Canadians Could Receive Part of the $35 Million Capital One Settlement

Canadians Could Receive Part of the $35 Million Capital One Settlement

Stick to the Facts

Add Nbsla.ca as a Preferred Source on Google to see more of our stories in your search results.

Add as a preferred source on Google

The settlement follows years of legal proceedings stemming from the massive 2019 cyberattack that exposed the personal and financial information of millions of Capital One customers and credit card applicants across Canada and the United States.

If approved by the court, eligible Canadians may be able to submit claims for reimbursement of financial losses, compensation for time spent responding to the breach, and refunds of annual credit card fees. Depending on the type of claim, some individuals could receive as much as $25,000, while others may qualify for smaller fixed payments.

Although Capital One has agreed to settle the lawsuit, the company continues to deny any wrongdoing or legal liability.

Here is everything Canadians need to know about the proposed settlement, including who qualifies, what information was compromised, how much compensation may be available, and what steps eligible individuals should take before claims officially open.

Capital One Reaches Proposed $35 Million Settlement

On July 16, Charney Lawyers announced that Capital One Financial Corporation, Capital One Bank (USA), National Association, and Capital One Bank (Canada Branch) had reached a proposed settlement worth $35 million.

The agreement is intended to resolve a Canadian class-action lawsuit filed after the company’s 2019 cybersecurity breach exposed sensitive customer information.

The settlement applies to affected Canadian customers outside Quebec and remains subject to approval by the court.

If the settlement receives judicial approval, eligible class members will be able to submit compensation claims through an official claims process.

Until the court grants approval, no payments will be issued.

The 2019 Data Breach That Triggered the Lawsuit

The proposed settlement originates from a cybersecurity incident that occurred in 2019 and quickly became one of the largest financial data breaches involving Canadian consumers.

Capital One stored customer application data using cloud infrastructure operated by Amazon Web Services in the United States.

According to court documents, an unauthorized individual gained access to that cloud-based database and downloaded sensitive information belonging to millions of Capital One customers and applicants.

The incident affected individuals who had applied for Capital One credit cards over a period spanning more than a decade.

The breach included customers who held Capital One-issued cards as well as co-branded credit cards issued for major retailers.

How the Cyberattack Happened

According to court filings, the cyberattack was carried out by Paige Thompson, a former software engineer based in the United States.

Authorities alleged that Thompson exploited a vulnerability that allowed unauthorized access to Capital One’s cloud-based systems.

After obtaining access, the attacker downloaded a significant volume of personal and financial records belonging to both American and Canadian customers.

The incident remained undiscovered until an independent cybersecurity researcher identified evidence of the stolen information online during July 2019.

The researcher alerted law enforcement authorities, leading to an FBI investigation.

Thompson was arrested on July 29, 2019.

Capital One publicly disclosed the breach on the same day.

Millions of Canadians Were Affected

The breach affected approximately six million Canadians.

The compromised records involved individuals who applied for Capital One credit cards between 2005 and 2019.

Many applicants were unaware that their information had been exposed until they received official notification from Capital One following the company’s public disclosure.

The scale of the breach immediately raised concerns regarding consumer privacy, cybersecurity practices, and the protection of sensitive financial information.

What Personal Information Was Stolen?

The stolen information varied depending on each individual’s records.

According to court documents, exposed information included:

Personal Identification Information

Compromised personal details included:

  • Full names
  • Home addresses
  • Telephone numbers
  • Email addresses
  • Dates associated with applications

Financial Information

The breach also exposed extensive financial information submitted during credit card applications.

This included:

  • Annual income
  • Banking information
  • Mortgage status
  • Credit scores
  • Credit limits
  • Account balances
  • Payment history
  • Certain transaction histories

The combination of personal and financial information significantly increased concerns regarding potential identity theft and financial fraud.

Around One Million Social Insurance Numbers Were Compromised

One of the most serious aspects of the breach involved Social Insurance Numbers.

Approximately one million Canadian SINs were reportedly accessed during the cyberattack.

Because Social Insurance Numbers are widely used to verify identity for financial, employment, taxation, and government services, their exposure significantly increased the risk of identity theft.

Individuals whose SIN was compromised may qualify for higher compensation under certain parts of the proposed settlement.

Why Was Capital One Sued?

Following the breach, Canadian plaintiffs filed a class-action lawsuit against Capital One.

The lawsuit alleged that the company failed to adequately protect customer information and did not implement sufficient cybersecurity safeguards to prevent unauthorized access.

The legal claims included allegations involving:

Privacy Violations

Plaintiffs argued that sensitive customer information was not adequately protected.

Breach of Contract

The lawsuit alleged that Capital One failed to fulfill obligations regarding safeguarding customer data.

Consumer Protection Issues

The legal action also claimed violations of applicable consumer protection legislation.

Despite agreeing to the proposed settlement, Capital One has denied all allegations of wrongdoing.

The company maintains that entering into the settlement does not represent an admission of liability.

Who May Qualify for Compensation?

Not every Capital One customer automatically qualifies.

According to the proposed settlement, eligibility generally applies to Canadian residents outside Quebec who meet specific conditions.

Eligible individuals are those who:

  • Were Canadian residents outside Quebec.
  • Applied for or held a Capital One credit card.
  • Received a notification letter advising that their personal information may have been affected by the 2019 data breach.

The notification letter serves as one of the key indicators of eligibility.

Individuals who never received such a notice may wish to monitor future updates once the claims process officially opens.

Which Capital One Credit Cards Are Included?

The settlement generally covers Capital One credit card products affected by the 2019 breach.

Capital One is known for issuing both its own branded credit cards as well as co-branded cards for major retail partners.

These include:

Capital One Credit Cards

Traditional consumer credit cards issued directly by Capital One.

Costco Credit Cards

Certain Costco-branded Capital One credit cards.

Hudson’s Bay Credit Cards

Capital One-issued credit cards associated with Hudson’s Bay Company.

Eligibility ultimately depends on whether an individual’s personal information formed part of the compromised data.

How Much Compensation Could Canadians Receive?

The proposed settlement establishes three separate categories of compensation.

Each category addresses different types of losses resulting from the data breach.

The amount each individual receives depends entirely on the category under which they qualify and the validity of their submitted claim.

Category A: Reimbursement for Financial Losses

The largest compensation category is intended for individuals who experienced direct financial costs because of the breach.

Eligible expenses may include money spent protecting personal information after learning about the incident.

Examples include:

Credit Monitoring Services

Individuals who purchased identity monitoring subscriptions may qualify for reimbursement.

Credit Freezes

Costs associated with placing security freezes on credit files may be recoverable.

Identity Theft Insurance

Insurance purchased to reduce fraud risk may qualify.

Identity Theft Losses

Claims involving actual identity theft, fraudulent tax returns, or other verified financial losses may also be eligible.

Individuals submitting approved Category A claims may receive reimbursement of up to $25,000, depending on documented losses.

Category B: Compensation for Time and Inconvenience

The settlement also recognizes that many Canadians spent considerable time responding to the breach.

Activities such as reviewing financial records, contacting financial institutions, monitoring credit reports, changing passwords, and addressing security concerns required significant personal time.

Eligible class members may receive compensation based on hours reasonably spent responding to the incident.

Individuals Whose SIN Was Not Compromised

Eligible individuals may claim:

  • $25 per hour
  • Up to five hours
  • Maximum payment of $125

Approved claims also qualify for an additional $75 payment.

The maximum available compensation becomes $200.

Individuals Whose SIN Was Compromised

Canadians whose Social Insurance Number formed part of the breached data may claim:

  • $25 per hour
  • Up to eight hours
  • Maximum payment of $200

Successful claimants also receive the additional $75 payment.

The maximum total compensation reaches $275.

Category C: Annual Credit Card Fee Reimbursement

Another category provides compensation for annual credit card fees.

Eligible class members who paid annual fees may receive reimbursement of up to $50 after submitting a valid claim.

Although smaller than other compensation categories, this payment recognizes costs incurred by eligible customers.

Can Someone Receive More Than One Type of Compensation?

Depending on individual circumstances, some class members may qualify under multiple categories.

For example, someone who:

  • Paid annual credit card fees,
  • Purchased identity protection services, and
  • Spent time responding to the breach,

could potentially submit claims under more than one compensation category, provided they satisfy all eligibility requirements.

Each category has its own documentation standards and payment limits.

Why Court Approval Is Still Required

Although the parties have agreed to the settlement, it does not automatically become effective.

Class-action settlements in Canada must receive court approval before compensation can be distributed.

The court reviews whether the proposed agreement is fair, reasonable, and in the best interests of affected class members.

Only after judicial approval can the official claims process begin.

When Is the Court Hearing?

The approval hearing has been scheduled for September 22, 2026.

During the hearing, the court will evaluate the proposed settlement agreement and determine whether it should proceed.

If approved, administrators will begin implementing the claims process.

Further information, including deadlines and claim procedures, will be announced after court approval.

What Should Eligible Canadians Do Right Now?

At this stage, affected Canadians are not required to submit any paperwork or take immediate action.

Instead, individuals should:

Keep Any Notification Letters

Anyone who received a letter informing them that their information may have been affected should retain that correspondence.

Preserve Supporting Documents

Individuals who purchased credit monitoring services or experienced financial losses should keep receipts, invoices, and related records.

Monitor Official Updates

Once the settlement receives court approval, official instructions regarding claim submissions, deadlines, and required documentation will be published.

Submitting a claim before the official claims process opens is not possible.

Importance of Cybersecurity After Major Data Breaches

The Capital One incident serves as another reminder of the growing importance of cybersecurity and personal data protection.

Even when organizations invest heavily in security infrastructure, sophisticated cyberattacks continue to expose sensitive customer information.

Consumers can reduce future risks by regularly monitoring financial accounts, reviewing credit reports, enabling multi-factor authentication, using strong and unique passwords, and responding promptly to suspicious account activity.

Although no security measure completely eliminates cyber risk, proactive monitoring can help identify fraud before it causes significant financial harm.

The Bottom Line

The proposed $35 million Capital One class-action settlement could provide meaningful compensation to millions of Canadians affected by the company’s 2019 data breach. Eligible customers outside Quebec who received notification that their personal information was compromised may qualify for payments covering documented financial losses, time spent responding to the breach, and annual credit card fees.

While some claimants could receive reimbursements of up to $25,000 for verified financial losses, others may qualify for fixed payments of up to $275 for time and inconvenience or up to $50 for annual credit card fees. However, no compensation will be distributed unless the court approves the settlement at the scheduled hearing on September 22, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *