MOVEit Data Breach Class Action 2026: MDL 3083 Status, Eligibility and How to Check Your Claim
The MOVEit Class Action in 2026, My Read First
Here’s the short version: MOVEit wasn’t a breach at one company — it was a supply-chain event that rippled through thousands of organizations that happened to rely on the same file-transfer software. That distinction matters more than most coverage of this case lets on, because it means “I’ve never heard of MOVEit” tells you nothing about whether your data was exposed.
This piece walks through where the consolidated litigation — MDL No. 3083 — actually stands as of 2026, how to check whether you’re in the affected population, what eligibility to file a claim really requires, and the mistakes I see people make most often when a data-breach settlement notice shows up in their mailbox. If you want the broader mechanics of how data-breach class actions work before diving into MOVEit specifics, our data breach class action settlement guide is a useful companion read. One caveat up front: this litigation is still moving, and it’s organized around dozens of separate defendant tracks rather than one unified case, so treat every date and status below as a starting point — verify against your own notice and the current docket before you act.
What Actually Happened in the MOVEit Breach?
In May 2023, the Cl0p ransomware and extortion group exploited a previously unknown SQL injection zero-day — tracked as CVE-2023-34362 — in Progress Software’s MOVEit Transfer, an enterprise tool used to move large batches of sensitive files securely between organizations. The vulnerability let attackers bypass authentication and reach the underlying database directly, which they used to automate mass data exfiltration across every organization running a vulnerable, internet-facing MOVEit instance.
What made this attack distinctive was the method: Cl0p didn’t lock systems down with encryption the way traditional ransomware does. It stole data first and then used the threat of publishing it as leverage — a tactic known as double extortion. Over the following months, Cl0p published lists of victim organizations and samples of stolen data on its leak site in waves, which is part of why the known scope of this breach kept expanding well past the initial disclosure. Government agencies, universities, insurers, payroll processors, and financial firms across multiple sectors were affected, making this one of the largest supply-chain data incidents on record.
Why Might This Affect Me Even If I Never Used MOVEit?
This is the part people miss most often. MOVEit Transfer is backend infrastructure, not a consumer product — organizations used it to move files like payroll batches, student records, or insurance claims data between systems. If an employer, university, health plan, or government agency you interacted with ran MOVEit internally and your personal data was in a file it processed, you can end up in the affected population without ever having opened the software yourself.
| Category of Affected Organization | Typical Role | Data Type Most Commonly Exposed |
|---|---|---|
| Government/public benefits | Federal and state benefit or pension agencies | Social Security numbers, addresses, benefit records |
| Higher education/student loans | Universities and student-loan-adjacent service providers | Student names, ID numbers, loan-related records |
| Healthcare/insurance | Health plans, long-term care insurers, benefits administrators | Claims and coverage data, Social Security numbers |
| Payroll/HR | Payroll processors and HR outsourcing firms | Pay records, tax data, bank account details |
| Financial services | Banks and asset/retirement management firms | Account-related and transaction records |
Rather than trying to recall a specific company name, it’s more useful to ask which of these five categories you’ve had a relationship with in the relevant timeframe. If exposed data later translated into real financial harm, the legal theory that often applies overlaps with what’s covered in our negligent security lawsuit guide, which explains how courts evaluate an organization’s duty to safeguard data it was entrusted with.
What Is MDL 3083 and Where Does It Stand Now?
Because MOVEit-related lawsuits were filed in federal courts scattered across the country, the Judicial Panel on Multidistrict Litigation consolidated them in fall 2023 into MDL No. 3083, formally titled In re: MOVEit Customer Data Security Breach Litigation, assigned to Judge Allison D. Burroughs in the U.S. District Court for the District of Massachusetts.
An MDL isn’t a single merged lawsuit the way a class action can appear to be. It’s a coordination mechanism: overlapping cases from different plaintiffs get centralized before one court for pretrial proceedings, especially discovery, without erasing the fact that they remain separate underlying claims. This case is unusual even by MDL standards because it names not just Progress Software but dozens of individual downstream companies that used MOVEit and whose customers’ or members’ data was exposed as a result — so the court has organized proceedings into separate tracks by defendant group.
| Timeframe | What Happened |
|---|---|
| May 2023 | Cl0p begins exploiting the MOVEit Transfer zero-day |
| Fall 2023 | JPML consolidates related federal cases into MDL 3083 |
| 2024 | Consolidated complaints filed; motion-to-dismiss briefing proceeds |
| July 2025 | Court denies most motions to dismiss from Progress and numerous individual defendants |
| 2025–2026 | Discovery continues by track; some defendant-specific settlements negotiated and preliminarily approved |
| 2026 (ongoing) | Settlement fairness hearings proceeding on a rolling basis across multiple tracks |
The core thing to understand: there is no single “MOVEit settlement.” Whether the company relevant to you has reached a settlement, is still in active litigation, or hasn’t been resolved at all depends entirely on which track it falls into. The court docket and each settlement’s own official notice site are the most reliable sources for current status.
Am I Actually Eligible to File a Claim?
Eligibility generally comes down to three things:
- Whether you fall within the class definition — the specific group of “affected individuals” a given settlement defines, typically tied to a particular company’s exposed data during a specific window.
- Whether you received notice or can independently confirm inclusion — if you got a mailed or emailed notice, it will include a unique Claim ID; if you didn’t, most claims processes still let you verify eligibility another way.
- Whether you’re filing before that track’s deadline — deadlines are set independently for each settlement and, once passed, generally close off the claim permanently.
Immigration or citizenship status isn’t the relevant test — inclusion depends on whether your personal information was in the exposed dataset, full stop. If you worked, studied, or held insurance coverage in the U.S. during the relevant period, you could be eligible regardless of visa status, but you still need to read the specific class definition in your notice rather than assume.
How Do I Check If My Data Was Actually Exposed?
You don’t have to wait passively for a notice to arrive. Work through this list directly:
- Recheck your mail and email, including spam/junk folders — notices get misfiled or bounce back after an address change.
- Visit the relevant organization’s own data security incident page — most affected companies maintain a dedicated notice page on their website.
- Search your state attorney general’s data breach notification database — many states publish a public log of breaches reported to them.
- Check the HHS Office for Civil Rights breach portal if health data is involved — HIPAA-covered entities report major breaches there.
- Use the official settlement administrator’s lookup tool — once a specific track’s settlement is active, its official site typically offers a name/email lookup.
Skipping these steps and entering personal information into a site you found through a search ad or unsolicited text is the single most common mistake — and the most common way people get scammed adjacent to a real breach event.
What Should I Realistically Expect From a Settlement?
I’ll be blunt: nobody can responsibly quote you a firm dollar figure right now, and anyone who does should raise a red flag. Most MOVEit-related settlements are structured as claims-made, meaning a fixed total fund gets distributed among everyone who files a valid claim before the deadline — so the actual per-person payout isn’t calculable until after claims close.
In this type of data-breach settlement, the structure typically combines:
- A modest flat cash payment available without proof of loss (the cap varies by settlement)
- Reimbursement for documented out-of-pocket losses tied to the breach, such as fraud-resolution costs
- A period of free identity and credit monitoring
- Non-monetary commitments from the defendant to improve security practices going forward
The key variable is total claim volume — the more valid claims filed, the smaller each individual share of a fixed fund becomes in a pro-rata structure. Any ad or unsolicited call promising a specific dollar amount before a settlement fund and claims volume are even known is overstating what it can actually deliver.
What Mistakes and Scams Should I Watch For?
| Mistake / Scam Pattern | Why It’s a Problem | What To Do Instead |
|---|---|---|
| Entering your SSN on a site found via search ad or text | Could be an unrelated phishing site | Match the URL and case name against your actual notice first |
| Ignoring the claims deadline | Late claims are generally rejected outright | Add the exact deadline from your notice to a calendar immediately |
| Filing for reimbursement with no documentation | Claims without proof are often reduced or denied | Keep bank/card statements and fraud-resolution receipts on hand |
| Filing duplicate claims across overlapping notices | Can trigger disqualification for claim duplication | Read the class definition in each notice carefully before filing |
| A caller asking for an upfront “filing fee” | Legitimate class claims are free to file | Treat any upfront payment request as a scam signal |
| Deleting the notice as junk mail | You lose your unique Claim ID | File official notices in a dedicated folder, physical or digital |
Most of what’s in this table comes down to one habit: read the actual notice before acting on anything else you find online.
Do I Need My Own Lawyer, or Is the Class Action Enough?
For most people, staying in the class and filing a claim is sufficient — it’s typically free, and class counsel’s fees come out of the settlement fund subject to court approval, not out of your pocket. Opting out to pursue your own lawsuit makes more sense in specific situations:
- You suffered significant, well-documented financial harm from identity theft that a standard settlement formula likely wouldn’t cover fairly
- The exposed data involves particularly sensitive categories — mental health records or a minor child’s information — where the harm doesn’t fit a standard payout tier
- You’re already working with an attorney on a related matter and want the breach claim handled alongside it
If you’re weighing whether your situation warrants individual representation, the questions worth asking an attorney mirror the general framework in our surgical error malpractice lawyer guide — much of that vetting checklist (fee structure, track record, communication expectations) applies just as well outside the medical context. And if the exposed data involved an elderly family member’s long-term care coverage, our nursing home neglect and bedsore lawsuit guide covers the related legal protections for vulnerable populations.
What Should I Do Right Now, While Litigation Is Still Pending?
You don’t need a settlement to arrive before defending yourself against the exposure itself:
- Freeze your credit with Equifax, Experian, and TransUnion — it’s free at all three.
- Review account and card statements regularly for small test charges, which are often the first sign of fraud.
- Enroll in any free identity monitoring the affected organization is offering, usually for a set period after notice.
- Consider an IRS Identity Protection PIN if your Social Security number was part of the exposure.
- Never give out full personal details to an unsolicited caller claiming to be your bank or a government agency.
While you’re rebuilding a margin of financial safety against breach-related costs, it’s also a reasonable moment to revisit how your broader finances are positioned — our SCHD dividend ETF guide covers building steady cash flow, and our stock capital gains tax guide is worth a look before the next filing season regardless of this breach.
Three Things Worth Remembering
First, you can be affected without ever having touched MOVEit yourself. Second, MDL 3083 isn’t one settlement — it’s a collection of tracks moving at different speeds, so you need to check the status specific to the company relevant to your data. Third, don’t trust any promise of a specific payout amount before a settlement fund and claims volume are actually known — the claims-made structure makes that mathematically impossible to know in advance. Your official notice, the court docket, and the settlement administrator’s site remain the most reliable sources throughout.
Further Reading
- 👉 Data Breach Class Action Settlement Guide
- 👉 Negligent Security Lawsuit: What Counts as a Breach of Duty
- 👉 Surgical Error Malpractice Lawyer Guide
- 👉 Nursing Home Neglect and Bedsore Lawsuit Guide
- 👉 Stock Capital Gains Tax Guide 2026
- 👉 SCHD Dividend ETF Guide 2026
- 👉 AI Stocks Investment Guide 2026
This article is for general information only and is not legal advice for your specific situation. The status of MDL 3083, the terms of each defendant-specific settlement, and claim eligibility and deadlines continue to change — before filing anything, confirm the current details against your own official notice, the court docket (PACER), and the relevant settlement administrator’s website, and consult a licensed attorney if you have questions about your particular circumstances.
What exactly was the MOVEit data breach?
In May 2023, the Cl0p ransomware and extortion group exploited a previously unknown SQL injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer, a file-transfer tool thousands of organizations used to move sensitive files. Rather than encrypting systems, Cl0p exfiltrated data and used the threat of publishing it to extort victims.
I've never used MOVEit myself — why would this affect me?
MOVEit isn't a consumer app; it's backend infrastructure organizations use to transfer bulk files like payroll records, student data, or insurance claims. If an employer, school, health plan, or government agency you dealt with used MOVEit internally and your data was in a file it moved, you could be in the affected population even though you personally never touched the software.
What is MDL 3083 and why were all these lawsuits combined?
Dozens of lawsuits over the MOVEit breach were filed in federal courts across the country. In fall 2023, the Judicial Panel on Multidistrict Litigation (JPML) consolidated them into MDL No. 3083, In re: MOVEit Customer Data Security Breach Litigation, assigned to Judge Allison D. Burroughs in the District of Massachusetts. Consolidation lets the court coordinate discovery instead of duplicating it across dozens of districts.
What happened with the motions to dismiss?
In July 2025, the court denied most of the motions to dismiss filed by Progress Software and the numerous individual company defendants, meaning most claims moved forward into discovery rather than being thrown out. Rulings can differ by defendant track, so check the current docket for the specific company relevant to you.
How much money will I actually get from a settlement?
There's no honest way to give you a firm number right now. MDL 3083 isn't one lawsuit against one defendant — it's Progress Software plus dozens of separate companies that used MOVEit, each negotiating its own settlement on its own timeline. Payouts in claims-made settlements like this depend on the total settlement fund and how many valid claims are filed, so per-person amounts aren't fixed until after the claims deadline passes.
Can I file a claim right now?
Only if a settlement covering the specific company relevant to your data has received preliminary court approval and the claims period has opened. Several tracks in this MDL are still in litigation or negotiation with no claims process yet. Your official notice — mailed or emailed — will tell you the specific deadline that applies to you.
What if I never received a notification letter?
That happens often — people move, change email addresses, or notices land in spam. Check the specific company's own data security incident page, your state attorney general's breach notification database, the HHS Office for Civil Rights breach portal if health information was involved, and the official settlement administrator's website for the relevant track.
Do I need to be a U.S. citizen to be eligible?
No — eligibility is defined by whether your information was in the affected dataset, not by immigration status. The precise class definition varies by settlement, so read the notice's language carefully rather than assuming.
Do I need to hire my own lawyer?
Most people don't need to. Filing a claim within the class is typically free — class counsel's fees are paid out of the settlement fund subject to court approval. Hiring your own attorney and opting out makes more sense only if you suffered documented, significant financial harm that a standard settlement wouldn't fairly cover.
How do I avoid scam claim websites?
Legitimate claim sites are named explicitly in the court-approved notice you received. Be suspicious of any site you found through a search ad or an unsolicited text message that asks for your Social Security number before you've verified the case name and claims administrator against your actual notice.
What should I do right now while the litigation is still pending?
Freeze your credit with all three bureaus, review account and card statements for unfamiliar charges, enroll in any free identity monitoring the affected company offers, and consider an IRS Identity Protection PIN if your Social Security number was involved. Don't wait for a settlement check to start protecting yourself.
관련 글

PowerSchool Data Breach Lawsuit 2026: What Parents Should Do About the MDL, Credit Freezes and Claims

FCRA Credit Report Dispute Attorney 2026: Inaccurate Reporting Damages Claims

GM OnStar Driving Data Privacy Lawsuit 2026: Did Your Car Raise Your Insurance Rate?

Workers Compensation Claims 2026: Exclusive Remedy, Disability Ratings, and Third-Party Suits

Hiring a Divorce Lawyer in 2026: Uncontested vs Contested, What You Pay, and How Courts Decide Property and Custody
