πŸ³οΈβ€βš§οΈ trans rights are human rights πŸ³οΈβ€βš§οΈ
Theme

30,000 Social Security Numbers Stolen: The Settlement That Values Your Identity at $40

30,000 Social Security Numbers Stolen: The Settlement That Values Your Identity at $40 | NJ Lenders Corp Data Breach

TL;DR

  • On August 18, 2025, a cyberattack on NJ Lenders Corp compromised files containing the names and Social Security numbers of approximately 30,000 individuals.
  • The company waited nearly two months to disclose the breach publicly on October 10, 2025.
  • A class action lawsuit (Case No. PAS-L-001210-26) was filed in Superior Court for Passaic County, New Jersey.
  • The proposed settlement offers victims either $40 cash or reimbursement for “documented losses” up to $2,500β€”but total victim compensation is capped at $100,000.
  • Class counsel is seeking $280,000 in attorneys’ fees and costsβ€”2.8 times the maximum amount allocated for all victims combined.
  • All class members receive one year of credit monitoring. Your Social Security number is permanent. The monitoring expires.
  • By accepting the settlement, victims release NJ Lenders Corp and all affiliated entities from all liability related to the breach. The company admits no wrongdoing.

The settlement administrator is Simpluris, Inc. The final approval hearing is scheduled but not yet publicly dated. The legal mechanics of how corporations convert mass privacy violations into accounting line items are detailed in Section 4.

The Breach Timeline: What Happened and When They Told You

On or about August 18, 2025, an unauthorized party accessed the computer systems of NJ Lenders Corp, a privately-owned residential mortgage banker operating out of Little Falls Township, New Jersey. The company’s own subsequent investigation revealed that files containing the names and Social Security numbers of approximately 30,000 individuals were potentially impacted.

Notice the word “potentially.” This is settlement language. It creates ambiguity where none exists in the lived experience of the 30,000 people whose most sensitive identifying information was accessed by an unknown hostile actor. Your SSN was either compromised or it wasn’t. The legal document uses “potentially” because certainty would establish liability.

NJ Lenders Corp did not issue public disclosure until October 10, 2025β€”nearly two months after the breach occurred. During that interval, the stolen data existed in an unknown threat actor’s possession while the impacted individuals remained unaware that their identities were actively at risk.

“On about August 18, 2025, Defendant experienced a Data Incident. In response, Defendant launched an investigation which revealed that the names and Social Security Numbers of approximately 30,000 individuals were potentially impacted.”
β€”Settlement Agreement, Procedural History, ΒΆ3

Following public disclosure in October 2025, multiple class action lawsuits were filed in the United States District Court for the District of New Jersey. The plaintiffsβ€”Patrick Castenie, David Garcia, and Brandy Albaneseβ€”filed a motion to consolidate the actions, which was granted on October 29, 2025. A consolidated complaint was filed on January 2, 2026.

Then something interesting happened. The parties began discussing settlement “to conserve resources for the benefit of those who may have been impacted in the Data Incident.” By April 2026, the case had been dismissed from federal court and re-filed in Superior Court for Passaic County, New Jersey (Case No. PAS-L-001210-26). The complaint alleges negligence, negligence per se, unjust enrichment, breach of implied contract, and breach of fiduciary duty on behalf of a national class.

The settlement was reached before any formal discovery process. Before depositions. Before document production. Before any adversarial testing of the defendant’s claims. The agreement explicitly states that NJ Lenders Corp “does not in any way acknowledge, admit to, or concede any of the allegations made in any of the complaints” and that “nothing contained in this Agreement shall be used or construed as an admission of liability.”

The Settlement Economics: Who Gets Paid and How Much

Let’s examine the financial architecture of this settlement with precision.

For the Victims

Victims may choose between two cash payment options:

  • Cash Payment A – Documented Losses: Victims who can prove “actual, documented out-of-pocket losses related to the Data Incident” may claim reimbursement up to $2,500. Eligible losses include identity theft or fraud losses, credit report fees, credit monitoring fees, credit freeze costs, ID replacement expenses, and postage for contacting financial institutions. Personal certifications, declarations, or affidavits do not constitute “reasonable documentation” but may be included to provide “clarification, context, or support for other submitted reasonable documentation.” You cannot claim expenses already reimbursed by a third party.
  • Cash Payment B – Alternate Cash: A flat $40 payment with no documentation required.

Here is the critical provision: “Claims for compensation of Documented Losses and Alternative Cash Payment is to be capped at $100,000. In the event Valid Claims exceed $100,000, those claims will be reduced pro rata.”

If every one of the 30,000 victims files a claim for the $40 flat payment, the total owed would be $1,200,000. The settlement caps total victim compensation at $100,000. This means that if participation is even moderately high, pro rata reduction will cut individual payments to a fraction of the advertised amount.

Do the math: $100,000 divided by 30,000 potential claimants equals $3.33 per person. That is the maximum average payout under this settlement if every victim participates.

$3.33
The maximum average settlement payout per victim if all 30,000 individuals file claims under the $100,000 total compensation cap

Additionally, all class members automatically receive enrollment codes for one year of “CyEx Financial Shield Complete” credit monitoring, which includes up to $1 million in identity theft insurance coverage and one-bureau credit monitoring. Enrollment codes were distributed, and activation instructions will be provided after final approval. The estimated cost of notice and settlement administration is $56,414, paid by the defendant.

For the Attorneys

Class counselβ€”Kenneth J. Grunfeld, Leanna A. Loginov, and Mark K. Svenssonβ€”will request the Court approve attorneys’ fees and costs of up to $280,000. This amount will be paid by NJ Lenders Corp separately from victim compensation.

Let that sink in. The lawyers are seeking 2.8 times the total amount allocated for all 30,000 victims combined.

Class counsel will also request $2,000 service awards for each of the three named plaintiffs. These payments are also separate from the victim compensation pool and will be paid by the defendant.

$280,000
Attorneys’ fees and costs requested by class counselβ€”nearly three times the $100,000 cap on total victim compensation

For the Defendant

NJ Lenders Corp admits no liability or wrongdoing. The settlement releases the company and “each entity which is controlled by, controlling or under common control with Defendant and their respective past, present, and future direct and indirect heirs, assigns, associates, corporations, investors, owners, parents, subsidiaries, affiliates, insurers, reinsurers, divisions, officers, directors, shareholders, members, agents, servants, employees, partners, predecessors, successors, managers, administrators, executors, and trustees” from all claims related to the breach.

This release is comprehensive. It bars victims from pursuing “any and all actual, potential, filed or unfiled, known or unknown, fixed or contingent, claimed or unclaimed, suspected or unsuspected claims, demands, liabilities, rights, causes of action, damages, punitive, exemplary or multiplied damages, expenses, costs, indemnities, attorneys’ fees and/or obligations, whether in law or in equity, accrued or unaccrued, direct, individual or representative, of every nature and description whatsoever” against the released parties.

The settlement explicitly includes a waiver of California Civil Code section 1542, which normally protects plaintiffs from unknowingly releasing claims they are not yet aware of. Victims are waiving the right to sue for harm they haven’t yet discovered stemming from this breach.

The agreement further states: “The Parties understand and acknowledge they: (a) have performed an independent investigation of the allegations of fact and law made in connection with this Action; and (b) that even if they may hereafter discover facts in addition to, or different from, those that they now know or believe to be true with respect to the subject matter of the Action as reflected in this Agreement, that will not affect or in any respect limit the binding nature of this Agreement.”

Translation: Even if substantially worse facts come to light after this settlement is approved, it cannot be challenged or reopened.

The Non-Financial Ledger: What the Settlement Doesn’t Measure

A Social Security number is not a password. You cannot change it. It is not multi-factor authentication. It is a permanent government-issued identifier tied to your tax records, credit history, employment verification, medical records, and eligibility for government benefits. When it is compromised, the exposure is permanent.

The settlement offers one year of credit monitoring. One year. For a piece of information that will remain valid and exploitable for the rest of your life. This is not a reasonable trade. This is not proportional harm mitigation. This is a legal maneuver designed to create the appearance of accountability while insulating the defendant from long-term liability.

Consider what is not measured in this settlement:

  • The time victims will spend over the next decade freezing and unfreezing credit with all three bureaus every time they apply for a loan, open a bank account, or change jobs.
  • The stress of monitoring financial accounts indefinitely for signs of fraud.
  • The increased vulnerability to synthetic identity theft, where stolen SSNs are combined with fake information to create new fraudulent identities.
  • The potential for these SSNs to be sold, resold, and traded on dark web marketplaces for years.
  • The fact that many victims may not experience fraud immediately, but years later, long after the one-year monitoring has expired.

The settlement acknowledges none of this. It treats the exposure of 30,000 Social Security numbers as a discrete, time-limited event with a defined remediation cost. This is a category error. It is a fundamental misunderstanding (or a deliberate misrepresentation) of the nature of the harm.

“Settlement Class Members shall not be reimbursed for expenses if they have been reimbursed for the same expenses by another source, including compensation provided in connection with the credit monitoring and identity theft protection product offered as part of the notification letter provided by Defendant or otherwise.”
β€”Settlement Agreement, Section IV, ΒΆ65(a)

This clause means that if a victim already signed up for the credit monitoring NJ Lenders offered immediately after the breach, they cannot claim those costs as documented losses in this settlement. The company’s initial response becomes a shield against later compensation.

Legal Receipts: What the Court Documents Actually Say

The settlement agreement is a 36-page document that functions as both a legal instrument and a masterclass in liability deflection. Here are key excerpts, verbatim:

On Admissions of Fault

“Defendant does not in any way acknowledge, admit to, or concede any of the allegations made in any of the complaints or in the Complaint, and disclaims and denies any fault or liability, or any charges of wrongdoing that have been or could have been asserted in the Complaint. Nothing contained in this Agreement shall be used or construed as an admission of liability, and this Agreement shall not be offered or received in evidence in any action or proceeding in any court or other forum as an admission or concession of liability or wrongdoing of any nature or for any other purpose other than to enforce the terms of this Agreement.”
β€”Settlement Agreement, Section I, ΒΆ10

On What Victims Release

“‘Released Claims’ means any and all actual, potential, filed or unfiled, known or unknown, fixed or contingent, claimed or unclaimed, suspected or unsuspected claims, demands, liabilities, rights, causes of action, damages, punitive, exemplary or multiplied damages, expenses, costs, indemnities, attorneys’ fees and/or obligations, whether in law or in equity, accrued or unaccrued, direct, individual or representative, of every nature and description whatsoever, based on any federal, state, local, statutory or common law or any other law, against the Released Parties, or any of them, arising out of or relating to actual or alleged facts, transactions, events, matters, occurrences, acts, disclosures, statements, representations, omissions or failures to act relating to the Data Incident or the claims alleged in the Action.”
β€”Settlement Agreement, Section II, ΒΆ50

On the Pro Rata Reduction

“Claims for compensation of Documented Losses and Alternative Cash Payment is to be capped at $100,000. In the event Valid Claims exceed $100,000, those claims will be reduced pro rata.”
β€”Settlement Agreement, Section IV, ΒΆ64

On Binding Future Discoveries

“The Parties understand and acknowledge they: (a) have performed an independent investigation of the allegations of fact and law made in connection with this Action; and (b) that even if they may hereafter discover facts in addition to, or different from, those that they now know or believe to be true with respect to the subject matter of the Action as reflected in this Agreement, that will not affect or in any respect limit the binding nature of this Agreement. All Parties recognize and acknowledge they reviewed and analyzed data that they and their experts used to make certain determinations, arguments, and settlement positions. The Parties agree this Settlement is fair, reasonable, and adequate, and will not attempt to renegotiate or otherwise void or invalidate or terminate the Settlement irrespective of what any unexamined data later shows.”
β€”Settlement Agreement, Section XV, ΒΆ127

This final clause is particularly striking. The parties are contractually agreeing that even if unexamined data reveals substantially worse facts about the breachβ€”greater exposure, additional compromised information, evidence of negligenceβ€”the settlement cannot be challenged. This transforms a legal agreement into a permanent shield against accountability, regardless of what the truth turns out to be.

Societal Impact Mapping: The Three-Domain Collapse

Economic Inequality: The Commodification of Identity Theft

This settlement crystallizes a brutal economic reality: Your personal data has a market value, and that value is determined not by the harm it causes you when stolen, but by what a defendant is willing to pay to make the legal problem disappear.

The $100,000 victim compensation cap represents a calculated risk assessment. NJ Lenders Corp and its counsel determined that the cost of defending this litigation through trial, plus the risk of a larger judgment, exceeds $100,000 in expected value. The settlement is not designed to make victims whole. It is designed to be the cheapest viable path to ending legal exposure.

This creates a perverse incentive structure. Companies facing data breach liability have no reason to offer victims more than the minimum amount required to achieve settlement approval. Judges, facing crowded dockets and limited resources, have institutional pressure to approve settlements that resolve cases efficiently. Class counsel, operating on a contingency basis, face pressure to accept settlements that guarantee payment rather than risk trial.

The only party without a seat at this negotiating table is the individual victim, whose identity has been permanently compromised and whose long-term risk cannot be quantified in a legal settlement negotiated months after the breach.

Public Health: The Invisible Epidemic of Financial Trauma

Data breaches are often discussed in technical or legal termsβ€”encryption failures, access controls, settlement values. What is rarely discussed is the psychological and physiological toll of financial identity theft.

Research on fraud victims consistently shows elevated rates of anxiety, depression, and stress-related physical symptoms. Victims report feelings of violation, helplessness, and chronic hypervigilance. The knowledge that your SSN is circulating in criminal networks creates a baseline level of ambient stress that does not resolve when the initial fraud is addressed.

This settlement offers no mental health resources. No counseling. No acknowledgment that identity theft is a form of financial trauma. It treats the breach as a discrete economic event rather than an ongoing attack on financial security and peace of mind.

The one-year monitoring window implicitly tells victims: “Your trauma has a 12-month expiration date.” This is not evidence-based. This is legal convenience.

Environmental Degradation: The Pollution Metaphor

Data breaches are environmental hazards. Once personal information is released into the wild, it does not degrade. It does not biodegrade. It persists indefinitely, circulating through criminal networks, being aggregated with other stolen data sets, and creating compounding risk over time.

The environmental parallel is precise. Just as industrial polluters externalize the long-term costs of contamination onto affected communities and future generations, companies that suffer data breaches externalize the long-term costs of identity theft onto individual victims.

NJ Lenders Corp’s settlement offerβ€”one year of monitoring for a permanent exposureβ€”is the equivalent of a polluter offering to test your drinking water for twelve months after dumping toxic waste into your aquifer. The contamination remains. The risk remains. The monitoring does not.

And just as pollution disproportionately harms low-income communities with fewer resources to relocate or litigate, data breaches disproportionately harm individuals with fewer resources to purchase comprehensive identity protection, hire attorneys, or absorb the time costs of fraud remediation.

The “Cost of a Life” Metric: Valuing the Unvaluable

$3.33
The average settlement value of permanently compromising your government-issued permanent identifier, calculated at maximum claim participation. Less than the cost of a gallon of milk. Less than a single transaction fee. This is what the legal system determined your Social Security number is worth.

Context: The black market value of a full identity packageβ€”SSN, name, date of birth, addressβ€”ranges from $40 to $200 depending on credit score and completeness of information. The criminals who stole this data can sell it for more than the victims will receive in compensation.

Context: The IRS estimates that identity theft tax refund fraud costs the federal government approximately $5.8 billion annually. A single fraudulent tax return filed using a stolen SSN can yield $3,000 to $5,000 to the perpetrator.

Context: The average cost to a victim of resolving identity theft is estimated at $1,100 in out-of-pocket expenses, plus 200 hours of time spent on remediation over six months.

The settlement offers $40 or, if you can document losses, up to $2,500 from a pool that will be reduced pro rata if claims exceed $100,000 total. This is not restorative justice. This is accounting.

What Now? The Watchlist and the Path Forward

If You Are Affected

If you received notification that your information was compromised in this breach, you have limited options:

  • File a claim by the deadline listed in your notice (likely 30 days before the final approval hearing). Submit it online at the settlement website administered by Simpluris, Inc.
  • Freeze your credit with all three major bureaus (Equifax, Experian, TransUnion) immediately if you haven’t already. This is free and prevents new accounts from being opened in your name.
  • Request your free annual credit report from AnnualCreditReport.com every four months, rotating through the three bureaus, so you have year-round monitoring without paying for a service.
  • File your taxes early every year to reduce the window for tax refund fraud.
  • Consider an IRS Identity Protection PIN, which adds an extra layer of security to your tax return.

Regulatory Watchlist

The following entities have jurisdiction over data breach notification, cybersecurity standards, and consumer protection related to this incident:

  • Federal Trade Commission (FTC) – Enforces data security standards under Section 5 of the FTC Act
  • Consumer Financial Protection Bureau (CFPB) – Regulates consumer financial services including mortgage lenders
  • New Jersey Division of Consumer Affairs – Enforces state data breach notification laws
  • Office of the Comptroller of the Currency (OCC) – Regulates national banks and federal savings associations (if applicable)

You can file complaints with these agencies even if you participate in the settlement. While the settlement bars you from suing the company, it does not prevent you from reporting the incident to regulators.

Structural Resistance

This settlement is a symptom of a system that treats data breaches as inevitable costs of business rather than preventable failures of corporate responsibility. Changing this requires action at multiple levels:

  • Support federal data breach notification standardization that eliminates the two-month disclosure delay seen in this case.
  • Advocate for mandatory minimum compensation floors in data breach settlements that reflect the permanent nature of SSN exposure.
  • Push for “loser pays” provisions in data breach class actions so that defendants who lose at trial pay plaintiffs’ attorneys’ fees, reducing the pressure on class counsel to accept low settlements.
  • Demand that credit monitoring duration match the duration of riskβ€”meaning lifetime monitoring for SSN breaches, not one-year plans.
  • Support mutual aid networks that help victims navigate fraud remediation, credit disputes, and identity restoration outside the for-profit credit monitoring industry.

Most importantly: Understand that your participation in this settlement is not consent to this system. You are making a rational choice within a structure you did not design and cannot individually change. The failure is not yours. The failure is the legal framework that makes settlements like this one possible.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2126