Cash App Distributed Payments for Security Settlement

The $15 million settlement addresses claims of negligence following unauthorized account access incidents.

Updated on Oct. 7, 2026 in Cybersecurity

Isometric editorial illustration of a heavy industrial steel vault mechanism, symbolizing digital data security and financial protection.
Block has begun distributing payments to Cash App users as part of a $15 million settlement resolving claims of negligence regarding data security. AI Illustration. Upload story photo >

Live Poll

Do you trust digital financial platforms to adequately protect your personal data and account security?

Cash App and its parent company, Block, have begun distributing payments to users following a $15 million security settlement. The funds compensate individuals impacted by unauthorized data access between 2018 and 2024.

Why it matters

This settlement resolves a class-action lawsuit that accused the financial service provider of negligence and failure to protect sensitive user account data. It provides financial relief to customers who experienced out-of-pocket losses or wasted time resolving account security issues.

Eligible users are receiving up to $2,500 for out-of-pocket losses resulting from security failures. The settlement also includes compensation for lost time at a rate of $25 per hour for a maximum of three hours.

The players

Cash App

This mobile payment service allows users to transfer money and perform financial transactions through its application.

Block

Formerly known as Square, this technology conglomerate owns Cash App and focuses on digital financial services and payment processing.

The details

The class-action case centered on two major security failures: a 2022 incident where a former employee accessed account data without permission and a 2023 breach involving unauthorized access through recycled phone numbers. Users affected by these events during the period from August 23, 2018, to August 20, 2024, were eligible to file claims by the November 2024 deadline.

Timeline

  1. August 23, 2018, to August 20, 2024: Incident eligibility window.

  2. 2022: Former employee accessed data without permission.

  3. 2023: Unauthorized access via recycled phone numbers occurred.

  4. November 2024: Deadline to file a settlement claim.

  5. October 2026: Distribution of settlement payments.

The Tech Race

This settlement highlights the critical industry transition toward stronger account verification as platforms struggle with legacy security vulnerabilities. It reflects a growing shift where tech companies face direct financial penalties for failing to secure infrastructure against identity-related threats.

Users who filed successful claims will see settlement funds processed through the official payout platform. This payout provides direct reimbursement for documented financial losses incurred while trying to regain control of compromised accounts.

The takeaway

This case underscores the importance of monitoring account activity and updating security settings frequently. Users should remain cautious about recycling phone numbers associated with sensitive financial services to avoid inheriting the digital security risks of previous owners.

Further reading

Learn more about evolving digital safety standards in our Cybersecurity section.

Live Poll

Do you trust digital financial platforms to adequately protect your personal data and account security?