Lands’ End has agreed to settle claims over a December 2024 data breach that exposed a wider set of identity documents than most retail hacks — Social Security numbers, driver’s license numbers, passport information and, for some customers, medical records. Shoppers whose data was compromised can file for an estimated $60 with no documentation, or up to $5,000 for documented losses, but the claim window closes October 22, and a separate, earlier deadline governs anyone who wants to opt out instead of accepting the settlement.
What the December 2024 breach exposed
The clothing retailer’s computer systems were compromised in December 2024, and the intrusion reportedly reached files containing Social Security numbers, driver’s license numbers, passport information and, in limited circumstances, medical data — a broader mix than the payment-card numbers that dominate most retail breach headlines. Consumers who received notice from Lands’ End argued the company could have prevented the incident with reasonable cybersecurity measures, and the retailer agreed to settle the resulting class action rather than continue litigating in the Circuit Court for Iowa County, Wisconsin.
Lands’ End has not admitted wrongdoing. The case, Jones, et al. v. Lands’ End Inc., benefits all U.S. residents whose private information was compromised in the incident, a class defined by whether a person’s data was exposed rather than by whether they made a purchase during any specific window — meaning even an infrequent, years-old customer could qualify if their file was affected. Someone who ordered a single catalog item years before the breach and never shopped again could still be part of the class, since eligibility tracks what data the company held, not recent purchase activity.
The presence of passport and driver’s license data in the exposed set raises the stakes above a typical card-number breach, since those documents support new-account fraud and identity verification in ways a compromised card number alone does not.
Lands’ End is a recognized national catalog and apparel brand, which sets this breach apart from the settlement involving True World Holdings, a wholesale distributor few consumers could name. A well-known retailer’s breach notice tends to draw more attention and be trusted more readily, precisely because the sender is familiar — but that familiarity says nothing about how sensitive the underlying data was, and in this case the exposed categories were broader than the payment-card numbers most shoppers assume a clothing retailer’s systems hold.
Free retirement updates: Enrollment and claim windows come and go, and missing one can cost you real money. The free Retirement Shield newsletter keeps you ahead of the deadlines that matter. Sign up free.
The $60 flat payment versus the $5,000 documented-loss option
Class members who did not experience documented losses can take a one-time estimated cash payment of $60, no proof required. Those who can show out-of-pocket costs tied to the breach — identity theft and fraud losses, credit-related fees, ID-replacement costs and similar expenses — can instead claim up to $5,000, provided they submit receipts, bank statements or other supporting documentation with the claim.
Every class member, regardless of which cash option they choose, also qualifies for two years of free credit monitoring through CyEx Financial Shield Complete, which includes $1 million in financial fraud insurance along with fraud, identity-theft and high-risk-transaction monitoring. Given the presence of passport and driver’s license data in this breach, that monitoring coverage carries more practical weight than the $60 baseline payment for most affected shoppers — the FTC’s own guidance on credit freezes and fraud alerts recommends pairing any offered monitoring with a credit freeze specifically when government ID numbers, not just card numbers, are exposed.
Claims can be filed online through the official settlement claim portal or by mailing a paper form, with any required supporting documentation, postmarked by the deadline. Background on the case, including the exact eligible-data categories, is detailed on the settlement tracker’s summary.
Two deadlines, not one, and why the gap matters
Unlike a settlement with a single cutoff date, this one runs two separate clocks. Anyone who wants to exclude themselves from the settlement — preserving the right to sue Lands’ End independently — had to submit that request by October 7, 2026. Missing that date does not eliminate a person’s ability to collect a payment; it simply means they remain bound by the settlement’s terms and give up the separate right to sue.
The claim-filing deadline for people staying in the class runs two weeks longer, to October 22, 2026, both for online submissions and for mailed paper forms postmarked by that date. The final approval hearing is scheduled for November 6, 2026, at the Circuit Court for Iowa County, Wisconsin, after which payments would begin processing for everyone who filed a timely, valid claim.
Because a driver’s license and Social Security number together can support a fraudulent state-issued ID application in someone else’s name, security researchers generally recommend a full three-bureau credit freeze rather than a fraud alert alone whenever a government-issued document is part of what leaked, in addition to whatever monitoring service a settlement provides. A freeze is free to place and free to lift when needed, and it blocks new-account approvals outright rather than merely flagging suspicious activity after the fact.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading