Quick Answer: Fidelity Investments Data Breach Lawsuit
The Fidelity Investments data breach lawsuit has settled for $2.5 million in a federal class action (In re: Fidelity Investments Data Breach Litigation, Case No. 1:24-CV-12601-LTS, D. Mass.), plus a separate $1.25 million penalty from the Massachusetts Attorney General's office — a combined $3.75 million exposure on a single incident. The breach, which ran August 17–19, 2024, exposed the personal information of approximately 155,000 Fidelity customers and related individuals. The claim deadline was July 27, 2026 (now closed), and the Final Approval Hearing was held on July 9, 2026. Payments are expected to begin in late 2026 or early 2027.
What Happened in the Fidelity Breach
Between August 17 and August 19, 2024, a third party gained unauthorized access to FMR LLC d/b/a Fidelity Investments' computer network through a vulnerability in a third-party vendor system. The intrusion exposed sensitive customer information including names, Social Security numbers, financial account and routing numbers, and in some cases driver's license information.
Plaintiffs alleged that Fidelity failed to adequately vet and monitor the third-party vendor's security controls — a recurring pattern in major financial-sector breaches during 2024 and 2025. The original complaint was filed in October 2024. Fidelity initially reported that approximately 77,000 accounts were affected, but subsequent investigations put the figure closer to 155,000 individuals, including both Fidelity customers and people whose data was held by Fidelity on behalf of workplace retirement plans and other institutional relationships.
Settlement at a Glance
| Detail | Information |
|---|---|
| Class action settlement | $2.5 million |
| Massachusetts AG penalty | $1.25 million |
| Combined exposure | $3.75 million |
| Case | In re: Fidelity Investments Data Breach Litigation, Case No. 1:24-CV-12601-LTS |
| Court | US District Court, District of Massachusetts |
| Breach date | August 17–19, 2024 |
| People affected | ~155,000 (revised upward from initial 77,000) |
| Claim deadline | July 27, 2026 |
| Final approval hearing | July 9, 2026 |
| Status | Final approval expected; payments processing |
How Much You Receive
The settlement provides two benefit tiers plus monitoring:
- Tier 1 — approximately $100 cash: No documentation required. California residents receive an additional $50 ($150 total) under California-specific consumer protection statutes.
- Tier 2 — up to $5,000: Reimbursement for documented identity theft losses, including credit monitoring fees, professional fees, lost wages, and other documented out-of-pocket expenses tied to the breach.
- Credit monitoring (all class members): Two years of free credit monitoring with $1 million in fraud insurance through the settlement's identity protection partner.
Why the Settlement Is Modest for 155,000 People
At $2.5 million for 155,000 class members, the per-person average (after attorneys' fees and service awards) works out to a small flat payment. The $100 flat-tier amount was set assuming a modest claim rate; if fewer than 30% of class members file, payments could exceed $100 per claimant. If more than 50% file, payments are subject to pro rata reduction. The two-year credit monitoring with $1 million fraud insurance is the more meaningful benefit for most class members — equivalent to $240–480 of retail identity protection services.
Payment Timeline
The Final Approval Hearing was held on July 9, 2026. The settlement administrator is now processing claims and will distribute payments once final approval is granted and any appeals are resolved. Based on typical timelines, expect payments to begin in late 2026 or early 2027 — approximately four to ten months after the July 27, 2026 claim deadline.
What to Do If You Were Affected
If you received a Fidelity breach notice but missed the claim deadline, you remain a class member unless you opted out by the published deadline. You do not need to take any further action to receive the credit monitoring benefit — activation instructions were included in the original notice.
Whether or not you filed a claim, take these protective steps:
- Activate the credit monitoring benefit if you have not already.
- Place a fraud alert or credit freeze with all three credit bureaus.
- Enable two-factor authentication on your Fidelity account and every financial account.
- Review your financial statements weekly for unauthorized transactions, especially ACH debits and wire transfers.
- Get an IRS Identity Protection PIN to prevent tax-refund fraud.
Lessons from the Fidelity Breach
The Fidelity breach is the third-largest financial sector class action of 2025–2026, after the MOVEit-related cases and the Capital One settlement. It illustrates the regulatory trend of treating third-party vendor risk as a direct compliance issue: even when the vulnerability is in a vendor's system, the financial institution bears the legal and reputational consequences. The Massachusetts $1.25 million penalty specifically referenced vendor management failures — a signal that state regulators are increasingly unwilling to accept outsourcing as a defense, even when the actual breach sits entirely inside the vendor's own perimeter and IT staff.
For broader guidance on what to do after any data breach — including credit freezes, fraud alerts, and whether to consider data breach insurance — see our complete guide to data breach insurance and consumer response.






