πŸ³οΈβ€βš§οΈ trans rights are human rights πŸ³οΈβ€βš§οΈ
Theme

Step right up! Here’s everything worth knowing about the InfoSource data breach settlement!

Privacy infrastructure under scrutiny

A proposed settlement covering approximately 23,499 people would offer claim-dependent compensation after a February 2025 cybersecurity incident. The same agreement would extinguish a sweeping range of related claims if the court approves it.

Document review Harris County, Texas Proposed class settlement Cybersecurity Privacy Class action

TL;DR

  • Plaintiffs allege AIS InfoSource’s systems were affected by cybercriminals between February 16 and February 21, 2025, potentially involving names, Social Security numbers and financial account numbers.
  • The proposed settlement class contains approximately 23,499 people who received notice that their information may have been involved.
  • Eligible class members could claim two years of one-bureau credit monitoring, up to $5,000 for documented losses and up to $80 for time spent responding to the incident.
  • AIS denies wrongdoing and liability. The supplied PDF contains a signed settlement agreement but only proposed, unsigned preliminary- and final-approval orders.
  • Class members who remain in the settlement would release AIS, named clients and a broad group of related parties from known and unknown claims tied to the incident.
  • The agreement permits AIS to terminate the settlement if more than 25 class members opt out, although termination would be optional rather than automatic.

The practical question is not simply what the settlement offers. It is whether the claim process, release and still-unresolved court review produce a fair exchange for the people whose information may have been exposed.

Transparency Notice

This investigation is based on the parties’ settlement agreement and its exhibits in Allen, et al. v. AIS InfoSource, L.P., Case No. 2026-18098. The agreement records allegations made by the plaintiffs, AIS’s denial of wrongdoing and terms that remain subject to court approval. The attached preliminary- and final-approval orders are labeled β€œproposed,” contain blank dates and judicial signature lines, and should not be confused with entered court orders. The supplied document therefore does not establish that AIS was liable, that the settlement has been approved or that benefits are currently available.

The Facts

According to the settlement agreement, plaintiffs allege that cybercriminals affected AIS InfoSource’s computer systems during a six-day period beginning February 16, 2025. They contend that the incident potentially involved information belonging to current and former customers of companies using AIS’s services.

The categories were not obscure marketing preferences or an abandoned username. The agreement identifies names, Social Security numbers and financial account numbers as information allegedly affected.

A draft class notice goes somewhat further in its description, saying a criminal third party gained unauthorized access to AIS’s network and that files containing private information were potentially accessed. Because that language appears in a proposed notice exhibit, this article treats it as the parties’ proposed accountβ€”not as an independent forensic finding by the court.

AIS began notifying affected people on July 21, 2025, the agreement says. The source does not disclose when AIS first discovered the incident, what security control allegedly failed, whether information was exfiltrated, how many people suffered misuse or how the incident was contained.

23,499 Approximate number of people in the proposed class
$5,000 Maximum documented-loss reimbursement per claimant
2 years Proposed one-bureau credit-monitoring period

From Incident to Settlement

The litigation moved toward settlement without a trial or a ruling on the merits. The chronology matters because the proposed resolution emerged after informal information exchange and mediationβ€”not after a court determined what happened inside AIS’s systems.

February 16–21, 2025

Plaintiffs allege AIS’s systems were affected by cybercriminals during the data incident.

July 21, 2025

The agreement says AIS began notifying plaintiffs and proposed class members.

July 2025

Three plaintiffs filed separate federal actions against AIS in the Southern District of Texas.

August 5, 2025

The plaintiffs moved to consolidate the federal cases.

August 22, 2025

The federal litigation was stayed pending consolidation.

January 28, 2026

After informal discovery and an exchange of information, the parties mediated and reached agreement on principal settlement terms.

March 18, 2026

The plaintiffs filed a class-action complaint in the 189th Judicial District Court in Harris County, Texas, alleging negligence, negligence per se, invasion of privacy and unjust enrichment.

What the Plaintiffs Alleged

The settlement agreement summarizes the state-court claims but does not reproduce the complaint’s detailed factual allegations. It says the plaintiffs alleged negligence, negligence per se, intrusion upon seclusion or invasion of privacy, and unjust enrichment.

In plain English, those theories contend that AIS failed to handle private information with legally adequate care, violated duties plaintiffs say applied to that information, intruded upon privacy interests and benefited in a way the plaintiffs contend would be unjust to retain.

The proposed final-order template characterizes the case as alleging that AIS failed to safeguard private information belonging to its own current and former customers and those of institutional clients, causing injury to the class. That remains an allegation. The supplied record contains no judicial finding that AIS’s safeguards were inadequate or that its conduct caused compensable harm.

What Class Members Could Receive

The agreement uses a claims-made structure: class members must submit valid, timely claim forms to receive benefits. It does not identify a single fixed settlement fund. That means the document supplies per-person benefits and payment rules, but not a guaranteed aggregate payout to the class.

Credit monitoring

Participating class members could enroll in two years of Financial Shield Complete with one-bureau credit monitoring. The notice and claim-form exhibits identify the service as CyEx Financial Shield Complete and describe $1 million in financial-fraud insurance, monitoring for suspicious financial activity and access to a fraud-resolution agent.

The agreement says activation codes would be sent within 14 days of the settlement’s effective date and remain usable for 180 days.

Documented losses

A claimant could seek up to $5,000 for unreimbursed losses fairly traceable to the incident. Listed examples include identity-theft or fraud losses, professional fees, credit-repair costs, expenses for freezing or unfreezing credit, monitoring purchased after the incident, postage, copying and mileage.

Receipts, bank statements or other third-party records would be required. Self-prepared documents could provide context but would not be sufficient on their own.

Lost time

Class members could claim up to four hours at $20 an hourβ€”a maximum of $80β€”for time spent responding to issues raised by the incident. Unlike documented-loss claims, this benefit would require an attestation rather than third-party receipts.

The settlement administrator would review claims for completeness and plausibility. If it found a claim deficient, the claimant would generally receive 21 days to try to cure the problem. If the administrator concluded that the attempted cure still failed, its determination would be final under the agreement.

The headline maximum is $5,000, but it is not an automatic check. Reimbursement depends on proof of an unreimbursed loss, a connection to the incident and approval by the settlement administrator.

The Price of Doing Nothing

The draft notice makes the choice unusually plain: doing nothing would produce no settlement benefit. Unless a person opted out, however, that person would remain in the class and become bound by the settlement if it received final approval.

The release is broad. It covers claims that result from, arise from or relate to the incident, AIS’s information-security practices, its maintenance or storage of personal information, and conduct that was or could have been alleged in the litigation. It includes known and unknown claims.

The released parties extend beyond AIS. The agreement includes AIS’s parents, subsidiaries, officers, employees, insurers, contractors and other related parties. It also expressly defines a group of AIS clients that includes entities associated with Ally, Capital One, Ford, Synchrony and T-Mobile, among others.

The agreement additionally calls for a waiver of protections similar to California Civil Code section 1542, which ordinarily limits the reach of a general release over claims a person does not know or suspect exist. In practical terms, participating class members would be trading not only the claims currently understood, but also certain incident-related claims that might become clearer later.

The settlement offers real, claim-dependent benefits. It also asks class members to release a broad field of claims, including unknown ones.

The Fine Print With Real Leverage

One provision gives AIS the option to terminate the settlement if more than 25 class members submit valid opt-out requests. Termination would not happen automatically, but the threshold is small compared with an estimated class of approximately 23,499 people.

If the agreement were terminated, the parties would return to their pre-settlement positions. Settlement-only class certification would become void, and AIS would retain the right to contest whether any litigation class should be certified.

The agreement also contains a broad release of unknown incident-related claims and says the release was separately bargained for. Another provision restricts the parties and their lawyers from publicizing the settlement except through specified court filings, legally authorized disclosures and approved notice-related information.

None of those terms proves the settlement is unfair. They do show why the agreement must be read as an exchange rather than a giveaway: benefits on one side, procedural finality on the other.

Fees, Awards and Administration

$325,000 Maximum requested attorneys’ fees and costs
$3,000 Maximum proposed award for each named plaintiff
$9,000 Combined maximum service awards for three plaintiffs

Class counsel intends to seek up to $325,000 in attorneys’ fees and litigation expenses. The three class representatives could each receive up to $3,000 for their work, subject to court approval. AIS would also pay notice and settlement-administration expenses.

The court could reduce or deny the requested fees or service awards without unraveling the rest of the agreement. In other words, the settlement’s continued existence would not depend on counsel or the named plaintiffs receiving the full amounts requested.

What the Court Hasβ€”and Has Notβ€”Decided

The supplied PDF includes templates for preliminary and final approval, but both are visibly incomplete. Dates, hearing information and the judge’s signature remain blank. Statements inside the proposed final orderβ€”including template language about objections, opt-outs, fee awards and final certificationβ€”are requested findings, not established events.

Preliminary approval, if granted, would generally mean the court finds the proposal sufficient to send notice and begin the claims, objection and opt-out process. It would not establish that AIS committed wrongdoing, and it would not finally determine that the settlement is fair.

Final approval would come later, after notice and an opportunity for class members to respond. Only then could the court approve the settlement, certify the class for settlement purposes, authorize the release and dismiss the claims with prejudice.

The distinction is decisive: the parties have signed an agreement, but the supplied source does not show an entered order approving it.

The Approval Process Ahead

The agreement ties its deadlines to an eventual preliminary-approval order rather than supplying completed calendar dates. If preliminary approval occurs, the schedule would generally work as follows:

  • AIS would provide the class list to the administrator within 10 days.
  • Notice would be issued within 30 days.
  • Objections and opt-out requests would be due 60 days after the notice deadline.
  • Claims would be due 90 days after the notice deadline.
  • The final-approval hearing would occur no sooner than 120 days after preliminary approval.
  • Approved fees, service awards and eligible cash claims would be paid after the settlement becomes effective under the agreement’s conditions.

The notice forms in the PDF still contain placeholders for the website, telephone number, mailing address and deadlines. Readers should not treat those drafts as active filing instructions.

What a Legitimate Fix Looks Like

Editorial analysis

The agreement can compensate some people, but it does not reveal enough about the underlying security failure to show how recurrence would be prevented. A credible response would pair individual relief with verifiable operational changes.

Regulatory Track

  • Require incident notices to distinguish clearly between unauthorized access, confirmed acquisition and suspected exposure.
  • Require disclosure of discovery dates, notification delays and the categories of affected records.
  • Publish measurable remediation commitments where doing so would not expose active security defenses.

Legislative Track

  • Create consistent minimum notification rules across jurisdictions.
  • Set enforceable baseline safeguards for companies processing sensitive information on behalf of institutional clients.
  • Require clearer explanations of how claims-made settlements distribute value and what rights non-claimants release.

Corporate Governance Track

  • Minimize the sensitive data retained and document why each category remains necessary.
  • Commission independent testing of post-incident controls and report meaningful results to affected clients.
  • Assign board-level responsibility for vendor security, incident response and notification performance.

What to Watch

  • The Harris County District Court: Whether it enters preliminary approval and whether any eventual order changes the settlement terms or notice plan.
  • AIS InfoSource: Whether the final court record provides additional facts about the incident, remediation or timing of discovery.
  • The settlement administrator: The final website, contact details, approved claim form and actual deadlines. The supplied drafts still contain placeholders.
  • Class counsel: The eventual fee-and-expense application and the evidence offered to support the requested amount.
  • The approval record: The number of claims, objections and opt-outs, including whether the more-than-25 opt-out termination provision becomes relevant.
  • The final approval hearing: Whether the court finds the settlement fair, approves the release and certifies the class solely for settlement purposes.

The unresolved issue is concrete: the document establishes what the parties want the settlement to become, but not whether the court will authorize that exchange or how many affected people will successfully claim its benefits. Until entered orders and completed notices appear, the proposal remains a negotiated blueprint rather than a finished remedy.

The source document for this investigation is attached below.

Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2189