SAN FRANCISCO — A federal judge has declined to give preliminary approval to a proposed $2.3 million settlement of class-action litigation stemming from a 2023 ransomware attack and data breach at OE Federal Credit Union, finding several deficiencies in the agreement that must be addressed before it can move forward.
U.S. District Judge Jon S. Tigar of the Northern District of California denied the plaintiffs’ motion for preliminary approval Wednesday without prejudice, meaning the parties can return with a revised proposal. Tigar ordered a revised motion to be filed by Nov. 4.
Among the judge’s primary concerns was a requirement that affected consumers submit claims before receiving money, even though OEFCU has records identifying the people affected by the breach.

Not ‘Necessary’
Tigar said the proposed settlement uses a claims-made distribution process when one does not appear necessary. According to the court, OEFCU can generate a list containing the names and current or last-known home and email addresses of settlement class members.
“The class members in this action are readily identifiable from OEFCU’s records,” Tigar wrote, noting they consist of current or former customers who received notices that their personally identifiable or protected health information had been affected by the breach.
The judge said requiring claims under those circumstances could reduce the amount ultimately distributed to affected consumers.
Proposed $2.3 Million Fund
Under the proposed agreement, OEFCU would establish a $2.3 million non-reversionary settlement fund, meaning money remaining in the fund would not return to the credit union.
Class members could seek reimbursement of as much as $5,000 for documented out-of-pocket losses traceable to the data incident, including expenses for credit monitoring or credit freezes, according to the court.
Members also could file claims for pro rata cash payments estimated at $50, although the amount could rise or fall depending on the number and type of claims submitted. California class members could claim an additional $75, also subject to adjustment.
The Proposal
The proposal calls for $766,666.66 in attorneys’ fees — approximately one-third of the settlement fund — along with $5,000 service awards for each of the three class representatives. Litigation expenses and settlement-administration costs also would be deducted from the fund.
Tigar cautioned that the 9th U.S. Circuit Court of Appeals has established 25% of a common settlement fund as the benchmark for attorneys’ fees in successful class actions. The judge said plaintiffs’ attorneys would need to justify any departure from that benchmark, although he stressed that he was not deciding the appropriate fee at this stage.
Judge Questions $50 Estimate
Tigar also questioned the plaintiffs’ estimate that class members would receive approximately $50 each.
The plaintiffs estimate the class includes more than 220,000 people, according to the order. Tigar calculated that after subtracting the proposed attorneys’ fees, slightly more than $6 per class member would remain if the money were spread across the entire class — even before subtracting administration expenses, litigation costs and the proposed awards to the class representatives.
The available pool also would be reduced by payments to people claiming as much as $5,000 for breach-related expenses.
300 Receive Maximum
Tigar noted that if slightly more than 300 people received the maximum $5,000 reimbursement, the amount available for pro rata payments to other class members potentially could be exhausted. The judge said the plaintiffs offered no evidence supporting their $50 estimated payment.
The court also found that plaintiffs had not provided information showing the maximum amount class members potentially could recover if they prevailed at trial, making it difficult to determine whether $2.3 million represented a reasonable compromise.
Tigar characterized plaintiffs’ counsel’s assertions that the settlement provided significant relief and was consistent with other data-breach settlements as “boilerplate language” that did not provide enough information for the court to evaluate the proposed recovery.

Strengths, Weaknesses Not Detailed
The court separately found the plaintiffs had not adequately analyzed the strengths and weaknesses of their lawsuit.
Instead, Tigar said, the preliminary-approval motion offered generalized descriptions of the risks and expenses associated with pursuing a class action through certification, summary judgment and trial.
The court said plaintiffs seeking settlement approval need to provide a more detailed analysis of their claims and potential defenses so a judge can determine whether the proposed compromise is reasonable.
Tigar also questioned why California class members would receive an additional $75 when the settlement does not establish a separate California subclass with different claims that would explain the higher payment.
Federal class-action rules require settlement proposals to treat class members equitably relative to one another, the judge said.
Another Problem ID’d
Another problem identified by the court involved inconsistencies between the preliminary-approval motion and the settlement agreement over when payments would be made.
Tigar said the motion represented that benefits would be provided within seven days after final approval if there were no appeals, or within 14 days after the settlement became effective. The provision cited by plaintiffs, however, did not address payment timing, according to the judge.
Another provision states payments would be issued after allocation and distribution of the settlement funds are determined, while OEFCU would have as long as 30 days after the settlement becomes effective to establish the fund. Tigar said those provisions appeared inconsistent with the payment schedule described in the plaintiffs’ motion.
Breach Discovered in 2023
The litigation stems from a ransomware attack that affected OEFCU systems between approximately Aug. 19 and Oct. 29, 2023, according to court records.
The California attorney general’s data-breach database shows OE Federal Credit Union reported the incident to the state on April 30, 2024, identifying Aug. 19 and Oct. 29, 2023, as the dates associated with the breach.
According to OEFCU’s breach notification quoted in the original lawsuit, the credit union detected unauthorized access to its network around Oct. 28, 2023. Following a forensic investigation and document review, OEFCU determined on April 1, 2024, that files containing personal information may have been accessed or acquired by an unauthorized party between Aug. 19 and Oct. 29. The notification said affected information included names, Social Security numbers and driver’s license or other government identification numbers.
Daniel Jimenez Jr. filed the original lawsuit against OEFCU on May 8, 2024. Erica Jaramillo subsequently filed a similar case, and the plaintiffs filed a joint amended complaint in July 2024. The litigation alleges the breach exposed personally identifiable and protected health information and asserts claims including negligence, invasion of privacy, unjust enrichment and violations of California consumer and privacy laws.
Move to Dismiss
OEFCU moved to dismiss the case, and Tigar in August 2025 granted that request in part and denied it in part. Among other things, the court dismissed the plaintiffs’ declaratory-relief claim with prejudice while dismissing several other claims with permission to amend them.
The parties notified the court Aug. 20, 2025, that they had reached a settlement, according to Tigar’s latest order.
The proposed settlement would cover U.S. residents whose private information was or may have been compromised in the incident, including those who received breach notifications from OEFCU.
For now, however, no settlement has received court approval. Tigar said the plaintiffs may submit a revised proposal addressing the deficiencies identified by the court by Nov. 4.



