A proposed settlement covering approximately 23,499 people would offer claim-dependent compensation after a February 2025 cybersecurity incident. The same agreement would extinguish a sweeping range of related claims if the court approves it.
TL;DR
- Plaintiffs allege AIS InfoSourceβs systems were affected by cybercriminals between February 16 and February 21, 2025, potentially involving names, Social Security numbers and financial account numbers.
- The proposed settlement class contains approximately 23,499 people who received notice that their information may have been involved.
- Eligible class members could claim two years of one-bureau credit monitoring, up to $5,000 for documented losses and up to $80 for time spent responding to the incident.
- AIS denies wrongdoing and liability. The supplied PDF contains a signed settlement agreement but only proposed, unsigned preliminary- and final-approval orders.
- Class members who remain in the settlement would release AIS, named clients and a broad group of related parties from known and unknown claims tied to the incident.
- The agreement permits AIS to terminate the settlement if more than 25 class members opt out, although termination would be optional rather than automatic.
The practical question is not simply what the settlement offers. It is whether the claim process, release and still-unresolved court review produce a fair exchange for the people whose information may have been exposed.
Transparency Notice
This investigation is based on the partiesβ settlement agreement and its exhibits in Allen, et al. v. AIS InfoSource, L.P., Case No. 2026-18098. The agreement records allegations made by the plaintiffs, AISβs denial of wrongdoing and terms that remain subject to court approval. The attached preliminary- and final-approval orders are labeled βproposed,β contain blank dates and judicial signature lines, and should not be confused with entered court orders. The supplied document therefore does not establish that AIS was liable, that the settlement has been approved or that benefits are currently available.
The Facts
According to the settlement agreement, plaintiffs allege that cybercriminals affected AIS InfoSourceβs computer systems during a six-day period beginning February 16, 2025. They contend that the incident potentially involved information belonging to current and former customers of companies using AISβs services.
The categories were not obscure marketing preferences or an abandoned username. The agreement identifies names, Social Security numbers and financial account numbers as information allegedly affected.
A draft class notice goes somewhat further in its description, saying a criminal third party gained unauthorized access to AISβs network and that files containing private information were potentially accessed. Because that language appears in a proposed notice exhibit, this article treats it as the partiesβ proposed accountβnot as an independent forensic finding by the court.
AIS began notifying affected people on July 21, 2025, the agreement says. The source does not disclose when AIS first discovered the incident, what security control allegedly failed, whether information was exfiltrated, how many people suffered misuse or how the incident was contained.
From Incident to Settlement
The litigation moved toward settlement without a trial or a ruling on the merits. The chronology matters because the proposed resolution emerged after informal information exchange and mediationβnot after a court determined what happened inside AISβs systems.
Plaintiffs allege AISβs systems were affected by cybercriminals during the data incident.
The agreement says AIS began notifying plaintiffs and proposed class members.
Three plaintiffs filed separate federal actions against AIS in the Southern District of Texas.
The plaintiffs moved to consolidate the federal cases.
The federal litigation was stayed pending consolidation.
After informal discovery and an exchange of information, the parties mediated and reached agreement on principal settlement terms.
The plaintiffs filed a class-action complaint in the 189th Judicial District Court in Harris County, Texas, alleging negligence, negligence per se, invasion of privacy and unjust enrichment.
What the Plaintiffs Alleged
The settlement agreement summarizes the state-court claims but does not reproduce the complaintβs detailed factual allegations. It says the plaintiffs alleged negligence, negligence per se, intrusion upon seclusion or invasion of privacy, and unjust enrichment.
In plain English, those theories contend that AIS failed to handle private information with legally adequate care, violated duties plaintiffs say applied to that information, intruded upon privacy interests and benefited in a way the plaintiffs contend would be unjust to retain.
The proposed final-order template characterizes the case as alleging that AIS failed to safeguard private information belonging to its own current and former customers and those of institutional clients, causing injury to the class. That remains an allegation. The supplied record contains no judicial finding that AISβs safeguards were inadequate or that its conduct caused compensable harm.
βNo action taken by the Parties either previously or in connection with the negotiations or proceedings connected with this Agreement shall be deemed or construed to be an admission of the truth or falsity of any claims or defenses heretofore made, or an acknowledgment or admission by any party of any fault, liability, or wrongdoing of any kind whatsoever.β
Settlement Agreement, paragraph 75
What Class Members Could Receive
The agreement uses a claims-made structure: class members must submit valid, timely claim forms to receive benefits. It does not identify a single fixed settlement fund. That means the document supplies per-person benefits and payment rules, but not a guaranteed aggregate payout to the class.
Credit monitoring
Participating class members could enroll in two years of Financial Shield Complete with one-bureau credit monitoring. The notice and claim-form exhibits identify the service as CyEx Financial Shield Complete and describe $1 million in financial-fraud insurance, monitoring for suspicious financial activity and access to a fraud-resolution agent.
The agreement says activation codes would be sent within 14 days of the settlementβs effective date and remain usable for 180 days.
Documented losses
A claimant could seek up to $5,000 for unreimbursed losses fairly traceable to the incident. Listed examples include identity-theft or fraud losses, professional fees, credit-repair costs, expenses for freezing or unfreezing credit, monitoring purchased after the incident, postage, copying and mileage.
Receipts, bank statements or other third-party records would be required. Self-prepared documents could provide context but would not be sufficient on their own.
Lost time
Class members could claim up to four hours at $20 an hourβa maximum of $80βfor time spent responding to issues raised by the incident. Unlike documented-loss claims, this benefit would require an attestation rather than third-party receipts.
The settlement administrator would review claims for completeness and plausibility. If it found a claim deficient, the claimant would generally receive 21 days to try to cure the problem. If the administrator concluded that the attempted cure still failed, its determination would be final under the agreement.
The headline maximum is $5,000, but it is not an automatic check. Reimbursement depends on proof of an unreimbursed loss, a connection to the incident and approval by the settlement administrator.
The Price of Doing Nothing
The draft notice makes the choice unusually plain: doing nothing would produce no settlement benefit. Unless a person opted out, however, that person would remain in the class and become bound by the settlement if it received final approval.
The release is broad. It covers claims that result from, arise from or relate to the incident, AISβs information-security practices, its maintenance or storage of personal information, and conduct that was or could have been alleged in the litigation. It includes known and unknown claims.
The released parties extend beyond AIS. The agreement includes AISβs parents, subsidiaries, officers, employees, insurers, contractors and other related parties. It also expressly defines a group of AIS clients that includes entities associated with Ally, Capital One, Ford, Synchrony and T-Mobile, among others.
The agreement additionally calls for a waiver of protections similar to California Civil Code section 1542, which ordinarily limits the reach of a general release over claims a person does not know or suspect exist. In practical terms, participating class members would be trading not only the claims currently understood, but also certain incident-related claims that might become clearer later.
The settlement offers real, claim-dependent benefits. It also asks class members to release a broad field of claims, including unknown ones.
The Fine Print With Real Leverage
One provision gives AIS the option to terminate the settlement if more than 25 class members submit valid opt-out requests. Termination would not happen automatically, but the threshold is small compared with an estimated class of approximately 23,499 people.
If the agreement were terminated, the parties would return to their pre-settlement positions. Settlement-only class certification would become void, and AIS would retain the right to contest whether any litigation class should be certified.
The agreement also contains a broad release of unknown incident-related claims and says the release was separately bargained for. Another provision restricts the parties and their lawyers from publicizing the settlement except through specified court filings, legally authorized disclosures and approved notice-related information.
None of those terms proves the settlement is unfair. They do show why the agreement must be read as an exchange rather than a giveaway: benefits on one side, procedural finality on the other.
Fees, Awards and Administration
Class counsel intends to seek up to $325,000 in attorneysβ fees and litigation expenses. The three class representatives could each receive up to $3,000 for their work, subject to court approval. AIS would also pay notice and settlement-administration expenses.
The court could reduce or deny the requested fees or service awards without unraveling the rest of the agreement. In other words, the settlementβs continued existence would not depend on counsel or the named plaintiffs receiving the full amounts requested.
What the Court Hasβand Has NotβDecided
The supplied PDF includes templates for preliminary and final approval, but both are visibly incomplete. Dates, hearing information and the judgeβs signature remain blank. Statements inside the proposed final orderβincluding template language about objections, opt-outs, fee awards and final certificationβare requested findings, not established events.
Preliminary approval, if granted, would generally mean the court finds the proposal sufficient to send notice and begin the claims, objection and opt-out process. It would not establish that AIS committed wrongdoing, and it would not finally determine that the settlement is fair.
Final approval would come later, after notice and an opportunity for class members to respond. Only then could the court approve the settlement, certify the class for settlement purposes, authorize the release and dismiss the claims with prejudice.
The distinction is decisive: the parties have signed an agreement, but the supplied source does not show an entered order approving it.
The Approval Process Ahead
The agreement ties its deadlines to an eventual preliminary-approval order rather than supplying completed calendar dates. If preliminary approval occurs, the schedule would generally work as follows:
- AIS would provide the class list to the administrator within 10 days.
- Notice would be issued within 30 days.
- Objections and opt-out requests would be due 60 days after the notice deadline.
- Claims would be due 90 days after the notice deadline.
- The final-approval hearing would occur no sooner than 120 days after preliminary approval.
- Approved fees, service awards and eligible cash claims would be paid after the settlement becomes effective under the agreementβs conditions.
The notice forms in the PDF still contain placeholders for the website, telephone number, mailing address and deadlines. Readers should not treat those drafts as active filing instructions.
What a Legitimate Fix Looks Like
Editorial analysisThe agreement can compensate some people, but it does not reveal enough about the underlying security failure to show how recurrence would be prevented. A credible response would pair individual relief with verifiable operational changes.
Regulatory Track
- Require incident notices to distinguish clearly between unauthorized access, confirmed acquisition and suspected exposure.
- Require disclosure of discovery dates, notification delays and the categories of affected records.
- Publish measurable remediation commitments where doing so would not expose active security defenses.
Legislative Track
- Create consistent minimum notification rules across jurisdictions.
- Set enforceable baseline safeguards for companies processing sensitive information on behalf of institutional clients.
- Require clearer explanations of how claims-made settlements distribute value and what rights non-claimants release.
Corporate Governance Track
- Minimize the sensitive data retained and document why each category remains necessary.
- Commission independent testing of post-incident controls and report meaningful results to affected clients.
- Assign board-level responsibility for vendor security, incident response and notification performance.
What to Watch
- The Harris County District Court: Whether it enters preliminary approval and whether any eventual order changes the settlement terms or notice plan.
- AIS InfoSource: Whether the final court record provides additional facts about the incident, remediation or timing of discovery.
- The settlement administrator: The final website, contact details, approved claim form and actual deadlines. The supplied drafts still contain placeholders.
- Class counsel: The eventual fee-and-expense application and the evidence offered to support the requested amount.
- The approval record: The number of claims, objections and opt-outs, including whether the more-than-25 opt-out termination provision becomes relevant.
- The final approval hearing: Whether the court finds the settlement fair, approves the release and certifies the class solely for settlement purposes.
The unresolved issue is concrete: the document establishes what the parties want the settlement to become, but not whether the court will authorize that exchange or how many affected people will successfully claim its benefits. Until entered orders and completed notices appear, the proposal remains a negotiated blueprint rather than a finished remedy.
The source document for this investigation is attached below.



