Court Tests Data Breach Settlements
Coverage from Class Action Defense, Lexology, and others

The Northern District of California rejected without prejudice preliminary approval of a proposed $2.
3 million class-action settlement tied to OE Federal Credit Union’s 2023 ransomware breach, which affected more than 220,000 current and former customers. Judge Jon S. Tigar cited unsupported recovery estimates, deficiencies in the claims-made process, unclear California-specific benefits, fee disclosures, and inaccurate or incomplete settlement documentation. Plaintiffs must submit a revised motion addressing the court’s concerns and Rule 23 requirements by November 4, 2026.
If you read one thing
It provides the clearest overall account of the court’s rejection and the settlement deficiencies that must be addressed.
Settlement approval is blocked pending stronger support
The Northern District of California denied preliminary approval without prejudice, leaving the proposed $2.3 million settlement unresolved. Plaintiffs must substantiate expected recoveries, litigation risks, allocation, and compliance with Rule 23(e)(2) before resubmission.
Claims-made mechanics face heightened scrutiny
The court questioned requiring claims forms when OEFCU can identify affected customers directly, finding that the process could suppress participation and payouts. Recovery estimates are also vulnerable: projected $50 payments could fall near $6 after fees, while large reimbursement claims could eliminate other distributions.
Settlement documentation requires material revision
The proposed agreement does not adequately explain unequal California and non-California payments, payment timing, administration costs, comparable recoveries, or attorneys’ fees. These disclosure and class-treatment issues must be clarified or revised to satisfy Rule 23(e)(2) and court procedures.
$2.3 million USD
proposed settlement fund
“The proposed settlement would have created a non-reversionary $2.3 million fund.”
more than 220,000 customers
customers affected by the data breach
“A federal court in California denied preliminary approval of a proposed $2.3 million class action settlement arising from a data breach affecting more than 220,000 OE Federal Credit Union customers.”
$2.3 million USD
non-reversionary settlement fund
“The proposed settlement established a non-reversionary $2.3 million fund.”
$5,000 USD
maximum documented out-of-pocket reimbursement per claimant
“The court noted that if slightly more than 300 claimants sought the full $5,000 reimbursement, the pro rata share for other class members could fall to nothing.”
slightly more than 300 claimants
full reimbursement claimants potentially exhausting pro rata funds
“The court noted that if slightly more than 300 claimants sought the full $5,000 reimbursement, the pro rata share for other class members could fall to nothing.”
There was no material change: no new topic-member articles were supplied beyond the existing account of the court’s rejection without prejudice of the proposed settlement.
Previously
The Northern District of California rejected without prejudice preliminary approval of a proposed $2.3 million class-action settlement tied to OE Federal Credit Union’s 2023 ransomware breach, which affected more than 220,000 current and former customers. Judge Jon S. Tigar cited unsupported recovery estimates, deficiencies in the claims-made process, unclear California-specific benefits, fee disclosures, and inaccurate or incomplete settlement documentation. Plaintiffs must submit a revised motion addressing the court’s concerns and Rule 23 requirements by November 4, 2026.
