Skip to main content

The Money Overview

A Doxim data-breach settlement pays credit-union members up to $5,000, or $100 with no proof, by October 13

A $5.5 million settlement is now open to people notified that their personal information was exposed in a December 2023 data breach at Doxim, Inc., a company that prepares account statements and tax forms for credit unions, including Credit Union ONE. Members who can document identity theft or fraud tied to the breach can claim up to $5,000; anyone who received a breach notice can instead take an estimated $100 with no proof required at all. Both options come with a year of free credit monitoring, but every version requires filing a claim by October 13, since nothing is paid automatically.

A Third-Party Vendor’s Breach Reached Multiple Credit Unions

The settlement resolves In re Doxim, Inc. Data Security Incident Litigation, filed in the U.S. District Court for the Eastern District of Michigan. Doxim is a financial-services vendor that prepares account statements and income tax forms for credit union clients, rather than a bank or credit union itself, which is why members of more than one institution are covered by a single settlement. The lawsuit alleged that Doxim failed to implement reasonable cybersecurity measures, leading to a data breach on or about December 30, 2023.

Court filings identify Beacon and Credit Union ONE among the credit union clients whose members received breach notices from Doxim or from the credit union itself. The private information exposed in the breach reportedly included names, addresses, financial account numbers and Social Security numbers, the combination most useful to someone attempting identity theft or account takeover. Doxim has not admitted wrongdoing, and the settlement resolves the case without a court ruling on the merits.

Doxim’s role illustrates how a single vendor breach can ripple across an entire industry. Because credit unions increasingly outsource statement printing, tax-document preparation and other back-office functions to shared vendors, a security failure at one processor can expose the same categories of financial data across accountholders at credit unions that otherwise have no connection to each other. That is why the settlement class is defined by whether a person received an official notice from Doxim or from an affected credit union, not by which specific institution they bank with.


Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.

Two Payment Paths, One Deadline

Members who can show a documented, out-of-pocket loss traceable to the breach, such as unauthorized charges or the cost of resolving identity theft, can file for up to $5,000 in reimbursement with supporting proof like receipts or bank statements. Members who prefer not to gather documentation, or who don’t have a quantifiable loss to point to, can instead claim an estimated $100 cash payment with no proof required; that amount may rise or fall depending on how many people ultimately file. Every class member, regardless of which payment option they choose, can also claim one year of credit monitoring that includes identity theft insurance.

Only one payment path applies per claim, and filing is the only way to receive anything at all — this is not the kind of settlement that mails a check without action. The deadline to submit a claim form, whether online or postmarked by mail, is October 13, 2026. Members who wanted to exclude themselves from the settlement or object to its terms had an earlier deadline of September 28, 2026, to do so.

The claims process runs on penalty-of-perjury rules similar to other class-action settlements: someone who submits false information to inflate a documented-loss claim risks having that claim rejected. That is one reason the no-proof $100 option exists in the first place — it gives members with real but hard-to-document harm, or those who simply don’t want to gather old statements, a straightforward way to receive something without reconstructing a paper trail nearly three years after the breach occurred.

A Final Approval Hearing Comes After the Claim Window Closes

A federal judge granted preliminary approval to the $5.5 million settlement on June 5, 2026, and the court-approved settlement website went live the following month. A final approval hearing is scheduled for October 28, 2026, before Judge Terrence G. Berg — 15 days after the claim-filing deadline, meaning members have to decide whether to file before the settlement has cleared its last court hurdle. Compensation is set to begin moving to class members only after final approval is granted and any appeal period has passed, a sequence that can add months even after a judge signs off.

Class members can find the unique ID and PIN needed for the online claim form on the notice Doxim or their credit union originally mailed them; those who no longer have that notice can request a paper claim form directly from the settlement administrator. As with any breach settlement of this size, only the official website and its listed contact information are authorized to process a claim, and legitimate correspondence will never demand a fee or a full Social Security number to “verify” eligibility beyond what the claim form itself already asks for. Anyone who suspects their exposed information has already been misused, separate from the settlement claim itself, can also file a report and get a free personalized recovery plan through the FTC’s IdentityTheft.gov, regardless of whether a settlement claim is filed.

This article was produced with the assistance of AI and reviewed by The Money Overview editorial team before publication.

More Financial Reading


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.