Bank of America and Ernst & Young LLP have agreed to a $2.5 million class action settlement covering roughly 198,000 people whose personal information was exposed when the 2023 MOVEit cyberattack hit files EY was handling for the bank. Under the Bank of America MOVEit settlement, class members can choose a flat $100 cash payment or reimbursement for documented out-of-pocket losses, and everyone in the class is eligible for two years of credit monitoring and identity theft protection.1Cohen Milstein. BofA, EY Strike $2.5M Deal to Settle MOVEit Breach Claims2Bloomberg Law. Bank of America, Ernst & Young Pay $2.5 Million in MOVEit Case
What Class Members Can Claim
There are two ways to take money from the fund, and you pick one:
- A flat $100 cash payment, with no requirement to document any specific harm.
- Reimbursement for documented out-of-pocket losses tied to the breach, as an alternative to the flat payment.
On top of the cash option you select, class members are eligible for two years of credit monitoring and identity theft protection services funded through the settlement.1Cohen Milstein. BofA, EY Strike $2.5M Deal to Settle MOVEit Breach Claims Bank of America previously offered affected customers a complimentary two-year membership in Experian’s IdentityWorks credit monitoring and identity theft restoration service after the breach was disclosed.3Going Concern. EY Bank of America Security Breach
Who Is in the Class
The settlement class covers approximately 198,000 individuals whose data was compromised through EY’s use of MOVEit Transfer.1Cohen Milstein. BofA, EY Strike $2.5M Deal to Settle MOVEit Breach Claims4Delaware Attorney General. EY US Notice to Delaware Attorney General5CISA. CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability
The exposed information included names, addresses, financial account numbers, debit and credit card numbers, Social Security numbers, and government-issued identification numbers.3Going Concern. EY Bank of America Security Breach EY began notifying affected individuals on August 9, 2023. A filing with the Maine Attorney General put the number of affected Bank of America customers at 30,210, while the total settlement class is larger.6teiss. Ernst & Young Says MOVEit Transfer Hack Impacted Over 30,000 Bank of America Customers
Key Dates and Approval
Bank of America and EY filed an unopposed motion for preliminary approval of the $2.5 million settlement on April 22, 2026, with the two companies jointly funding the payout.2Bloomberg Law. Bank of America, Ernst & Young Pay $2.5 Million in MOVEit Case U.S. District Judge Allison D. Burroughs, who presides over the consolidated MOVEit multidistrict litigation in the District of Massachusetts, granted preliminary approval on April 29, 2026. A final approval hearing is scheduled for October 15, 2026.7PACER Monitor. Morris et al v. Progress Software Corporation The case is part of In re: MOVEit Customer Data Security Breach Litigation, MDL No. 1:23-md-03083.8U.S. District Court, District of Massachusetts. MDL Order No. 19
Not the Same as the Infosys McCamish Breach
If you received a Bank of America breach notice in early 2024, it may not relate to this settlement. A separate incident involving a different third-party provider, Infosys McCamish Systems, affected 57,028 Bank of America customers with deferred compensation plans after a compromise on or around November 3, 2023. Affected customers were notified on February 2, 2024, and offered two years of identity theft protection.9Cybersecurity Dive. Bank of America Customer Data Breach Tied to Infosys McCamish Systems10American Banker. Data Breach Affects 57,000 Bank of America Accounts That breach is a separate matter from the EY/MOVEit settlement described here.