πŸ³οΈβ€βš§οΈ trans rights are human rights πŸ³οΈβ€βš§οΈ
Theme

Excel Fitness Data Breach Settlement: $175K to Silence Employee Claims

Excel Fitness Data Breach Settlement: $175K to Silence Employee Claims After January 2025 Hack

The Breach: What Happened and Who Was Exposed

On or around January 17, 2025, Excel Fitness Consolidator LLC (operating as Excel Fitness Management, LLC) discovered that unauthorized individuals had accessed certain employee email accounts. According to the settlement agreement filed in Oklahoma County District Court, the compromised emails contained sensitive personal information including names, addresses, dates of birth, Social Security numbers, and financial account information.

The breach was not immediately disclosed to affected employees. The company’s internal timeline shows the incident was discovered in mid-January 2025, but the lawsuit was not filed until February 9, 2026β€”more than a year later. During that time, affected employees were left in the dark about the extent of the exposure and the risks they faced.

“Defendant discovered [the Data Incident] on or around January 17, 2025, and asserted claims for negligence, negligence per se, breach of implied contract, and unjust enrichment.”
β€” Settlement Agreement, Recitals Section

The lawsuit, filed by Seychelle Kessler and Reginald Lipford on behalf of all similarly situated employees, alleged that Excel Fitness failed to implement adequate data security measures and failed to timely notify affected individuals of the breach. The plaintiffs argued that this negligence exposed current and former employees to heightened risks of identity theft, financial fraud, and other harms.

Excel Fitness has consistently denied all allegations. The settlement agreement explicitly states that the company does not admit any wrongdoing, fault, or liability. The agreement is framed solely as a business decision to avoid the costs and uncertainties of continued litigation.

The Settlement: What Employees Can Claim

The settlement establishes a capped fund of $175,000 to cover all claims for out-of-pocket losses, lost time reimbursement, and alternative cash payments. If total claims exceed this amount, all payments will be reduced on a pro-rata basis. Notably, this cap does not include the cost of credit monitoring services, which Excel Fitness will provide separately.

Credit Monitoring Services

All class members are eligible to enroll in two years of CyEx Financial Shield Complete, which includes:

  • One-bureau credit monitoring
  • Dark web monitoring
  • Real-time inquiry alerts
  • $1 million in identity theft insurance
  • Access to fraud resolution agents

This benefit is available to all class members regardless of whether they file a claim for cash compensation. However, the settlement does not specify whether enrollment is automatic or requires affirmative action by class members, a gap that could result in low participation rates.

Cash Reimbursement for Documented Losses

Employees who incurred actual, documented losses as a result of the data breach can claim reimbursement of up to $4,000. Eligible expenses include:

  • Losses from identity theft or fraud
  • Fees for credit reports, credit monitoring, or freezing/unfreezing credit
  • Cost to replace government-issued IDs
  • Professional fees (attorneys, accountants, credit repair services)
  • Miscellaneous expenses (notary fees, postage, long-distance calls)

To qualify, claimants must provide third-party documentation (bank statements, receipts, police reports) showing that the loss was more likely than not caused by the data breach and occurred between January 17, 2025, and the claims deadline. Crucially, claimants must also attest that they have exhausted all available credit monitoring insurance and identity theft insurance before seeking reimbursement from the settlement fund.

This requirement effectively shifts the burden of loss mitigation onto the victims. If a class member’s identity theft insurance covers part of the loss, that portion is not reimbursable under the settlement, even if the breach directly caused the loss.

Lost Time Reimbursement

Class members can claim up to three hours of lost time at $25 per hour (maximum $75) for time spent responding to the breach. Eligible activities include:

  • Changing passwords
  • Investigating suspicious account activity
  • Researching the data breach
  • Communicating with financial institutions

Claimants must attest under penalty of perjury that the time claimed was spent as a direct result of the data breach. No documentation is required, but the attestation subjects claimants to potential legal consequences if found to be false.

Lost time claims are subject to the same $4,000 aggregate cap as out-of-pocket losses. This means that a claimant who has already reached the $4,000 limit in documented losses cannot also claim lost time reimbursement.

Alternative Cash Payment

Instead of filing documented claims for losses or lost time, class members can elect to receive a one-time payment of $50. This payment requires no documentation or explanation. It is intended as a simplified option for class members who do not have receipts or who prefer not to go through the claims review process.

The $50 payment is expected to be the amount received, but the settlement agreement includes a clause stating that the actual payment “may be larger or smaller depending on the total claims filed.” If a large number of class members opt for the $50 payment and the aggregate cap is reached, these payments could be reduced pro-rata.

Importantly, class members who elect the $50 alternative payment cannot also claim reimbursement for documented losses or lost time. It is an either-or choice.

The Non-Financial Ledger: What Employees Lost That Can’t Be Reimbursed

The settlement’s focus on documented, reimbursable losses obscures the deeper, non-compensable harms inflicted by the breach. Social Security numbers do not expire. Once exposed, they remain a permanent vulnerability. Financial account numbers can be changed, but the time, stress, and psychological toll of doing soβ€”repeatedly, over yearsβ€”cannot be undone with a $4,000 check.

Employees affected by this breach now face a lifetime of heightened vigilance. Every credit application, every loan inquiry, every unexpected call from a debt collector carries the shadow of the breach. The settlement offers two years of credit monitoring, but the risk does not end when the monitoring subscription expires.

Consider the scenario of an employee whose Social Security number was exposed in January 2025. By the time the settlement is finalized and credit monitoring begins in 2026 or 2027, the two-year monitoring period will expire in 2028 or 2029. At that point, the employee is on their ownβ€”still vulnerable, still exposed, but no longer protected by the settlement’s remedial measures.

The settlement also does not account for the emotional distress of discovering that a trusted employer failed to protect sensitive personal information. Employees entrust their Social Security numbers and financial data to their employers as a condition of employment. When that trust is breached, the relationship is fundamentally altered. Yet the settlement explicitly excludes claims for emotional distress, stating: “No payment shall be made for emotional distress, personal/bodily injury, or punitive damages.”

This exclusion is standard in data breach settlements, but it reflects a legal system that struggles to value intangible harm. A person whose identity is stolen may spend years rebuilding their credit, fighting fraudulent charges, and proving to creditors that they are not responsible for debts incurred in their name. The settlement’s $4,000 cap assumes that this ordeal can be neatly quantified and compensated. It cannot.

Legal Receipts: What the Documents Actually Say

“Defendant denies the allegations and all liability with respect to any and all facts and claims alleged in the Action, that the Class Representative and the class that have suffered any damage(s) or harm, and/or that the Action satisfies the requirements to be tried as a class action under Oklahoma Rules of Civil Procedure.”
β€” Settlement Agreement, Recitals Section, Page 1
“This Agreement is for settlement purposes only, and nothing in this Agreement shall constitute, be construed as, or be admissible in evidence as any admission of the validity of any claim or fact alleged by Plaintiff in this Action or in any other pending or subsequently filed action, or of any wrongdoing, fault, violation of law, or liability of any kind on the part of Released Parties.”
β€” Settlement Agreement, Recitals Section, Page 1
“The Parties understand and acknowledge that this Agreement constitutes a compromise and settlement of disputed claims. No action taken by the Parties either previously or in connection with the negotiations or proceedings connected with this Agreement shall be deemed or construed to be an admission of the truth or falsity of any claims or defenses heretofore made, or an acknowledgment or admission by any party of any fault, liability, or wrongdoing of any kind whatsoever.”
β€” Settlement Agreement, Section XV: No Admission of Liability, Paragraph 78
“Excel Fitness has agreed to enter into this Agreement to avoid the further expense, inconvenience, and distraction of burdensome and protracted litigation, and to be completely free of any further claims that were asserted or could possibly have been asserted in the Action.”
β€” Settlement Agreement, Section XV: No Admission of Liability, Paragraph 78

These clauses are not incidental. They are the legal architecture that allows Excel Fitness to resolve the lawsuit without acknowledging fault and without providing the public with any information about what went wrong, how it was fixed, or whether similar breaches are likely in the future.

Societal Impact Mapping

Environmental Degradation

While this case does not directly involve environmental harm, the digital infrastructure that enabled the breach has significant environmental costs. Data centers consume vast amounts of energy, much of it generated from fossil fuels. The server farms that stored the exposed employee dataβ€”and the redundant backup systems designed to prevent data lossβ€”operate 24/7, drawing power equivalent to small cities. When corporations fail to invest in robust cybersecurity, they often do invest in physical security measures: more servers, more backups, more redundant systems. Each additional layer of physical infrastructure adds to the carbon footprint of the corporate operation.

The environmental cost of digital negligence is rarely discussed in data breach litigation, but it is real. Every breach that requires forensic investigation, data restoration, and system overhaul generates additional computing load, additional energy consumption, and additional electronic waste. The settlement’s requirement that Excel Fitness provide a confidential declaration to class counsel describing its “information security enhancements since the Data Incident” suggests that the company has added new systems, new software, and new hardware. None of this is carbon-neutral.

Public Health

The stress and anxiety associated with identity theft and financial fraud have documented public health impacts. Studies have shown that victims of identity theft experience elevated rates of depression, anxiety, and sleep disturbance. The settlement’s exclusion of emotional distress claims means these health impacts are not compensable, even when they are directly caused by the breach.

Employees who discover fraudulent charges on their accounts, or who receive collection notices for debts they did not incur, often experience acute psychological distress. The process of disputing fraudulent charges, freezing credit, and proving one’s identity to creditors can take months or years. During that time, the victim may be denied credit, face difficulty securing housing or employment, and endure repeated invasions of privacy as they are forced to disclose the breach to banks, credit agencies, and law enforcement.

The settlement’s two-year credit monitoring period provides some relief, but it does not address the long-term psychological toll. After the monitoring expires, affected employees are left to manage their own vigilance, often without the financial resources or expertise to do so effectively.

Economic Inequality

The settlement’s structure disproportionately benefits claimants with the resources to document their losses. Employees who can afford to pay for professional credit repair services, legal consultations, and forensic accountingβ€”and who have the time and expertise to compile supporting documentationβ€”are more likely to receive the full $4,000 reimbursement. Employees who lack these resources, or who work multiple jobs and cannot take time off to pursue claims, are more likely to opt for the $50 alternative payment.

The claims review process itself is a barrier. Claimants must submit third-party documentation, respond to deficiency notices within 21 days, and potentially participate in an appeals process if their claim is denied. Each of these steps requires time, literacy, and access to documentation that low-wage workers may not have. The settlement agreement states that the settlement administrator may contact claimants by email, telephone, or mail to “seek clarification regarding a submitted claim,” but it does not specify whether translation services or accessibility accommodations will be provided.

The result is a two-tier system: well-resourced claimants receive meaningful compensation, while less-resourced claimants receive a token payment that does not come close to covering their actual losses or the ongoing risk they face.

The settlement also reinforces economic inequality by capping total payouts at $175,000. If claims exceed this amount, all payments are reduced pro-rata. This means that the more people who file claims, the less each claimant receives. The settlement effectively pits class members against each other, creating an incentive for individuals to file quickly and hope that others do not file at all.

The “Cost of a Life” Metric

$175,000
The total value Excel Fitness placed on the privacy, financial security, and peace of mind of every affected employee combined.

The settlement’s $175,000 aggregate cap is the clearest measure of how little corporations value employee data. Divide that by the number of affected employees (the exact number is not disclosed in the public documents) and the per-person value is likely to be a few hundred dollars at mostβ€”less than the cost of a single gym membership.

This figure is not an accident. It is the result of a deliberate calculation by Excel Fitness and its legal team: what is the minimum amount we can pay to make this lawsuit go away?

Compare this to the cost of robust data security. Industry estimates suggest that implementing enterprise-level email security, multi-factor authentication, employee training, and regular security audits costs between $50,000 and $200,000 annually for a mid-sized organization. Excel Fitness chose not to spend that money before the breach. Now, it is spending $175,000β€”plus attorneys’ fees, plus the cost of credit monitoring, plus the cost of settlement administrationβ€”to clean up the mess.

The real cost, however, is borne by the employees. They are the ones who will spend years checking their credit reports, disputing fraudulent charges, and living with the knowledge that their most sensitive personal information is in the hands of unknown actors. The settlement does not compensate them for that. It pays them to stop talking about it.

What Now?

The settlement is pending final approval by the Oklahoma County District Court. A final approval hearing is scheduled for a date to be determined, no earlier than 120 days after the preliminary approval order was entered. Affected employees have 90 days from the notice deadline to submit claims.

Class counsel is seeking $150,000 in attorneys’ fees and costs. The plaintiff, Seychelle Kessler, is seeking a $3,000 service award for her role as class representative. Both requests will be considered at the final approval hearing.

Who to Watch

The settlement was negotiated by William B. Federman of Federman & Sherwood (class counsel) and Amanda N. Harvey of Mullen Coughlin LLC (counsel for Excel Fitness). The case is pending before a judge in Oklahoma County District Court (the judge’s name is not disclosed in the public documents).

Excel Fitness Consolidator LLC operates fitness centers under various brand names. The company is privately held, and its ownership structure is not disclosed in the settlement documents.

Watchlist

The following regulatory bodies have jurisdiction over data breach response and consumer protection in cases like this:

  • Federal Trade Commission (FTC) – Enforces data security standards and investigates deceptive trade practices related to consumer data protection.
  • Oklahoma Attorney General’s Office – Enforces state data breach notification laws and consumer protection statutes.
  • Department of Justice (DOJ) – Prosecutes criminal violations related to unauthorized access to computer systems and identity theft.
  • Consumer Financial Protection Bureau (CFPB) – Regulates financial data practices and consumer reporting agencies.

What You Can Do

If you are an affected employee: File a claim. Even if you have no documented losses, file for the $50 alternative payment. The more people who participate, the more visible the harm becomes. Do not let corporations buy your silence for free.

Support data breach notification reform. Current federal law does not require companies to notify affected individuals of a data breach within any specific timeframe. Some states have notification laws, but they vary widely. National legislation requiring prompt notification and minimum security standards is the only way to prevent these breaches from becoming routine.

Demand transparency. The settlement’s confidential declaration clause (Section II, Paragraph 48) allows Excel Fitness to describe its post-breach security measures only to class counsel. The public will never know what changes were made or whether they are sufficient. This secrecy serves the corporation, not the victims. Demand that all settlement agreements in data breach cases include public disclosure of remedial measures.

Organize. Workers have more power collectively than individually. If you work for a company that has suffered a data breach, talk to your coworkers. Share information. If your employer is not taking data security seriously, file complaints with the FTC, your state attorney general, and any relevant industry regulators. Collective action works.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2114