Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

CUSO Financial Services Reaches $1.75 Million Class Action Settlement Following Cybersecurity Incident

CUSO Financial Services, L.P. has reached a $1.75 million class action settlement to resolve claims arising from a 2023–2024 cybersecurity incident that exposed the sensitive personal and financial data of 75,116 credit union clients nationwide.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

CUSO Financial Services, L.P. has agreed to pay $1.75 million to resolve a class action lawsuit stemming from a security breach involving a third-party vendor. The breach potentially exposed sensitive personal, financial, and identifying information for tens of thousands of credit union clients and individuals across the country.

If you received an official notice informing you that your personal information was impacted by the CUSO Financial Services cybersecurity incident, you may be eligible to receive cash compensation, reimbursement for out-of-pocket losses, or free credit monitoring services. To secure your benefits under the settlement, you must file a valid claim by November 16, 2026.

What Caused the CUSO Financial Services Data Breach?

The litigation, Sinitsa v. CUSO Financial Services, L.P. (Case No. VCU326251), pending in the Superior Court of California for Tulare County, centered on a security incident detected in early 2024. CUSO Financial Services—a San Diego-based company providing investment and wealth management solutions to credit unions nationwide—discovered unauthorized activity within an account managed by a third-party vendor used to archive communications for regulatory compliance.

According to court records and breach notifications, an unauthorized party accessed the archived communications environment between December 19, 2023, and January 19, 2024. During this one-month window, the intruder gained access to files containing sensitive personal identification details.

Plaintiffs filed a class action lawsuit alleging that CUSO Financial Services failed to implement reasonable cybersecurity safeguards, delayed notifying impacted individuals, and inadequately protected sensitive customer data. CUSO Financial Services denies all allegations of wrongdoing and maintains that its security protocols were appropriate, but agreed to the $1.75 million settlement fund to resolve the litigation and avoid the expenses and risks of prolonged court proceedings.

What Personal Information Was Compromised?

Data breach filings indicate that the cybersecurity incident affected approximately 75,116 individuals nationwide. The types of compromised data varied depending on the communications stored in the affected vendor account, but exposed information may include:

  • Full names

  • Social Security numbers

  • Driver’s license numbers or state identification card details

  • Financial account information and investment records

  • Protected medical or health information

When highly sensitive details like Social Security numbers and financial account numbers fall into unauthorized hands, individuals face an elevated risk of identity theft, fraudulent bank transactions, tax fraud, and unauthorized credit applications.

Who Is Covered by the CUSO Settlement?

You are considered a settlement class member if you reside in the United States and received a written data breach notification from CUSO Financial Services regarding the December 2023–January 2024 security incident.

The settlement agreement divides eligible individuals into two primary categories:

  • Nationwide Settlement Class: All individuals residing in the U.S. whose personal data was stored on CUSO Financial Services systems or third-party vendor systems impacted by the incident.

  • California Subclass: All members of the nationwide class who were residents of California at the time of the cybersecurity incident.

What Benefits Can You Receive From the Settlement Fund?

The $1.75 million settlement fund provides multiple tiers of compensation to address out-of-pocket expenses, identity protection, and statutory privacy claims:

1. Reimbursement for Documented Out-of-Pocket Losses (Up to $5,000)

Class members who suffered financial losses directly traceable to the security incident can claim up to $5,000 in cash reimbursement. Eligible out-of-pocket costs include unreimbursed bank or credit charges, professional fees for identity theft consultation, costs associated with placing credit freezes or fraud alerts, and administrative fees like notary or copying costs. Claims must be accompanied by supporting documentation, such as bank statements, receipts, or police reports.

2. Free Credit Monitoring and Identity Protection Services

All class members, regardless of whether they experienced direct financial loss, can claim two years of complimentary three-bureau credit monitoring services. This package includes active credit report tracking, dark web surveillance, and up to $1 million in identity theft insurance coverage.

3. California Statutory Cash Payments (Up to $100)

Class members who qualify as part of the California Subclass may claim an additional statutory cash payment of up to $100 to address claims brought under California consumer privacy laws.

4. Residual Cash Payments (Up to $599)

If settlement funds remain after fulfilling documented loss claims, administrative fees, credit monitoring costs, and California subclass payments, any leftover funds will be distributed as pro-rata residual cash payments of up to $599 to class members who submitted valid claims.

Understanding Data Privacy Laws and Corporate Accountability

Financial services firms and credit union vendors operate under strict federal and state regulatory mandates—including California privacy statutes and Financial Industry Regulatory Authority (FINRA) standards—requiring them to safeguard non-public personal information.

When corporations outsource communications archiving or financial record management to third-party providers, they remain responsible for ensuring that external systems meet modern cybersecurity standards. Class action lawsuits allow consumers to join together, hold financial institutions accountable when data security breakdowns occur, and recover cash compensation for identity theft prevention and financial harm.

Important Settlement Deadlines and Court Schedule

If you are a class member, you must take action before specific court-ordered deadlines to protect your rights or claim cash benefits:

Action or Event Deadline Date What It Means
Opt-Out Deadline October 1, 2026 Last day to exclude yourself from the settlement if you wish to retain your right to sue CUSO independently.
Objection Deadline October 1, 2026 Final date to file formal legal objections to the settlement terms with the court.
Claim Form Deadline November 16, 2026 Deadline to submit a claim online or postmark a paper form for cash compensation or credit monitoring.
Final Approval Hearing February 18, 2027 The court will determine whether to grant final approval to the $1.75 million settlement deal.

Settlement checks and credit monitoring access codes will be distributed after the court grants final approval and any potential appeals are resolved.

How to File Your Claim Step-by-Step

Filing a claim for cash compensation or credit monitoring services can be completed online or through the mail in a few simple steps:

  1. Locate Your Official Notice: Find the mailed or emailed notice sent by the settlement administrator. Locate your unique Claim Number and PIN printed on the document.

  2. Gather Proof of Losses: If you are claiming out-of-pocket expenses (up to $5,000), gather digital copies or physical receipts, account statements, and documentation showing identity theft expenses incurred as a result of the incident.

  3. Visit the Official Settlement Portal: Access the court-approved website at cusocybersecurityincident.com.

  4. Complete the Online Claim Form: Enter your unique Claim Number and PIN to access the pre-filled form, or fill in your personal contact details manually if you do not have your notice handy.

  5. Select Your Desired Benefits: Choose whether you are requesting credit monitoring, documented loss reimbursement, California statutory payments, or residual cash distributions.

  6. Submit Before November 16, 2026: Complete your digital submission before 11:59 p.m. Pacific Time on November 16, 2026, or ensure paper claim forms mailed to the settlement administrator are postmarked by November 16, 2026.

Data breaches put your personal identity and long-term financial stability at risk. When major financial service organizations and their third-party vendors fail to safeguard your private details, everyday people shouldn’t be left carrying the burden alone.

If your information was exposed in the CUSO Financial Services cybersecurity incident, exercise your legal rights and file your claim before the November 16, 2026 deadline.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Reported to Vermont AGO on September 10, 2026
Date of Breach: January 26, 2026 - February 3, 2026
Date of Breach: Claimed September 10, 2026 (unconfirmed by the company)
Latest News