Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Bank of America and Ernst & Young Agree to $2.5 Million Settlement Over May 2023 MOVEit Data Breach

Ernst & Young LLP and Bank of America have agreed to a $2.5 million class action settlement to resolve claims from a May 2023 MOVEit file transfer data breach affecting nearly 200,000 individuals.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

Ernst & Young LLP and Bank of America have agreed to a $2.5 million class action settlement to resolve claims stemming from a May 2023 data breach involving MOVEit file transfer software. The security incident compromised sensitive personal and financial records belonging to nearly 200,000 Bank of America customers. Affected individuals may now claim up to $10,000 in cash benefits or two years of free credit monitoring.

What Caused the Ernst & Young and Bank of America MOVEit Data Breach?

The settlement resolves claims from a high-profile cybersecurity incident that unfolded between May 27 and May 31, 2023. Ernst & Young, an accounting and consulting firm, used the popular third-party software MOVEit Transfer to store and share sensitive financial files on behalf of Bank of America.

Cybercriminals exploited a severe security flaw in the MOVEit software to breach corporate servers and access stored files. While the attack targeted the file-transfer system directly, plaintiffs in the class action lawsuit alleged that both Ernst & Young and Bank of America failed to take adequate precautions to safeguard customer information, leaving highly sensitive personal files exposed to unauthorized third parties.

What Personal Information Was Exposed in the May 2023 Security Incident?

When major corporations handle your private records, a breach can put almost every aspect of your personal identity at risk. According to federal court records filed in Massachusetts, the exposed files contained extensive personal data belonging to Bank of America clients.

The compromised information may include:

  • Full names and current home addresses

  • Dates of birth and Social Security numbers

  • Financial account details, including debit and credit card numbers

  • Account usernames, passwords, and security PINs

  • Unique government-issued ID numbers and personal health information

When sensitive details like Social Security numbers and bank account credentials leak online, victims face heightened risks of identity theft, fraudulent bank withdrawals, and phishing scams for years following the event.

How Much Money Can You Receive From the $2.5 Million Settlement Fund?

The $2.5 million settlement agreement received preliminary approval from a federal court on April 29, 2026. Designed to help everyday people recover losses and protect their identity, the settlement structure offers several distinct cash options and service choices for class members.

Option 1: Direct $100 Cash Payment (No Receipts Required)

If you do not have documented financial losses or simply want a straightforward cash recovery, you can elect to receive a flat $100 cash payout. You do not need to provide receipts, bank statements, or proof of out-of-pocket expenses to select this option.

Option 2: Up to $2,500 for Documented Ordinary Losses

Class members who spent money responding to the breach can claim reimbursement up to $2,500 for documented ordinary out-of-pocket expenses incurred between May 31, 2023, and October 8, 2026. Covered expenses include bank fees, credit report purchases, credit monitoring subscriptions, postage, gasoline, and communication charges. You can also claim up to four hours of lost time spent addressing the breach, compensated at $25 per hour.

Option 3: Up to $10,000 for Extraordinary Losses

If you experienced direct, uncompensated financial fraud or identity theft linked to the breach, you can submit a claim for up to $10,000 in extraordinary losses. This category covers proven monetary harm, attorney fees, accountant expenses, and professional credit repair services.

Note: Cash payouts may be adjusted higher or lower on a pro rata basis depending on the total number of valid claims submitted.

Free Credit Monitoring and Identity Theft Protection Services Available

In addition to or in place of monetary compensation, every eligible individual can sign up to receive two years of free credit monitoring and identity theft protection services.

This service includes active dark web monitoring, real-time credit bureau alerts, and identity theft insurance coverage. Enrolling in credit protection provides an essential safety net, helping you detect suspicious activity on your financial accounts before significant damage occurs.

Legal Framework Behind Data Privacy and Corporate Accountability

When you share private details with a bank or professional firm, companies have a legal duty under state consumer protection laws and common law frameworks to maintain reasonable cybersecurity standards.

Data breach class actions allow affected consumers to group together and hold powerful companies accountable when safeguard protocols fall short. Under established privacy law principles, companies that store personal data must implement robust technical defenses, conduct routine security audits, and promptly notify impacted individuals when a breach occurs.

While Ernst & Young and Bank of America agreed to this settlement without admitting fault, the $2.5 million fund provides tangible financial relief to victims without requiring a lengthy trial. However, litigation remains ongoing against Progress Software Corporation, the developer behind the MOVEit software.

Who May Be Eligible to File a Claim in This Settlement?

Court documents estimate that approximately 198,667 individuals are covered under the scope of this settlement. You may be eligible to submit a claim if:

  • You are a living resident of the United States.

  • Your personal or financial information was contained in the files transferred between Ernst & Young and Bank of America that were impacted by the May 2023 MOVEit data breach.

Class members typically receive a formal notice in the mail or via email containing a unique Claimant ID and PIN. You can use these credentials to complete your claim quickly online through the court-approved settlement portal at MOVEitSettlementEYBOA.com.

Important Filing Deadlines and Next Steps for Class Members

To secure your cash payout or credit monitoring services, you must act before the upcoming court deadlines.

  • Claim Submission Deadline: All online claim forms must be submitted—or paper claim forms postmarked—by October 8, 2026.

  • Final Approval Hearing: The court will hold a final approval hearing on October 15, 2026, to decide whether to give the deal final approval.

Payments and credit monitoring activation codes will be distributed after the court grants final approval and any potential legal appeals are resolved.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: July 26, 2026
Date of Breach: March 27, 2026
Date of Breach: August 31, 2025 (JLR's response date to the incident)
Latest News