In 2020, Infosys—a major technology and consulting company headquartered in India with significant operations in the United States—disclosed that it had experienced a data breach. Attackers accessed systems containing sensitive personal information belonging to thousands of people, including employees, clients, and individuals connected to the company's operations. The breach became public knowledge in December 2020, though investigations revealed the unauthorized access had occurred months earlier.
Learn About Recording Laws and Privacy Rights →
The compromised data included names, addresses, Social Security numbers, dates of birth, and financial information. For many people affected, this meant their personal details were exposed to criminals who could potentially use the information for identity theft, fraudulent financial transactions, or other harmful purposes. Infosys took steps to contain the breach and notify affected parties, but the incident triggered legal consequences and settlement obligations.
Following the breach disclosure, multiple lawsuits were filed against Infosys by affected individuals and groups. These cases alleged that the company failed to maintain adequate cybersecurity protections despite handling highly sensitive personal information. Over the following years, these legal claims worked through the court system, ultimately leading to a settlement agreement.
The settlement represented a resolution where Infosys agreed to pay money to people harmed by the breach without admitting wrongdoing (a common settlement structure in data breach cases). Beyond monetary compensation, the settlement also required Infosys to implement enhanced security measures and monitoring systems going forward.
Practical Takeaway: Understanding what data was compromised in a breach—and when—helps you determine whether you might have been affected and what steps you should take to protect yourself.
The Infosys data breach settlement was structured to provide compensation to people whose personal information was exposed. The settlement fund was established at a specific amount (amounts vary depending on the particular settlement agreement, as Infosys faced multiple lawsuits). This fund was then divided among different categories of victims based on factors like what type of information was exposed and what harm they might have experienced.
Understanding Insurance Claim Payments and Taxes →
Settlement agreements in data breach cases typically include multiple components. The monetary compensation is just one piece. Settlements also usually mandate that the breached company must implement new security technologies, hire security professionals, conduct regular audits, and maintain insurance coverage for future incidents. These requirements attempt to prevent similar breaches from occurring again.
The Infosys settlement also established a claims administration process—this is the system by which affected people are notified about the settlement and instructed on how to receive their portion. A neutral third party, called a claims administrator, manages this process. Their job is to verify that people claiming compensation were actually affected by the breach and to distribute funds according to the settlement terms.
Different settlement categories may have offered different amounts. For example, people who experienced identity theft or fraud as a result of the breach might have been in a different compensation tier than those who experienced no documented harm. Some settlements provide additional benefits like credit monitoring services or identity theft insurance for a set period (often two to three years).
The settlement also included provisions for attorney's fees and administrative costs. These fees come from the settlement fund and cover the lawyers who brought the case forward and the companies hired to manage the claims process. While this reduces the total amount available for individual payouts, it's a standard part of how settlement structures work.
Practical Takeaway: Settlement money is distributed through a formal process managed by a neutral administrator, not directly by the company. Knowing this structure helps you understand what to expect during the claims process.
Once a settlement agreement is finalized and approved by the court, the claims administrator takes over responsibility for notifying affected individuals and managing payment distribution. This process typically unfolds in stages. First, the administrator sends notifications—either by mail, email, or both—to people believed to have been affected by the breach. These notices contain critical information about the settlement, what data was compromised, and instructions for filing a claim.
Learn About Capital One Payment Settlement Dates →
In data breach settlements, not everyone automatically receives payment. People generally must file a claim to receive their portion of the settlement fund. This claim process involves submitting information to verify that you were indeed affected by the breach. The claims administrator uses this information to cross-reference against the list of compromised individuals obtained from Infosys.
The verification process exists to prevent fraud and to ensure that settlement money goes to legitimate victims. When you file a claim, you're asked to provide personal details that the administrator can match against the breach data. This might include your name, address, Social Security number, date of birth, or the dates when you may have had contact with Infosys systems.
Payment methods vary depending on the settlement. Some settlements allow claimants to choose how they receive their money—through check, direct deposit to a bank account, or prepaid debit card. Others specify a single payment method. The timeline for receiving payments typically occurs in waves, with payments distributed over several months rather than all at once. This staggered approach helps prevent the payment processing system from becoming overwhelmed.
If you file a claim and are approved, you can expect payment anywhere from a few weeks to several months after the approval, depending on the settlement administrator's processing speed and the payment method you choose. Direct deposit generally processes faster than checks sent through the mail.
Some settlements also included provisions for people who could document specific damages caused by the breach—such as money spent on identity theft protection or time spent addressing fraudulent accounts opened in their name. These "cy pres" claims or "documented loss" claims might result in larger individual payouts for people who could provide evidence of actual harm.
Practical Takeaway: Settlement payments require active participation—you must file a claim and provide verification information. Simply being affected by the breach doesn't automatically put money in your account.
The total size of the Infosys settlement fund was determined through negotiation between the company's lawyers, the plaintiffs' attorneys, and the court. This negotiated amount was then divided among all people who filed valid claims. The key factor in calculating individual payouts is determining how many legitimate claims would be filed against the settlement fund.
Learn About Capital One Class Action Settlements and Payments →
Settlement administrators typically use what's called a "pro rata" distribution method. This means the total settlement fund is divided equally among all valid claims, or nearly equally if the settlement has different claim categories. For example, if a settlement fund totaled $10 million and 5,000 valid claims were filed, each claimant might receive approximately $2,000, assuming all claims were in the same category.
However, most settlements establish multiple claim categories with different payment amounts. A common structure looks like this: Category A might include people who suffered documented identity theft or fraud (highest payout), Category B might include people who had data exposed but experienced no documented harm (moderate payout), and Category C might include people who were potentially affected but cannot fully verify their exposure (lowest payout or no payout).
The actual dollar amounts depend on several variables. First is the total settlement fund size—larger settlements produce larger individual payouts, assuming similar numbers of claims. Second is the number of valid claims filed—more claims spread the fund thinner. Third is how claims are categorized—settlements often pay more to people who documented real-world harm.
In data breach settlements, individual payouts often range from $50 to $500 per person, though this varies widely. Some settlements pay less; others—particularly those involving massive breaches affecting millions of people—might pay only $10 to $50 per person. Settlements involving fewer people but serious documented harm sometimes produce per-person payouts exceeding $1,000.
The settlement payment amount is not the same as compensation for damages. Settlement amounts represent a negotiated compromise—the company isn't necessarily paying what courts might have awarded if the case had gone to trial. Instead, settlement amounts reflect what both sides agreed was fair given the uncertainty of litigation.
Practical Takeaway: Your individual payout depends on how many other people file claims and what category your claim falls into. Settlements rarely result in large per-person payments, but every dollar distributed to you represents some recovery for your data exposure.
Once you receive notification that you may be part of the Infosys settlement, you'll need to understand the claims filing process and associated deadlines. The claims administrator provides detailed instructions—usually in the settlement notice letter and on a dedicated website. The process typically involves several steps.
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.