CUSO Financial Sent Its Customers Two Breach Letters in 2024. The Second One — 75,116 People, an Intruder Inside a Compliance-Archiving Vendor for a Month — Is Now a $1.75 Million Settlement: Up to $5,000 Documented, Up to $599 in Cash, and Nothing Without the Claim Number and PIN From the Letter. Claims Close November 16.
CUSO Financial Services is the San Diego broker-dealer that sells investments through credit unions. Sinitsa v. CUSO Financial Services, L.P. (Tulare County Superior Court, No. VCU326251) settles the incident CUSO disclosed in October 2024: unauthorized access to one employee's account at the third-party vendor that archives its communications for FINRA, between December 19, 2023 and January 19, 2024. It is not the incident CUSO wrote to customers about that February, which involved an email-system vulnerability and data from 2022. The official site lists the benefits and dates; the fee request and the class size come from the notice as reported by claim trackers and the state breach filings, and we say so where it matters.
By Settlement Insight Data Desk ·

Two letters, two incidents — this settlement covers the second
CUSO Financial Services, L.P. is a registered broker-dealer and investment adviser headquartered in San Diego that places investment representatives inside credit unions; it is a subsidiary of Atria Wealth Solutions, which LPL Financial agreed to acquire in 2024. In 2024 its customers heard from it twice about their data.
The first letter, dated February 16, 2024 and filed with the California Attorney General as a sample, described an email-system vulnerability: “On October 20, 2023, CFS learned about an email security event … an email application, Barracuda Networks, had a vulnerability that allowed an unauthorized party to gain access to historical emails and attachments,” with information “from July 5, 2022” potentially involved. That incident is not what is being settled.
The second letter went out on October 28, 2024. As CUToday reported from the Maine Attorney General filing the next day, CUSO said that on January 19, 2024 it “became aware of suspicious activity involving a third-party service provider which CUSO utilizes for archiving communications, as required by The Financial Industry Regulatory Authority.” An unauthorized person had access to one CUSO employee's account on that archiving system from December 19, 2023 to January 19, 2024. The filing put the count at 75,116 individuals. Claim-tracking summaries of the settlement notice list the exposed fields as names, Social Security numbers, driver's license numbers, medical information and financial account information; the official FAQ says only that “Personal Identification information and data” were compromised in that window. Nine months passed between discovery and the letters.
The lawsuit that followed, Stan Sinitsa v. CUSO Financial Services, L.P., is in the Superior Court of California, County of Tulare, No. VCU326251. CUSO “denies all material allegations” and settles with “no admission of liability,” per the settlement site.
What the $1.75 million buys, in the order the money is spent
The settlement site's FAQ describes four benefits and, importantly, the order in which they draw on the fund. The residual cash payment is calculated “pro rata from funds remaining after Credit Monitoring Services, Documented Loss payments, California Statutory Payments, attorneys' fees, and administrative costs.” That sentence decides what the $599 headline is worth.
| Benefit | Terms (official FAQ) |
|---|---|
| Credit monitoring | “two (2) years of three-bureau credit monitoring with Credit Monitoring & Alerts, CyberScan Dark Web Monitoring, $1M Reimbursement Insurance” |
| Documented losses | Reimbursement “up to a maximum of $5,000” for out-of-pocket losses traceable to the incident |
| California statutory payment | “up to $100 on a claims-made basis” for California residents |
| Residual cash payment | “up to $599,” which “may be less than $599” depending on approved claims — paid from whatever is left |
The fund is $1,750,000. The notice, as summarized by ClaimDepot, has class counsel requesting fees of up to $583,333 (one third), costs up to $20,000 and a $5,000 service award for Mr. Sinitsa; the official FAQ does not list those figures, so treat them as the request, not the award. Take those out and administration, monitoring, documented losses and the California payments still come ahead of the residual pool. Our arithmetic, for scale only: with about $1.14 million left before administration and monitoring costs, the residual pool would pay $599 to no more than about 1,900 people; spread across all 75,116 class members it would be about $15 each. The people who get near $599 will be the ones who file when few others do — exactly the pattern in every breach settlement we have covered this year.
The 12 months of Experian monitoring CUSO offered in its 2024 letters have long expired for most recipients; the two years of three-bureau monitoring here is the benefit with the most certain value, and it does not depend on how many people claim.
The Claim Number and PIN are the whole game
Unlike the consumer-product settlements that let anyone attest to a purchase, this one is closed to people who cannot show they were in the class. The official FAQ is direct: to file, class members use the “Claim Number and PIN found in the notice you received.” The site is cusocybersecurityincident.com and the claims portal sits on the administrator's domain. If you received the October 2024 breach letter but not a 2026 settlement notice, contact the administrator, Analytics Consulting LLC — 866-356-5835, CUSOCybersecurityIncident@noticeadministrator.com, P.O. Box 2010, Chanhassen, MN 55317-2010 — rather than filing blind.
The dates from the official site and the court-authorized notice:
- Opt-out and objection deadline: October 1, 2026
- Claim deadline: November 16, 2026
- Final approval hearing: February 18, 2027, Tulare County Superior Court (date per the notice as reported by ClaimDepot; the official FAQ page did not list it when we read it on September 2)
Documented-loss claims need paperwork — bank statements, fraud reports, receipts for credit freezes or professional help — and the losses have to be plausibly traceable to a breach that happened between December 2023 and January 2024. The California $100 is for residents of the state and does not require documentation beyond the claim itself. Everyone in the class can take the monitoring. And no one should hand a Social Security number to a third-party “claim service” for this: the form is free, and the PIN is the proof.
The Data Behind This Story
- Case
- Stan Sinitsa v. CUSO Financial Services, L.P., Superior Court of California, County of Tulare, No. VCU326251
- Settlement fund
- $1,750,000
- Incident settled
- Unauthorized access to one CUSO employee's account at a third-party communications-archiving vendor (FINRA-required archiving), December 19, 2023 – January 19, 2024; discovered January 19, 2024; customer letters October 28, 2024
- People affected
- 75,116 (Maine Attorney General filing, as reported by CUToday, October 29, 2024)
- Not this settlement
- The February 16, 2024 letter about a Barracuda email-system vulnerability (learned October 20, 2023; data from July 5, 2022) is a separate incident
- Documented losses
- Up to $5,000
- California statutory payment
- Up to $100, claims-made, California residents
- Residual cash payment
- Up to $599, pro rata from what remains after monitoring, documented losses, California payments, fees and administration
- Credit monitoring
- Two years, three-bureau, with dark-web monitoring and $1 million reimbursement insurance
- Fee request (per notice, as reported)
- Attorneys' fees up to $583,333 (one third); costs up to $20,000; service award up to $5,000
- To file
- Claim Number and PIN from the settlement notice; online or by mail
- Opt-out / objection deadline
- October 1, 2026
- Claim deadline
- November 16, 2026
- Final approval hearing
- February 18, 2027 (per the notice as reported by ClaimDepot)
- Administrator
- Analytics Consulting LLC — P.O. Box 2010, Chanhassen, MN 55317-2010 · 866-356-5835 · CUSOCybersecurityIncident@noticeadministrator.com · cusocybersecurityincident.com
- Company
- CUSO Financial Services, L.P., San Diego — broker-dealer and RIA serving credit unions; subsidiary of Atria Wealth Solutions (LPL Financial agreed to acquire Atria in 2024)
- Source: cusocybersecurityincident.com — home page (case name, court, case number, incident window, “denies all material allegations,” deadlines November 16 and October 1, 2026) and Frequently Asked Questions (benefits, pro rata order, Claim Number and PIN, administrator contact), read September 2, 2026
- Source: CUToday, “CUSO Financial Services Reports Breach That May Have Impacted More Than 75,000 Individuals,” October 29, 2024 — 75,116 individuals, quoted description of the archiving-vendor incident, letters sent October 28, 2024
- Source: California Attorney General, submitted breach notification sample, CUSO Financial Services, LP, letter dated February 16, 2024 — Barracuda email-system incident, “information from July 5, 2022,” Experian monitoring offer (the separate, earlier incident)
- Source: ClaimDepot, “Cuso Financial Services $1.75 million data breach settlement,” read September 2, 2026 — fee, cost and service-award requests, final approval hearing February 18, 2027, exposed data fields as described in the notice
- Source: The Daily Hodl, September 1, 2026 — settlement summary and quoted CUSO statement
- Source: LPL Financial Holdings, Form 8-K exhibit, February 2024 — agreement to acquire Atria Wealth Solutions; CUSO's own notice footer: “CUSO Financial is a subsidiary of Atria”
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.