Telmate LLC, the prison-communications company now doing business as ViaPath Technologies, has agreed to pay $4,225,000 to settle a class action over a 2020 data breach. The deal, filed as Cooper v. Telmate LLC d/b/a ViaPath Technologies, still needs a judge’s sign-off, but the claims window is already open. Anyone who got a breach notice has until December 21, 2026 to file.
The settlement adds a fifth line item to ViaPath’s ledger of regulatory and legal costs tied to how it handles data for incarcerated people and their families. It also lands at a moment when data-breach settlements involving sensitive personal records, Social Security numbers among them, are drawing closer scrutiny from both plaintiffs’ attorneys and federal regulators. Here’s what the settlement actually says, what happened in 2020, and why this case sits inside a bigger pattern at the company.
A $4.23 Million Settlement Lands for Telmate’s 2020 Breach
The proposed settlement fund totals $4,225,000, a figure that’s been rounded to $4.23 million across most settlement trackers and legal notices, including Claim Depot’s summary of the deal. That fund isn’t going straight to claimants. Under the terms disclosed so far, it covers four separate categories: cash payments to class members, costs to run the settlement administration, an attorneys’ fee award, and a service award, plus reimbursement of court-approved costs.
Kroll Settlement Administration LLC is handling claims processing. Kroll is one of the largest class-action settlement administrators in the country, and its name shows up on breach settlements across healthcare, finance, and retail. Anyone unsure whether they’re a class member can reach the administrator by mail at Cooper v. Telmate LLC d/b/a Viapath Technologies, c/o Kroll Settlement Administration LLC, P.O. Box 225391, New York, NY 10150-5391, or by phone at (833) 453-3721.
The case moved through the system the way most breach class actions do now. A vendor or company discloses an incident, one or more law firms file suit on behalf of affected individuals, and rather than litigate the underlying security failures for years, the parties negotiate a fund and a release of claims. Telmate has not admitted wrongdoing as part of the deal, which is standard for settlements of this type.
What Happened in the 2020 Telmate Data Breach
The breach at the center of the case dates back to August 2020, when unauthorized parties accessed Telmate’s network over a short window. According to the official press release announcing the settlement, the intrusion ran from August 11 to August 13, 2020. In three days, the compromised data reportedly included names, dates of birth, contact information, Social Security numbers, and payment card or financial account details.
That combination of data points, Social Security numbers plus financial account information, is the kind that fuels identity theft and account takeover fraud. It’s a heavier payload than a typical email-and-password leak, which is part of why plaintiffs’ lawyers argued Telmate should have caught and stopped the intrusion faster than it did.
What Data Was Exposed
Telmate runs several services under its umbrella, including GettingOut, VisitNow, Command, Telmate Inmate Telephone, and Guardian. These platforms handle everything from inmate phone calls to video visitation to money transfers for families of incarcerated people, which means the company sits on a large pool of financial and personal data for a population that often has limited options for choosing an alternative provider.
That lack of choice is a recurring theme in criticism of the prison-telecom sector. Families can’t simply switch providers if they don’t like a company’s security practices, because facilities typically contract with a single vendor. It’s one reason regulators have paid closer attention to firms like Telmate and its parent brand over the past two years.
Who’s Eligible and What They Could Receive
Eligibility is tied to notice, not to a public sign-up list. If a person received a letter or notification from Telmate about the 2020 incident, they fall inside the settlement class. The available materials don’t specify a confirmed total headcount for the class, so treat any number circulating online as an estimate rather than a verified figure from the settlement itself.
Payment amounts per claimant also haven’t been finalized publicly. That’s typical at this stage. Settlement funds get divided after the claims deadline closes and the administrator knows how many valid claims came in, plus how much of the fund survives after fees and costs. A smaller pool of claimants means a bigger per-person check. A larger pool spreads the fund thinner.
People who want documented proof of out-of-pocket losses, like fraud-related expenses or time spent resolving identity theft, should hold onto receipts and records. Settlements like this one typically offer a baseline payment to all valid claimants and a higher tier for people who can show measurable harm.
Key Dates to Know Before December 21
The claims deadline is fixed at December 21, 2026. That gives affected individuals a firm window to submit a claim form, whether online through the settlement site or by mail through Kroll. Missing that date typically forecloses the right to a payment, though it usually doesn’t affect the separate right to opt out or object, which carries its own earlier deadline set by the court.
A final approval hearing is scheduled for February 12, 2027, when the judge overseeing the case will decide whether the settlement terms are fair, reasonable, and adequate. If approved, the settlement administrator generally issues payments roughly 90 days after that approval, which would place checks or transfers around mid-May 2027 for most claimants, assuming no appeals delay the process.
Court-approved settlements frequently see the payout timeline slip if an objector appeals the approval order. That’s worth watching here, since any breach settlement involving Social Security numbers draws more scrutiny from consumer advocates than a routine marketing-data leak would.
How to File a Claim
Filing a claim doesn’t require an attorney. The process mirrors most consumer class-action settlements: confirm eligibility, fill out the claim form, and submit supporting documentation if claiming reimbursement for actual losses. The settlement’s dedicated site, TelmateDataBreachSettlement.com, hosts the claim form and the full settlement notice, and the phone line at (833) 453-3721 connects claimants directly to Kroll.
A few practical steps cut down on errors:
- Locate the original breach notice letter or email from Telmate, since it usually contains a claimant ID number that speeds up processing.
- Gather any documentation of fraud, unauthorized charges, or credit monitoring costs tied to the breach before filing.
- Submit before the December 21, 2026 cutoff. Late claims are typically rejected outright.
- Watch for a follow-up notice about the payment timeline after the February 2027 final approval hearing.
Anyone contacted out of the blue by a caller claiming to “process” a Telmate settlement payment for an upfront fee should treat that as a red flag. Legitimate settlement administrators never charge claimants to file, and Kroll won’t ask for a payment to release settlement funds.
The Allegations Against Telmate and ViaPath
The complaint underlying Cooper v. Telmate alleges the company failed to implement adequate security measures to protect the personal data it held, and that it didn’t notify affected individuals quickly enough once the intrusion was discovered. Those two claims, weak security and delayed notice, show up in nearly every breach class action filed in the past five years, but they carry extra weight when the exposed data includes Social Security numbers rather than just usernames.
Telmate has not conceded any of these allegations, and the settlement includes no factual findings on fault. That’s a standard feature of negotiated class settlements: the company buys certainty and avoids years of expensive discovery and trial risk, while plaintiffs get a faster, guaranteed recovery instead of gambling on a verdict.
ViaPath’s Bigger Regulatory Problem: The FTC Case
The Cooper settlement doesn’t exist in isolation. ViaPath Technologies, the corporate umbrella that also owns Global Tel*Link (GTL) and, per the Federal Trade Commission’s case file on Global Tel Link Corporation, Telmate LLC and TouchPay Holdings, has spent the past two years under separate federal scrutiny for the same underlying weakness: how it secures data belonging to incarcerated people and their families.
In February 2024, FTC commissioners found that the facts substantiated allegations that GTL and its affiliates failed to secure personal information, letting a third-party vendor copy sensitive, unencrypted data on roughly 650,000 people into a publicly accessible cloud environment, according to reporting from The Record. By mid-2025, the agency had ordered the company to pay $2 million to affected consumers and a $1 million civil penalty, a combined $3 million remedy covering that separate cloud-exposure incident, as detailed by Prison Legal News.
A Pattern Beyond One Breach
It’s not clear whether the roughly 650,000 accounts named in the FTC’s cloud-exposure order overlap with the class covered by Cooper v. Telmate, since the settlement notices for the 2020 breach don’t specify an exact headcount. The two matters involve different legal theories, one a federal consumer-protection order and the other a private class action, but together they paint a picture of a company that regulators and plaintiffs alike have flagged more than once for the same category of failure: insufficient safeguards around personal data.
GTL, under the ViaPath name, has also settled separate price-fixing litigation over inflated call rates, unrelated to data security but part of the same broader pattern of legal exposure facing the prison-communications sector. Security Magazine’s coverage of the FTC order noted the agency specifically required the company to build out better breach-disclosure practices going forward, a requirement that puts future incidents under a tighter compliance clock.
Telmate/ViaPath Settlement at a Glance
| Detail | Figure |
|---|---|
| Total settlement fund | $4,225,000 |
| Rounded headline figure | $4.23 million |
| Breach window | August 11–13, 2020 |
| Claim filing deadline | December 21, 2026 |
| Final approval hearing | February 12, 2027 |
| Estimated payout timing | ~90 days after final approval |
| Settlement administrator | Kroll Settlement Administration LLC |
| Data types allegedly exposed | Names, DOB, contact info, SSNs, payment/financial data |
That table covers the case-specific mechanics. The next one places this settlement inside the wider run of legal and regulatory actions ViaPath and its subsidiaries have faced since 2024, since one breach rarely tells the full story of a company’s risk profile.
How This Stacks Up Against Other Breach and Telecom Settlements
| Case / Action | Company | Amount | Year | Type |
|---|---|---|---|---|
| Cooper v. Telmate LLC d/b/a ViaPath | Telmate / ViaPath | $4,225,000 | 2026 | Data breach class action |
| FTC consumer remedy + civil penalty | GTL / ViaPath | $3,000,000 ($2M + $1M) | 2025 | FTC data-security order |
| Price-fixing settlement (preliminary approval) | Global Tel*Link | $17,000,000 | 2024 | Call-pricing class action |
| Price-fixing settlement, co-defendant | GTL co-defendant | $21,300,000 | 2025 | Call-pricing class action |
Lined up together, the pattern is hard to miss. Every major legal action against this corporate family in the past two years, whether it targets pricing practices or data security, ends in a settlement rather than a trial. That’s common across the class-action world broadly, but the frequency here suggests the underlying compliance issues run deeper than a single bad breach year. For comparison, our earlier coverage of the Wisconsin Labcorp breach settlement shows a similar multi-year gap between incident and payout, a pattern that seems to be the norm rather than the exception in breach litigation.
Why Prison Communications Companies Keep Getting Breached
The prison-telecom industry runs on a structure that limits competitive pressure to improve security. Facilities sign exclusive contracts with a single vendor, families have no alternative provider to switch to, and the customer base, incarcerated individuals and their relatives, has historically had less political leverage to demand change than typical consumers.
That captive-market dynamic shows up in the financial side of the business too. Vendors like GTL and Securus have built revenue models around per-minute call charges and money-transfer fees, both of which require storing financial account data for a population that often can’t shop around for a cheaper or safer option. When that data sits in weakly secured systems, as the FTC alleged happened with the 2024 cloud exposure, the fallout lands on families who had zero say in choosing the vendor in the first place.
Regulators have started treating that captive dynamic as an aggravating factor rather than a footnote. The FTC’s 2024-2025 order against GTL/ViaPath went beyond a fine, requiring specific changes to how the company handles and discloses future incidents, a remedy structure that signals agencies now expect ongoing compliance monitoring, not just a one-time check.
Market and Industry Impact
A $4.23 million settlement won’t move markets or trigger a credit downgrade on its own. ViaPath is privately held, so there’s no stock reaction to track the way there would be for a public breach disclosure. The real impact shows up in how insurers price cyber coverage for the prison-telecom sector and how facility contracts get negotiated going forward.
Cyber-insurance underwriters typically raise premiums or tighten exclusions for companies with a repeat pattern of breach litigation, and ViaPath now carries a multi-year track record across at least two distinct incidents and several separate legal actions. That history feeds directly into renewal negotiations, and it can push a company toward spending more on security controls simply to keep coverage affordable.
Government contracting officers who oversee facility communication vendors also watch this kind of litigation history. A state corrections department renewing a multi-year contract now has a documented paper trail showing repeated data-handling failures at the vendor, which gives procurement teams leverage to demand stronger contractual security requirements or third-party audits as a condition of renewal. That same pressure is showing up across other sectors handling sensitive personal records, from the CenterPoint Energy breach disclosure filed with the SEC to the fallout at identity-verification vendor IDScan.net, where regulators and customers alike are demanding faster, clearer breach reporting.
Readers tracking how other companies handle breach disclosure can find ongoing coverage on our security news hub.
What Happens Next in Cooper v. Telmate
Three procedural steps remain before anyone sees a check. First, the claims period runs through December 21, 2026, giving class members roughly three months from today to file. Second, the court holds its final approval hearing on February 12, 2027, where a judge weighs objections, if any were filed, against the settlement’s fairness. Third, assuming approval and no appeal, Kroll begins distributing funds about 90 days later.
Any objector who appeals the final approval order could push that entire timeline back by months or longer, since appellate review of a class settlement can take a year or more to resolve. Nothing in the currently available filings suggests an objection has been lodged, but that’s worth watching as the December deadline approaches and the class size becomes clearer.
What This Settlement Signals for 2027
A few things look likely to play out over the next year, based on how similar breach settlements and the parallel FTC action have unfolded so far:
- Expect the per-claimant payout to land modestly, likely well under $200 per person, once fees, administration costs, and the size of the class get factored in, mirroring the pattern seen in comparable breach settlements of similar fund size.
- Watch for ViaPath to publicize its FTC-mandated security upgrades as a way to reassure state corrections agencies during contract renewal cycles.
- Expect plaintiffs’ firms to keep filing breach suits against prison-telecom vendors specifically, given the sector’s track record and the captive nature of its customer base.
- State attorneys general in states with large incarcerated populations may open independent inquiries if the December 2026 claims period reveals a larger-than-expected class size.
- Cyber-insurance renewal terms for ViaPath and comparable vendors will likely tighten further, pushing more security spending into 2027 budgets across the sector.
None of these are guaranteed outcomes. They’re reasonable extrapolations from a pattern that’s repeated across at least four separate legal and regulatory actions against the same corporate family since 2024.
Protecting Yourself if You Received a Notice
Beyond filing a claim, anyone notified about the Telmate breach should treat the exposure of Social Security numbers as a standing risk, not a one-time event. Credit monitoring, even a free tier, catches new-account fraud faster than checking statements manually. Placing a fraud alert or credit freeze with the three major bureaus costs nothing and blocks most attempts to open new credit lines using a stolen SSN.
Anyone who used Telmate’s money-transfer or account-funding services around 2020 should also review old statements for unfamiliar charges, since payment card data was among the categories allegedly exposed. Reporting suspicious activity within a bank’s fraud-dispute window matters more than the size of the charge, since older disputes get harder to resolve the longer they sit unreported.
For readers tracking how other breach cases have handled disclosure timing, our coverage of the Florida DMV breach disclosure timeline and the Roanoke phishing-driven data breach both walk through how notification delays shape a victim’s practical options.
Frequently Asked Questions
What is the Telmate data breach settlement?
It’s a $4,225,000 class-action settlement resolving claims that Telmate LLC, doing business as ViaPath Technologies, failed to secure personal data before a network intrusion between August 11 and August 13, 2020.
Who qualifies for a payment?
Anyone who received a notice letter or email from Telmate about the 2020 data security incident falls within the settlement class. There’s no separate public sign-up sheet.
How do I file a claim?
Submit a claim form through the settlement’s dedicated site, TelmateDataBreachSettlement.com, or by contacting the administrator, Kroll Settlement Administration LLC, at (833) 453-3721 or by mail at the address listed in the official settlement notice.
What is the deadline to file a claim?
December 21, 2026. Claims submitted after that date are typically rejected.
How much money will each claimant receive?
That hasn’t been finalized publicly. Per-claimant amounts depend on how many valid claims come in against the $4,225,000 fund after fees, administration costs, and awards are deducted.
Is this the same as the FTC action against ViaPath?
No. The FTC’s 2024-2025 order addressed a separate cloud-exposure incident affecting roughly 650,000 accounts and required a $3 million remedy. Cooper v. Telmate is a private class action tied specifically to the August 2020 network intrusion.
When will the settlement be finalized?
A federal judge is scheduled to hold a final approval hearing on February 12, 2027. If approved, payments typically follow within about 90 days.
Does Telmate admit fault in this settlement?
No. The settlement resolves the litigation without any finding or admission of wrongdoing by Telmate or ViaPath Technologies.




