Cash App Security Class Action Claims Users Lost Money After Unauthorized Access

Yes, Cash App users did lose money as a result of multiple security breaches and unauthorized account access, and several class action settlements have...

Yes, Cash App users did lose money as a result of multiple security breaches and unauthorized account access, and several class action settlements have been filed to compensate victims. Between April 2022 and October 2023, Cash App (operated by Block) experienced at least two major security incidents that resulted in unauthorized access to user accounts, fraudulent withdrawals, and exposure of sensitive financial information. Users who lost money through these compromises have legal recourse through multiple settlements, including a $15 million data breach settlement, a $12.5 million spam text settlement, and a $120 million CFPB automatic redress fund for fraud victims. The scope of these security failures was significant.

Over 667,000 people filed claims in the data breach settlement alone, though only approximately 40,380 claims were approved for payment, receiving an average of $138 per claimant. Beyond settlements tied to specific breaches, Block has agreed to automatic payments to fraud victims through the CFPB, requiring no claim filing at all. Combined, Block faces approximately $322.5 million in financial exposure across five major legal actions from 2025–2026. These settlements represent the consequences of systemic failures in Cash App’s security infrastructure. The incidents expose a broader problem in the financial technology industry: how quickly and thoroughly companies respond when consumer data and funds are compromised, and what compensation victims actually receive when that response is inadequate.

Table of Contents

What Happened—The Cash App Security Breaches Behind Class Action Claims

Cash App’s security problems stem from two distinct incidents, each exposing different vulnerabilities in the platform. In April 2022, a former Cash App Investing employee downloaded customer data after leaving the company, capturing names, portfolio values, brokerage account numbers, and detailed trading activity. This breach demonstrated a classic security failure: an employee with access to sensitive systems did not have that access immediately revoked upon termination, allowing them to exfiltrate information from thousands of users. The second major breach occurred in October 2023, involving unauthorized access to accounts through a different vulnerability: recycled phone numbers.

When users don’t actively maintain their accounts and their phone numbers are reassigned by wireless carriers, third parties can exploit the account recovery process to gain control of those dormant accounts. This particular vulnerability is not unique to Cash App—it’s a recurring problem across fintech platforms—but its exploitation here resulted in real financial losses as attackers transferred funds out of compromised accounts. Both incidents highlight a critical distinction: data breaches (exposure of information) and account takeovers (actual loss of control and money) are related but separate harms. The April 2022 breach primarily exposed investment information, while the October 2023 incident resulted in actual unauthorized withdrawals and transfers.

What Happened—The Cash App Security Breaches Behind Class Action Claims

How Users Lost Money Through Account Compromise and Fraudulent Transfers

Once third parties gained unauthorized access to Cash App accounts, victims experienced direct financial losses through fraudulent withdrawals and transfers. Unlike data breaches where stolen information is the primary harm, account takeovers result in immediate, tangible losses. Users reported finding money missing from their accounts with no record of authorized transactions—a particularly troubling scenario because Cash App transfers can be difficult to reverse once completed. The mechanics of these losses reveal why account takeovers are so damaging. When an attacker gains access to an account, they can immediately withdraw funds to their own banking information, transfer money to other Cash App accounts they control, or send funds to peer-to-peer payment apps that obscure the money trail.

Unlike credit card fraud, where users typically dispute unauthorized charges within days and their credit issuer covers losses, mobile payment app fraud often leaves users personally responsible for the loss. This is a critical limitation: not all Cash App fraud victims are automatically protected or reimbursed, which is why the CFPB intervention became necessary. The October 2023 breach is particularly instructive as a real-world example of how recycled phone numbers create vulnerabilities. A user with an older Cash App account linked to a phone number they no longer owned might not discover the account was compromised until they received notification of unauthorized activity—or worse, didn’t receive any notification at all. This represents a gap in Cash App’s security monitoring and notification practices.

Cash App Security Settlement Payouts vs. Total Settlement AmountData Breach Settlement5.6$ millionSpam Text Settlement5$ millionCFPB Redress Fund120$ millionOther Block Settlements191.9$ millionTotal Exposure322.5$ millionSource: Cash App Security Settlement Official, Credible Law, CFPB Settlement, Best Lawyers in United States

The April 2022 Data Breach Settlement—Investing Customer Information Exposed

The Salinas v. Block settlement, worth $15 million, addresses the April 2022 data breach where customer investment information was stolen. This settlement has been paying out continuously since April 2025, with approved claimants receiving an average of approximately $138 per person. Of the 667,000+ claims filed, only about 40,380 were approved, resulting in approximately $5.6 million actually distributed to victims. The disparity between claims filed and claims approved raises important questions about settlement requirements and proof standards.

To receive compensation from this settlement, claimants had to demonstrate they were customers of Cash App Investing and affected by the data breach during the relevant period. Many claims likely failed due to insufficient documentation, inability to prove membership in the class, or deadlines passing before claimants submitted evidence. This is a common pattern in class action settlements: the compensation pool, while substantial in absolute terms, becomes modest when divided among hundreds of thousands of claimants, and many eligible individuals never complete the claims process. The claim deadline for this settlement was November 18, 2024, meaning anyone who missed that date lost eligibility regardless of whether they were affected. This limitation highlights a critical downside of class action settlements: they require active participation, and those who don’t monitor legal notices or understand the claims process often receive nothing, even if they qualify.

The April 2022 Data Breach Settlement—Investing Customer Information Exposed

The October 2023 Unauthorized Access Settlement and Regional Limitations

The Bottoms v. Block settlement, worth $12.5 million, addresses the spam text incident and unauthorized account access. This settlement is notably different in that it’s Washington-specific, with approved claimants receiving exactly $394.36 per person, a substantially higher payout than the data breach settlement. Payments began on February 2, 2026, and the claim deadline was October 27, 2025. The geographic limitation on this settlement—applying only to Washington state residents—is an important restriction.

Cash App has a national user base, so security incidents affect people across all 50 states, yet this particular settlement’s scope is narrower. This reflects the legal jurisdiction and facts of the specific lawsuit; other affected users outside Washington may have remedies through other settlements or may have no compensation available depending on their losses and circumstances. This is a significant limitation worth understanding: being affected by a security breach does not guarantee access to settlement compensation if you live outside the targeted region or if the settlement terms require proof that exceeds available evidence. The higher per-person payout in this settlement compared to the data breach settlement ($394.36 versus $138 average) suggests that fewer total claims were filed, or that the pool of approved claimants was smaller relative to the settlement amount. This demonstrates how the same company’s security failures can result in vastly different compensation levels depending on the legal vehicle used and the number of claimants involved.

The $120 Million CFPB Automatic Redress Fund—No Claim Required

Beyond the settlement agreements, Block agreed to a $120 million automatic redress fund as part of regulatory action by the Consumer Financial Protection Bureau (CFPB). This fund is fundamentally different from the class action settlements because it requires no claim filing. The CFPB automatically identifies fraud victims and issues payments directly, removing the burden of proof that plagues traditional class actions. This automatic redress approach addresses a significant problem with settlement claims processes: many victims either don’t know settlements exist, don’t know they’re eligible, or lack the documentation to prove their losses.

By identifying fraudulent transactions and compensating victims without requiring them to file claims, the CFPB fund ensures broader coverage. However, the automatic nature also means there’s less individual control—the CFPB calculates compensation amounts based on its own methodology, and victims cannot necessarily appeal or contest the amount they receive. The CFPB fund was specifically created to address fraudulent access to accounts, which overlaps with but is distinct from the data breach. A user might qualify for automatic redress under the CFPB fund if they experienced actual unauthorized transfers, while separately qualifying for the data breach settlement if their information was exposed. However, a critical limitation is that victims cannot generally receive double compensation for the same loss, so the CFPB may offset or limit payments if other settlements have already reimbursed someone for specific fraudulent activity.

The $120 Million CFPB Automatic Redress Fund—No Claim Required

What Happened to Block’s Other Cash App Settlements

Block’s legal exposure extends beyond Cash App security breaches. Combined across five major legal actions from 2025–2026, Block faces approximately $322.5 million in financial exposure.

This includes settlements for issues beyond security—such as deceptive practices, failure to protect consumer data adequately, and inadequate fraud response procedures. For context, consider that the 2022 data breach alone resulted in $15 million in settlement costs, but the total approved payout to victims was only $5.6 million, with the remainder covering settlement administration, legal fees, and unclaimed funds. This comparison illustrates a reality that many don’t understand: settlement amounts announced by companies or media are often much larger than the actual dollars that reach affected consumers, as administrative and legal costs consume a significant portion of the total.

What You Need to Know if You Were Affected by Cash App Security Issues

If you used Cash App during the April 2022 or October 2023 security incidents and experienced unauthorized access or fraudulent transactions, multiple paths to compensation existed, though some may have already passed their claim deadlines. The data breach settlement deadline (November 18, 2024) has passed, but if you haven’t checked whether you qualified, contacting the settlement administrator may still reveal options, particularly if you have documentation of membership in the class.

For Washington state residents affected by unauthorized access, the October 2023 settlement deadline was October 27, 2025, but checking whether your claim was filed or whether you can still file may be worthwhile. Separate from settlements, if you experienced fraudulent transactions, you may be eligible for the CFPB automatic redress fund, which doesn’t require claims filing and should issue payments automatically over time. Going forward, the core lesson is that mobile payment apps like Cash App require the same security vigilance as traditional banking: use strong, unique passwords; enable two-factor authentication; monitor for unauthorized activity; and consider keeping larger sums in more established financial institutions rather than payment app accounts.

Conclusion

The Cash App security failures between 2022 and 2023 resulted in real financial losses for users and triggered multiple class action settlements and regulatory actions totaling over $320 million in combined liability. However, the actual compensation reaching individual victims has been modest—averaging $138 in the data breach settlement and $394.36 in the spam text settlement—reflecting the reality that class action remedies, while important, often provide limited individual recovery when losses are spread across hundreds of thousands of claimants. The CFPB’s automatic redress fund represents a more progressive approach to victim compensation by removing the burden of proving losses and claiming benefits.

If you were affected, review the deadlines and eligibility requirements for the settlements mentioned here, particularly if you live in Washington or lost money to unauthorized transactions. While settlement compensation may not fully restore your losses, it provides a mechanism for accountability and ensures that companies face financial consequences for security failures. Going forward, Cash App and similar platforms have financial and reputational incentive to improve security practices, and consumers should expect ongoing scrutiny of their fraud response procedures and data protection standards.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase: