Quick Answer: The FinWise Bank data breach settlement pays eligible people up to $5,000 in documented losses, or a no-paperwork pro rata cash payment plus two years of three-bureau credit monitoring, for a 2024 data incident that, per the settlement notice, exposed names, dates of birth, Social Security numbers and account numbers for somewhere between roughly 600,000 and 689,000 people — and by FinWise’s own account to the SEC, the incident wasn’t outside hackers: the data was “exposed by a former employee following termination of their employment.” The deadline to file a claim is October 29, 2026 . An earlier date matters to anyone who would rather keep the right to sue on their own: September 29, 2026 is the last day to opt out, by mail — and it matters most if your documented losses run well past the $5,000 cap.
Expert Context: I’ve helped people navigate debt relief and class action claims since launching GetOutOfDebt.org in 2008, and I’ve learned which settlements actually pay out and which ones quietly expire because nobody filed. This one is easy to miss for a specific reason: almost nobody who’s eligible has ever heard the name “FinWise.”
FinWise Bank is a small Utah bank most people have never heard of, because its business is originating loans that get sold to consumers under other companies’ names — and its own 2025 annual report lists its current lending partners as Upstart, Elevate, Reach, Plannery, Backd, Albert, Tilt, Earnest, PowerPay, Clasp, LendingPoint, OppLoans, Mulligan Funding, and American First Finance. Only the American First Finance relationship is named in this case, so borrowing through one of the others doesn’t mean you’re in the class — but if you’ve ever borrowed under any of those names, check the settlement site rather than assume either way. In May 2024, personal information tied to FinWise accounts was accessed — not by outside hackers but, according to FinWise’s own SEC filing, by a former employee “following termination of their employment.” FinWise didn’t start notifying people until more than a year later, and a $2.8 million class action settlement is now open for claims.
Key Terms Defined
Data Incident: The settlement’s own term for what happened — deliberately not “breach,” “hack,” or “cyberattack,” because FinWise disputes any wrongdoing. It refers to unauthorized access to systems containing Settlement Class Members’ Private Information around May 31, 2024.
Documented Losses Payment: Reimbursement of up to $5,000 for specific, provable out-of-pocket costs “fairly traceable” to the incident — identity theft losses, credit-monitoring or freeze/unfreeze fees incurred on or after May 31, 2024, and related miscellaneous expenses like notary or postage fees.
Cash Fund Payment: A no-documentation alternative — instead of proving losses, you get an equal (“pro rata”) share of whatever’s left in the settlement fund after documented claims, fees, and administrative costs are paid.
Settlement Class: Every living person in the United States whose Private Information was affected by the Data Incident, including everyone who received a notice about it — whether or not you remember getting that notice.

What You Need to Know
A $2,800,000 settlement has been reached in Minter v. FinWise Bank et al., Case No. 2:25-cv-00569-JNP-CMR, pending in the U.S. District Court for the District of Utah before Judge Jill N. Parrish, according to the official settlement website administered by Epiq. The defendants are FinWise Bank, FinWise Bancorp, and American First Finance. The Court entered its Preliminary Approval Order on July 1, 2026, and will decide whether to grant Final Approval at a hearing on December 10, 2026, at 10:00 a.m. No money goes out until that happens.
Every date, dollar figure and deadline in this post was checked against the official settlement site on September 9, 2026. Settlement calendars can move — confirm there before you rely on one.
Here’s what actually occurred, in FinWise’s own words. In its Form 10-K for fiscal year 2025, filed with the Securities and Exchange Commission on March 23, 2026, FinWise Bancorp disclosed:
“In July 2025, the Company notified approximately 600,000 individuals of an alleged data breach in which their personal data was exposed by a former employee following termination of their employment.”
— FinWise Bancorp, Form 10-K, filed with the SEC March 23, 2026
That is a materially different story than “hackers broke in.” This was unauthorized access by someone who had worked at the bank, discovered sometime after the fact, involving data going back to on or about May 31, 2024 — the date the official settlement site itself uses to describe when the Data Incident occurred.
The Daily Money Brief — Free, at 10 AM
Money you may be owed, scams to dodge, and the fine print decoded — the consumer money news that affects your wallet, every weekday.
The headcount itself moved as the investigation continued. FinWise’s Form 10-Q covering the period ended June 30, 2025 put the number at “approximately 600,000 individuals.” Reporting from Banking Dive and American Banker, both published after notification letters went out on July 29, 2025, put the total at approximately 689,000. The official settlement site itself doesn’t publish a specific headcount at all — so the honest answer is: roughly 600,000 to 689,000 people, depending on which document you read, and FinWise’s own most recent SEC filings are the most conservative end of that range.
American Banker’s reporting is also the source for the timeline gap that matters most here: the data was accessed in May 2024, and FinWise did not begin sending notification letters until July 29, 2025 — American Banker reported the bank waited roughly a year to disclose it, attributing the delay to a FinWise spokesperson’s statement that “identifying and finalizing a list of 600k+ impacted takes a while and it’s something that has to be done very carefully.” That’s the company’s own explanation, not a finding by any court — I’m reporting what was said, not what a judge determined.
Defendants deny any wrongdoing. Per the settlement’s own FAQ page: “Defendants deny the legal claims and deny any wrongdoing or liability. The Court has not made any determination of any wrongdoing by Defendants, or that any law has been violated. Instead, the Plaintiffs and Defendants have agreed to a settlement to avoid the risk, cost, and time of continuing the Action.” Nothing here is a finding of fact against FinWise, FinWise Bancorp, or American First Finance — it’s a negotiated settlement of disputed claims.
Why You Need to Know It
The Claim: “I never got a letter from FinWise, so I’m not in this settlement.”
The Reality: The Settlement Class is defined, per the official site, as “all living, natural persons residing in the United States whose Private Information was affected by the Data Incident, including all individuals who were sent a notice.” That’s broader than “people who remember getting a letter.” Notification letters get lost, tossed as junk mail from a bank name you don’t recognize, or sent to an old address. According to American Banker’s reporting, the exposed data was tied specifically to FinWise’s lending partnership with American First Finance, its lending partner in that program — so if you ever took out a loan through that partnership, it’s worth checking directly with the settlement administrator rather than assuming you’re excluded because no letter comes to mind.
This is the real reason this settlement is worth ten minutes of your time even if the name FinWise means nothing to you. Most people don’t apply for a “FinWise loan.” They apply for financing at a furniture store, a dental office, or a fintech app’s checkout screen — and the bank actually underwriting and funding that loan, sitting behind the scenes, is FinWise. That’s not unusual; it’s how a lot of consumer lending works now. It just means the notice you should have been watching for came from a name you’d never connect to your own loan.
The underlying mechanism of identity theft is exactly what’s at risk here: a Social Security number and account number, once exposed, don’t need to be “used” by the original wrongdoer to hurt you. They can be sold, resold, and used months or years later by someone with no connection at all to the original incident.
Things to Consider
The Claim: “I’ll just write up a list of what this cost me and submit it for the $5,000 documented-losses payment.”
The Reality: Per the settlement’s own FAQ: “‘Self-prepared’ documents such as handwritten receipts are, by themselves, insufficient to receive reimbursement, but can be considered to add clarity to or support other submitted documentation.” You need actual receipts, statements, or records — not a list you typed up yourself. If you don’t have documentation for specific losses, the no-paperwork Cash Fund Payment (a pro rata share of what’s left in the fund) is the realistic option, plus credit monitoring either way.
There’s a second catch worth knowing before you file: you can’t double-dip. The settlement FAQ states plainly that you “will not be reimbursed for expenses if you have been reimbursed for the same expenses by another source, including compensation provided in connection with the identity protection and credit monitoring services offered as part of the notification letter provided by FinWise.” If FinWise’s original notification letter already gave you free monitoring and you used it, you can still claim the settlement’s separate two-year credit monitoring benefit — but you can’t claim reimbursement twice for the identical expense.
Eligible documented losses, per the settlement, include costs incurred on or after May 31, 2024 for identity theft or fraud, for purchasing or extending credit monitoring or identity theft protection, for accessing or freezing/unfreezing your credit reports at any bureau, and miscellaneous costs like notary, fax, postage, copying, mileage, and long-distance charges tied to fixing the problem. Keep every receipt from the moment you suspect something is wrong.
And because any settlement this size draws opportunists: the real settlement administrator will never call you demanding a fee to “process” your claim, and you cannot exclude yourself from the settlement by phone or email — only by mail, postmarked by September 29, 2026. If someone calls offering to file your claim for a cut of the payout, that call is the scam this settlement exists to protect you from, not a service connected to it.
What to Think About Doing
Do these roughly in this order. None of them require remembering a FinWise letter — start by checking your eligibility directly.
- Check the official settlement site directly — don’t rely on a search result or a text message. Go to finwisedatasettlement.com or call the administrator at 1-877-419-3877. If you ever had a fintech loan, a buy-now-pay-later plan, or an in-store financing agreement in the last few years — especially through American First Finance — it’s worth five minutes to check, even without a letter in hand.
- Gather real documentation before you file, not a self-written list. Pull actual receipts and statements for any costs tied to identity theft, fraud, credit monitoring purchases, or credit freeze/unfreeze fees incurred on or after May 31, 2024. If you don’t have documentation, plan to file for the no-paperwork Cash Fund Payment plus credit monitoring instead — both are real options, not consolation prizes.
- File your Claim Form online, or by mail postmarked, by October 29, 2026. That’s the only way to get any Settlement Class Member Benefit. Mailed forms go to FinWise Data Incident, Settlement Administrator, P.O. Box 4390, Portland, OR 97208-4390.
- If you want to preserve the right to sue on your own instead, you have to opt out by September 29, 2026 — in writing, by mail. You cannot exclude yourself by phone or email, and the exclusion goes to the address in the settlement site’s exclusion instructions — don’t assume it’s the claims P.O. box. Opting out is irreversible, so if your losses are real and documented, talk to a consumer attorney before September 29 (NACA can connect you with one; data-breach cases are often taken on contingency). If you do nothing at all, you get no benefits and give up your legal rights, so “doing nothing” is the one option that leaves you worse off than either filing or opting out.
- Freeze your credit at all three bureaus regardless of what you decide about the claim. Here’s exactly how, and what a freeze does and doesn’t cover — it’s free, and Social Security numbers exposed in incidents like this one don’t expire.
- If you find signs of actual identity theft — accounts you don’t recognize, hard inquiries you didn’t make — move fast and use the federal recovery process. Here’s the full identity-theft recovery path, including the FTC’s IdentityTheft.gov, which builds you a personalized recovery plan once you report what happened.
I also covered a very different kind of health-data breach this month — DentaQuest’s exposure of 15 million dental and Medicaid patients’ records — and the lesson from both stories together is the same one: the advice that fits one breach doesn’t automatically fit the next. Here, the exposed data is financial (SSNs and account numbers), so a credit freeze is genuinely central to your defense. In DentaQuest’s case, the exposed data was medical, so a freeze barely touches the real risk. Read the specifics of what was actually exposed before you decide your response is “done.”
Key Takeaways
- According to FinWise’s own SEC filings, this was not an outside cyberattack — the company says the data was “exposed by a former employee following termination of their employment.”
- The number of people affected has been reported differently across documents: roughly 600,000 in FinWise’s SEC filings, roughly 689,000 in banking-trade reporting once notification finished. The official settlement site gives no specific number.
- You don’t need a letter in hand to check your eligibility — the class includes everyone whose data was affected, whether or not the notice reached you.
- Self-written expense lists don’t count as documentation. You need real receipts, and you can’t be reimbursed for a cost already covered by FinWise’s original monitoring offer.
- The claim deadline is October 29, 2026. The exclusion and objection deadline is earlier — September 29, 2026.
The Bottom Line
If you’re reading this because someone forwarded it, not because you remember a letter from a bank you’d never heard of — that’s exactly the gap this settlement falls into for most people. You’re not careless for missing a notice from a name you don’t recognize; that’s how modern lending is built, with a bank like FinWise working behind other companies’ storefronts. The reframe is simple: check first, decide second. It costs nothing to look up your name at the settlement site, and the downside of skipping it is a check and two years of credit monitoring you may never claim. Be realistic about the check: a pro rata share of what’s left after fees and documented claims is more likely tens of dollars than hundreds, and the fewer people who file, the bigger each share gets. I’ve watched a lot of settlements like this one quietly expire because nobody connected their loan to the company name in the letter. Don’t let this be one of them — check today, file by October 29, and move on with your life.
Frequently Asked Questions
Am I part of the FinWise Bank data breach settlement even if I don’t remember getting a letter?
Possibly, yes. The Settlement Class is defined by the official settlement site as everyone whose Private Information was affected by the Data Incident, “including all individuals who were sent a notice” — that phrasing includes people who were sent a notice but may not have opened it, recognized the sender, or kept it. If you ever had a FinWise-originated loan, most commonly through its partnership with American First Finance, check directly at finwisedatasettlement.com or by calling 1-877-419-3877 rather than assuming a missing memory of a letter means you’re excluded.
How much money can I actually get from the FinWise settlement?
Two paths, plus a third benefit available either way. You can submit documented losses (receipts, statements — not self-written lists) for reimbursement up to $5,000 per person, or you can skip documentation and take a pro rata Cash Fund Payment, which is an equal share of whatever remains in the fund after fees and documented claims are paid. Either way, you can also claim two years of three-bureau credit monitoring. California residents who lived in California at the time of the incident may qualify for up to double the Cash Fund Payment amount.
Was the FinWise data breach caused by hackers?
Not according to FinWise — and this is the detail most coverage of this story gets wrong. FinWise Bancorp’s own Form 10-K, filed with the SEC on March 23, 2026, states that personal data “was exposed by a former employee following termination of their employment.” That’s an unauthorized-access incident involving someone who had worked at the bank, not an external cyberattack. FinWise and the other defendants deny any wrongdoing or liability, and no court has made a finding against them — this is a negotiated settlement of disputed claims, not a verdict.
What counts as a “documented loss” for the $5,000 payment, and what doesn’t?
Per the settlement’s FAQ, eligible documented losses include unreimbursed costs from identity theft or fraud, costs incurred on or after May 31, 2024 to purchase or extend credit monitoring or identity theft protection, costs to access or freeze/unfreeze your credit reports, and related miscellaneous expenses like notary, postage, or mileage. What doesn’t count: handwritten or self-prepared receipts by themselves (they can support other documentation but aren’t sufficient alone), and any expense you’ve already been reimbursed for elsewhere — including through the free monitoring FinWise offered in its original notification letter.
What’s the actual deadline, and what happens if I miss it?
The deadline to submit a Claim Form is October 29, 2026, either online or postmarked by mail. The earlier deadline — September 29, 2026 — is for two different actions: excluding yourself from the settlement (which must be done by mail; you cannot opt out by phone or email) or objecting to its terms. If you do nothing at all by October 29, 2026, you receive no Settlement Class Member Benefits and give up your right to sue over these claims separately — doing nothing is the only option that leaves you with nothing.
This is what the settlement’s own documents and FinWise’s own SEC filings say, and how I’d walk through it if it were my own name in that database — but you know your own loan history and your own risk tolerance better than I do. Take this as input, not instruction.
If someone in your life took an in-store or fintech financing loan in the last couple of years and doesn’t recognize the name FinWise, send them this. The settlement doesn’t announce itself under a name most people would connect to their own loan — and October 29, 2026 comes fast.
Dealing With Debt? Understanding your options is the first step. See how all your debt relief options compare — including ones most sites won’t tell you about. The Find Your Path quiz gives a recommendation based on your actual numbers, and the Scam-O-Meter checks any company’s complaint history before you sign. Federal Reserve Bank of New York research shows bankruptcy filers recover faster than those who don’t file.
Claiming money you are owed is one good day. What you do over the following year is what actually changes your position.
In the latest issue (Sep 9): The paycheck advance app said it wasn’t a loan. Connecticut just made it give every fee back.
I write Your Money Actually most weekdays — what I am watching in debt and money, and the small decisions that compound. It is free, I sell nothing, and I take no money from any company I write about.