Monday, April 21, 2025
HomeCyber Security NewsInfosys to Pay $17.5M in Settlement for 2023 Data Breach

Infosys to Pay $17.5M in Settlement for 2023 Data Breach

Published on

SIEM as a Service

Follow Us on Google News

Infosys, a leading IT services company, has announced that it has reached an agreement in principle to settle a series of class action lawsuits related to a data breach incident involving its subsidiary, Infosys McCamish Systems LLC.

The proposed settlement involves a payment of $17.5 million to resolve all allegations without admitting liability.

Background of the Incident

The data breach occurred in 2023, prompting the filing of six class action lawsuits in the United States against Infosys McCamish Systems LLC and some of its customers.

- Advertisement - Google News

These lawsuits were initiated by plaintiffs who claimed that the breach led to significant losses and vulnerabilities in the handling of sensitive data.

In a statement dated March 14, 2025, Infosys revealed that the settlement agreement was reached during mediation on March 13, 2025.

Under the terms of this agreement, Infosys McCamish will contribute $17.5 million into a fund to settle all pending lawsuits.

The settlement still requires finalization of its terms, confirmation by the plaintiffs, and both preliminary and final court approval.

This settlement marks a significant step towards resolving the legal challenges faced by Infosys following the cyber incident.

By settling without admitting any liability, Infosys aims to move forward without the uncertainties associated with prolonged legal processes.

Quotes from Officials

While specific quotes from Infosys officials are not available in the latest update, the company’s commitment to transparency is evident from its regular communications regarding the case.

“This is for your information and records,” states A.G.S. Manikantha, Company Secretary of Infosys Limited. The settlement agreement will be hosted on the company’s website, indicating a commitment to keeping stakeholders informed.

The resolution of these lawsuits will likely enhance the company’s reputation for handling cybersecurity incidents effectively, even though it does not admit liability.

It demonstrates Infosys’s proactive approach to addressing legal disputes and underscores its focus on maintaining trust with clients and stakeholders.

The settlement aligns with industry trends where companies increasingly opt for early settlement rather than risking protracted legal battles.

This approach can help mitigate long-term reputational damage and financial uncertainty associated with ongoing litigation.

Infosys’s decision to settle the class action lawsuits for $17.5 million reflects its commitment to resolving disputes and ensuring continuity in its operations.

As the settlement progresses through the necessary approvals, Infosys will likely continue to emphasize its commitment to improving cybersecurity measures to prevent similar incidents in the future.

This settlement marks a crucial step in the aftermath of the 2023 data breach, showcasing Infosys’s strategic approach to managing legal and reputational risks in the complex landscape of technology and cybersecurity.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Hackers Abuse Zoom’s Remote Control to Access Users’ Computers

A newly uncovered hacking campaign is targeting business leaders and cryptocurrency firms by abusing...

Speedify VPN Vulnerability on macOS Exposes Users to System Takeover

A major security flaw in the Speedify VPN application for macOS, tracked as CVE-2025-25364, has...

Critical PyTorch Vulnerability Allows Hackers to Run Remote Code

A newly disclosed critical vulnerability (CVE-2025-32434) in PyTorch, the widely used open-source machine learning...

ASUS Router Flaw Allows Hackers to Remotely Execute Malicious Code

ASUS has acknowledged multiple critical vulnerabilities affecting its routers that could allow hackers to...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Abuse Zoom’s Remote Control to Access Users’ Computers

A newly uncovered hacking campaign is targeting business leaders and cryptocurrency firms by abusing...

Speedify VPN Vulnerability on macOS Exposes Users to System Takeover

A major security flaw in the Speedify VPN application for macOS, tracked as CVE-2025-25364, has...

Critical PyTorch Vulnerability Allows Hackers to Run Remote Code

A newly disclosed critical vulnerability (CVE-2025-32434) in PyTorch, the widely used open-source machine learning...