The Fidelity Data Breach Settlement Closed on July 27. Its Own Website Still Says the Court “Still Has to Decide” — and the Regulator's File Says Fidelity Never Told Some of the Victims at All.
In re: Fidelity Investments Data Breach Litigation, No. 1:24-cv-12601-LTS (D. Mass.), was finally approved and judgment entered on July 9, 2026. The claim deadline was July 27, 2026; the claim page now says so, while the homepage and FAQ of the same site still carry the pre-hearing language. If you are arriving now, there is nothing to file. What is still worth knowing is in a document almost nobody has read: the Massachusetts Securities Division consent order, which puts the intrusion at 23.7 million automated requests that pulled roughly 373,000 document images — and finds that Fidelity “failed to provide notice … to certain Massachusetts residents,” beneficiaries and minors among them.
By Settlement Insight Data Desk ·

First, the answer: the window is shut
The claim deadline was Monday, July 27, 2026. The settlement's own claim page now returns “The Claim Deadline has passed.” Judgment was entered on July 9, 2026. Nothing on this page is a route to money, and any site offering you a “Fidelity claim form” today is either stale or a scam.
Two things are still genuinely unknown, and we are not going to pretend otherwise. There is a docket entry dated July 30, 2026 whose text is not freely retrievable, so we cannot tell you whether anyone appealed. And no payment date has been published anywhere — not on the dates page, not in the FAQ. The agreement says payments issue “within thirty (30) days after the allocation and distribution of funds are determined by the Settlement Administrator following the Effective Date,” and that checks go void 90 days after they are cut. If you filed in time, that is your timetable: after finality, not after approval.
There is one small irony worth recording. The homepage and FAQ of fidelitydatasettlement.com still tell readers the court “still has to decide whether to approve” a settlement it approved on July 9. Only the claim form page was updated. We have now seen this on three court-authorised settlement websites in three weeks.
Make sure it is even your case: three different “Fidelity” breaches
The search term collapses three separate incidents across four entries — the second row is the regulatory track of the first. Only the first is this settlement.
| Incident | Company | Case / outcome |
|---|---|---|
| August 17–19, 2024 — Fidelity's own network | FMR LLC and Fidelity Brokerage Services LLC, both d/b/a Fidelity Investments | This one. $2.5 million, 1:24-cv-12601-LTS (D. Mass.), final approval July 9, 2026 |
| Same incident, regulatory track | Fidelity Brokerage Services LLC | Massachusetts Securities Division, Docket No. E-2024-0373 — $1,250,000 fine, paid to the Commonwealth, not to victims |
| October 29 – November 2, 2023 — a vendor's network | Fidelity Investments Life Insurance Company and Empire Fidelity Investments Life Insurance Company; about 28,268 people | No separate Fidelity proceeding found; covered by McNally v. Infosys McCamish Systems, LLC, 1:24-cv-00995-JPB (N.D. Ga.), $17.5 million, final approval December 18, 2025 — deadline also long gone |
| November 2023 | Fidelity National Financial / LoanCare — a title insurer, a different company entirely; about 1.3 million people | $5.9 million, final approval September 10, 2025 |
If your letter came from a life insurance company, or if the name on it was Fidelity National, this is not your case.
What the regulator established that the class action did not
The consent order from the Massachusetts Securities Division is the most detailed public account of what happened, and it reads nothing like a press release.
In July 2024 the attacker opened two brokerage accounts under other people's identities — the order calls it “a type of identity theft known as 'true name fraud'.” Logged in as an authenticated customer, the threat actor reached the document image retrieval function, where the image identifier was a plain ten-digit number. Changing the number returned somebody else's document.
On August 17 came a test run of roughly a thousand requests. On August 18 and 19 roughly 23.7 million requests — most likely scripted — hit randomly generated ten-digit IDs and pulled down roughly 373,000 document images belonging to other customers.
It was not the security team that caught it. At 8:06 a.m. on August 19 a denial-of-service detector fired; only when analysts looked did they find no DDoS, but a mass download. The accounts were closed the same day. No customer money or account access was involved.
The finding that stings, in the order's own words: “At the time of the data breach, Fidelity did not reasonably enforce its technical security policies designed to restrict users… to accessing only the images in the Document Image Repository that are associated with the user's account.”
And this, which explains why some people never heard about any of it: “On or about October 9, 2024, Fidelity undertook to provide notice of the Data Breach to Massachusetts residents but failed to provide notice of the Data Breach to certain Massachusetts residents.” The order does not itemise who was missed; trade coverage of the case names beneficiaries, relatives and minors. What the order itself records is that of at least 2,768 affected Massachusetts residents, at least 2,650 were FBS customers or otherwise connected to FBS accounts. Fidelity was ordered to notify the Massachusetts residents it had missed within 30 days, to retain an independent cybersecurity consultant, to certify its revised controls within 90 days, and it was formally censured.
Notification of everyone else came on October 9, 2024 — about seven weeks after detection. That delay is one of the things the class action complained about.
What the settlement paid, and the arithmetic behind the $100
The fund is $2,500,000 and it does not grow: “The Settlement Fund represents the total extent of Defendants' monetary obligations under the Settlement Agreement.”
- Documented monetary losses: up to $5,000 per class member
- Pro-rata cash payment with no documentation: expected $100, with the standard caveat “may be larger or smaller depending on the total claims filed”
- California subclass: an additional $50 under the CCPA
- Two years of CyEx credit and identity monitoring with $1,000,000 of identity-theft insurance
- Class counsel asked for up to one third of the fund plus $45,000 in costs; five class representatives asked for $2,500 each. What the court actually awarded on July 9 is not in any freely available document
Here is the number that explains everything about breach settlements. The agreement states the intended class: “It is intended that these approximately 155,000 individuals or joint accountholders shall constitute the members of the Class.” $2.5 million across 155,000 people is about $16 each, gross — before fees, service awards and administration. A $100 payment only works because most of the class never files. That is not a criticism of this deal; it is how every one of these works, and it is worth knowing before you read the next headline promising “up to $5,000.”
The class was wider than the mailing list, which is a detail worth keeping for future cases: Fidelity “determined that approximately 77,099 individuals were required to be notified,” and the settlement then added roughly 86,000 more people and joint accountholders whose account number and routing number were exposed but who no state law required anyone to tell. Receiving no letter did not mean being outside the class.
If you were in this class and did nothing
Then the judgment binds you. The opt-out deadline was June 26, 2026; you did not take it, so your claims against Fidelity arising from this incident are released whether or not you ever saw a letter. That is the part of these settlements people discover far too late, and it is the reason the deadline mattered even to someone who did not want the $100.
What is still worth doing has nothing to do with this settlement: the exposed categories included Social Security numbers, passport and driver's licence numbers, bank account and routing numbers and scanned images of active credit cards. A security freeze at all three bureaus is free, permanent and unrelated to any deadline. If you are a Massachusetts resident who thinks a document of yours was in someone else's file — a beneficiary, a spouse, a child — the consent order required Fidelity to reach you; if it never did, that is a matter for the Securities Division, not for the closed claims process.
We will update this page when a payment date appears.
The Data Behind This Story
- Case
- In re: Fidelity Investments Data Breach Litigation, No. 1:24-cv-12601-LTS
- Court
- U.S. District Court for the District of Massachusetts, Boston
- Judge
- Leo T. Sorokin
- Defendants
- FMR LLC and Fidelity Brokerage Services LLC, both d/b/a Fidelity Investments
- Incident
- August 17–19, 2024 — about 23.7 million automated requests, roughly 373,000 document images retrieved
- Detected
- 8:06 a.m., August 19, 2024, by a denial-of-service detector
- Notified
- October 9, 2024 — about seven weeks later
- Class size (intended)
- About 155,000 — 77,099 who had to be notified plus about 86,000 more whose account and routing numbers were exposed
- Settlement fund
- $2,500,000, non-expanding
- No-proof payment
- Expected $100 pro rata; California subclass +$50
- Documented losses
- Up to $5,000
- CLAIMS DEADLINE
- July 27, 2026 — passed; the claim page says so
- Opt-out / objection
- June 26, 2026 — passed
- Final approval
- July 9, 2026, judgment entered the same day
- Payment date
- Not published anywhere. Checks void 90 days after issue
- Regulatory fine
- $1,250,000 to the Commonwealth of Massachusetts, Docket No. E-2024-0373 — none of it goes to victims
- Not this case
- Fidelity National Financial / LoanCare ($5.9M) is a different company; for the FILI/EFILI exposure we found no separate Fidelity proceeding — it was covered by McNally v. Infosys McCamish ($17.5M)
- Source: Settlement Agreement in In re: Fidelity Investments Data Breach Litigation, No. 1:24-cv-12601-LTS (D. Mass.), PDF read September 4, 2026 — the defendants, the five class representatives, class counsel, the seven causes of action in Recital C, the 77,099 required notifications and roughly 86,000 additional individuals in Recital B, the “approximately 155,000 individuals or joint accountholders” language at ¶ 48, the class and California subclass definitions at ¶ 4 and ¶ 37, the $2,500,000 fund as the total extent of monetary obligations at ¶ 64, the benefit structure at ¶ 58, and the payment mechanics and 90-day check expiry at ¶ 65–66.
- Source: Official settlement website fidelitydatasettlement.com — the dates page (notification mailing April 27, 2026; opt-out and objection June 26, 2026; final approval hearing July 9, 2026 at 2:00 p.m.; claim deadline July 27, 2026, with no payment date listed), the FAQ (expected $100 pro rata payment, $50 CCPA payment, up to $5,000 documented losses, the fee and service-award requests), and the claim form page, which on September 4, 2026 returned “The Claim Deadline has passed.” The homepage and FAQ still carried pre-hearing language on the same date.
- Source: Docket for the case on CourtListener (docket id 69248634), read September 4, 2026 — docket opened October 10, 2024, preliminary approval March 11, 2026 (Dkt. 62) — the consolidated complaint date of February 10, 2025 comes from Recital C of the settlement agreement, not from the docket text, and on July 9, 2026 both an order on the motion for attorney fees and a Judgment (Dkt. 84). A further order dated July 30, 2026 appears on the docket; its text is not freely retrievable, so whether an appeal was filed is unknown to us.
- Source: Massachusetts Securities Division, In the Matter of Fidelity Brokerage Services LLC, Docket No. E-2024-0373, consent order PDF read September 4, 2026 — the July 2024 opening of two brokerage accounts described as “true name fraud” (¶ 24–25), access to the document image retrieval function (¶ 26), the roughly 1,000 test calls on August 17 (¶ 27), about 23.7 million calls on August 18–19 (¶ 29), roughly 373,000 document images retrieved (¶ 30), at least 2,768 Massachusetts residents affected (¶ 31), the 8:06 a.m. August 19 denial-of-service alert (¶ 32–34), the finding that notice was not given to certain Massachusetts residents (¶ 12), and the $1,250,000 fine, censure, independent consultant, 90-day certification and 30-day re-notification requirements (Section IX).
- Source: Fidelity Investments breach notification to the Iowa Attorney General dated October 9, 2024 — 561 Iowa residents, the data categories, and the statement that no accounts or funds were accessed. New Hampshire's filing records 508 residents. A figure of 337 for Maine circulates in trade press; the Maine entry itself answered HTTP 404 when we tried to read it.
- Source: Long-form class notice in the same case (classaction.org copy), read September 4, 2026 — the court's address and the list of reimbursable out-of-pocket categories.
- Source: For the separation of the four incidents: the Infosys McCamish settlement site (infosysdatasettlement.com) and McNally v. Infosys McCamish Systems, LLC, No. 1:24-cv-00995-JPB (N.D. Ga.), $17.5 million with final approval December 18, 2025, covering the 28,268 Fidelity Investments Life Insurance Company and Empire Fidelity customers exposed in the October–November 2023 vendor breach; and the separate Fidelity National Financial / LoanCare settlement of $5.9 million, finally approved September 10, 2025, which involves a title insurer and not Fidelity Investments.
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.