Illustration of legal documents and data privacy representing the MOVEit data breach class action
Legal

MOVEit Data Breach Class Action 2026: MDL 3083 Status, Eligibility and How to Check Your Claim

Daylongs ·
#MOVEit Data Breach #Class Action Lawsuit #MDL 3083 #Cl0p Ransomware #Data Breach Settlement #Identity Theft #Progress Software #Consumer Rights

The MOVEit Class Action in 2026, My Read First

Here’s the short version: MOVEit wasn’t a breach at one company — it was a supply-chain event that rippled through thousands of organizations that happened to rely on the same file-transfer software. That distinction matters more than most coverage of this case lets on, because it means “I’ve never heard of MOVEit” tells you nothing about whether your data was exposed.

This piece walks through where the consolidated litigation — MDL No. 3083 — actually stands as of 2026, how to check whether you’re in the affected population, what eligibility to file a claim really requires, and the mistakes I see people make most often when a data-breach settlement notice shows up in their mailbox. If you want the broader mechanics of how data-breach class actions work before diving into MOVEit specifics, our data breach class action settlement guide is a useful companion read. One caveat up front: this litigation is still moving, and it’s organized around dozens of separate defendant tracks rather than one unified case, so treat every date and status below as a starting point — verify against your own notice and the current docket before you act.


What Actually Happened in the MOVEit Breach?

In May 2023, the Cl0p ransomware and extortion group exploited a previously unknown SQL injection zero-day — tracked as CVE-2023-34362 — in Progress Software’s MOVEit Transfer, an enterprise tool used to move large batches of sensitive files securely between organizations. The vulnerability let attackers bypass authentication and reach the underlying database directly, which they used to automate mass data exfiltration across every organization running a vulnerable, internet-facing MOVEit instance.

What made this attack distinctive was the method: Cl0p didn’t lock systems down with encryption the way traditional ransomware does. It stole data first and then used the threat of publishing it as leverage — a tactic known as double extortion. Over the following months, Cl0p published lists of victim organizations and samples of stolen data on its leak site in waves, which is part of why the known scope of this breach kept expanding well past the initial disclosure. Government agencies, universities, insurers, payroll processors, and financial firms across multiple sectors were affected, making this one of the largest supply-chain data incidents on record.


Why Might This Affect Me Even If I Never Used MOVEit?

This is the part people miss most often. MOVEit Transfer is backend infrastructure, not a consumer product — organizations used it to move files like payroll batches, student records, or insurance claims data between systems. If an employer, university, health plan, or government agency you interacted with ran MOVEit internally and your personal data was in a file it processed, you can end up in the affected population without ever having opened the software yourself.

Category of Affected OrganizationTypical RoleData Type Most Commonly Exposed
Government/public benefitsFederal and state benefit or pension agenciesSocial Security numbers, addresses, benefit records
Higher education/student loansUniversities and student-loan-adjacent service providersStudent names, ID numbers, loan-related records
Healthcare/insuranceHealth plans, long-term care insurers, benefits administratorsClaims and coverage data, Social Security numbers
Payroll/HRPayroll processors and HR outsourcing firmsPay records, tax data, bank account details
Financial servicesBanks and asset/retirement management firmsAccount-related and transaction records

Rather than trying to recall a specific company name, it’s more useful to ask which of these five categories you’ve had a relationship with in the relevant timeframe. If exposed data later translated into real financial harm, the legal theory that often applies overlaps with what’s covered in our negligent security lawsuit guide, which explains how courts evaluate an organization’s duty to safeguard data it was entrusted with.


What Is MDL 3083 and Where Does It Stand Now?

Because MOVEit-related lawsuits were filed in federal courts scattered across the country, the Judicial Panel on Multidistrict Litigation consolidated them in fall 2023 into MDL No. 3083, formally titled In re: MOVEit Customer Data Security Breach Litigation, assigned to Judge Allison D. Burroughs in the U.S. District Court for the District of Massachusetts.

An MDL isn’t a single merged lawsuit the way a class action can appear to be. It’s a coordination mechanism: overlapping cases from different plaintiffs get centralized before one court for pretrial proceedings, especially discovery, without erasing the fact that they remain separate underlying claims. This case is unusual even by MDL standards because it names not just Progress Software but dozens of individual downstream companies that used MOVEit and whose customers’ or members’ data was exposed as a result — so the court has organized proceedings into separate tracks by defendant group.

TimeframeWhat Happened
May 2023Cl0p begins exploiting the MOVEit Transfer zero-day
Fall 2023JPML consolidates related federal cases into MDL 3083
2024Consolidated complaints filed; motion-to-dismiss briefing proceeds
July 2025Court denies most motions to dismiss from Progress and numerous individual defendants
2025–2026Discovery continues by track; some defendant-specific settlements negotiated and preliminarily approved
2026 (ongoing)Settlement fairness hearings proceeding on a rolling basis across multiple tracks

The core thing to understand: there is no single “MOVEit settlement.” Whether the company relevant to you has reached a settlement, is still in active litigation, or hasn’t been resolved at all depends entirely on which track it falls into. The court docket and each settlement’s own official notice site are the most reliable sources for current status.


Am I Actually Eligible to File a Claim?

Eligibility generally comes down to three things:

  1. Whether you fall within the class definition — the specific group of “affected individuals” a given settlement defines, typically tied to a particular company’s exposed data during a specific window.
  2. Whether you received notice or can independently confirm inclusion — if you got a mailed or emailed notice, it will include a unique Claim ID; if you didn’t, most claims processes still let you verify eligibility another way.
  3. Whether you’re filing before that track’s deadline — deadlines are set independently for each settlement and, once passed, generally close off the claim permanently.

Immigration or citizenship status isn’t the relevant test — inclusion depends on whether your personal information was in the exposed dataset, full stop. If you worked, studied, or held insurance coverage in the U.S. during the relevant period, you could be eligible regardless of visa status, but you still need to read the specific class definition in your notice rather than assume.


How Do I Check If My Data Was Actually Exposed?

You don’t have to wait passively for a notice to arrive. Work through this list directly:

  • Recheck your mail and email, including spam/junk folders — notices get misfiled or bounce back after an address change.
  • Visit the relevant organization’s own data security incident page — most affected companies maintain a dedicated notice page on their website.
  • Search your state attorney general’s data breach notification database — many states publish a public log of breaches reported to them.
  • Check the HHS Office for Civil Rights breach portal if health data is involved — HIPAA-covered entities report major breaches there.
  • Use the official settlement administrator’s lookup tool — once a specific track’s settlement is active, its official site typically offers a name/email lookup.

Skipping these steps and entering personal information into a site you found through a search ad or unsolicited text is the single most common mistake — and the most common way people get scammed adjacent to a real breach event.


What Should I Realistically Expect From a Settlement?

I’ll be blunt: nobody can responsibly quote you a firm dollar figure right now, and anyone who does should raise a red flag. Most MOVEit-related settlements are structured as claims-made, meaning a fixed total fund gets distributed among everyone who files a valid claim before the deadline — so the actual per-person payout isn’t calculable until after claims close.

In this type of data-breach settlement, the structure typically combines:

  • A modest flat cash payment available without proof of loss (the cap varies by settlement)
  • Reimbursement for documented out-of-pocket losses tied to the breach, such as fraud-resolution costs
  • A period of free identity and credit monitoring
  • Non-monetary commitments from the defendant to improve security practices going forward

The key variable is total claim volume — the more valid claims filed, the smaller each individual share of a fixed fund becomes in a pro-rata structure. Any ad or unsolicited call promising a specific dollar amount before a settlement fund and claims volume are even known is overstating what it can actually deliver.


What Mistakes and Scams Should I Watch For?

Mistake / Scam PatternWhy It’s a ProblemWhat To Do Instead
Entering your SSN on a site found via search ad or textCould be an unrelated phishing siteMatch the URL and case name against your actual notice first
Ignoring the claims deadlineLate claims are generally rejected outrightAdd the exact deadline from your notice to a calendar immediately
Filing for reimbursement with no documentationClaims without proof are often reduced or deniedKeep bank/card statements and fraud-resolution receipts on hand
Filing duplicate claims across overlapping noticesCan trigger disqualification for claim duplicationRead the class definition in each notice carefully before filing
A caller asking for an upfront “filing fee”Legitimate class claims are free to fileTreat any upfront payment request as a scam signal
Deleting the notice as junk mailYou lose your unique Claim IDFile official notices in a dedicated folder, physical or digital

Most of what’s in this table comes down to one habit: read the actual notice before acting on anything else you find online.


Do I Need My Own Lawyer, or Is the Class Action Enough?

For most people, staying in the class and filing a claim is sufficient — it’s typically free, and class counsel’s fees come out of the settlement fund subject to court approval, not out of your pocket. Opting out to pursue your own lawsuit makes more sense in specific situations:

  • You suffered significant, well-documented financial harm from identity theft that a standard settlement formula likely wouldn’t cover fairly
  • The exposed data involves particularly sensitive categories — mental health records or a minor child’s information — where the harm doesn’t fit a standard payout tier
  • You’re already working with an attorney on a related matter and want the breach claim handled alongside it

If you’re weighing whether your situation warrants individual representation, the questions worth asking an attorney mirror the general framework in our surgical error malpractice lawyer guide — much of that vetting checklist (fee structure, track record, communication expectations) applies just as well outside the medical context. And if the exposed data involved an elderly family member’s long-term care coverage, our nursing home neglect and bedsore lawsuit guide covers the related legal protections for vulnerable populations.


What Should I Do Right Now, While Litigation Is Still Pending?

You don’t need a settlement to arrive before defending yourself against the exposure itself:

  • Freeze your credit with Equifax, Experian, and TransUnion — it’s free at all three.
  • Review account and card statements regularly for small test charges, which are often the first sign of fraud.
  • Enroll in any free identity monitoring the affected organization is offering, usually for a set period after notice.
  • Consider an IRS Identity Protection PIN if your Social Security number was part of the exposure.
  • Never give out full personal details to an unsolicited caller claiming to be your bank or a government agency.

While you’re rebuilding a margin of financial safety against breach-related costs, it’s also a reasonable moment to revisit how your broader finances are positioned — our SCHD dividend ETF guide covers building steady cash flow, and our stock capital gains tax guide is worth a look before the next filing season regardless of this breach.


Three Things Worth Remembering

First, you can be affected without ever having touched MOVEit yourself. Second, MDL 3083 isn’t one settlement — it’s a collection of tracks moving at different speeds, so you need to check the status specific to the company relevant to your data. Third, don’t trust any promise of a specific payout amount before a settlement fund and claims volume are actually known — the claims-made structure makes that mathematically impossible to know in advance. Your official notice, the court docket, and the settlement administrator’s site remain the most reliable sources throughout.


Further Reading


This article is for general information only and is not legal advice for your specific situation. The status of MDL 3083, the terms of each defendant-specific settlement, and claim eligibility and deadlines continue to change — before filing anything, confirm the current details against your own official notice, the court docket (PACER), and the relevant settlement administrator’s website, and consult a licensed attorney if you have questions about your particular circumstances.

What exactly was the MOVEit data breach?

In May 2023, the Cl0p ransomware and extortion group exploited a previously unknown SQL injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer, a file-transfer tool thousands of organizations used to move sensitive files. Rather than encrypting systems, Cl0p exfiltrated data and used the threat of publishing it to extort victims.

I've never used MOVEit myself — why would this affect me?

MOVEit isn't a consumer app; it's backend infrastructure organizations use to transfer bulk files like payroll records, student data, or insurance claims. If an employer, school, health plan, or government agency you dealt with used MOVEit internally and your data was in a file it moved, you could be in the affected population even though you personally never touched the software.

What is MDL 3083 and why were all these lawsuits combined?

Dozens of lawsuits over the MOVEit breach were filed in federal courts across the country. In fall 2023, the Judicial Panel on Multidistrict Litigation (JPML) consolidated them into MDL No. 3083, In re: MOVEit Customer Data Security Breach Litigation, assigned to Judge Allison D. Burroughs in the District of Massachusetts. Consolidation lets the court coordinate discovery instead of duplicating it across dozens of districts.

What happened with the motions to dismiss?

In July 2025, the court denied most of the motions to dismiss filed by Progress Software and the numerous individual company defendants, meaning most claims moved forward into discovery rather than being thrown out. Rulings can differ by defendant track, so check the current docket for the specific company relevant to you.

How much money will I actually get from a settlement?

There's no honest way to give you a firm number right now. MDL 3083 isn't one lawsuit against one defendant — it's Progress Software plus dozens of separate companies that used MOVEit, each negotiating its own settlement on its own timeline. Payouts in claims-made settlements like this depend on the total settlement fund and how many valid claims are filed, so per-person amounts aren't fixed until after the claims deadline passes.

Can I file a claim right now?

Only if a settlement covering the specific company relevant to your data has received preliminary court approval and the claims period has opened. Several tracks in this MDL are still in litigation or negotiation with no claims process yet. Your official notice — mailed or emailed — will tell you the specific deadline that applies to you.

What if I never received a notification letter?

That happens often — people move, change email addresses, or notices land in spam. Check the specific company's own data security incident page, your state attorney general's breach notification database, the HHS Office for Civil Rights breach portal if health information was involved, and the official settlement administrator's website for the relevant track.

Do I need to be a U.S. citizen to be eligible?

No — eligibility is defined by whether your information was in the affected dataset, not by immigration status. The precise class definition varies by settlement, so read the notice's language carefully rather than assuming.

Do I need to hire my own lawyer?

Most people don't need to. Filing a claim within the class is typically free — class counsel's fees are paid out of the settlement fund subject to court approval. Hiring your own attorney and opting out makes more sense only if you suffered documented, significant financial harm that a standard settlement wouldn't fairly cover.

How do I avoid scam claim websites?

Legitimate claim sites are named explicitly in the court-approved notice you received. Be suspicious of any site you found through a search ad or an unsolicited text message that asks for your Social Security number before you've verified the case name and claims administrator against your actual notice.

What should I do right now while the litigation is still pending?

Freeze your credit with all three bureaus, review account and card statements for unfamiliar charges, enroll in any free identity monitoring the affected company offers, and consider an IRS Identity Protection PIN if your Social Security number was involved. Don't wait for a settlement check to start protecting yourself.

공유하기

관련 글