Chime Class Action Lawsuit 2026: Data Breach, Text Spam, Refund Claims, and Frozen Accounts

Chime class action lawsuit
  • Post author:
  • Post published:August 8, 2025
  • Post category:Lawsuits
  • Reading time:12 mins read
Written by: Musarat Bano

Chime Financial faces four separate legal matters in 2026, and they cover four different kinds of harm. A federal data breach lawsuit leads the pack in size and severity. A Washington text-message case runs alongside it. Two closed regulatory orders, one federal and one state, round out the picture. This guide separates confirmed facts from active allegations and walks through exactly who qualifies for what.

Key Takeaways

  • Data breach lawsuit: Castaneda, et al. v. Chime Financial, Inc., Case No. 3:26-cv-02924, N.D. Cal., filed April 3, 2026. Alleges an April 1 cyberattack by a group called Team 313 exposed customer data and locked out an estimated 20,000+ users.
  • Text message lawsuit: Charles v. Chime Financial Inc., Case No. 2:25-cv-01361, King County Superior Court, Washington. Alleges Chime’s refer-a-friend program violated the state’s anti-spam law (CEMA).
  • CFPB order: Closed May 7, 2024 (Docket 2024-CFPB-0002). Chime paid $3.25 million in penalties and at least $1.3 million in consumer redress over delayed account-closure refunds.
  • DFPI order: Closed February 27, 2024. Chime paid $2.5 million to California’s Department of Financial Protection and Innovation over slow complaint handling during 2021.
  • None of these require you to hire a lawyer or sign up today. Two are still active litigation; two already closed.

What Is the Chime Lawsuit About?

“The Chime lawsuit” is not one case. Court records show at least two active civil suits, one closed federal enforcement order, and one closed state enforcement order, each addressing separate conduct: a 2026 data breach, unsolicited referral texts, delayed account refunds, and slow complaint handling. The table below breaks down each one.

Legal MatterStatusCourt or AgencyFiledCoversPossible Recovery
Data breach class actionActive, early stageU.S. District Court, N.D. Cal.April 3, 2026April 2026 cyberattack, exposed PIIActual and statutory damages; CCPA claim allows $100–$750 per violation
Text message class actionActiveKing County Superior Court, WAAugust 2025Unsolicited refer-a-friend texts$100 statutory floor per text, plus actual, treble, and exemplary damages
Text message investigationOpen, pre-filingN/A (law firm-led)OngoingAdditional Washington residents who received referral textsFeeds into a future filing; no guaranteed payout yet
CFPB consent orderClosedCFPB, administrative proceedingOrder issued May 7, 2024Delayed refunds on closed accounts$3.25M penalty paid; $1.3M+ already distributed as redress
DFPI consent orderClosedCalifornia DFPIOrder issued Feb. 27, 2024Slow complaint handling in 2021$2.5M penalty paid; no direct consumer claim process

The April 2026 Data Breach Lawsuit

Two Chime customers, Cindy Castaneda and Lauren Goodloe, sued Chime Financial on April 3, 2026, just two days after the incident that triggered the case. The complaint, filed in the U.S. District Court for the Northern District of California under Case No. 3:26-cv-02924, alleges a cybercriminal group known as Team 313 broke into Chime’s systems on or around April 1, 2026. Team 313 claimed responsibility on its own leak site and social media, according to the filing.

The outage hit hard. Castaneda says she could not see updated balances in her checking or savings accounts. Goodloe says he logged in to pay rent and instead saw a black screen with an outdated balance, leaving him unable to move money or pay bills. At peak disruption, an estimated 20,000 or more users reported problems, the complaint states. Because Chime runs entirely through its app with no physical branches, affected customers had no backup way to reach their own money, the plaintiffs argue.

The lawsuit brings eight separate legal claims, among them negligence and a California Consumer Privacy Act (CCPA) violation for an alleged failure to maintain “reasonable security” over unencrypted personal data. That CCPA claim matters because it carries its own statutory damages range of $100 to $750 per consumer per incident, on top of whatever a court awards for actual harm. The complaint also alleges Chime’s security fell short of FTC guidelines, the NIST Cybersecurity Framework, and CIS Critical Security Controls, though Chime has publicly stated no data was confirmed stolen. That dispute remains unresolved.

Court records show an initial case management conference set for July 7, 2026. That step alone signals this case sits at an early stage: no class has been certified, and no settlement talks have surfaced yet.

Who likely qualifies: anyone who held a Chime account on or around April 1, 2026, and noticed a login failure, a frozen balance, or an inability to move money during the outage. You do not need confirmed identity theft to have a claim. Exposure of your personal data can itself support a data breach case.

The Washington Text Message Lawsuit (CEMA)

A second, separate case addresses Chime’s marketing rather than its security. Plaintiff Taft Charles filed Charles v. Chime Financial Inc., Case No. 2:25-cv-01361, in the Superior Court for the State of Washington in King County. The complaint targets Chime’s refer-a-friend program, which pays $100 to a current customer and $100 to a new signup when someone joins through a referral link. The app lets a user send a prewritten invite to every contact in their phone with one tap.

Washington’s Commercial Electronic Mail Act, or CEMA, bars unsolicited commercial texts sent to state residents without clear, advance consent. The complaint argues Chime’s referral system crossed that line by helping customers blast promotional messages to people who never agreed to receive them. Recipients of a violating text are owed at least $100 under the statute, and the Charles complaint also seeks actual, treble, and exemplary damages beyond that floor.

A second, separate track runs alongside the filed case. Law firm Berger Montague continues an open investigation and still seeks Washington residents who received an unwanted Chime referral text but have not yet joined any action. No court has certified a class in either track, and no settlement exists yet in this matter.

Who likely qualifies: Washington residents who received a Chime referral text from a friend or family member and never gave consent to receive it.

The CFPB Order Over Delayed Refunds

This matter is already closed, and its facts come straight from the regulator’s own record. The Consumer Financial Protection Bureau issued a consent order against Chime on May 7, 2024, under Docket No. 2024-CFPB-0002. The Bureau found that Chime, which designs and services accounts through FDIC-insured partner banks, failed to refund closed-account balances within 14 days in thousands of cases. In thousands more, refunds took longer than 90 days.

Consumers locked out of their own funds often turned to credit cards or payday loans to cover basic costs, the order notes. The CFPB ruled this conduct unfair under the Consumer Financial Protection Act and ordered Chime to pay a $3.25 million civil penalty plus at least $1.3 million in redress to affected consumers. The order does not list a fixed dollar figure per person; redress amounts depended on individual harm as the Bureau’s own distribution process determined it.

Where this stands now: the CFPB matter is already closed, and redress has already gone out. If you closed a Chime account and waited well past 14 days for your balance, that history still matters. Separate private civil suits over the same underlying conduct continue in the courts, and any future settlement in those cases could add to what consumers already recovered.

The California DFPI Settlement

A fourth, older action rounds out Chime’s regulatory history and adds useful context on the company’s pattern of compliance issues. California’s Department of Financial Protection and Innovation reached a consent order with Chime on February 27, 2024, over how the company handled customer complaints submitted from January through March 2021, during the COVID-19 pandemic. The DFPI found “occasional mistakes” in complaint responsiveness and called the volume small relative to the total complaints received, though it noted the mistakes still mattered to the affected consumers. Chime neither admitted nor denied the findings, agreed to pay a $2.5 million penalty, and committed to round-the-clock customer service support from that point on.

This settlement offers no direct consumer claim process. It matters mainly as background: three separate regulators, plus two private lawsuits, have now examined Chime’s operational practices within five years.

Who Qualifies and What to Do Right Now

Match your situation to the track that fits.

  • You lost access to your Chime account around April 1, 2026. You may fall under the data breach class in Castaneda v. Chime. Save any error screens, outdated balance screenshots, and support tickets.
  • You live in Washington and got an unwanted Chime referral text. You may fall under the filed Charles case, the open Berger Montague investigation, or both. Preserve the text message and your phone bill from that period.
  • You closed a Chime account and waited past 14 days for your balance. The CFPB matter is already closed, but documented harm still helps if a related private suit moves forward. Keep your closure notice and bank statements.
  • You filed a complaint with Chime in early 2021 and got a slow response. The DFPI settlement already resolved this at the regulatory level; no separate consumer claim process exists for it today.

None of these tracks requires you to sign anything today. Courts and administrators notify class members automatically once a settlement wins approval. Three steps protect your position in the meantime. Change your Chime password and turn on two-factor authentication now. Save every breach notice, referral text, or account email tied to your situation. Keep bank statements that show late fees, missed payments, or other costs connected to any of these disruptions.

What Happens Next

Each matter sits at a different point in its life cycle. The data breach case just cleared its first weeks in federal court, with a case management conference set for July 2026, so expect a long stretch of motions and discovery before settlement talk realistically starts. The Charles CEMA case sits in Washington state court without a certified class yet, while the parallel Berger Montague effort still gathers additional plaintiffs. Both CFPB and DFPI matters are already closed at the regulatory level, though related private litigation over the same underlying conduct continues separately.

A settlement in either active case would likely follow a familiar pattern. Notice goes out to class members by email or mail. Members file a claim form within a set window, often 90 to 120 days. A judge reviews and approves the deal, and checks follow months later. Given how early the data breach litigation stands today, a realistic payout window points toward 2027 at the earliest.

FAQs

Is there an active Chime lawsuit right now?

Yes, more than one. A federal data breach class action was filed April 3, 2026, in the Northern District of California. A Washington CEMA case, Charles v. Chime Financial Inc., has already been filed in King County Superior Court, alongside a separate open investigation for more plaintiffs. Two earlier matters, the CFPB and DFPI orders, are already closed.

How much could I receive from the Chime lawsuit?

It depends on which track applies to you. Data breach payouts vary by court and proven harm, though the CCPA claim alone allows $100 to $750 per person under California law. CEMA sets a $100 statutory floor per unlawful text in Washington, with room for higher damages based on how the case ends. The CFPB and DFPI orders set no fixed per-person figure; both already finished their own distribution processes.

Do I need a lawyer to join a Chime class action?

No, not at this stage. Class members typically get notified automatically once a court approves a settlement. A consumer attorney helps most when you have real, documented losses, such as fraud charges tied to the breach or a pattern of unwanted referral texts.

Is my money safe at Chime today?

Chime remains FDIC-insured through its partner banks, and that coverage protects deposits apart from any current litigation over data security or marketing practices. Chime went public on NASDAQ under the ticker CHYM in 2025 and reports roughly 9.5 million active members as of early 2026, for context on its current scale.

When will Chime lawsuit payments go out?

No settlement exists yet in either active case. Realistic timelines run twelve to eighteen months from a filed complaint to a first payment, which puts 2027 as the earliest plausible window for the data breach matter.

What data was exposed in the Chime breach?

The complaint alleges personally identifiable information was put at risk during the April 2026 incident, though Chime has stated no data was confirmed stolen. That factual dispute remains unresolved as the case moves through early discovery.

Bottom Line

Chime’s 2026 legal picture spans two active lawsuits and two closed regulatory orders, each tied to a different failure: a data breach, unwanted text messages, delayed refunds, and slow complaint handling. Your best move depends entirely on which situation touches your own experience. Save your records now, watch only for official court notices, and skip any site that asks for payment or sensitive personal data upfront. Real class action claims never charge a fee to join.

Sources

Disclaimer: This article provides a general overview of active and closed Chime legal matters, based on court filings and government records available as of August 12, 2026. It is for informational purposes only and does not constitute legal advice. Case details can change as litigation proceeds; verify current status through official court dockets before relying on this information for a claim.

Written by

Musarat Bano is a content writer for JudicialOcean.com who covers lawsuits, legal news, and general legal topics. Her work focuses on research-based, informational content developed from publicly available sources and is intended to support public awareness. She does not provide legal advice or professional legal services.