Understanding the Infosys McCamish Data Breach Settlement
Overview of the Infosys McCamish Data Breach Settlement In 2021, Infosys, a major multinational information technology company based in India, disclosed a da...
Overview of the Infosys McCamish Data Breach Settlement
In 2021, Infosys, a major multinational information technology company based in India, disclosed a data breach affecting McCamish Systems, a subsidiary that handles insurance industry operations. The breach exposed sensitive personal information belonging to individuals whose data was stored in McCamish's systems. This settlement represents a legal agreement reached to compensate individuals affected by this security incident.
The breach itself involved unauthorized access to systems containing names, Social Security numbers, dates of birth, policy information, and other personally identifiable information. McCamish Systems primarily provides technology services to insurance companies, meaning the breach potentially affected policyholders and customers of various insurance providers across the United States. The breach was discovered during a routine security audit, and Infosys subsequently notified affected individuals and regulatory authorities.
The settlement process emerged after affected individuals and legal representatives pursued claims against Infosys for the security failure. Rather than proceeding through lengthy court battles, the parties agreed to a settlement that would provide monetary compensation to those who could demonstrate they were impacted by the breach. The total settlement amount reflected the scope of the breach and the potential harm caused to affected individuals.
Understanding this settlement matters for several reasons. First, if your personal information was stored in McCamish Systems, you may have the right to receive compensation. Second, this case demonstrates how data breaches at major technology companies can have wide-ranging consequences. Third, the settlement process shows how compensation claims work when personal data is compromised.
Practical Takeaway: If you believe you may have been affected by this breach—particularly if you held insurance policies from companies that used McCamish's systems—learning about the settlement process can help you understand what options may be available for pursuing compensation.
How the Data Breach Occurred and What Information Was Exposed
The Infosys McCamish breach resulted from security vulnerabilities in the systems managed by McCamish Systems. While the exact technical details of the breach have been disclosed in limited fashion to protect ongoing security, the fundamental issue involved unauthorized individuals gaining access to databases containing sensitive customer information. Infosys, which owned McCamish Systems, was responsible for maintaining adequate security measures to protect this data.
The types of information exposed in the breach included:
- Full names and addresses of policyholders
- Social Security numbers
- Dates of birth
- Insurance policy numbers and coverage details
- Financial account information in some cases
- Driver's license numbers
- Email addresses and phone numbers
This combination of information is particularly sensitive because it can be used for identity theft and financial fraud. When someone has access to a person's Social Security number along with their name, address, and date of birth, they possess the core components needed to open fraudulent accounts, apply for loans, or commit other forms of identity theft.
The breach affected a significant number of individuals. While exact numbers varied depending on how the breach was measured, the exposure involved hundreds of thousands of records. Given that McCamish Systems serves as a backend provider for multiple insurance companies, individuals may not have been directly aware they were McCamish customers—their insurers used McCamish's technology to store and process their information.
Timeline of disclosure: Infosys discovered the breach during security audits in 2021 and began the process of notifying affected individuals through mailings and public announcements. Regulatory agencies including state attorneys general and the Insurance Commissioners Association were also notified. The notification process took several months to complete as the company worked to identify all affected parties.
Practical Takeaway: If you received notification letters about this breach from your insurance company or directly from Infosys, those letters typically contained specific details about what information of yours was exposed and instructions for monitoring your accounts and pursuing settlement claims.
The Settlement Agreement: Key Terms and Compensation Structure
The settlement agreement established a structured process for compensating affected individuals. Rather than each person filing a separate lawsuit, a class action settlement created a single legal framework where all eligible claimants could pursue compensation through a standardized process. This approach is common for data breaches affecting large numbers of people.
The settlement included a total fund from which individual payments would be drawn. This fund was divided among all approved claims. The amount each person received depended on several factors, including the category of their claim and how many total claims were submitted. The settlement structure typically included:
- Compensation for individuals who experienced documented identity theft or fraud as a result of the breach
- Compensation for individuals whose personal information was exposed even if they did not experience theft
- Reimbursement for documented out-of-pocket expenses related to the breach, such as credit monitoring costs or fraud recovery expenses
- Payment of attorneys' fees and administrative costs for managing the settlement
One important aspect of the settlement involved establishing different claim categories. People who could prove they suffered actual identity theft or fraud typically received higher compensation than those who could only prove their information was exposed. This distinction reflected the actual harm caused—someone whose identity was stolen and used fraudulently experienced more concrete damage than someone whose data was exposed but not misused.
The settlement also generally provided access to credit monitoring services for affected individuals for a set period—often two to three years. These services alert people if new credit accounts are opened in their names or if their credit reports show unusual activity. This benefit was included because people whose data was breached face elevated risk of identity theft long after the initial breach.
Per-person payment amounts varied significantly based on the specific settlement structure. Some settlements offered fixed amounts to all claimants ($25 to $100 per person was common in similar cases), while others were pro-rata distributions where the fund was divided equally among all approved claimants. If 500,000 people made claims and the fund totaled $50 million, for example, each person would receive roughly $100 (before deductions for administration and attorneys' fees).
Practical Takeaway: Understanding the different claim categories—and gathering documentation if you experienced identity theft—can significantly affect the compensation amount you receive, as individuals with documented harm typically receive more than those without it.
Identifying Whether You Were Affected by the Breach
Determining whether you were personally affected by the Infosys McCamish breach requires understanding the scope of McCamish's business operations. McCamish Systems primarily provided technology infrastructure and services to insurance companies. This means you may have been affected even if you were never directly aware of McCamish's involvement in handling your data.
The following categories of people were most likely affected:
- Current and former policyholders of insurance companies that used McCamish Systems for data storage and processing
- Individuals with active policies during the time period when the breach occurred and data was exposed
- Beneficiaries and family members listed on insurance policies
- People who had cancelled policies within a certain timeframe before the breach (as historical data was also affected)
Insurance companies that used McCamish Systems spanned multiple types of coverage including life insurance, health insurance, disability insurance, and workers' compensation insurance. The breach was not limited to a single company or insurance type, but rather affected multiple carriers that relied on McCamish's technology platform.
To determine whether you may have been affected, consider these questions: Did you hold an insurance policy from a major insurance provider during 2021? If so, did that company send you notification letters about a data breach involving McCamish Systems? Many people did not recognize the McCamish name because they interact only with their insurance company, not McCamish directly.
If you received official notification about the breach, those letters typically included specific information about what data was exposed and instructions for submitting a claim. These notification letters came either from your insurance company or directly from Infosys. Official notifications were mailed to addresses on file with the insurance company and sometimes also included digital notifications or public announcements.
You can also research whether your insurance provider used McCamish Systems by reviewing your insurance company's website for security incident announcements or by contacting your insurer directly. If you're uncertain, insurance company customer service representatives can confirm whether your data was stored in systems affected by this breach.
Practical Takeaway:
Related Guides
More guides on the way
Browse our full collection of free guides on topics that matter.
Browse All Guides →