A Mortgage Vendor You Never Hired Was Breached: SitusAMC’s $5.3 Million Settlement Covers About 662,796 People — $75 Estimated With No Proof, Up to $5,000 With Receipts, $50 More for Californians. The Fund Works Out to About $8 a Head Before Fees. Claim Deadline November 6, 2026.
Does this affect you?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
In re SitusAMC Holdings Corporation Data Breach Litigation, Case No. 1:25-cv-09748-LJL, United States District Court for the Southern District of New York, Judge Lewis J. Liman. SitusAMC, a company that handles mortgage loan files for banks and lenders, discovered on or about November 12, 2025 that an outsider had taken data from its systems; its breach letters in early 2026 went to customers of its clients, many of whom may never have heard of it. On June 29, 2026, Judge Liman preliminarily approved a $5,300,000 non-reversionary settlement for the roughly 662,796 people on the class list. Each can claim a no-proof Flat Cash payment estimated at $75, documented losses up to $5,000, and — for people who lived in California between November 12 and 22, 2025 — an extra $50; one year of credit monitoring comes automatically with the postcard. The court-authorized site is SAMCDataSettlement.com, run by Simpluris. Claims are due November 6, 2026; opt-outs and objections October 22, 2026; the final approval hearing is November 11, 2026.
By Settlement Insight Data Desk ·

Why a company you never dealt with is sending you a settlement postcard
If you have the postcard: the claim deadline is November 6, 2026. File at SAMCDataSettlement.com with the Unique Class Member Login ID and PIN printed on it, or mail the paper claim form, postmarked by that date, to SitusAMC Data Incident Settlement, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799-9958. The no-proof Flat Cash payment is estimated at $75. Filing is the only way to get cash; people who do nothing get no money and still give up their claims — against SitusAMC and, under the release, against the lender whose loan files were involved.
SitusAMC Holdings Corporation is not a bank, and the people on the class list are, in the plaintiffs’ words, “current and former customers of Defendant’s clients.” The settlement agreement says the company “provides, among other things, technology, data, and advisory services to the real estate finance industry,” and “in the course of providing these services, Defendant receives loan file information from its clients, which in some instances includes Personal Information.” The plaintiffs’ complaint lists what that work covers: “mortgage origination, loan underwriting and servicing, asset management, and valuation of real estate debt and equity.” Put simply, your information reached SitusAMC through a loan file, not through an account you opened with SitusAMC. The breach letter SitusAMC mailed in January 2026 put it this way: the company “works with various financial institutions to provide certain services related to your mortgage loan.” The version dated April 3, 2026 is broader: the services “may involve borrower information and, in some cases, non-borrower information in connection with mortgage transactions.”
Which banks? The settlement notice, the claim form and the four breach letters filed with California’s attorney general name no lender. The plaintiffs’ amended complaint alleges, citing a trade-press report, that SitusAMC’s clients “include major US banks and financial institutions, such as JPMorgan Chase, Citigroup, and Morgan Stanley,” and that its “clients impacted by the breach include several major US banks, such as JPMorgan Chase and Citigroup.” Two of the six class representatives are described in it as customers of Rocket Mortgage. Those are allegations, and none of them tells you whose file you were in. What decides membership is simpler: the class is “All persons in the United States who were sent notice of the Data Incident as identified in the Class List” — approximately 662,796 people, according to the settlement agreement. If you got a SitusAMC breach letter in 2026, you should be on that list; the administrator can confirm it.
What happened in November 2025, and the two different letters
SitusAMC says it became aware of “unauthorized access to certain systems within its information technology network” on or about November 12, 2025. Its letters say an unauthorized third party “acquired data from certain SitusAMC systems” — between November 12 and 19, 2025, according to the January letter, and between November 13 and 21, according to the April letter. On November 22, 2025 the company posted a statement, quoted in the complaint, that “corporate data associated with certain of our clients’ relationship with SitusAMC such as accounting records and legal agreements has been impacted. Certain data relating to some of our clients’ customers may also have been impacted.” An update on December 29, 2025 said “the forensic investigation is now closed.” According to the settlement website, the information “may have included names, dates of birth, Social Security or individual taxpayer identification numbers, driver’s license numbers, state identification numbers or other government issued identifiers, financial account numbers, medical records, and health insurance policy numbers” — not every item for every person.
The individual letters went out in waves. California’s attorney general lists four SitusAMC filings, reported January 28, February 20, March 10 and April 3, 2026. The January sample came from P.O. Box 989728 in West Sacramento, California — the same return box we have documented on other breach letters handled by the identity-protection firm IDX — and offered 24 months of IDX credit monitoring with an enrollment code. Those enrollment windows have closed: the January letter set April 28, 2026, the April letter July 3, 2026. That envelope was the breach notice. The court settlement is a separate step with its own administrator, and the IDX enrollment code is not your settlement login. Our page on the IDX data breach letter explains that envelope in detail.
The lawsuits came quickly. The first was filed in the same New York federal court on November 24, 2025; six related class actions followed, and on December 19, 2025 the court consolidated them and appointed Mariya Weekes of Milberg, PLLC and Gregory Haroutunian of Emery Reddy, PC as interim co-lead counsel. The amended consolidated complaint of March 16, 2026 asserts negligence, negligence per se, breach of third-party beneficiary contract, unjust enrichment, declaratory judgment and violations of the California Consumer Privacy Act and the California Consumer Records Act. After a full-day mediation in New York on April 16, 2026 before Marc E. Isserles of JAMS, the parties reached this deal, and Judge Liman granted preliminary approval in an order signed June 29, 2026. SitusAMC denies wrongdoing, and the court has not decided who is right.
How much: $75 is an estimate, and the math is tight
SitusAMC pays $5,300,000 into a non-reversionary fund — nothing flows back to the company. It pays $300,000 within ten days of preliminary approval to cover notice, and the remaining $5,000,000 within ten days after the settlement becomes final. Out of that fund come court-awarded attorneys’ fees (class counsel will ask for up to one-third, plus costs), service awards of up to $2,500 for each of the six class representatives, the administrator’s costs and the credit monitoring. The rest is paid in a fixed order: documented losses first, then the California payments, and then everyone who chose Flat Cash splits what remains pro rata.
- Flat Cash (Cash Payment B): no documents, no explanation. In the settlement site’s words, “The amount of this cash payment is estimated to be $75.00, but it could be higher or lower depending on, among other things, the number of valid claims submitted.” You can take it instead of, or in addition to, documented losses.
- Documented Losses (Cash Payment A): up to $5,000 for unreimbursed out-of-pocket losses from the breach — bank or card charges, the cost of replacing a driver’s license or other ID, credit reports, and credit monitoring or identity protection first bought between November 12, 2025 and the claims deadline (with proof of purchase and a written statement that you bought it primarily because of this breach). Receipts or other third-party documents are required; “self-prepared documents by themselves are not sufficient.” A documented claim that is rejected and not cured is converted to Flat Cash.
- California Statutory Payment: an extra $50 for people who lived in California between November 12 and November 22, 2025, “subject to downward pro-ration based on the number of valid claims submitted.”
- Credit monitoring, automatic: one year of CyEx Financial Shield Complete with one-bureau credit monitoring, dark-web scanning, identity restoration and $1,000,000 in identity theft insurance. The enrollment code is on your postcard; no claim is needed. The agreement values it at $179 per person per year.
The benefit list has no separate payment for time spent dealing with the breach.
The arithmetic, which is ours: $5.3 million spread over 662,796 class members is about $8 a person before anything is deducted. If the court awards the full one-third in fees ($1,766,667) and $15,000 in service awards, about $3.52 million is left — before notice, administration and monitoring costs, whose amounts are not in the documents we read. At $75 a head, $3.52 million would pay roughly 46,900 people, about 7 percent of the class, and less once those costs and the documented-loss and California claims, which are paid first, come out. By our arithmetic, then, the $75 figure holds only if a small share of the class files. If many more people claim, the Flat Cash share falls; if fewer do, it can rise. Our data breach settlement calculator walks through the same pro rata logic for other cases.
What to do, the deadlines, and what staying in gives up
File a claim online at SAMCDataSettlement.com or by mail postmarked by November 6, 2026. You need the Unique Class Member Login ID and PIN from your postcard; the site says they are also “available from the Settlement Administrator.” The claim form asks for your name, address, email, phone and that ID, which payments you are claiming, and how you want to be paid: PayPal, Venmo, Zelle or a paper check. You sign under penalty of perjury. After payment you have 90 days to cash the check or accept the electronic payment; after that it is void. Money left over goes to a second round for people who were paid if that is economical, otherwise to a cy pres recipient the court approves.
Opt out with a letter postmarked by October 22, 2026, by U.S. mail only, to SitusAMC Data Incident Settlement, ATTN: Exclusion Request, P.O. Box 25226, Santa Ana, CA 92799-9958. It must name the case and include your full name, mailing address, phone number, email address if any, your personal signature and a statement that you want to be excluded. Mass or group opt-outs signed by an attorney are not accepted. Opting out is the only way to keep your own right to sue — and you then get nothing from this settlement.
Object by the same October 22, 2026 deadline, either by filing on the court’s docket or by mail, postmarked by that date, to the clerk, class counsel, SitusAMC’s lawyers at Alston & Bird in Atlanta and the administrator. The final approval hearing is set for November 11, 2026, at 10:00 a.m. Eastern Time at 500 Pearl Street in New York; the settlement site warns that “the date and time of this hearing may change without further notice.” Class counsel’s fee application is due 95 days after preliminary approval, which by our count is October 2, 2026; as of September 30, 2026 it was not yet among the documents posted on the settlement site. No money moves before final approval and any appeals; the agreement then gives the administrator 60 days after the settlement becomes effective, “or as soon as reasonably practicable thereafter.”
What staying in gives up. The release does not only cover SitusAMC. The “Released Parties” expressly include “all current and former clients and customers of the SitusAMC Persons that provided information to the SitusAMC Persons that was compromised, accessed, exfiltrated, or otherwise impacted by the Data Incident” — the lenders and institutions whose loan files were taken. If you stay in the class, you give up claims over this incident against them too, whether or not you file for money, and the release names California Consumer Privacy Act claims explicitly. Keeping those claims is what an opt-out is for.
Is the postcard real?
The court appointed Simpluris, Inc. as settlement administrator. The official channels, as listed on the settlement site on September 30, 2026: the website SAMCDataSettlement.com, the email info@SAMCDataSettlement.com, the toll-free line (833) 421-7329, answered 24/7, and P.O. Box 25226, Santa Ana, CA 92799-9958. The site dates the notice mailing to August 13, 2026. The notice is headed “If SitusAMC Holdings Corporation sent you a notice that your personal information was involved in a November 2025 data incident,” and in the court-approved draft the postcard carries a Class Member number, a Unique ID, a Claim Login PIN and, on its last page, the enrollment code for the credit monitoring.
How to spot a fake: the official claim form has no field for a Social Security number, a bank password or a card number; digital payment needs only the email or phone number tied to your PayPal, Venmo or Zelle account. Filing costs nothing. The notice asks people not to call the court, the clerk’s office, SitusAMC or its lawyers. And do not mix up the two phone numbers in circulation: (844) 814-3163 is the IDX line printed on the 2026 breach letters, while the settlement line is (833) 421-7329. If you received a SitusAMC breach letter but no settlement postcard, ask the administrator for your ID through the official channels above, not through a third-party site.
How it compares, and what comes next
Per person, this is a small fund: about $8 per class member before fees, by our count. The FinWise Bank settlement we covered on September 25, which also wrote to many people who knew the company only indirectly — American First Finance customers — comes to about $4.19 per person across up to 668,000 people. SitusAMC’s deal has four parts: a no-proof payment whose size depends on how many people file, a $5,000 cap for documented losses, a California add-on, and monitoring. Two things stand out. The release reaches the lenders themselves, not only SitusAMC. And the people it pays are customers of SitusAMC’s clients, not of SitusAMC — if you are looking up the SitusAMC data breach settlement because a postcard arrived from a company you do not know, that is the reason.
What happens next: the fee application and final approval motion, which should show what class counsel asks for and may report how many people have claimed; then the hearing on November 11, 2026. Under the court’s order, the fee application is to be posted on the settlement website once it is filed.
The Data Behind This Story
- Case
- In re SitusAMC Holdings Corporation Data Breach Litigation, No. 1:25-cv-09748-LJL
- Court
- U.S. District Court for the Southern District of New York, Judge Lewis J. Liman; preliminary approval signed June 29, 2026
- Settlement fund
- $5,300,000, non-reversionary: $300,000 within ten days of preliminary approval for notice, $5,000,000 within ten days after the settlement becomes final
- Class
- About 662,796 people in the U.S. who were sent notice of the November 2025 SitusAMC data incident (Class List); California subclass: residents between November 12 and November 22, 2025
- Cash benefits
- Flat Cash estimated at $75 (pro rata, no proof) · documented losses up to $5,000 with third-party documentation · California Statutory Payment $50, may be reduced pro rata
- Credit monitoring
- One year of CyEx Financial Shield Complete (one bureau, $1,000,000 identity theft insurance), enrollment code on the postcard, no claim needed; valued at $179 per year
- Deadlines
- Claims November 6, 2026 (online or postmark) · opt-out and objections October 22, 2026
- Final approval hearing
- November 11, 2026, 10:00 a.m. Eastern Time, 500 Pearl Street, New York
- Fees requested
- Up to one-third of the fund plus costs; service awards up to $2,500 each for six class representatives; application due 95 days after preliminary approval (October 2, 2026, our count)
- Payment
- PayPal, Venmo, Zelle or paper check, after final approval and any appeals; 90 days to cash or accept
- Breach
- Discovered on or about November 12, 2025; data acquired November 12–19 or November 13–21, 2025, per SitusAMC’s letters; breach letters January–April 2026 offered 24 months of IDX monitoring
- Administrator
- Simpluris, Inc. — SAMCDataSettlement.com · (833) 421-7329 · info@SAMCDataSettlement.com · P.O. Box 25226, Santa Ana, CA 92799-9958
- Source: SAMCDataSettlement.com — home page, FAQ 1–21, Important Dates and Contact pages, read September 30, 2026: case caption, class definition, benefits and amounts ($75 estimate, $5,000 cap, $50 California payment, monitoring), claim, opt-out and objection deadlines and procedures, hearing date, release incl. Released Parties, fee request, administrator contacts, notice mailing 8/13/2026
- Source: Simpluris document list for case SDC6 (cw.simpluris.com/docs/public/SDC6), read September 30, 2026: posted documents are the Preliminary Approval Order, Amended Consolidated Class Action Complaint, Settlement Agreement, Claim Form and Long Form Notice — no fee application yet
- Source: Order Granting Plaintiffs’ Unopposed Motion for Preliminary Approval, Judge Lewis J. Liman, signed June 29, 2026 (Dkt. 57; PDF header reads Filed 06/26/26), read September 30, 2026: class certification, class counsel, Simpluris appointment, mediator, 95/115/130-day schedule, no group opt-outs, hearing November 11, 2026, administrator fee cap per Dkt. 56
- Source: Settlement Agreement (Dkt. 54-1, filed June 22, 2026), read September 30, 2026: SitusAMC’s business, procedural history (first suit November 24, 2025, six related suits, consolidation December 19, 2025, mediation April 16, 2026), Class List of approximately 662,796, $5,300,000 non-reversionary fund and funding schedule, payment order, CyEx monitoring valued at $179, 90-day check rule, residual and cy pres, court-approved postcard draft
- Source: Amended Consolidated Class Action Complaint (ECF 47, filed March 16, 2026), read September 30, 2026: SitusAMC statements of November 22 and December 29, 2025 as quoted; allegations naming JPMorgan Chase, Citigroup and Morgan Stanley as clients (citing CPO Magazine) and two plaintiffs as Rocket Mortgage customers — cited as allegations
- Source: Claim Form and Long Form Notice (Simpluris, CaseID 9571), read September 30, 2026: claim fields (no Social Security number field), payment options PayPal, Venmo, Zelle, physical check, attestation under penalty of perjury, notice heading
- Source: California Attorney General, data breach list filtered for SitusAMC and the sample letters dated January 28, 2026 and April 3, 2026, read September 30, 2026: four filings reported January 28, February 20, March 10 and April 3, 2026; breach windows; mortgage-services wording; IDX 24-month monitoring; enrollment deadlines April 28 and July 3, 2026; IDX line (844) 814-3163; return address P.O. Box 989728, West Sacramento
- Source: Settlement Insight, IDX data breach letter page and FinWise news of September 25, 2026, read September 30, 2026: the P.O. Box 989728 return address on other IDX-handled letters; FinWise’s $2.8 million fund for up to 668,000 people, $4.19 per person before fees
- Source: situsamc.com/databreach answered 403 on September 30, 2026 — SitusAMC’s own statements are quoted from the complaint
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.