Cognizant Technology Solutions Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Cognizant
Active investigation Data breach · Technology Notices mailed Aug 18, 2026

Received an August 2026 breach notice from Cognizant?

Dapeer Law, P.A. is investigating a potential class action against Cognizant Technology Solutions US Corporation, a Teaneck, New Jersey information technology and business process outsourcing firm, on behalf of individuals whose Social Security numbers may have been exposed in the April 2026 security incident disclosed in August 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
On or about Apr 21, 2026
Unauthorized access to personal information
Notification delay
About 4 months
Incident Apr 2026, notices Aug 2026
Credit monitoring
24 months
IDX credit and CyberScan monitoring
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Cognizant dated August 2026.
  • Your letter offered enrollment in 24 months of free IDX identity protection services, including credit and CyberScan monitoring, up to $1 million in identity theft insurance reimbursement, and fully managed identity theft recovery assistance.
  • You had personal information held by Cognizant in its capacity as an information technology, consulting, and business process outsourcing provider, whether as an employee, a contractor, or an individual whose data Cognizant handled on behalf of one of its clients.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Cognizant Technology Solutions US Corporation ("Cognizant"), a multinational information technology, consulting, and business process outsourcing firm headquartered in Teaneck, New Jersey, reports that a security incident occurred on or around April 21, 2026 that resulted in unauthorized access to certain personal information. The company states that it has no reason to believe the information has been misused. The public notice does not state when the activity was detected, how the unauthorized actor gained access, or how long the access continued.

Cognizant reported the incident to the Massachusetts Attorney General on August 18, 2026 and mailed written notices to affected individuals. The Attorney General's record lists Social Security numbers among the data involved and identifies 4 Massachusetts residents. No additional states are listed in that record, and Cognizant has not publicly disclosed a nationwide total. The company is offering 24 months of complimentary IDX identity protection services, including credit and CyberScan monitoring, up to $1 million in identity theft insurance reimbursement, and fully managed identity theft recovery assistance, with an enrollment deadline stated in each individual letter.

Because Social Security numbers can be used to open fraudulent credit accounts, file false tax returns, and claim benefits in another person's name, the categories of data reportedly involved in this incident raise heightened concerns. Roughly four months passed between the April 2026 incident and the August 2026 notices. Whether Cognizant's pre-breach security practices met legal standards, when the company actually detected the activity, and whether notice was given without unreasonable delay are among the issues being evaluated.

IT outsourcing breach Social Security numbers exposed Massachusetts AG filing IDX monitoring Notification delay
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the free IDX identity protection services and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 24-month IDX identity protection services

Enroll in the IDX credit and CyberScan monitoring offered in your letter before the deadline printed on it, using the enrollment code on your notice. IDX representatives are available Monday through Friday, 9 a.m. to 9 p.m. Eastern Time, at the dedicated number in your letter. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because Social Security numbers were reportedly involved, you should also place a fraud alert or security freeze on your credit file with all three major bureaus, watch for unfamiliar tax filings or unemployment claims filed under your Social Security number, and report anything suspicious to IDX so it can be documented through the recovery service.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options under Massachusetts and other state breach-notification and consumer-protection laws, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

On or about Apr 21, 2026 Passed
Security incident results in unauthorized access to personal information
Not disclosed Passed
Incident detected and forensic investigation begins
Before Aug 18, 2026 Passed
Review of the affected data completed
Aug 18, 2026 Passed
Incident reported to the Massachusetts Attorney General, notice letters mailed
Aug 21, 2026 Passed
Public breach disclosure record updated
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Cognizant has not publicly disclosed when the April 2026 activity was detected, so the exact notification delay cannot be measured from the public record. The roughly four-month gap between the incident and the notices is among the procedural issues being evaluated. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, Social Security number-based identity theft, tax-refund fraud, fraudulent benefit claims, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Cognizant to implement stronger data security practices going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Cognizant. What should I do? +

Keep the letter, enroll in the free 24-month IDX identity protection services before the deadline printed on your notice using the code provided, activate credit monitoring as soon as you enroll, request your free reports at AnnualCreditReport.com and review them for unfamiliar activity, place a fraud alert or security freeze with the credit bureaus, and contact a data breach attorney for a free consultation. Accepting credit monitoring does not waive your right to sue.

Am I eligible to join a class action against Cognizant? +

If you received an August 2026 data breach notice from Cognizant, you are likely eligible for a free case evaluation. Eligibility depends on your state of residence, the categories of your data that were involved, and any losses you have suffered. Dapeer Law will review your notice at no cost.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The Massachusetts Attorney General's breach record for this incident lists Social Security numbers among the data involved. Cognizant's letter states that a breach of security of personal information occurred but does not itemize every data element in the public version of the notice. Your individual letter should confirm the specific data elements identified for you.

Did Cognizant offer free credit monitoring? +

Yes. Cognizant is providing 24 months of complimentary identity protection services through IDX, including credit and CyberScan monitoring, up to $1 million in identity theft insurance reimbursement, and fully managed identity theft recovery assistance. IDX representatives are available Monday through Friday, 9 a.m. to 9 p.m. Eastern Time. The enrollment deadline and dedicated phone number appear in your individual letter. Enrollment is separate from, and does not waive, your right to pursue a claim.

How many people were affected by the Cognizant breach? +

The record filed with the Massachusetts Attorney General lists 4 Massachusetts residents, and no additional states are listed in that record. Cognizant has not publicly disclosed a nationwide total, and residents of other states may also have received notices. This page will be updated as additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The notice is publicly available through the Massachusetts Attorney General's data breach notification records (linked in Sources below). If you received a letter but no longer have it, Dapeer Law can assist you in obtaining a copy during your free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Cognizant Technology Solutions US Corporation, IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on August 18, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Kern Psychiatric Health and Wellness Center Data Breach Lawsuit Investigation

Next
Next

POLAM Federal Credit Union Data Breach Lawsuit Investigation