---
title: "The Million-Dollar Email Account"
description: "There's a settlement hiding in the public record that cost American Consumer Credit Counseling as much as two million dollars, and not a single tech blog covered it. The silence isn't a conspiracy; nobody watched the Massachusetts Superior Court docket"
url: https://kaynemcgladrey.com/blog/the-million-dollar-email-account/
date: 2026-09-15
modified: 2026-09-15
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/09/pexels-rdne-7821703.webp
categories: ["Blog"]
type: post
lang: en-US
---

# The Million-Dollar Email Account

There’s a settlement hiding in the public record that cost American Consumer Credit Counseling as much as two million dollars, and not a single tech blog covered it. The silence isn’t a conspiracy; nobody watched the Massachusetts Superior Court docket for case number 2581CV02933; part of that might be because their website’s not the friendliest.

This was a data breach affecting 11,611 people, resolved through standard civil procedure and buried under pages of administrative filings. You might expect headlines about identity theft or ransomware. Instead you get a claims-made settlement structure, a fee motion, and a Form 990 showing IT spend doubling in the breach year.

This wasn’t a cyber failure. It was a budget line item that got missed.

> “The retail value of the three years of state-of-the-art credit monitoring and identity theft protection services made available to all Settlement Class Members exceeds $10 million.”

## What Happened

Unauthorized actors accessed specific employee email accounts between January 27 and February 18, 2025. Discovery took forty-nine days after the access window closed. ACCC determined scope on June 27, 2025, and mailed notification letters via U.S. First-Class mail by July 15.

Pull the timeline apart against those hard dates and it reads like a slow-motion audit:

- **22 days** of attacker access to employee mailboxes (January 27 to February 18)
- **49 days** from the end of the access window to detection (February 18 to April 8)
- **80 days** from detection to scope determination, then **18 more** to put letters in the mail (April 8 to June 27 to July 15)
- **169 days** total from first unauthorized touch to the first affected consumer knowing about it

State regulators received a narrower story than the litigation record tells. The settlement agreement claims Social Security numbers, driver’s license numbers, and payment card information may have been implicated. Yet the Nebraska [breach notification](https://www.nebraska.gov/ago/data-breach/documents/4f7129dc-8be0-4680-b8da-00976219c22c.pdf) lists only name and financial account number for forty-eight residents, and Montana sent a [matching letter](https://dojmt.gov/wp-content/uploads/2025/08/Consumer-notification-letter-27.pdf) with identical language. Either the exposure genuinely varied by geography, or the settlement described the broadest plausible category of exposed data, which has the convenient effect of inflating face value. On the evidence in the public record, the conservative reading wins.

### Why an Email Compromise Hurts a Debt Counselor

ACCC serves consumers drowning in debt, so a single compromised mailbox leaks more than account numbers. It reveals payment habits, financial desperation, and vulnerability to the exact social engineering that follows a breach. Attackers who read a counselor’s inbox for three weeks know precisely who to target and how.

## The Settlement Machine

The legal path moved with assembly-line efficiency:

- Federal suits filed July 22 and July 30, 2025, then consolidated August 4
- Full-day mediation before Bruce Friedman of Judicial Arbitration and Mediation Services (JAMS) on October 14, ending in an agreement in principle the same day
- Federal cases dismissed so plaintiffs could refile in state court on November 24, 2025, a delivery vehicle for the already-negotiated deal
- Preliminary approval May 6, 2026; final approval hearing October 8, 2026

You can find the filings on [Mass Courts](https://www.masscourts.org/), though they don’t allow deep linking to the PDFs themselves. The amended agreement removed opt-out rights entirely, binding every class member with no exit path. The original complaint referred to ACCC’s “patients” and cited the Health Insurance Portability and Accountability Act (HIPAA), which is odd for a nonprofit debt counseling firm that **isn’t** a healthcare provider. That boilerplate error tells you a bit how much case-specific attention went into the filing. Milberg, PLLC led the plaintiff side, and their firm resume claims over one hundred data breach class actions settled in three years. Speed is the business model, and the HIPAA boilerplate is what speed leaves behind.

> “As a material term of the Settlement, the Parties agreed Plaintiffs would dismiss the federal court case and refile before this Court.”

The [Top Class Actions summary](https://topclassactions.com/lawsuit-settlements/open-lawsuit-settlements/american-consumer-credit-counseling-data-breach-class-action-settlement/) confirms the deadlines and administrator contacts. It reads like a checklist, which is precisely what this case was.

## The Real Bill

Class Counsel requested $225,000 in combined fees and expenses for 176.9 hours of work, a blended rate just shy of $1,200 an hour once the $13,701.69 in expenses comes out. Service awards added $8,000 for the two named plaintiffs. The monitoring benefit carried a retail valuation of $10.4 million across the class at $900 per member over three years, a number Class Counsel leaned on to justify their fee. Wholesale pricing for CyEx Financial Shield Complete runs closer to $5 to $8 per seat per year, which would still cost under $280,000 to cover the full class. But monitoring is opt-in, and take rates in claims-made settlements typically run in the low single digits, so the actual cash outlay probably lands south of $40,000. Face value is marketing. Cash is accounting.

| Cost Component | Amount | Basis |
| --- | --- | --- |
| Plaintiff fees + expenses | $225,000 | Contractual cap from fee motion |
| Service awards | $8,000 | $4,000 each for Hicks and Dinkel |
| Defense counsel | $200,000 – $400,000 | Estimate from plaintiff lodestar multiplier |
| Forensics investigation | $100,000 – $300,000 | Estimate for email compromise review |
| Notification mailings | $15,000 – $60,000 | USPS First-Class plus fulfillment |
| Settlement administration | $50,000 – $125,000 | Simpluris claims intake and reporting |
| Expected claim payouts | $25,000 – $150,000 | Category 1 and 2 participation |
| Credit monitoring at wholesale | $15,000 – $40,000 | Bulk rate at expected take rates |
| **Hard cash subtotal** | **$638,000 – $1.31M** | |
| Remediation IT spend | $420,000 – $842,000 | FY2025 IT line item delta |
| **Cash-plus-remediation total** | **$1.06M – $2.15M** | |

Reasonable people can argue the IT delta is an investment, not loss, which is the same objection I level at plaintiffs’ counsel over the $10.4 million. Strip it out entirely and the incident still cost north of $600,000 in hard cash, which is the more conservative way to read the ledger.

### The 990 Trail

ProPublica’s [Nonprofit Explorer page](https://projects.propublica.org/nonprofits/organizations/43166982) shows FY2025 revenue at $23,610,031 with a surplus of $4,889,868. The smoking gun is the IT budget, where the “IT, Cloud Network and VPN” line jumped from $636,816 in FY2024 to $1,478,341 in FY2025, an increase of $841,525. Revenue grew thirty-two percent that year, so some expansion was organic. Attribute half the delta to the breach and $420,000 remains a defensible floor. You can verify the prior-year numbers in the [FY2024 Form 990 XML](https://projects.propublica.org/nonprofits/download-xml?object_id=202521339349308972) filed May 13, 2025. Depreciation nearly doubled to $1,283,940, consistent with hardware replaced during hardening. These figures don’t prove negligence. They prove spending that follows an incident timeline.

## What Prevention Would Have Cost

We don’t know if multi-factor authentication (MFA) was on or off, or even available. What we know is that mailbox access persisted for three weeks without detection, which is what missing controls look like from the outside. If MFA existed and was bypassed, better logging catches the bypass. If it didn’t exist, enabling it costs nothing beyond a licensing tier.

| Control Layer | Annual Cost | Status at ACCC |
| --- | --- | --- |
| Multi-factor authentication | $0 – $49,000 | Unknown, possibly bypassed |
| Security awareness training | $3,000 – $8,000 | Not documented |
| Advanced email filtering | $2,000 – $7,000 | Likely baseline only |
| Managed detection and response (MDR) | $10,000 – $30,000 | No alerting visible |
| Incident response retainer | $20,000 – $50,000 | Not contracted |
| **Total package** | **$40,000 – $90,000** | |

Those training and filtering figures come from published 2026 market rates for platforms serving sub-200-seat organizations. None of these are the latest expensive AI-enabled defenses; these are basic cybersecurity controls. A nonprofit with 186 employees buys all five layers for what the settlement’s mediation fees alone cost plaintiffs’ counsel.

## The Ratio

Put simply, preventing this would have cost ACCC roughly $40,000 to $90,000 per year. The breach itself burned through $638,000 to $1.31 million in hard cash, or up to $2.15 million once remediation spending is included.

- **The incident consumed $1.06M to $2.15M**, or four to nine percent of one year’s $23.6M revenue
- **Prevention runs $40K to $90K annually**, or 0.17 to 0.38 percent of revenue, every year, indefinitely
- **Depending on where each estimate lands**, the incident cost seven to fifty-four times the price of a year’s prevention
- **Against the FY2025 surplus of $4.9 million**, the incident burned somewhere between a fifth and nearly half of it

So a year of the full prevention package costs less than the settlement’s fee motion asks for. Two years of it cost less than the low-end estimate of defense counsel. Four years of it, for every one of those 186 employees, still costs less than the cheapest estimate of the remediation spend alone.

These percentages ignore what doesn’t show up in the docket, too. Management attention diverted to litigation can’t grow a mission. And in November 2025, mid-crisis, the board adopted a $25,000 deferred compensation trust for the CEO. Draw your own conclusions about priorities.

## What We Still Don’t Know

The root cause is documented in the confidential mediation disclosures. Insurance status stays unverified, though the $187,550 insurance line might include cyber coverage that softened the blow. Claim rates remain open until the September 16, 2026 deadline passes and the October 8 final approval hearing concludes.

## The Docket Doesn’t Care About Your Budget

The seven-figure email account wasn’t a headline. It was a ledger entry spread across three fiscal years, funded by a nonprofit’s donors and debt-management fees. Technology made the breach possible; business decisions made the cost inevitable. Every executive reading this has a similar mailbox sitting in a similar budget posture. You can secure it for pennies on the dollar, or you can wait for your turn on the docket.
