Tuesday, August 11, 2026 Digital Forensics & Evidence Sign in
Lars Daniel

Digital forensics expert & expert witness · The Forbes digital forensics columnist

Data Breaches & Privacy

ParkMobile $32.8 Million Data Breach Settlement—Are You Eligible?

ParkMobile User? You might be eligible for compensation—Here's how to find out.

Parkmobile
ParkMobile meter. · Getty Images

ParkMobile, a popular parking application, has reached a $32.8 million settlement in a class-action lawsuit stemming from a massive data breach in March 2021. The breach exposed the personal information of approximately 21 million users, including email addresses, phone numbers, license plate details, and, in some cases, mailing addresses. While payment card information and Social Security numbers were reportedly not compromised, the exposed data presented significant privacy risks to affected users.

The Allegations Against ParkMobile

The lawsuit alleged that ParkMobile failed to implement adequate security measures to protect users' personal data. According to the amended complaint, the breach occurred when unauthorized parties accessed an Amazon Web Services S3 bucket used to store data related to the app’s services. Plaintiffs accused ParkMobile of negligence in maintaining secure systems, violating state consumer protection laws and breaching its contractual obligations to safeguard user information.

Details Of The 2021 ParkMobile Data Breach

An AWS S3 bucket, is a common tool in cloud computing. It functions as a scalable and secure digital storage solution, allowing businesses to store large volumes of data and access it efficiently for their applications. However, as with any storage system, its security depends heavily on proper configuration and monitoring.

In this breach, attackers gained access to the S3 bucket containing personal information from approximately 21 million ParkMobile users. The exposed data included license plate numbers, email addresses, phone numbers, and, in some instances, mailing addresses. Although ParkMobile confirmed that no payment information or Social Security numbers were compromised, the data that was accessed posed significant risks, such as phishing attacks and identity theft.

The breach likely occurred due to common vulnerabilities associated with cloud storage. One frequent issue is misconfiguration, where access controls are not properly set. For example, an S3 bucket might inadvertently be left open to public access, allowing anyone with the correct URL to view or download its contents. Even when access controls are applied, weak credentials or compromised access keys can provide a foothold for attackers.

How To File a Claim For Compensation

ParkMobile has agreed to pay $32.8 million to settle the claims, providing compensation to affected users. Key aspects of the settlement include:

  • Compensation for Losses: Eligible users can claim reimbursement for documented out-of-pocket expenses incurred due to the breach, such as credit monitoring services, identity theft protection or losses caused by fraudulent activity.
  • Time Compensation: Users can also receive compensation for time spent addressing the breach, such as contacting banks or updating passwords.
  • No Proof Required Claims: For users who cannot provide specific documentation of losses, a smaller payment may still be available through a general claim process.

Visit ParkMobileSettlement.com to check your eligibility and file a claim before the deadline of March 5th, 2024.


This column originally appeared in Forbes.

The newsletter

Digital forensics, explained before you need it

AI evidence, deepfakes and cell phone forensics from an expert witness who works these cases. No hype, no fear-mongering. Free.

Check your inbox to confirm your subscription.