A Pennsylvania-based collection agency has agreed to pay $2.6 million and implement sweeping data security reforms to settle claims stemming from a 2024 cyberattack that compromised the personal and financial information of nearly 1.6 million consumers.
The background: The February 2023 breach at NCB Management Services exposed information linked to closed Bank of America credit card accounts, including consumers’ names, addresses, Social Security numbers, dates of birth, driver’s license numbers, employment data, and account details. The company discovered the intrusion three days after it occurred and notified affected consumers soon after. NCB’s notification letter — filed with the Maine Attorney General — stated it had “obtained assurances that the third party no longer has any of the information,” language that cybersecurity experts often interpret as indicating a ransom payment.
The breach prompted multiple class-action lawsuits accusing NCB and Bank of America of negligence and breach of fiduciary duty, among other claims. Plaintiffs alleged the defendants failed to implement and maintain reasonable safeguards to prevent unauthorized access to sensitive personal information, even as they advertised secure data-handling practices.
The settlement: According to the settlement approval order, NCB will establish a $1.9 million settlement fund to provide payments to affected consumers who can demonstrate out-of-pocket expenses or lost time tied to the breach. Consumers who experienced identity theft or fraud as a result of the incident may receive up to $5,000 in reimbursement. Those who spent time resolving credit or account issues may receive compensation for up to five hours of documented time.
Attorneys representing the plaintiffs will receive $875,000 in fees and costs.
.




