Skip to main content

The Money Overview

Anyone caught in the Doxim data breach has until October 13 to file for up to $100

People whose personal information was exposed in the 2023 Doxim data breach have a limited window to claim money, and the clock runs out on October 13, 2026. The $5.5 million settlement offers an estimated $100 to eligible class members who file with no proof of loss, or reimbursement of up to $5,000 for those who can document breach-related expenses, plus a year of free credit monitoring. Doxim is a behind-the-scenes vendor that prepares account statements and tax forms for banks and credit unions, so many of the people affected never dealt with the company directly and may not realize they are covered.

What the Doxim settlement pays

The agreement resolves a class-action lawsuit over a December 2023 data incident at Doxim, in which names and financial account information handled by the firm were reportedly exposed. Under the terms, a valid claim brings a flat cash payment estimated at around $100 without any receipts, an option designed for people who cannot point to a specific out-of-pocket cost but were still put at risk. Those who did lose money — to fraudulent charges, frozen accounts or the hours spent cleaning up after identity theft — can instead seek reimbursement of documented losses up to $5,000.

Both tracks also include a year of credit monitoring, a benefit that carries real value for older adults, who are disproportionately targeted once account details leak. According to a summary of the settlement, the total fund stands at $5.5 million, and the flat-payment amount could adjust up or down depending on how many people file — the same pro rata math that governs most breach settlements.

Because Doxim sits upstream of the institutions consumers actually bank with, eligibility does not depend on having heard of the company. What matters is whether a person’s information passed through Doxim’s systems, which the settlement administrator determines from the breach records and the notices already mailed to affected individuals.

Doxim’s customers are financial institutions across North America, and the incident reached the account data those institutions had entrusted to it. That is why a notice may arrive from a bank or credit union a person already does business with, or directly from the settlement administrator, even though the consumer never opened an account with Doxim itself. Receiving such a notice — by mail or email — is the clearest sign of eligibility, and it typically carries a unique claim number that lets a class member file in a few minutes without hunting for account records.


Free retirement updates: Social Security and Medicare change every year, and nobody sends you a memo. Our free Retirement Shield newsletter breaks down what changed and what to do. Get it free in your inbox.

The deadlines that actually matter

The headline date is October 13, 2026 — the last day to submit a claim, whether filed online by 11:59 p.m. Eastern time or mailed with a postmark by that same date. An earlier date, September 28, 2026, is the cutoff to instead exclude oneself from the settlement or to formally object to its terms, steps that only make sense for someone weighing a separate legal path. A federal judge in the U.S. District Court for the Eastern District of Michigan is set to consider final approval on October 28, 2026.

The official claim portal and the governing court documents are posted at the administrator’s site, doximdatasecuritysettlement.com, which is the authoritative place to file and to check for any change to the hearing date. As with most settlements, payments do not go out immediately; they follow final approval and the resolution of any appeals, so a filer may wait months after the October deadline before money arrives.

The practical takeaway is that the no-proof $100 option lowers the effort to almost nothing — a short form and an accurate mailing address. For anyone who received a breach notice, letting the deadline pass simply leaves that money on the table while keeping all of the underlying risk.

Turning a breach notice into lasting protection

A data breach settlement addresses the past, but the exposed information can circulate for years, which is why the free credit monitoring is more than a token. Beyond enrolling in it, security experts point to a stronger, no-cost step available to everyone: freezing a credit file at all three major bureaus, which blocks most attempts to open new accounts in someone else’s name and can be lifted temporarily when a legitimate application is needed.

Vigilance also has to extend to the settlement process itself, because criminals mimic real breach notices to harvest exactly the data the breach already put at risk. A message demanding a fee to file, or asking for a full Social Security number and online banking password to “verify” a claim, is fraud — legitimate administrators never operate that way. Anyone who suspects their identity has already been misused can build a recovery plan at the FTC’s identity theft site. The harder question the Doxim case leaves open is one no single claim resolves: once financial data has traveled through a vendor most consumers cannot even name, the exposure outlasts any one settlement check.

This article was researched and drafted with the assistance of AI and reviewed by The Money Overview editorial team.

More Financial Reading