Cash App Distributed Payments in $15M Security Settlement

Payments to users conclude a class-action lawsuit over negligence and unauthorized account access.

Updated on Oct. 7, 2026 in Cybersecurity

Bold flat-color editorial illustration of a brass vault key on a pedestal, evoking the institutional resolution of data security.
Cash App has begun distributing $15 million in settlement payments to users affected by security breaches between 2018 and 2024. AI Illustration. Upload story photo >

Live Poll

Do you trust digital financial platforms to adequately protect your personal data and account security?

Cash App has begun distributing funds from a $15 million settlement following a class-action lawsuit that accused the company and Block of security negligence. The settlement compensates users who experienced unauthorized access between August 2018 and August 2024.

Why it matters

The settlement addresses failures in data security protocols and account safeguards, specifically involving unauthorized access by a former employee and vulnerabilities linked to recycled phone numbers. It establishes a financial outcome for users affected during a six-year period of alleged oversight.

Eligible users are receiving up to $2,500 for documented out-of-pocket losses. Additionally, claimants are being compensated for time spent addressing account issues at a rate of $25 per hour, capped at three hours.

The players

Cash App

A mobile payment service provider and division of Block that offers peer-to-peer money transfers and financial tools.

Block

A financial technology company that operates Cash App and the Square point-of-sale platform.

The details

The litigation centered on two distinct security failures: a 2022 incident where a former employee accessed user account data without authorization, and a 2023 breach where external actors gained access using recycled phone numbers. These incidents prompted the class-action suit alleging that Cash App and its parent firm, Block, failed to maintain adequate safeguards to protect user information. Payments are being processed for all claims that met the eligibility criteria and were submitted by the November 2024 deadline.

Timeline

  1. Aug. 23, 2018, to Aug. 20, 2024: Window for eligible data security incidents.

  2. 2022: Unauthorized data access by a former employee occurred.

  3. 2023: Unauthorized account access via recycled phone numbers took place.

  4. November 2024: Deadline to file a settlement claim.

  5. October 2026: Distribution of settlement payments.

The Tech Race

This resolution follows a pattern of heightened legal and regulatory scrutiny regarding the security of digital wallets and peer-to-peer payment platforms. It highlights the growing importance of account recovery standards, particularly as firms move to mitigate risks associated with mobile identity and recycled phone numbers.

Users who successfully filed claims before the November 2024 deadline will receive payments throughout October 2026. These funds are distributed directly via the official settlement portal, and no further action is required from those who have already completed the filing process.

The takeaway

This case underscores the financial liability firms face when account security mechanisms are exploited by insiders or through recycled credentials. Users should continue to monitor account activity logs and enable multi-factor authentication to prevent unauthorized access.

Further reading

For more on the evolving standards for financial data protection, visit the Cybersecurity section.

Source note: This article includes information reported by New Haven Register.

Live Poll

Do you trust digital financial platforms to adequately protect your personal data and account security?