Cargill Settles Class-Action Suit Over Kronos Ransomware Attack, Pays $2.4 Million to Employees

In a significant development, a federal judge approved a $2.4 million settlement on Wednesday for a class-action suit between food corporation Cargill and a group of current and former employees. The employees alleged that Cargill failed to pay them for all hours worked following the 2021 Kronos ransomware attack. The settlement, in the case of Futrell v. Cargill, comes after employees filed the suit in April 2022, citing pay discrepancies resulting from the Kronos attack on Cargill’s timekeeping and payroll systems.

Background

The Kronos ransomware attack caused widespread disruptions to Cargill’s operations, including its timekeeping and payroll systems. The impact of the attack resulted in significant pay discrepancies for employees, leading to the class-action suit. The suit specifically highlighted Cargill’s failure to pay non-exempt hourly workers and salaried employees their full overtime premium for overtime hours worked.

Allegations made in the lawsuit

According to the lawsuit, Cargill neglected to fully compensate employees for all hours worked, which is a violation of labor laws. The failure to pay overtime premiums to nonexempt hourly workers and salaried employees added to the grievances outlined in the suit.

Settlement terms

Under the terms of the settlement, Cargill has agreed to pay all underpaid collective members a proportional amount of the unpaid wages as liquidated damages. Additionally, nonexempt employees who worked in New York will receive an additional flat rate payment, while employees who were overpaid during the Kronos outage will also receive a per-person payment.

Ongoing fallout from the Kronos outage

Cargill is not the only employer facing litigation over its handling of the Kronos outage. The incident’s fallout continues to settle almost two years after the Kronos Private Cloud platform outage. In September, the University of Massachusetts Memorial Medical Center agreed to a $1.2 million settlement of wage-and-hour claims resulting from the breach. This ongoing litigation highlights the enduring impact of the Kronos attack on businesses and their employees.

Impact on HR departments

The Kronos outage created chaos for numerous HR departments, particularly during the critical 2021 holiday season. In the absence of functioning timekeeping and payroll systems, many HR departments had to resort to manual time sheets or duplicate payrolls from earlier pay periods to ensure workers could be paid on time. Such makeshift solutions further highlight the severe disruptions caused by the ransomware attack.

Employer Reactions and Future Use of Kronos

Despite the challenges posed by the Kronos attack, multiple employers interviewed after the incident expressed their intention to continue using Kronos and its parent company, UKG. Employers cited the company’s range of capabilities and the potential expense of finding an alternative as reasons for sticking with the system. The decision to remain with Kronos underscores the complex considerations involved in choosing and transitioning to a new platform.

Settlement by UKG

In addition to Cargill, UKG, the company that owns Kronos, also faced pressure to settle with affected employees. The outcome of this settlement is not explicitly mentioned in the current report, but it highlights the broader impact of the Kronos attack on businesses and their responsibility to address the grievances of their employees.

The $2.4 million settlement reached between Cargill and its employees is a significant milestone in addressing the pay discrepancies resulting from the Kronos ransomware attack. The case sheds light on the importance of safeguarding timekeeping and payroll systems against cyber threats to protect employee rights. As businesses increasingly rely on digital platforms, the incident serves as a reminder of the need for robust cybersecurity measures and proactive response strategies to mitigate the impact on employees and overall business operations.

Explore more

Ethereum Tests Glamsterdam Upgrade Amid Market Volatility

The activation of the Glamsterdam upgrade on the Sepolia testnet marks a critical phase in Ethereum’s infrastructure scaling as the network tests a gas limit increase from 60 million to 200 million. This substantial expansion of the gas limit represents a calculated gamble on the robustness of current hardware, aimed at accommodating a new wave of high-throughput decentralized applications. While

How to Design and Optimize AI Prompts for Production

The shift from experimental chatbots to high-scale enterprise intelligence systems in 2026 has transformed prompt engineering from a creative writing exercise into a disciplined branch of software engineering. The most effective production prompts use structural separation to distinguish between trusted system instructions and untrusted content from user inputs or retrieved documents. When an application processes thousands of model calls against

What Are the Best Email Marketing Tools for SMBs in 2026?

Small businesses often choose Constant Contact because it offers an extensive library of templates and specialized tools for managing event registrations and ticketing directly through emails. However, the broader landscape of digital outreach has shifted significantly, transforming email from a simple messaging tool into a sophisticated infrastructure for revenue growth and long-term customer retention. In 2026, the success of a

EY Breach Exposes Goldman Sachs and Man Group Client Data

Administrative IT tickets used for routine tax services inadvertently served as a repository for sensitive client data that was eventually stolen by hackers. This security failure at Ernst & Young (EY) has sent ripples through the financial sector, as it compromised the personal information of high-net-worth individuals associated with Goldman Sachs and the London-based hedge fund Man Group. While these

New Phishing Campaign Impersonates AI Tools to Steal MFA Codes

The campaign exploits the established trust that advertising agencies place in AI tools to bypass multi-factor authentication protocols that were previously considered secure. This sophisticated operation, identified in late 2026, represents a significant shift in the threat landscape, moving away from generic banking lures and toward the highly specialized tools used by modern marketing professionals. By impersonating platforms such as