What Happened in the Fidelity Data Breach
Between August 17 and August 19, 2024, a third party gained unauthorized access to Fidelity Investments’ computer network, according to court documents. A forensic investigation later confirmed that the breach compromised sensitive personal data, including names, Social Security numbers, financial account information, and driver’s license details for tens of thousands of customers. Fidelity did not notify affected customers until early October 2024.
The Scope of the Breach
The compromised data files reportedly contained personal information belonging to 77,099 people. A separate group of approximately 86,000 individuals or joint account holders whose financial account and routing numbers were exposed were not formally notified, since they weren’t subject to certain state-law notification requirements, though they may still be eligible for settlement benefits.
The Lawsuit and Settlement
The case, formally titled In re: Fidelity Investments Data Breach Litigation, was filed in the U.S. District Court for the District of Massachusetts against FMR LLC and Fidelity Brokerage Services LLC, both doing business as Fidelity Investments. The lawsuit alleged Fidelity failed to implement reasonable cybersecurity measures that could have prevented the breach. Fidelity denied any wrongdoing but agreed to a $2.5 million settlement to resolve the litigation, with final court approval heard on July 9, 2026.
Who Is Eligible and What They Can Claim
More than 160,000 people may be eligible for the settlement, including both those formally notified of the breach and others whose account and routing numbers were allegedly exposed. Class members without documented losses can receive an estimated $100 cash payment (plus an additional $50 for California residents), while those with documented monetary losses tied to the breach can claim up to $5,000. All eligible members also qualify for two years of identity theft protection and credit monitoring.
How to File a Claim
Eligible individuals who received a breach notification, or who believe their financial account and routing number were compromised, can file a claim through the official settlement website or by contacting the settlement administrator directly. Claims needed to be submitted by the stated deadline, and unless a class member formally opted out, they remain part of the settlement automatically.
Final Thoughts
The Fidelity Investments settlement is a reminder that even large, well-resourced financial institutions remain vulnerable to cybersecurity incidents, and that affected customers often have a path to compensation through class action settlements, even without needing to prove extensive documented losses.
