The Regents-Accellion data breach settlement is a $5.8 million class action resolution in Erazo v. The Regents of the University of California, resolving claims that the University of California failed to protect the personal information of roughly 353,265 students, employees, retirees, and program participants whose data was exposed during a late-2020 cyberattack on the Accellion File Transfer Appliance used by the UC Office of the President. The court granted final approval, and payments to class members who filed valid claims began going out in early 2026.1Desert Sun. Over 350,000 Were Paid in a Class Action Against Erazo v. The Regents of the University of California The UC Regents did not admit fault.
Who the Settlement Covers
The class is defined as the approximately 353,265 individuals who received notice from UC that their information may have been disclosed during the December 2020 to January 2021 breach of the Accellion File Transfer Appliance used by the UC Office of the President.2Regents-Accellion Data Breach Settlement. Settlement Home Page That group includes current and former UC students, employees, retirees, dependents, and people who took part in UC programs.3Office of the California Attorney General. UCOP General Notice of Data Breach
The data exposed in the breach included names, addresses, Social Security numbers, driver’s license and passport information, bank routing and account numbers, health and disability information, and birthdates.4UCLA Office of the Chief Information Security Officer. Accellion Security Incident – UCOP Responses to the 2020 University of California Undergraduate Experience Survey and medical records for members of the UC community were also compromised.2Regents-Accellion Data Breach Settlement. Settlement Home Page
What Claimants Can Receive
Class members who filed a valid claim could seek payment in more than one category.
- A flat $150 statutory payment for individuals with potential claims under California’s Confidentiality of Medical Information Act.
- Reimbursement of up to $10,000 per person for documented out-of-pocket losses tied to the breach — bank fees, credit monitoring costs, or identity theft expenses incurred after December 24, 2020.
- Compensation for time spent dealing with breach-related problems at $30 per hour, with a five-hour minimum.
- A pro rata share of any money left in the fund after those payments and administrative costs, distributed equally among participating class members as long as each share came to at least $5.
Claims for out-of-pocket costs or lost time required supporting documentation such as receipts or bank statements. Personal declarations by themselves were not enough.5Regents-Accellion Data Breach Settlement. Long-Form Notice
The $5.8 million fund also covers litigation expenses, court-approved attorneys’ fees, and administrative costs. The exact breakdown of those amounts was not publicly detailed.1Desert Sun. Over 350,000 Were Paid in a Class Action Against Erazo v. The Regents of the University of California
Cybersecurity Changes UC Agreed To
Beyond the money, the UC Regents agreed to maintain enhanced cybersecurity measures for at least two years. Those steps include retiring the Accellion File Transfer Appliance entirely, migrating to new file transfer products, increasing monitoring of data systems, and running employee security awareness training.1Desert Sun. Over 350,000 Were Paid in a Class Action Against Erazo v. The Regents of the University of California
Key Dates and Current Status
The parties reached the settlement agreement on May 29, 2025. The deadline to file a claim, opt out, or object was October 20, 2025.6Regents-Accellion Data Breach Settlement. Important Dates Motions for final approval and for attorneys’ fees were filed on September 15, 2025, with the final fairness hearing set for December 9, 2025. The court then issued a final approval order.7Regents-Accellion Data Breach Settlement. Court Documents
By March 2026 the case had moved into distribution. Class members who filed valid claims and did not opt out were notified by email about their payments.1Desert Sun. Over 350,000 Were Paid in a Class Action Against Erazo v. The Regents of the University of California The claim filing window has closed, so people who did not submit a claim by the October 20, 2025 deadline are not eligible to receive a payment from this fund.6Regents-Accellion Data Breach Settlement. Important Dates
How the Breach Happened
The UC Office of the President used the Accellion File Transfer Appliance to move sensitive files. Between mid-December 2020 and January 2021, attackers exploited previously unknown vulnerabilities in that legacy tool to steal data from users worldwide, then tried to extort victims by threatening to publish the stolen information.8CISA. Exploitation of Accellion File Transfer Appliance UC disclosed the breach to the university community in early April 2021, sent individual notifications by mail and email, and offered affected individuals one year of free credit monitoring and identity theft protection through Experian.9UC Merced. Accellion Data Breach
This settlement resolves claims against the UC Regents only. A separate $8.1 million settlement involving Accellion itself (now Kiteworks) explicitly did not cover claims against Accellion’s individual customers, including the University of California.10SecurityWeek. Accellion Reaches $8.1 Million Settlement Over FTA Data Breach
Settlement Administrator Contact
CPT Group is administering the settlement. Class members with questions about a payment or claim status can call 1-888-317-2945 or email Regents-AccellionDataBreachSettlement@cptgroup.com.7Regents-Accellion Data Breach Settlement. Court Documents