approximately 13,778
On September 25, 2026, the U.S. District Court for the District of Maryland granted final approval for a $675,000 settlement to resolve the class-action lawsuit against media company Urban One, Inc. The lawsuit stemmed from a data breach discovered in March 2025 that compromised the personally identifiable information (PII) of approximately 13,778 current and former employees. The settlement fund will provide reimbursement for out-of-pocket losses, lost time, and credit monitoring services for all affected individuals, bringing a legal conclusion to the nearly two-year-old incident.
The case, Gomian Konneh v. Urban One, Inc., was filed following the disclosure of a data breach that Urban One detected on or around March 15, 2025. The lawsuit alleged that the company was negligent in protecting employee data and had breached an implied contract to keep their information secure. The parties reached a settlement agreement through mediation on September 17, 2025, which has now received its final court approval.
The compromised data was highly sensitive, including:
The $675,000 non-reversionary settlement fund is structured to provide several benefits to the class members:
The primary impact of the original breach was the exposure of sensitive employee PII, placing them at risk of identity theft and financial fraud. The settlement now quantifies the financial impact on Urban One, which includes the $675,000 fund plus legal fees. For the affected employees, the settlement provides a mechanism for compensation for damages incurred and proactive protection through credit monitoring. The case serves as a reminder to all organizations of the legal and financial liabilities associated with failing to adequately protect employee data.
This settlement offers several lessons for other organizations regarding data protection and incident response:
Encrypting sensitive employee data like SSNs and financial information at rest can prevent it from being usable by an attacker even if they breach the system.
Implement the principle of least privilege to ensure that only a minimal number of authorized personnel have access to sensitive employee data repositories.
To prevent incidents like the Urban One breach, organizations must treat employee PII with the same level of protection as customer data. A primary technical control is encryption at rest. Sensitive files, such as those containing W-2 information, direct deposit details, and Social Security Numbers, should be encrypted. This can be achieved through file-level encryption or full-disk encryption on the servers and databases where this data is stored. Had the exfiltrated files been encrypted, the data would have been useless to the attackers, and the breach would have been a low-severity privacy event rather than a high-severity PII compromise leading to a costly settlement.
Implement the principle of least privilege for all access to employee data. Access to HR databases and file shares containing sensitive information should be strictly limited to HR personnel who have a legitimate business need. User account permissions should be reviewed regularly, and access for former employees must be terminated immediately upon separation. By minimizing the number of accounts that can access this data, the organization reduces the attack surface and limits the potential for both external attackers and malicious insiders to compromise the information.
Urban One discovers a data breach affecting its network and employee data.
The parties in the resulting class-action lawsuit reach a settlement agreement.
A U.S. District Court grants final approval for the $675,000 settlement.
Deadline for class members to file a claim for reimbursement.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.