The Square Cash App data breach class action settlement provides compensation to millions of users whose personal information was compromised in two separate security incidents. Block Inc., the parent company of Square Cash App, established a $15 million settlement fund to resolve claims arising from a 2022 breach that exposed data for 8.2 million investing customers and a 2023 breach affecting additional users. The settlement was finalized on March 27, 2025, marking the conclusion of litigation that began when unauthorized access and third-party exploitation exposed sensitive account information to potential fraud and identity theft.
If you used Cash App between August 23, 2018, and August 20, 2024, you may have been affected by these breaches. For example, a Cash App user who invested through the platform during this window could have had their personal identification numbers, account history, and linked financial information exposed when a former employee gained unauthorized access in August 2022, or later when someone exploited recycled phone numbers in the app’s passwordless authentication system in 2023. The settlement allows affected users to recover documented losses and compensation for time spent addressing the breach’s consequences.
Table of Contents
- WHAT HAPPENED IN THE SQUARE CASH APP DATA BREACHES?
- THE SETTLEMENT TERMS AND COMPENSATION STRUCTURE
- ELIGIBILITY REQUIREMENTS AND CLAIM DEADLINES
- UNDERSTANDING THE ACTUAL PAYOUTS AND AVERAGE COMPENSATION
- WHY MOST CLAIMS WERE DENIED AND WHAT THIS MEANS
- WHAT CASH APP USERS SHOULD DO NOW
- WHAT THIS SETTLEMENT MEANS FOR DATA BREACH ACCOUNTABILITY
- Frequently Asked Questions
WHAT HAPPENED IN THE SQUARE CASH APP DATA BREACHES?
Two separate data breaches compromised Cash App user information over an 18-month period. The first breach occurred in August 2022 when a former Block employee with access to the company’s systems gained unauthorized entry to customer data without proper authorization. This breach alone affected 8.2 million Cash App Investing users, exposing names, dates of birth, Social Security numbers, and investment transaction history. The second breach followed in 2023 when a third party exploited a vulnerability in Cash App’s passwordless authentication system by recycling phone numbers—a common security weak point where old phone numbers are reassigned to new users who can then access accounts tied to those numbers. The 2022 breach demonstrated a failure in employee access controls, a critical security concern for financial services companies.
Block Inc. had not implemented adequate restrictions to prevent a departing employee from accessing large customer databases. The 2023 breach highlighted architectural flaws in how the app handled phone number-based authentication without additional verification steps. Together, these incidents exposed Cash App users to identity theft, fraudulent account access, and unauthorized financial transactions. Users who discovered unauthorized activity on their accounts faced months of disputes with Cash App, credit bureaus, and financial institutions to restore their accounts and credit scores.

THE SETTLEMENT TERMS AND COMPENSATION STRUCTURE
Block Inc. agreed to pay $15 million to settle class action lawsuits, though the company did not admit to any wrongdoing in the settlement agreement. This is a common provision in data breach settlements where defendants resolve claims while maintaining they operated appropriately. The settlement fund covers multiple categories of compensation: users can claim up to $2,500 for documented out-of-pocket losses directly caused by the breaches, and they can receive up to $25 per hour for time spent addressing breach-related issues, with a maximum of three hours ($75) allowable without additional documentation.
The settlement process revealed a significant gap between claims filed and claims approved. Over 667,000 users submitted claims for compensation, but only approximately 40,380 claims were approved, resulting in roughly $5.6 million distributed. This means nearly 94% of claims were either denied or reduced, highlighting a critical limitation: simply filing a claim doesn’t guarantee payment. The approval process required claimants to provide documentation of actual losses—receipts for fraud, credit monitoring bills, bank statements showing unauthorized charges—rather than just declaring themselves affected by the breach. Users who lost money to fraudulent transactions but lacked documentation found their claims rejected, while those who filed without specific evidence received nothing.
ELIGIBILITY REQUIREMENTS AND CLAIM DEADLINES
Cash App users with accounts active at any point between August 23, 2018, and August 20, 2024, qualified for the settlement. This broad window captures users affected by both the 2022 and 2023 breaches, as well as users who had dormant or closed accounts during the breach period but held accounts within the overall timeframe. The eligibility criteria did not require proof of actual harm or fraudulent activity; being an account holder during the vulnerable period was sufficient to submit a claim. However, the claim filing deadline has passed.
Claimants needed to submit their claims by November 18, 2024, which occurred before this article was written. This deadline means that users who delayed filing or were unaware of the settlement miss the opportunity to claim compensation. Once settlement deadlines close, courts rarely allow late claims, even if an individual can prove they were affected by the breach. The March 27, 2025 final approval date meant the court had already reviewed all submitted claims and determined which ones qualified for payment by that point.

UNDERSTANDING THE ACTUAL PAYOUTS AND AVERAGE COMPENSATION
The approved claims distributed approximately $5.6 million across 40,380 recipients, resulting in an average payout of around $200 per claim. This average masks significant variation in individual payouts based on documented losses. Someone who lost $1,500 to fraudulent Cash App transactions and submitted receipts received substantially more than someone who claimed $50 in losses. The settlement structure meant claimants were not equally compensated simply for being affected by the breach; compensation directly tied to documented harm. Comparing this payout to the overall settlement fund reveals another limitation: with 40,380 approved claims sharing approximately $5.6 million, and a potential maximum compensation of $2,575 per claimant ($2,500 in losses plus $75 in time compensation), the actual payouts represent a small fraction of what was theoretically available.
This discrepancy reflects several factors. First, the majority of users who filed claims couldn’t substantiate significant documented losses—they experienced no direct financial harm or couldn’t prove what fraud was attributable to the breach. Second, many claims lacked the documentation required by the settlement administrator to approve compensation. A user who suspected fraudulent activity but had no statements or bank records showing the charge faced claim denial. The settlement’s design created a situation where having documentation mattered as much as being a breach victim.
WHY MOST CLAIMS WERE DENIED AND WHAT THIS MEANS
The dramatic discrepancy between 667,000 claims filed and 40,380 claims approved reveals a harsh reality in data breach settlements: documenting actual harm is difficult, and proving that harm is attributable to a specific breach is harder still. Many Cash App users filed claims because they were affected by the breach and received notification about the settlement, but they hadn’t experienced concrete financial losses they could document. Others had experienced fraud but couldn’t connect it to the specific breach dates or couldn’t prove the fraudulent activity occurred as a result of the stolen data. The settlement claims process required clear evidence: credit card statements showing fraudulent charges, fraud investigation reports from financial institutions, credit monitoring bills, or letters from creditors. This approval pattern should influence how users approach future data breaches.
Rather than assuming notification of a settlement means automatic payment, affected individuals should begin documenting everything immediately when they learn of a breach. Take screenshots of your credit reports, print statements showing account activity, obtain written confirmation from your bank about fraudulent transactions, and save all correspondence with financial institutions about fraud disputes. Users who waited months to file claims often found that documentation had been deleted, archived, or was no longer retrievable. Additionally, Block Inc.’s settlement without admission of wrongdoing, while standard in many settlements, means the company didn’t acknowledge what specific security lapses led to the breaches or commit to specific remediation measures beyond paying this settlement. This structure protects the defendant legally but provides no guarantee of systemic security improvements.

WHAT CASH APP USERS SHOULD DO NOW
For those who had active Cash App accounts during the breach window and haven’t yet addressed the breaches’ potential impact, immediate action is necessary. Check your credit reports through the three major bureaus—Equifax, Experian, and TransUnion—which offer free annual reports at AnnualCreditReport.com. Look for accounts or inquiries you don’t recognize, as thieves often use stolen Social Security numbers to open new credit accounts. Place a fraud alert with the bureaus and consider a credit freeze if you’re not actively seeking new credit, which prevents unauthorized credit applications in your name.
Monitor your bank and credit card statements regularly for unauthorized transactions, and enable two-factor authentication on any financial accounts you use. If you haven’t already, file a Data Breach Affidavit with the Federal Trade Commission if you believe you experienced fraud as a result of the breach. While this doesn’t directly lead to compensation, it creates an official record that can support disputes with creditors and credit bureaus. Keep meticulous records of all correspondence with Cash App, your bank, and credit bureaus related to the breach. These documents become invaluable if you discover fraudulent activity months or years later and need to prove the fraud’s timeline and origin.
WHAT THIS SETTLEMENT MEANS FOR DATA BREACH ACCOUNTABILITY
The Square Cash App settlement serves as an example of how data breach litigation typically concludes: with a settlement amount that seems substantial but, when divided among millions of affected users, provides minimal actual compensation. The $15 million fund sounds impressive until divided by the number of users affected, and even smaller when divided by the number who actually received payments. This pattern appears across numerous data breach settlements in recent years, from healthcare breaches affecting millions to financial services incidents compromising customer data.
Looking forward, this settlement underscores the importance of individuals protecting themselves rather than relying on settlements for recovery. While class action lawsuits serve a purpose in holding companies accountable and providing some compensation, the actual recovery available is limited. Users should treat data breaches as inevitable events and maintain strong personal security practices: using strong, unique passwords managed by a password manager, enabling two-factor authentication wherever available, limiting the personal information you provide to companies, and regularly monitoring your financial accounts and credit reports.
Frequently Asked Questions
Has the claim filing deadline passed?
Yes. The claim filing deadline was November 18, 2024. The settlement was finalized on March 27, 2025. If you did not file a claim by the deadline, you cannot file one now, and you cannot receive compensation from this settlement.
How much will I receive if I file a claim?
The average approved claim received approximately $200, though individual payouts varied based on documented losses. Maximum compensation was up to $2,500 for out-of-pocket losses plus $75 for time spent (three hours at $25/hour). However, as noted above, the claim deadline has passed.
What data was exposed in the Square Cash App breaches?
The breaches exposed names, dates of birth, Social Security numbers, and for investing customers, transaction history and investment information. A former employee caused the 2022 breach through unauthorized access, and recycled phone numbers exploited in the authentication system caused the 2023 breach.
Does the settlement mean Square/Block admitted wrongdoing?
No. Block Inc. agreed to the $15 million settlement without admitting wrongdoing. This is standard in settlement agreements and does not constitute an admission of liability or fault.
How do I check if I was affected by the breach?
If you had a Cash App account active between August 23, 2018, and August 20, 2024, you were eligible for the settlement. Block Inc. also sent notification emails to affected users during the settlement process.
What should I do now to protect myself?
Check your credit reports at AnnualCreditReport.com, place a fraud alert with credit bureaus, monitor bank and credit card statements for unauthorized activity, enable two-factor authentication on financial accounts, and consider a credit freeze if you’re not actively seeking new credit.
You Might Also Like
- Forever 21 Employee Data Breach Class Action
- Temu Consumer Data Privacy Class Action Lawsuit
- Shopify Merchant Data Class Action
Open Settlements You Can Claim Now
Browse current class action settlements accepting claims — several require no proof of purchase:
