved. Eligibility is tied to receiving that notice rather than to guessing at exposure, so the mailing or email itself is the key document. The official settlement site lets class members confirm eligibility and file, and a claims phone line is available for those who prefer to submit by mail.

What makes bank and credit-union breaches especially serious is the sensitivity of the data. A leaked email address is a nuisance; a leaked Social Security number paired with a financial account number is durable, because it can be used for years to open credit or attempt fraud long after the incident itself fades from the news. Unlike a compromised password, a Social Security number cannot simply be changed, which is why a single exposure can shadow a household indefinitely. That durability is the reason a settlement like this offers not just cash but credit monitoring as an alternative, a benefit aimed at the long tail of risk rather than the moment of the breach.


Free retirement updates: Enrollment and claim windows come and go, and missing one can cost you real money. The free Retirement Shield newsletter keeps you ahead of the deadlines that matter. Sign up free.

The two cash options and how to choose

The settlement offers a clear fork. A class member can file for an estimated $100 flat payment with no documentation required, a straightforward choice for someone who has seen no direct harm but wants compensation for the exposure. Alternatively, a member who suffered out-of-pocket losses, such as fraudulent charges, fees, or costs from resolving identity theft, can claim reimbursement of up to $5,000, provided the losses are documented and can be traced to the breach.

The larger claim demands more effort and more evidence. Receipts, bank statements, and records tying a specific loss to the breach are what separate a $5,000 claim from a rejected one, and vague or unsupported figures will not clear that bar. For most people who noticed nothing unusual, the $100 no-proof payment is the realistic option; the higher tier exists for the smaller group who can show the breach actually cost them money. A third choice, roughly a year of credit monitoring, is available for those who value ongoing watchfulness over immediate cash.

One caveat applies to the flat payment. Because the fund is a fixed $5.5 million, the final per-person amount can rise or fall depending on how many valid claims are filed, so the estimated $100 is a target rather than a guarantee. That is standard for settlements of this structure, and it is a reason to file promptly rather than assume the number is locked.

Why the timing matters

The October 13 deadline is firm, and missing it forfeits the claim entirely. A settlement notice is not a payment; it is an invitation that expires, and class members who set it aside lose their share to the people who did file. Coverage of the agreement, including reporting from class-action trackers, has emphasized that the date applies to online submissions and mailed forms alike.

Payment, however, will not be immediate even for those who file on time. A final approval hearing is scheduled for late October, and money is distributed only after the court grants final approval and any appeals are resolved, a process that can stretch months beyond the claim deadline. Filing early secures the claim; patience is required for the payout.

Regardless of the cash decision, the exposure itself warrants a response. Anyone whose Social Security number was in the breached files can take free protective steps, including placing a credit freeze and reviewing accounts for unfamiliar activity, and the federal government’s identity-theft recovery site walks through the process. The $100 is a small settlement of a real risk, and the deadline is the only part of it fully within a class member’s control.

This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.

More Financial Reading