Yes, employee information was exposed in the Complete Payroll Solutions data breach that occurred on March 10, 2024. The incident compromised sensitive personal data for approximately 376,943 individuals who used the payroll service or worked for clients of the company. A $2.6 million class action settlement has been established to compensate affected individuals and provide protective services to prevent further harm from identity theft.
The exposed data includes some of the most sensitive information a company can collect: names, addresses, Social Security numbers, driver’s license numbers, financial account information, and health insurance details. For workers whose employers used Complete Payroll Solutions, this breach represents a significant risk because payroll processors maintain intimate details about compensation, employment status, and personal identifying information all in one place. The settlement provides multiple forms of compensation and protection, though the per-claimant cash payout is modest. Eligible individuals can receive an estimated $100 in direct compensation (subject to variation based on claim volume), up to $5,000 in reimbursement for out-of-pocket expenses related to the breach, three years of credit monitoring, and $1 million in identity theft insurance with fully managed recovery services.
Table of Contents
- What Information Was Exposed in the Complete Payroll Solutions Data Breach?
- The Timeline and Discovery of the Breach
- Settlement Details and Compensation
- How to File a Claim
- Credit Monitoring and Identity Theft Protection
- Common Concerns and Limitations
- What This Breach Means for Payroll Service Users
- Frequently Asked Questions
What Information Was Exposed in the Complete Payroll Solutions Data Breach?
The Complete Payroll Solutions breach exposed a comprehensive profile of employee information that went far beyond basic contact details. The compromise included names, home addresses, Social Security numbers, driver’s license numbers, financial account information, and health insurance information. This combination of data types creates a particularly high-risk scenario for identity theft because it provides attackers with the foundational elements needed to open fraudulent accounts, apply for credit, or commit other forms of identity fraud. The inclusion of Social Security numbers is especially concerning because SSNs cannot be changed and are used as a primary identifier across credit reporting, financial systems, and government services. When an SSN is exposed, the risk persists indefinitely.
A person whose SSN was compromised in the Complete Payroll Solutions breach could potentially face fraudulent credit applications years after the breach occurred. The presence of driver’s license numbers compounds this risk by providing a second form of government identification that attackers could use to authenticate fraudulent transactions. Financial information exposed in the breach created additional immediate risks for account takeover. If attackers obtained banking details or credit card information, they could potentially access funds or open new accounts. Health insurance information, while perhaps less commonly exploited, can be misused for fraudulent medical claims or sold to other criminals for targeted phishing attacks against healthcare consumers.
The Timeline and Discovery of the Breach
The Complete Payroll Solutions data breach occurred on March 10, 2024, but like many data breaches, there was a lag between the incident date and public notification. The company eventually notified affected individuals that their information had been compromised, triggering the legal process that led to the class action settlement. This delay between breach and discovery is common in payroll processor breaches because the companies often take time to investigate the scope of the incident and determine what occurred. The extended timeline between breach and notification highlights a persistent problem in data breach incidents: affected individuals remain unaware of their compromised information during the period when fraudsters are most likely to exploit it.
During the months between March 2024 and the eventual notification, people whose data was stolen had no opportunity to implement protective measures or monitor their accounts closely. This delay is one reason why credit monitoring services included in settlements are valuable, even if they come months after the exposure. The discovery process for data breaches in payroll companies presents unique challenges because these firms process sensitive information for large numbers of employers and employees. A breach at a payroll processor potentially affects not just the employees of one company but potentially thousands of companies whose data passed through the compromised systems. This scale makes investigation and notification more complex than breaches at smaller organizations.
Settlement Details and Compensation
The $2.6 million class action settlement establishes a fund to compensate affected individuals and provide protective services. The settlement was structured to provide multiple forms of compensation rather than a single cash payment, reflecting the reality that different people face different risks and expenses following a data breach. The estimated per-claimant cash payout is approximately $100, though this amount may vary depending on how many individuals actually submit claims. In class action settlements, when a fixed amount must be divided among claimants, the actual payment per person can fluctuate. If 50,000 people file claims, the per-claimant amount might be considerably higher than if 200,000 people file claims.
Claimants should understand that the $100 figure is an estimate based on certain participation assumptions. The settlement also provides up to $5,000 in reimbursement for unreimbursed out-of-pocket expenses that individuals incurred as a result of the breach, such as costs for credit reports, fraud monitoring services they purchased independently, or expenses related to resolving identity theft issues. This structure means the settlement prioritizes protecting people who actually suffered documented expenses over providing equal cash compensation to all. A person who experienced identity theft and paid for resolution services could receive substantial reimbursement, while someone who suffered no financial impact receives only the base cash payment. The settlement recognizes that not all breach victims experience the same level of harm.
How to File a Claim
The claims deadline for the Complete Payroll Solutions settlement is June 18, 2026, making this a time-sensitive matter for eligible individuals. Anyone who received notification of the breach and believes their data was compromised should review the settlement notice they received for instructions on how to submit a claim. The claims process typically requires proof of class membership and, for expense reimbursement claims, documentation of actual costs incurred. Filing a claim is generally a straightforward process but requires organization and attention to detail, particularly for anyone seeking expense reimbursement.
Individuals claiming reimbursement should gather receipts and documentation for any costs related to identity theft, credit monitoring, fraud resolution, or other breach-related expenses. Unlike the base $100 payment, which requires only proof of class membership, the $5,000 reimbursement requires evidence of actual expenses with documentation. Missing the June 18, 2026 deadline means forfeiting eligibility to receive settlement benefits. The claim deadline is absolute, and there is typically no extension period. For individuals who may be on vacation, dealing with life events, or simply disorganized at the time the deadline passes, this represents a loss of compensation they would otherwise be entitled to receive.
Credit Monitoring and Identity Theft Protection
The settlement includes three years of complimentary credit monitoring services, which is one of the most valuable components for long-term protection against identity theft. Credit monitoring services alert subscribers when someone attempts to open new accounts, apply for credit, or make other changes to their credit profiles in their name. For someone whose SSN, driver’s license number, and financial information were exposed in the Complete Payroll Solutions breach, three years of monitoring provides meaningful early warning of fraudulent activity. The settlement also provides $1 million in identity theft insurance coverage combined with fully managed identity recovery services. This is substantially more protective than credit monitoring alone.
If identity theft does occur, the insurance covers costs associated with resolving the fraud, and the recovery services means the person doesn’t have to personally navigate the complex process of contacting creditors, disputing fraudulent accounts, and rebuilding their credit. With fully managed recovery services, a specialist handles communication with financial institutions and works to restore the victim’s credit profile. However, three years of protection has a clear endpoint. Once the monitoring period expires, individuals are no longer automatically alerted to suspicious activity. This is a limitation worth understanding: the settlement provides protection for 36 months, but the risk of fraud from information exposed in a 2024 breach extends well beyond that timeframe. Someone whose SSN was compromised should consider maintaining some form of credit monitoring or fraud protection after the settlement-provided services expire.
📨 Get Free Mass Tort Guides Alerts
Free · No spam · Unsubscribe anytime
Common Concerns and Limitations
One common concern with data breach settlements is that the compensation sometimes doesn’t align with the actual harm experienced. A person who had their identity stolen and spent hundreds of hours and thousands of dollars resolving fraud might receive only a few hundred dollars in compensation and reimbursement under a settlement. The $2.6 million fund, while substantial, is being divided among nearly 377,000 people, which necessarily limits individual payments. This is an inherent limitation of class action settlements: they provide broader coverage at lower per-person amounts rather than maximum compensation for individual victims. Another limitation is that settlements do not generally compensate for intangible harms like stress, anxiety, or the time spent dealing with fraud concerns.
A person who checks their credit reports regularly for months out of worry, monitors their accounts obsessively, or experiences significant anxiety about identity theft typically receives no additional compensation for these non-financial impacts. The settlement framework focuses on concrete, documentable expenses rather than emotional harm. The settlement also does not prevent future breaches or hold Complete Payroll Solutions to specific security standards going forward. Class action settlements are typically designed to compensate past harm rather than mandate future behavior changes. Someone who received this settlement has recourse for the 2024 breach, but the legal agreement does not include requirements that the company implement specific security improvements to prevent future incidents.
What This Breach Means for Payroll Service Users
The Complete Payroll Solutions breach illustrates a broader vulnerability in how employee data is centralized at payroll processors. When a company outsources payroll to a third-party provider, they’re transferring vast amounts of employee information—including SSNs, addresses, compensation history, and tax information—to that vendor. If the vendor experiences a breach, entire employee populations are compromised simultaneously rather than individual companies being affected one at a time.
Employees should recognize that their personal data security depends not only on their employer’s practices but on every vendor their employer uses. A person whose employer implemented strong security measures could still have their data exposed through a breach at a payroll processor, a benefits administrator, or another third-party vendor. The Complete Payroll Solutions incident affected nearly 377,000 people, demonstrating that significant exposure can occur even at companies primarily known for handling routine payroll functions rather than being targeted as high-value security targets. The June 25, 2026 final approval hearing will formalize the settlement, after which the distribution of settlement funds to eligible claimants will begin.
Frequently Asked Questions
If my data was exposed in the Complete Payroll Solutions breach, will my identity definitely be stolen?
No. Being part of a data breach increases your risk of identity theft, but it doesn’t guarantee it will happen. The settlement provides monitoring and insurance specifically because many people will never experience fraudulent activity, while others will. Taking protective measures like monitoring credit reports and fraud alerts substantially reduces the likelihood that fraud will succeed.
Do I have to provide claim documentation to get the base $100 payment?
No. The approximately $100 base payment requires only proof that you were part of the affected class (typically having received breach notification). The $5,000 expense reimbursement requires documentation of actual costs incurred, but the base payment does not.
Can I get more than $5,000 in reimbursement if my identity theft costs exceeded that amount?
The settlement caps out-of-pocket reimbursement at $5,000. If someone incurred $15,000 in costs resolving identity theft, the settlement reimburses only $5,000. However, the $1 million identity theft insurance with recovery services provides additional protection beyond the reimbursement cap.
Does the three-year credit monitoring extend beyond three years if identity theft occurs during the monitoring period?
That depends on the specific terms of the monitoring service as written in the settlement agreement. Generally, three years means the monitoring service is available for three years from activation. If fraud occurs during that period, the identity theft insurance and recovery services continue to provide coverage, but the automatic monitoring alerts would end after three years.
What happens to unclaimed settlement money if not all eligible people file claims?
Settlement unclaimed money typically goes to a cy pres award (distribution to related nonprofits or charities) or back to the defendant company, depending on settlement terms and court approval. Filing a claim before the June 18, 2026 deadline ensures your share is allocated to you rather than potentially going elsewhere.
How do I prove I was affected if I didn’t receive a breach notification?
If you believe you should have been affected but didn’t receive notification, contact the claims administrator information provided in the settlement documentation. Proof of employment with a company using Complete Payroll Solutions during the relevant period typically establishes class membership.
You Might Also Like
- Fidelity Investments Data Breach Settlement Covers Customers Whose Information Was Exposed
- Kaiser Privacy Settlement Claims Patient Website Data Was Shared With Third Parties
- Capital Health Data Breach Settlement Resolves Claims Over Hospital Cyberattack