More than six million people whose personal data was exposed in a late-2023 breach at Infosys McCamish Systems now face a deadline-driven decision: whether to file a claim against a $17.5 million settlement fund tied to the incident. Bank of America customers make up a significant share of those affected, and the advertised per-person cap of up to $6,000 sets expectations that the math behind the fund may not fully support.
Why six million affected people could overwhelm a $17.5 million fund
The breach ran from October 29 through November 2, 2023, and compromised data held by Infosys McCamish Systems, LLC, a third-party vendor that processed information on behalf of Bank of America. According to Maine regulators, 6,078,263 persons were affected. That figure alone raises a straightforward tension: if even a fraction of those individuals file claims approaching the advertised $6,000 maximum, the total requested amount would dwarf the settlement pool.
A simple calculation illustrates the gap. If just 3,000 claimants sought the full $6,000, the fund would be nearly exhausted. If tens of thousands file, each approved claim would shrink through pro-rata reduction. The primary government records that establish the scale of the breach do not contain details about the settlement’s distribution formula, per-person caps, or eligibility tiers. Those specifics will surface in court dockets as the claims process advances, and the ratio of filed claims to available dollars will determine what any individual actually receives.
Settlement funds in large data-breach cases often operate on a tiered system: claimants with documented out-of-pocket losses may qualify for higher payments, while others receive a flat amount for time spent dealing with the fallout. When the number of valid claims exceeds the money available, courts typically authorize proportional reductions so the fund is shared among all eligible participants. That structure can turn headline figures like “up to $6,000” into something far smaller once the total demand is known.
What Maine filings and SEC records confirm about the breach
Two sets of government records anchor the verified facts. The Maine Attorney General’s breach notification database lists the incident under Infosys McCamish Systems, LLC, recording the four-day breach window, the total affected population of 6,078,263, and the offer of 24 months of identity theft protection through Kroll. A separate entry in the same database associates the incident with Bank of America as the affected entity and links to the consumer notice letter sent to impacted customers.
Bank of America warned customers about the breach after the vendor hack, a fact corroborated by both the Maine filing and a related SEC document. The bank itself was not breached directly. Instead, the compromise occurred at Infosys McCamish, which handled sensitive data on the bank’s behalf. That distinction matters because it shifts questions of security responsibility toward the vendor relationship and the contractual safeguards that were or were not in place when attackers accessed the system.
The 24-month Kroll enrollment was offered as an immediate remedy, but it functions as monitoring rather than compensation. It alerts enrollees to suspicious activity tied to their personal information without reimbursing losses that may have already occurred. For customers who experienced identity theft or fraud between late 2023 and now, the settlement represents a potential avenue to recover documented costs, but only within the constraints of the finite fund and whatever proof requirements the court ultimately approves.
What the Bank of America notice tells affected customers
The consumer notification sent to Bank of America account holders lays out the bank’s explanation of the incident, the categories of information that may have been exposed, and the free monitoring being provided. The notice, which is accessible through Maine’s public breach portal, clarifies that Infosys McCamish was performing services for the bank when its systems were compromised. The linked copy of the letter also instructs recipients on how to enroll in Kroll’s identity protection and how to watch for unauthorized activity on their accounts and credit reports.
Those instructions form the baseline of what affected individuals can do even before deciding whether to participate in the settlement. Monitoring credit reports, placing fraud alerts or credit freezes, and promptly reporting suspicious transactions remain standard defensive steps in the wake of any large-scale data exposure. The notice underscores that no customer action could have prevented the underlying vendor breach, but consumers are left managing the downstream risks.
How to think about filing a claim
For people whose information was caught up in the Infosys McCamish breach, the decision to file a claim will hinge on three practical questions: whether they fall within the settlement’s class definition, whether they can document any financial harm or time spent addressing the breach, and how much effort they are willing to invest for a potentially modest payout. With millions eligible and only $17.5 million available, individual awards are likely to be far lower than the theoretical maximum for most claimants.
Still, submitting a claim can serve as a way to recoup at least some costs associated with monitoring, account changes, or resolving fraudulent activity. It also adds another data point to the overall tally of affected consumers, which in turn shapes how courts and companies evaluate the true impact of vendor-side security failures. In that sense, even small individual recoveries contribute to a broader accountability mechanism for large institutions that outsource the handling of sensitive personal data.