ParkMobile, a widely used mobile and web parking payments platform based in Atlanta, reached a settlement following a class action lawsuit stemming from a significant data breach in 2021 that affected approximately 22 million users. The breach resulted in the theft of sensitive user information, including names, email addresses, phone numbers, mailing addresses, license plate numbers, vehicle information, and bcrypt-hashed passwords. Notably, payment information was not compromised in the incident. The stolen data was subsequently leaked on a hacking forum, making it accessible to anyone who downloaded the database. In response to the breach and ensuing legal action, ParkMobile agreed to a $32.8 million settlement, though the company denied any wrongdoing or liability as part of the agreement. Affected users who filed claims were eligible to receive up to $25 in cash, while those who did not file claims received an alternative compensation in the form of a $1 in-app credit. This credit is only applicable to ParkMobile service fees, not actual parking fees, and must be redeemed in $0.25 increments, requiring manual entry into the user's account. The credit is also subject to an expiration date, with users needing to utilize it by October 8, 2026. ParkMobile communicated these details to affected users via email, which some recipients initially questioned for legitimacy due to its unusual terms. The company also issued a separate advisory warning customers about an ongoing smishing campaign, urging vigilance against phishing attempts. The settlement and its terms have drawn criticism and raised eyebrows online, particularly due to the low compensation amount and the restrictions on how the credit can be used. Despite the settlement, ParkMobile continues to deny all accusations of negligence or failure to protect user data. The incident highlights the ongoing challenges companies face in securing user data and the complexities of compensating victims after large-scale breaches. The breach and subsequent settlement have prompted discussions about the adequacy of legal remedies and user compensation in the wake of major cybersecurity incidents. The case also underscores the importance of robust data protection measures and transparent communication with affected users. ParkMobile's experience serves as a cautionary tale for organizations handling large volumes of sensitive customer information. The company’s response, including the settlement structure and user notifications, reflects broader industry trends in addressing the aftermath of data breaches. The incident remains a significant example of the legal and reputational risks associated with cybersecurity failures in the digital services sector.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting highlighted that part of the ParkMobile settlement compensation involved credit with an expiration condition, drawing attention to limitations in the relief offered to victims. This clarified the practical impact of the settlement for affected users.
By early October 2025, ParkMobile had agreed to resolve litigation over the 2021 breach through a settlement offering compensation to affected users. Reports said eligible claimants could receive about $1 each or account credit, depending on the settlement terms.
In 2021, ParkMobile disclosed a data breach that impacted approximately 22 million users. The incident became the basis for later legal claims and a class-action settlement.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.