Latest Posts Latest Episodes Free Tools

Cook v. SoFi Technologies, Inc., Case No. 3:26-cv-01722

Active Filed: February 27, 2026 Plaintiff: Cook Court: U.S. District Court (DISTRICT COURT, N.D. CALIFORNIA) Case: 3:26-cv-01722 Last Updated: August 4, 2026

Quick Answer: On February 27, 2026, Joshua Cook filed a class action lawsuit against SoFi Technologies, Inc. in the Northern District of California (Case No. 3:26-cv-1722), alleging the company failed to protect customers’ private information — including names, dates of birth, addresses, email addresses, phone numbers, and employment and education information — from a data breach. The complaint asserts seven counts including negligence, breach of contract, and violation of the Illinois Consumer Fraud Act. The class seeks monetary damages, lifetime credit monitoring funded by SoFi, and injunctive relief.

Case Update — August 4, 2026

2026-02-27: Doc 5 — Initial Case Management Scheduling Order with ADR Deadlines — Link

2026-02-27: Doc 4 — Summons Issued — Link

2026-02-27: Doc 3 — Case assigned to Magistrate Judge Sallie Kim. Counsel for plaintiff or the removing party is responsible for serving the Complaint or Notice of Removal, Summons and the assigned judge’s standing orders and all other new case documents upon the opposing parties. For information, visit E-Filing A New Civil Case at http://cand.uscourts.gov/ecf/caseopening.Standing orders can be downloaded from the court’s web page at www.cand.uscourts.gov/judges. Upon receipt, the summons will be issued and returned electronically. A scheduling order will be sent by Notice of Electronic Filing (NEF) within two business days. Consent/Declination due by 3/13/2026. (amf, COURT STAFF) (Filed on 2/27/2026) (Entered: 02/27/2026) — Link

2026-02-27: ~Util – Case Assigned by Intake — Link

2026-02-27: Doc 2 — Proposed Summons. (Berry, M.) (Filed on 2/27/2026) (Entered: 02/27/2026) — Link

2026-03-09: Doc 6 — Certificate of Interested Entities, Corporate Disclosure Statement, or Rule 7.1 Disclosures — Link

2026-03-16: Clerk’s Notice re: Consent or Declination — Link

2026-03-19: Doc 8 — Summons Returned Executed — Link

2026-03-27: Doc 9 — Stipulation without Proposed Order — Link

2026-03-31: Doc 10 — Order AND ~Util – Set Deadlines/Hearings — Link

2026-04-21: Clerk’s Notice re: Consent or Declination — Link

2026-05-04: Doc 14 — Notice of Voluntary Dismissal — Link

2026-05-04: Doc 13 — Notice of Voluntary Dismissal — Link

2026-05-04: Doc 12 — Consent/Declination to Proceed Before a US Magistrate Judge — Link

2026-05-06: Doc 15 — ORDER DISMISSING CASE WITH PREJUDICE RE. DKT 14 . Signed by Judge Sallie Kim on 5/6/2026. (jaf, COURT STAFF) (Filed on 5/6/2026) — Link

📄 Download document from CourtListener →

Primary Source: View Original Complaint (PDF)

Facts as Alleged in the Complaint

The following is taken verbatim from the complaint filed in federal court. These are allegations; no finding of fact has been made.

The Parties

  1. Plaintiff Joshua Cook is, and at all times mentioned herein was, an individual citizen of the State of Illinois.
  2. Defendant SoFi is a financial tech company incorporated in Delaware with its principal place of business at 234 1st Street, San Francisco, CA 94105 in San Francisco County. Defendant’s registered agent is Corporation Service Company, located at 251 Little Falls Drive, Wilmington, DE 19808 in Newcastle County.

Factual Allegations

  1. SoFi is a financial technology and banking company which operates as a nationally chartered online bank and is a technology provider to other financial institutions. Founded in 2011, SoFi is the largest online lender based in the United States, serving millions of
  2. As a condition of receiving financial technology and banking services, SoFi requires that its customers entrust it with highly sensitive personal information. In the ordinary course of receiving service from SoFi, Plaintiff and Class Members were required to provide their Private Information to Defendant.
  3. In its privacy policy, SoFi promises its customers that it will not share this Private Information with third parties: SoFi takes the privacy and security of its members’ personal information seriously. We maintain administrative, technical, and physical safeguards designed to protect your information’s security, confidentiality, and integrity.1
  4. By obtaining, collecting, using, and deriving a benefit from Plaintiff’s and Class Members’ Private Information, SoFi assumed legal and equitable duties and knew or should have known that it was responsible for protecting Plaintiff’s and Class Members’ Private Information from unauthorized disclosure and exfiltration. B. The Data Breach and SoFi’s Failure to Notify Plaintiff and Class Members
  5. Upon information and belief, and according to Defendant’s letter to the Washington State Attorney General, Defendant, experienced unauthorized access to its computer systems on or between December 31, 2025, and January 3, 2026. /// /// /// https://www.sofi.com/online-privacy-policy/ (last visited on Feb. 26, 2026).
  6. Through the Data Breach, the unauthorized cybercriminal(s) accessed a cache of highly sensitive Private Information, including names, dates of birth, addresses, email addresses, phone numbers, employment information, and education information, of at least 38,049 individuals.
  7. Plaintiff and Class Members have been denied access to crucial details like the root cause of the Data Breach, the vulnerabilities exploited, the unauthorized actor responsible for the Data Breach, and the remedial measures undertaken to ensure such a breach does not occur again. To date, these critical facts have not been explained or clarified to Plaintiff and Class Members, who retain a vested interest in ensuring that their Private Information is protected.
  8. and representations made to Plaintiff and Class Members to keep Plaintiff’s and Class Members’ Private Information confidential and to protect it from unauthorized access and disclosure.
  9. to keep such information confidential and secure from unauthorized access and to provide timely notice of any security breaches.
  10. SoFi’s data security obligations were particularly important given the substantial increase in cyberattacks in recent years. Plaintiff and Class Members provided their Private Information to SoFi with the reasonable expectation and mutual understanding that SoFi would comply with its obligations SoFi had obligations created by contract, industry standards, common law,
  11. SoFi knew or should have known that its electronic records would be targeted by cybercriminals. /// /// ///
  12. SoFi’s negligence, including its gross negligence, in failing to safeguard Plaintiff’s and Class Members’ Private Information is particularly stark, considering the highly public increase of cybercrime similar to the hacking incident that resulted in the Data Breach.
  13. Data thieves regularly target entities like SoFi due to the highly sensitive information they maintain. SoFi knew and understood that Plaintiff’s and Class Members’ Private Information is valuable and highly sought after by criminal parties who seek to illegally monetize it through unauthorized access.
  14. According to the Identity Theft Resource Center’s 2023 Data Breach Report, the overall number of publicly reported data compromises in 2023 increased more than 72-percent over the previous high-water mark and 78-percent over 2022.2
  15. Despite the prevalence of public announcements of data breach and data security compromises, SoFi failed to take appropriate steps to protect Plaintiff’s and Class Members’ Private Information from being compromised in this Data Breach. /// /// /// 2023 Annual Data Breach Report, IDENTITY THEFT RESOURCE CENTER, (Jan. 2024), available online at: https://www.idtheftcenter.org/wp-content/uploads/2024/01/ITRC_2023-Annual-DataBreach-Report.pdf (last visited on Feb. 26, 2026).
  16. As a national financial technology and banking services provider in possession of millions of customers’ Private Information, SoFi knew, or should have known, the importance of safeguarding the Private Information entrusted to it by Plaintiff and Class Members and of the foreseeable consequences they would suffer if SoFi’s data security systems were breached. Such consequences include the significant costs imposed on Plaintiff and Class Members due to the unauthorized exposure of their Private Information to criminal actors. Nevertheless, SoFi failed to take adequate cybersecurity measures to prevent the Data Breach or the foreseeable injuries it caused.
  17. Given the nature of the Data Breach, it was foreseeable that Plaintiff’s and Class Members’ Private Information compromised therein would be targeted by hackers and cybercriminals, for use in variety of different injurious ways. Indeed, the cybercriminals who possess Plaintiff’s and Class Members’ Private Information can easily obtain their tax returns or open fraudulent credit card accounts in Plaintiff’s and Class Members’ names.
  18. SoFi was, or should have been, fully aware of the unique type and the significant volume of data on SoFi’s network server(s) and systems and the significant number of individuals who would be harmed by the exposure of the unencrypted data.
  19. Plaintiff and Class Members were the foreseeable and probable victims of SoFi’s inadequate security practices and procedures. SoFi knew or should have known of the inherent risks in collecting and storing the Private Information and the critical importance of providing adequate security for that data, particularly due to the highly public trend of data breach incidents in recent years. D. SoFi Failed to Comply with FTC Guidelines
  20. The Federal Trade Commission (“FTC”) has promulgated numerous guides
  21. In October 2016, the FTC updated its publication, Protecting Personal Information: A Guide for Business, which established cybersecurity guidelines for businesses.3 The guidelines note that businesses should protect the personal customer information that they keep, properly dispose of personal information that is no longer needed, encrypt information stored on computer networks, understand their network’s vulnerabilities, and implement policies to correct any security problems. The guidelines also recommend that businesses use an intrusion detection system to expose a breach as soon as it occurs, monitor all incoming traffic for activity indicating someone is attempting to hack into the system, watch for large amounts of data being transmitted from the system, and have a response plan ready in the event of a breach.
  22. The FTC further recommends that companies not maintain personally identifiable information (“PII”) longer than is needed for authorization of a transaction, limit access to sensitive data, require complex passwords to be used on networks, use industry-tested methods for security, monitor the network for suspicious activity, and verify that third-party service providers have implemented reasonable security measures. Protecting Personal Information: A Guide for Business, FEDERAL TRADE COMMISSION (October 2016), available at https://www.ftc.gov/system/files/documents/plain-language/pdf0136_proteting-personal-information.pdf (last visited on Feb. 26, 2026).
  23. The FTC has brought enforcement actions against businesses for failing to adequately and reasonably protect customer data by treating the failure to employ reasonable and appropriate measures to protect against unauthorized access to confidential consumer data as an unfair act or practice prohibited by Section 5 of the FTC Act, 15 U.S.C. § 45 et seq. Orders resulting from these actions further clarify the measures businesses must take to meet their data security obligations.
  24. Such FTC enforcement actions include those against businesses that fail to adequately protect customer data, like SoFi here. See, e.g., In the Matter of LabMD, Inc., 2016- 2 Trade Cas. (CCH) ¶ 79708, 2016 WL 4128215, at *32 (MSNET July 28, 2016) (“[T]he Commission concludes that LabMD’s data security practices were unreasonable and constitute an unfair act or practice in violation of Section 5 of the FTC Act.”).
  25. Section 5 of the FTC Act, 15 U.S.C. § 45, prohibits “unfair . . . practices in or affecting commerce,” including, as interpreted and enforced by the FTC, the unfair act or practice by businesses like SoFi of failing to use reasonable measures to protect Private Information they collect and maintain from consumers. The FTC publications and orders described above also form part of the basis of SoFi’s duty in this regard.
  26. The FTC has also recognized that personal data is a new and valuable form of currency. In an FTC roundtable presentation, former Commissioner Pamela Jones Harbour stated that “most consumers cannot begin to comprehend the types and amount of information collected by businesses, or why their information may be commercially valuable. Data is currency. The larger the data set, the greater potential for analysis and profit.”4 FTC Commissioner Pamela Jones Harbour, Remarks Before FTC Exploring Privacy Roundtable (Dec. 7, 2009), transcript available at https://www.ftc.gov/sites/default/files/documents/public_statements/remarks-ftc-exploringprivacy-roundtable/091207privacyroundtable.pdf (last visited on Feb. 26, 2026).
  27. As evidenced by the Data Breach, SoFi failed to properly implement basic data security practices. SoFi’s failure to employ reasonable and appropriate measures to protect against unauthorized access to Plaintiff’s and Class Members’ Private Information constitutes an unfair act or practice prohibited by Section 5 of the FTCA.
  28. SoFi was at all times fully aware of its obligation to protect the Private Information of its customers yet failed to comply with such obligations. Defendant was also aware of the significant repercussions that would result from its failure to do so. E. SoFi Failed to Comply with Industry Standards
  29. vulnerable to cyberattacks because of the value of the Private Information which they collect and maintain. As noted above, experts studying cybersecurity routinely identify businesses as being particularly
  30. The Center for Internet Security’s (CIS) Critical Security Controls (CSC) recommends certain best practices to adequately secure data and prevent cybersecurity attacks, including Critical Security Controls of Inventory and Control of Enterprise Assets, Inventory and Control of Software Assets, Data Protection, Secure Configuration of Enterprise Assets and Software, Account Management, Access Control Management, Continuous Vulnerability Management, Audit Log Management, Email and Web Browser Protections, Malware Defenses, Data Recovery, Network Infrastructure Management, Network Monitoring and Defense, Security Awareness and Skills Training, Service Provider Management, Application Software Security, Incident Response Management, and Penetration Testing.5
  31. certain practices to safeguard systems, such as the following: a. Control who logs on to your network and uses your computers and other devices. The National Institute of Standards and Technology (“NIST”) also recommends The 18 CIS Critical Security Controls, CENTER FOR INTERNET SECURITY, https://www.cisecurity.org/controls/cis-controls-list (last visited on Feb. 26, 2026).
  32. Further still, the United States Cybersecurity and Infrastructure Security Agency (“CISA”) makes specific recommendations to organizations to guard against cybersecurity attacks, including (a) reducing the likelihood of a damaging cyber intrusion by validating that “remote access to the organization’s network and privileged or administrative access requires multi-factor authentication, [e]nsur[ing] that software is up to date, prioritizing updates that address known exploited vulnerabilities identified by CISA[,] [c]onfirm[ing] that the organization’s IT personnel have disabled all ports and protocols that are not essential for business purposes,” and other steps; (b) taking steps to quickly detect a potential intrusion, including “[e]nsur[ing] that cybersecurity/IT personnel are focused on identifying and quickly assessing any unexpected or unusual network behavior [and] [e]nabl[ing] logging in order to better investigate issues or events[;] [c]onfirm[ing] that the organization’s entire network is protected by antivirus/antimalware software and that signatures in these tools are updated,” and (c) “[e]nsur[ing] that the organization is prepared to respond if an intrusion occurs,” and other steps.6
  33. Upon information and belief, Defendant failed to implement industry-standard cybersecurity measures, including by failing to meet the minimum standards of both the NIST Shields Up: Guidance for Organizations, CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY, https://www.cisa.gov/shields-guidance-organizations (last visited Feb. 26, 2026).
  34. In addition to its obligations under federal and state laws, SoFi owed a duty to Plaintiff and Class Members to exercise reasonable care in obtaining, retaining, securing, safeguarding, deleting, and protecting the Private Information in its possession from being compromised, lost, stolen, accessed, and misused by unauthorized persons. SoFi owed a duty to Plaintiff and Class Members to provide reasonable security, including complying with industry standards and requirements, training for its staff, and ensuring that its computer systems, networks, and protocols adequately protected the Private Information of Class Members
  35. Upon information and belief, SoFi breached its obligations to Plaintiff and Class Members and/or was otherwise negligent and reckless because it failed to properly maintain and safeguard its computer systems and data. SoFi’s unlawful conduct includes, but is not limited to, the following acts and/or omissions: a. data breaches and cyberattacks; Failing to maintain an adequate data security system that would reduce the risk of b. Failing to adequately protect customers’ Private Information; c. Failing to properly monitor its own data security systems for existing intrusions;
  36. Plaintiff’s and Class Members’ Private Information by allowing cyberthieves to access its computer network and systems which contained unsecured and unencrypted Private Information.
  37. Upon information and belief, SoFi negligently and unlawfully failed to safeguard Had SoFi remedied the deficiencies in its information storage and security systems, followed industry guidelines, and adopted security measures recommended by experts in the field, it could have prevented intrusion into its information storage and security systems and, ultimately, the theft of Plaintiff’s and Class Members’ confidential Private Information.
  38. Accordingly, Plaintiff’s and Class Members’ lives were severely disrupted. What’s more, they have been harmed as a result of the Data Breach and now face an increased risk of future harm that includes, but is not limited to, fraud and identity theft. Plaintiff and Class Members also lost the benefit of the bargain they made with SoFi. /// /// ///
  39. The FTC hosted a workshop to discuss “informational injuries,” which are injuries that consumers like Plaintiff and Class Members suffer from privacy and security incidents such as data breaches or unauthorized disclosure of data.7 Exposure of highly sensitive personal information that a consumer wishes to keep private may cause harm to the consumer, such as the ability to obtain or keep employment. Consumers’ loss of trust in e-commerce also deprives them of the benefits provided by the full range of goods and services available which can have negative impacts on daily life.
  40. Any victim of a data breach is exposed to serious ramifications regardless of the nature of the data that was breached. Indeed, the reason why criminals steal information is to monetize it. They do this by selling the spoils of their cyberattacks on the black market to identity thieves who desire to extort and harass victims or to take over victims’ identities in order to engage in illegal financial transactions under the victims’ names.
  41. Because a person’s identity is akin to a puzzle, the more accurate pieces of data an identity thief obtains about a person, the easier it is for the thief to take on the victim’s identity or to otherwise harass or track the victim. For example, armed with just a name and date of birth, a data thief can utilize a hacking technique referred to as “social engineering” to obtain even more information about a victim’s identity, such as a person’s login credentials or Social Security number. Social engineering is a form of hacking whereby a data thief uses previously acquired FTC Information Injury Workshop, BE and BCP Staff Perspective, FEDERAL TRADE COMMISSION (Oct. 2018), available at https://www.ftc.gov/system/files/documents/reports/ftcinformational-injury-workshop-be-bcp-staffperspective/informational_injury_workshop_staff_report_-_oct_2018_0.pdf (last visited on Feb. 26, 2026).
  42. In fact, as technology advances, computer programs may scan the Internet with a wider scope to create a mosaic of information that may be used to link compromised information to an individual in ways that were not previously possible. This is known as the “mosaic effect.” Names and dates of birth, combined with contact information like telephone numbers and email addresses, are very valuable to hackers and identity thieves as it allows them to access users’ other accounts.
  43. Thus, even if certain information was not purportedly involved in the Data Breach, the unauthorized parties could use Plaintiff’s and Class Members’ Private Information to access accounts, including, but not limited to, email accounts and financial accounts, to engage in a wide variety of fraudulent activity against Plaintiff and Class Members.
  44. One such example of how malicious actors may compile Private Information is through the development of “Fullz” packages.
  45. Cybercriminals can cross-reference two sources of the Private Information compromised in the Data Breach to marry unregulated data available elsewhere to criminally stolen data with an astonishingly complete scope and degree of accuracy in order to assemble complete dossiers on individuals. These dossiers are known as “Fullz” packages.
  46. The development of “Fullz” packages means that the stolen Private Information from the Data Breach can easily be used to link and identify it to Plaintiff’s and the proposed Class’s phone numbers, email addresses, and other sources and identifiers. In other words, even if certain information such as emails, phone numbers, or credit card or financial account numbers may not be included in the Private Information stolen in the Data Breach, criminals can easily create a Fullz package and sell it at a higher price to unscrupulous operators and criminals (such
  47. For these reasons, the FTC recommends that identity theft victims take several time-consuming steps to protect their personal and financial information after a data breach, including contacting one of the credit bureaus to place a fraud alert on their account (and an extended fraud alert that lasts for 7 years if someone steals the victim’s identity), reviewing their credit reports, contacting companies to remove fraudulent charges from their accounts, placing a freeze on their credit, and correcting their credit reports.8 However, these steps do not guarantee protection from identity theft but can only mitigate identity theft’s long-lasting negative impacts.
  48. Identity thieves can also use stolen personal information such as Social Security numbers for a variety of crimes, including credit card fraud, phone or utilities fraud, bank fraud, to obtain a driver’s license or official identification card in the victim’s name but with the thief’s picture, to obtain government benefits, or to file a fraudulent tax return using the victim’s information. In addition, identity thieves may obtain a job using the victim’s Social Security number, rent a house in the victim’s name, receive medical services in the victim’s name, and even give the victim’s personal information to police during an arrest resulting in an arrest warrant being issued in the victim’s name.
  49. PII is data that can be used to detect a specific individual. PII is a valuable property right. Its value is axiomatic, considering the value of big data in corporate America and the See IdentityTheft.gov, FEDERAL TRADE COMMISSION, available at: https://www.identitytheft.gov/Steps (last visited on Feb. 26, 2026).
  50. The U.S. Attorney General stated in 2020 that consumers’ sensitive personal information commonly stolen in data breaches “has economic value.” 9 The increase in cyberattacks, and attendant risk of future attacks, was widely known and completely foreseeable to the public and to anyone in Defendant’s industry.
  51. The PII of consumers remains of high value to criminals, as evidenced by the prices they will pay through the dark web. Numerous sources cite dark web pricing for stolen identity credentials. For example, PII can be sold at a price ranging from $40 to $200, and bank details have a price range of $50 to $200.10 Experian reports that a stolen credit or debit card number can sell for $5 to $110 on the dark web and that the “fullz” (a term criminals who steal credit card information use to refer to a complete set of information on a fraud victim) sold for $30 in 2017.11
  52. Furthermore, even information such as names, email addresses and phone numbers, can have value to a hacker. Beyond things like spamming customers, or launching phishing attacks using their names and emails, hackers, inter alia, can combine this information with other hacked data to build a more complete picture of an individual. It is often this type of piecing together of a puzzle that allows hackers to successfully carry out phishing attacks or See Attorney General William P. Barr Announces Indictment of Four Members of China’s Military for Hacking into Equifax, U.S. DEP’T OF JUSTICE (Feb. 10, 2020), https://www.justice.gov/opa/speech/attorney-general-william-p-barr-announces-indictmentfour-members-china-s-military (last visited on Feb. 26, 2026). Your personal data is for sale on the dark web. Here’s how much it costs, DIGITAL TRENDS (Oct. 16, 2019), available at https://www.digitaltrends.com/computing/personal-data-sold-onthe-dark-web-how-much-it-costs (last visited on Feb. 26, 2026). Here’s How Much Your Personal Information Is Selling for on the Dark Web, EXPERIAN (Dec. 6, 2017), https://www.experian.com/blogs/ask-experian/heres-how-much-your-personalinformation-is-selling-for-on-the-dark-web (last visited on Feb. 26, 2026).
  53. The Dark Web Price Index of 2023, published by PrivacyAffairs, shows how valuable just email addresses alone can be, even when not associated with a financial account: 13
  54. Beyond using email addresses for hacking, the sale of a batch of illegally obtained email addresses can lead to increased spam emails. If an email address is swamped with spam, that address may become cumbersome or impossible to use, making it less valuable to its owner.
  55. Likewise, the value of PII is increasingly evident in our digital economy. Many companies, including SoFi, collect PII for purposes of data analytics and marketing. These companies, collect it to better target customers, and shares it with third parties for similar purposes.14 See Dark Web Price Index: The Cost of Email Data, MAGICSPAM, https://www.magicspam.com/blog/dark-web-price-index-the-cost-of-email-data/ (last visited on Feb. 26, 2026). See Dark Web Price Index 2023, PRIVACY AFFAIRS, https://www.privacyaffairs.com/darkweb-price-index-2023/ (last visited on Feb. 26, 2026). See Privacy Policy, ROBINHOOD, https://robinhood.com/us/en/support/articles/privacypolicy/ (last visited on Feb. 26, 2026).
  56. One author has noted: “Due, in part, to the use of PII in marketing decisions, commentators are conceptualizing PII as a commodity. Individual data points have concrete value, which can be traded on what is becoming a burgeoning market for PII.”15
  57. Consumers also recognize the value of their personal information and offer it in exchange for goods and services. The value of PII can be derived not only by a price at which consumers or hackers actually seek to sell it, but rather by the economic benefit consumers derive from being able to use it and control the use of it.
  58. profile is infected by misuse or fraud. For example, a consumer with false or conflicting information on their credit report may be denied credit. Also, a consumer may be unable to open an electronic account where their email address is already associated with another user. In this sense, among others, the theft of PII in the Data Breach led to a diminution in value of the PII.
  59. participate in the economic marketplace.
  60. identity crime victims, researchers found that as a result of the criminal misuse of their PII: • • • The Identity Theft Resource Center documents the multitude of harms caused by fraudulent use of PII in its 2023 Consumer Impact Report. 16 After interviewing over 14,000 Data breaches, like that at issue here, damage consumers by interfering with their fiscal autonomy. Any past and potential future misuse of Plaintiff’s PII impairs their ability to A consumer’s ability to use their PII is encumbered when their identity or credit 77-percent experienced financial-related problems; 29-percent experienced financial losses exceeding $10,000; 40-percent were unable to pay bills; See John T. Soma, Corporate Privacy Trend: The “Value” of Personally Identifiable Information (‘PII’) Equals the “Value” of Financial Assets, 15 Rich. J. L. & Tech. 11, 14 (2009). 2023 Consumer Impact Report (Jan. 2024), IDENTITY THEFT RESOURCE CENTER, available online at: https://www.idtheftcenter.org/wp-content/uploads/2023/08/ITRC_2023-ConsumerImpact-Report_Final-1.pdf (last visited on Feb. 26, 2026).
  61. 28-percent were turned down for credit or loans; 37-percent became indebted; 87-percent experienced feelings of anxiety; 67-percent experienced difficulty sleeping; and 51-percent suffered from panic of anxiety attacks.17 It must also be noted that there may be a substantial time lag between when harm occurs and when it is discovered, and also between when PII and/or personal financial information is stolen and when it is used. According to the U.S. Government Accountability Office, which conducted a study regarding data breaches:18 [L]aw enforcement officials told us that in some cases, stolen data may be held for up to a year or more before being used to commit identity theft. Further, once stolen data have been sold or posted on the Web, fraudulent use of that information may continue for years. As a result, studies that attempt to measure the harm resulting from data breaches cannot necessarily rule out all future harm.
  62. been compromised, criminals often trade the information on the “cyber black market” for years. PII is such a valuable commodity to identity thieves that once the information has
  63. As a result, Plaintiff and Class Members are at an increased risk of fraud and identity theft for many years into the future. Thus, Plaintiff and Class Members have no choice but to vigilantly monitor their accounts for many years to come. /// /// Id at pp 21-25. Data Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited; However, the Full Extent Is Unknown, U.S. GOVERNMENT ACCOUNTABILITY OFFICE (June 2007), available at https://www.gao.gov/assets/gao-07-737.pdf (last visited on Feb. 26, 2026).
  64. Plaintiff Cook became a customer of SoFi in or around February of 2017.
  65. When Plaintiff Cook first became a customer, Defendant required that he provide it with substantial amounts of his Private Information.
  66. Upon information and belief, Plaintiff Cook’s Private Information was subject to Defendant’s Data Breach.
  67. Plaintiff Cook would not have provided his Private Information to Defendant had Defendant timely disclosed that its systems lacked adequate computer and data security practices to safeguard its customers’ personal information from theft, and that those systems were subject to a data breach.
  68. Plaintiff Cook suffered actual injury in the form of having his Private Information compromised and/or stolen as a result of the Data Breach.
  69. Plaintiff Cook suffered actual injury in the form of damages to and diminution in the value of his personal information – a form of intangible property that Plaintiff Cook entrusted to Defendant for the purpose of receiving banking services from Defendant and which was compromised in, and as a result of, the Data Breach.
  70. Plaintiff Cook suffered imminent and impending injury arising from the substantially increased risk of future fraud, identity theft, and misuse posed by his Private Information being placed in the hands of criminals.
  71. Plaintiff Cook has a continuing interest in ensuring that his Private Information, which remains in the possession of Defendant, is protected and safeguarded from future breaches. This interest is particularly acute, as Defendant’s systems have already been shown to be susceptible to compromise and are subject to further attack so long as Defendant fails to
  72. undertake the necessary and appropriate security and training measures to protect its customers’ As a result of the Data Breach, Plaintiff Cook has suffered anxiety as a result of the release of his Private Information to cybercriminals, which Private Information he believed would be protected from unauthorized access and disclosure. These feelings include anxiety about unauthorized parties viewing, selling, and/or using his Private Information for purposes of committing cyber and other crimes against his. Plaintiff Cook is very concerned about this increased, substantial, and continuing risk, as well as the consequences that identity theft and fraud resulting from the Data Breach will have on his life.
  73. Plaintiff Cook also suffered actual injury as a result of the Data Breach in the form of (a) damage to and diminution in the value of his Private Information which, upon information and belief, was subject to Defendant’s Data Breach; (b) violation of his privacy rights; and (c) present, imminent, and impending injury arising from the increased risk of identity theft, and fraud he now faces.
  74. As a result of the Data Breach, Plaintiff Cook anticipates spending considerable time and money on an ongoing basis to try to mitigate and address the many harms caused by the Data Breach.
  75. Upon information and belief, Plaintiff and Class Members have been damaged by the compromise of their Private Information in the Data Breach.
  76. Plaintiff and Class Members entrusted their Private Information to Defendant in order to receive Defendant’s services.
  77. As a direct and proximate result of SoFi’s actions and omissions, Plaintiff and Class Members have been harmed and are at an imminent, immediate, and continuing increased risk of harm, including but not limited to, having medical services billed in their names, loans
  78. Plaintiff and Class Members also face a substantial risk of being targeted in future phishing, data intrusion, and other illegal schemes through the misuse of their Private Information, since potential fraudsters will likely use the compromised Private Information to carry out such targeted schemes against Plaintiff and Class Members.
  79. The Private Information maintained by and stolen from Defendant’s systems, combined with publicly available information, allows nefarious actors to assemble a detailed mosaic of Plaintiff and Class Members, which can also be used to carry out targeted fraudulent schemes against Plaintiff and Class Members.
  80. Plaintiff and Class Members also lost the benefit of the bargain they made with SoFi. Plaintiff and Class Members overpaid for services that were intended to be accompanied by adequate data security but were not. Indeed, part of the price Plaintiff and Class Members paid to SoFi was intended to be used by SoFi to fund adequate security of SoFi’s system and protect Plaintiff’s and Class Members’ Private Information. Thus, Plaintiff and the Class did not receive what they paid for.
  81. Additionally, as a direct and proximate result of SoFi’s conduct, Plaintiff and Class Members have also been forced to take the time and effort to mitigate the actual and potential impact of the data breach on their everyday lives, including placing “freezes” and “alerts” with credit reporting agencies, contacting their financial institutions, closing or modifying financial accounts, and closely reviewing and monitoring bank accounts and credit reports for unauthorized activity for years to come.
  82. Plaintiff and Class Members may also incur out-of-pocket costs for protective measures such as credit monitoring fees, credit report fees, credit freeze fees, and similar costs directly or indirectly related to the Data Breach.
  83. Upon information and belief, Plaintiff and Class Members also suffered a loss of value of their Private Information when it was acquired by cyber thieves in the Data Breach. Numerous courts have recognized the propriety of loss of value damages in related cases. An active and robust legitimate marketplace for Private Information also exists. In 2019, the data brokering industry was worth roughly $200 billion.19 In fact, consumers who agree to provide their web browsing history to the Nielsen Corporation can in turn receive up to $50 a year.20 99. Upon information and belief, as a result of the Data Breach, Plaintiff’s and Class Members’ Private Information, which has an inherent market value in both legitimate and illegal markets, has been harmed and diminished due to its acquisition by cybercriminals. This transfer of valuable information happened with no consideration paid to Plaintiff or Class Members for their property, resulting in an economic loss. Moreover, the Private Information is apparently readily available to others, and the rarity of the Private Information has been destroyed because it is no longer only held by Plaintiff and the Class Members, and because that data no longer necessarily correlates only with activities undertaken by Plaintiff and the Class Members, thereby causing additional loss of value.
  84. Plaintiff and Class Members were also damaged via benefit-of-the-bargain damages. The contractual bargain entered into between Plaintiff and SoFi included Defendant’s See How Data Brokers Profit from the Data We Create, THE QUANTUM RECORD, https://thequantumrecord.com/blog/data-brokers-profit-from-our-data/ (last visited on Feb. 26, 2026). Frequently Asked Questions, NIELSEN COMPUTER & MOBILE PANEL, https://computermobilepanel.nielsen.com/ui/US/en/faqen.html (last visited on Feb. 26, 2026).
  85. Finally, Plaintiff and Class Members have suffered or will suffer actual injury as a direct and proximate result of the Data Breach in the form of out-of-pocket expenses and the value of their time that they will now be forced to reasonably incur to remedy or mitigate the effects of the Data Breach such as closely reviewing and monitoring bank accounts and credit reports for additional unauthorized activity for years to come.
  86. Private Information, which is believed to still be in the possession of SoFi, is protected from future additional breaches by the implementation of more adequate data security measures and safeguards, including but not limited to, ensuring that the storage of data or documents containing personal and financial information is not accessible online, that access to such data is passwordprotected, and that such data is properly encrypted.
  87. Upon information and belief, as a direct and proximate result of SoFi’s actions and inactions, Plaintiff and Class Members have suffered a loss of privacy and have suffered cognizable harm, including an imminent and substantial future risk of harm, in the forms set forth above. VI. Moreover, Plaintiff and Class Members have an interest in ensuring that their

Claims for Relief

COUNT I — NEGLIGENCE (On behalf of Plaintiff and the Nationwide Class): Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. SoFi knowingly collected, came into possession of, and maintained Plaintiff’s and Class Members’ Private Information, and had a duty to exercise reasonable care in safeguarding, securing, and protecting such Information from being disclosed, compromised, lost, stolen, and misused by unauthorized parties. SoFi’s duty also included a res…

COUNT II — NEGLIGENCE PER SE (On behalf of plaintiff and the nationwide class): Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. Pursuant to Section 5 of the FTCA, SoFi had a duty to provide fair and adequate computer systems and data security to safeguard the Private Information of Plaintiff and Class Members. SoFi breached its duties by failing to employ industry-standard cybersecurity measures in order to comply with the FTCA, including but not limited to pro…

The Daily Money Brief — Free, at 10 AM

Money you may be owed, scams to dodge, and the fine print decoded — the consumer money news that affects your wallet, every weekday.

No spam. Your email stays private.

COUNT III — BREACH OF CONTRACT (On behalf of plaintiff and the nationwide class): In the Privacy Policy, SoFi commits to protecting the privacy and security of private information and promises to never share Plaintiff’s and Class Members’ Private Information except under certain limited circumstances. Plaintiff and Class Members fully performed their obligations under their contracts with SoFi. However, upon information and belief, SoFi did not secure, safeguard, and/or keep private Plaintiff’s and Class Members’ Private Infor…

COUNT IV — BREACH OF IMPLIED CONTRACT (On behalf of plaintiff and the nationwide class): Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. This Count is pleaded in the alternative to Count III above. SoFi provides financial technology and banking services to Plaintiff and Class Members. Plaintiff and Class Members formed an implied contract with Defendant regarding the provision of those services through their collective conduct, including by Plaintiff and Class Members p…

COUNT V — VIOLATION OF ILLINOIS CONSUMER FRAUD AND DECEPTIVE BUSINESS: Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. As fully alleged above, SoFi engaged in unfair and deceptive acts and practices in violation of the Illinois CFA. Plaintiff and the Illinois Subclass are “consumers” as that term is defined in 815 ILL. COMP. STAT. § 505/1(e)….

COUNT VI — UNJUST ENRICHMENT (on behalf of plaintiff and the nationwide class): Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. This Count is pleaded in the alternative to Counts III and IV above. Plaintiff and Class Members conferred a benefit on SoFi by turning over their Private Information to Defendant and by paying for products and services that should have included cybersecurity protection to protect their Private Information. Plaintiff and Class Members …

COUNT VII — DECLARATORY JUDGMENT (on behalf of plaintiff and the nationwide class): Plaintiff restates and realleges all of the allegations stated above and hereafter as if fully set forth herein. Under the Declaratory Judgment Act, 28 U.S.C. § 2201, et seq., this Court is authorized to enter a judgment declaring the rights and legal relations of the parties and to grant further necessary relief. Furthermore, the Court has broad authority to restrain acts that are tortious and violate the terms of the federal and state statute d…

Remedies Sought

  • Class certification under Fed. R. Civ. P. 23, with Plaintiff as representative of the Nationwide Class and Illinois Subclass
  • Actual damages, statutory damages, equitable relief, restitution, and disgorgement
  • Injunctive and other equitable relief to protect the interests of the Class
  • An order requiring SoFi to fund lifetime credit monitoring and identity theft insurance for Plaintiff and all Class Members
  • Payment of costs for notifying Class Members about the judgment and administering the claims process
  • Prejudgment and post-judgment interest, reasonable attorneys’ fees, costs, and expenses as allowable by law
  • Such other and further relief as the Court may deem just and proper
  • Jury trial on all triable issues

About This Coverage

I monitor federal court cases involving debt relief companies as an educational resource for consumers, other companies in the industry, and regulators. This project began on February 27, 2026, and covers cases filed on or after February 20, 2026. Cases filed before that date are not included. I am currently monitoring 334 companies in the debt relief space.

I report on all cases I am able to monitor — no company is singled out or targeted. The goal is comprehensive, fair coverage that helps consumers understand the legal landscape.

Important: The information on this page comes directly from court documents. I present the allegations exactly as stated in those filings — I do not interpret, summarize, or paraphrase complaint language, as doing so could introduce unintended bias. These are allegations, not findings of fact. Every defendant is presumed innocent and has the right to contest the claims in court. A lawsuit is not a finding of wrongdoing.

You can view the full docket at CourtListener.

Are you a party to this case? I welcome statements, corrections, and updates from any party — plaintiff, defendant, or their counsel. If you'd like to add context or a statement for readers, please contact me directly. I will publish it here.

Frequently Asked Questions

What is the Cook v. SoFi Technologies lawsuit about?

Joshua Cook v. SoFi Technologies, Inc. (Case No. 3:26-cv-1722) is a putative class action filed February 27, 2026 in the U.S. District Court for the Northern District of California. Plaintiff alleges SoFi failed to adequately protect customers’ private information from a data breach, exposing names, dates of birth, addresses, email addresses, phone numbers, and employment and education information. SoFi has not publicly acknowledged the breach or confirmed all personal data was recovered or destroyed.

What data was allegedly compromised in the SoFi data breach?

The complaint defines “Private Information” as: names, dates of birth, home addresses, email addresses, phone numbers, employment information, and education information. The complaint alleges this data is now in the hands of cybercriminals and that Class Members face a lifetime risk of identity theft, financial fraud, and other harms.

What federal and state laws are alleged to have been violated?

The complaint alleges seven causes of action: Count I (Negligence); Count II (Negligence Per Se under Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45); Count III (Breach of Contract based on SoFi’s Privacy Policy); Count IV (Breach of Implied Contract); Count V (Violation of the Illinois Consumer Fraud and Deceptive Business Practices Act, 815 Ill. Comp. Stat. §§ 505/1 et seq., for the Illinois Subclass); Count VI (Unjust Enrichment); and Count VII (Declaratory Judgment under 28 U.S.C. § 2201).

What damages does the class seek from SoFi?

The complaint seeks actual damages, statutory damages, restitution, and disgorgement; an order requiring SoFi to fund lifetime credit monitoring and identity theft insurance for all Class Members; injunctive relief; payment of class notification costs; prejudgment interest; and attorneys’ fees. The amount in controversy is alleged to exceed $5 million, satisfying the Class Action Fairness Act threshold under 28 U.S.C. § 1332(d)(2).

Who is included in the proposed class?

The complaint defines a Nationwide Class of all individuals whose Private Information was accessed or compromised in the SoFi data breach. It also defines an Illinois Subclass of Illinois residents asserting the Illinois Consumer Fraud Act claim. The complaint alleges the class exceeds 100 members with diverse state citizenship, meeting the minimal diversity requirement under 28 U.S.C. § 1332(d)(2)(A). SoFi serves millions of customers across the United States as a nationally chartered online bank.

Source: CourtListener Docket 72341753. Information on this page is taken verbatim from the court complaint filed February 27, 2026. These are allegations only; no finding of fact has been made.

Free Newsletter

Your Money Actually

The unfiltered debt takes I can't fit on this site — for people making good money who are still drowning in debt.

Dealing With Debt? Understanding your options is the first step. See how all your debt relief options compare — including ones most sites won’t tell you about. The Find Your Path quiz gives a recommendation based on your actual numbers, and the Scam-O-Meter checks any company’s complaint history before you sign. Federal Reserve research shows bankruptcy filers recover faster than those who don’t file.

Are you dealing with a debt relief company? If you're considering working with a debt relief company or have already signed a contract, use my free Find Your Path tool to get personalized guidance on your situation.