Skip to main content

The Money Overview

Bank of America customers hit by the MOVEit data breach can claim up to $100 before October 8

Roughly 200,000 Bank of America customers whose personal information was exposed in the 2023 MOVEit hack now have a way to collect a flat cash payment with no receipts required, but the claim window shuts on October 8. A $2.5 million settlement with the accounting firm Ernst & Young and Bank of America gives affected people two choices: a no-proof payment of about $100, or reimbursement of up to $2,500 in documented losses. For older account holders whose Social Security numbers were caught in the breach, the flat option is the fastest way to recover something from a data failure they had no part in.

How Ernst & Young ended up holding Bank of America’s data

The breach traces to a stretch of late May 2023, when cybercriminals exploited a vulnerability in MOVEit Transfer, a file-moving tool used across corporate America to shuttle sensitive records. Ernst & Young used the software in its ordinary business and had received customer data from Bank of America, so when attackers broke in, the personal information of some of the bank’s customers went with it. Court filings estimate that 198,667 people are covered by the settlement class, all of them living individuals in the United States whose information sat in the files EY exchanged.

The lawsuit accused both companies of negligent data-security practices for failing to protect that information. Both deny wrongdoing and agreed to the payout to close the case rather than fight it. The settlement does not end the broader litigation: claims against Progress Software, the company that makes MOVEit, remain live and are being pursued separately, so this deal resolves only the piece tied to Ernst & Young and Bank of America.


Free retirement updates: Enrollment and claim windows come and go, and missing one can cost you real money. The free Retirement Shield newsletter keeps you ahead of the deadlines that matter. Sign up free.

The $100 flat payment versus documented losses

The settlement offers two paths, and a class member picks one. The simplest is an alternative cash payment of $100 that requires no documentation at all, an option built for people who cannot tie a specific dollar loss to the breach but were still exposed. The official settlement terms note that the $100 figure is subject to pro rata adjustment, meaning it can shrink if claims are heavy or edge higher if the fund is underused, so the final check may land near but not exactly at that number.

The second path reimburses documented losses, up to $2,500 for ordinary costs and up to $10,000 for extraordinary losses such as proven identity theft. Ordinary losses can include money spent on credit reports, credit monitoring, identity-theft insurance, bank fees, postage and related out-of-pocket costs incurred because of the breach. That route pays more but demands paperwork, and for most people the exposure never produced a traceable, receipted loss, which is why the flat $100 is the realistic option for the majority of the class.

Two deadlines, and only one gets attention

Every class member can also claim two years of identity-theft protection services on top of whichever cash option they select. The claim form must be submitted online or postmarked by October 8, 2026, and a separate deadline of September 8 governs anyone who wants to opt out of the settlement or object to its terms. The opt-out date matters because staying in and doing nothing means being bound by the settlement while collecting no money, the worst of both outcomes.

There is also a mailing wrinkle worth noting. The administrator warns that recent changes to the Postal Service’s postmark system can stamp a claim form days after it is actually dropped off, which could push a last-minute mailed claim past the deadline. Filing online through the official portal sidesteps that risk entirely, and a federal judge is set to weigh final approval of the settlement at a hearing on October 15, 2026.

Why breach settlements reward the people who move first

Data-breach settlements are structured so that the fund is fixed while the payout floats, which means early, valid claims are protected and the pro rata math only bites when the pool of claimants is large. A person who exposed information in the MOVEit incident and files the flat claim locks in a stake; a person who assumes the payment is too small to bother with simply hands their share to everyone else. The recovery is modest, but it costs nothing beyond a few minutes and no supporting documents.

The larger lesson sits underneath the deadline. Bank of America’s customers did nothing wrong and had no control over a vendor’s file-transfer software, yet their Social Security numbers moved through a system that failed. The settlement cannot undo that exposure, and the identity-theft protection it offers is the more durable benefit, because a stolen Social Security number can surface in fraud attempts years after the breach that produced it.

This article was researched and drafted with the assistance of AI and reviewed by The Money Overview editorial team.

More Financial Reading