Subscribe To Our Newsletter
Ernst & Young LLP and Bank of America have agreed to a $2.5 million class action settlement to resolve claims from a May 2023 MOVEit file transfer data breach affecting nearly 200,000 individuals.
Ernst & Young LLP and Bank of America have agreed to a $2.5 million class action settlement to resolve claims stemming from a May 2023 data breach involving MOVEit file transfer software. The security incident compromised sensitive personal and financial records belonging to nearly 200,000 Bank of America customers. Affected individuals may now claim up to $10,000 in cash benefits or two years of free credit monitoring.
The settlement resolves claims from a high-profile cybersecurity incident that unfolded between May 27 and May 31, 2023. Ernst & Young, an accounting and consulting firm, used the popular third-party software MOVEit Transfer to store and share sensitive financial files on behalf of Bank of America.
Cybercriminals exploited a severe security flaw in the MOVEit software to breach corporate servers and access stored files. While the attack targeted the file-transfer system directly, plaintiffs in the class action lawsuit alleged that both Ernst & Young and Bank of America failed to take adequate precautions to safeguard customer information, leaving highly sensitive personal files exposed to unauthorized third parties.
When major corporations handle your private records, a breach can put almost every aspect of your personal identity at risk. According to federal court records filed in Massachusetts, the exposed files contained extensive personal data belonging to Bank of America clients.
The compromised information may include:
Full names and current home addresses
Dates of birth and Social Security numbers
Financial account details, including debit and credit card numbers
Account usernames, passwords, and security PINs
Unique government-issued ID numbers and personal health information
When sensitive details like Social Security numbers and bank account credentials leak online, victims face heightened risks of identity theft, fraudulent bank withdrawals, and phishing scams for years following the event.
The $2.5 million settlement agreement received preliminary approval from a federal court on April 29, 2026. Designed to help everyday people recover losses and protect their identity, the settlement structure offers several distinct cash options and service choices for class members.
If you do not have documented financial losses or simply want a straightforward cash recovery, you can elect to receive a flat $100 cash payout. You do not need to provide receipts, bank statements, or proof of out-of-pocket expenses to select this option.
Class members who spent money responding to the breach can claim reimbursement up to $2,500 for documented ordinary out-of-pocket expenses incurred between May 31, 2023, and October 8, 2026. Covered expenses include bank fees, credit report purchases, credit monitoring subscriptions, postage, gasoline, and communication charges. You can also claim up to four hours of lost time spent addressing the breach, compensated at $25 per hour.
If you experienced direct, uncompensated financial fraud or identity theft linked to the breach, you can submit a claim for up to $10,000 in extraordinary losses. This category covers proven monetary harm, attorney fees, accountant expenses, and professional credit repair services.
Note: Cash payouts may be adjusted higher or lower on a pro rata basis depending on the total number of valid claims submitted.
In addition to or in place of monetary compensation, every eligible individual can sign up to receive two years of free credit monitoring and identity theft protection services.
This service includes active dark web monitoring, real-time credit bureau alerts, and identity theft insurance coverage. Enrolling in credit protection provides an essential safety net, helping you detect suspicious activity on your financial accounts before significant damage occurs.
When you share private details with a bank or professional firm, companies have a legal duty under state consumer protection laws and common law frameworks to maintain reasonable cybersecurity standards.
Data breach class actions allow affected consumers to group together and hold powerful companies accountable when safeguard protocols fall short. Under established privacy law principles, companies that store personal data must implement robust technical defenses, conduct routine security audits, and promptly notify impacted individuals when a breach occurs.
While Ernst & Young and Bank of America agreed to this settlement without admitting fault, the $2.5 million fund provides tangible financial relief to victims without requiring a lengthy trial. However, litigation remains ongoing against Progress Software Corporation, the developer behind the MOVEit software.
Court documents estimate that approximately 198,667 individuals are covered under the scope of this settlement. You may be eligible to submit a claim if:
You are a living resident of the United States.
Your personal or financial information was contained in the files transferred between Ernst & Young and Bank of America that were impacted by the May 2023 MOVEit data breach.
Class members typically receive a formal notice in the mail or via email containing a unique Claimant ID and PIN. You can use these credentials to complete your claim quickly online through the court-approved settlement portal at MOVEitSettlementEYBOA.com.
To secure your cash payout or credit monitoring services, you must act before the upcoming court deadlines.
Claim Submission Deadline: All online claim forms must be submitted—or paper claim forms postmarked—by October 8, 2026.
Final Approval Hearing: The court will hold a final approval hearing on October 15, 2026, to decide whether to give the deal final approval.
Payments and credit monitoring activation codes will be distributed after the court grants final approval and any potential legal appeals are resolved.
New cases and investigations, settlement deadlines, and news straight to your inbox.