[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ku946l86ea4r":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a71abd024036b702b552ea6","SunSource2026","SunSource Data Breach","sunsource-2026","sun-source.com","2026-03-31T00:00:00.000Z","2026-08-04T09:07:28.427Z","SunSource consumer notice published by the Massachusetts Attorney General","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-988-sunsource-borrower-llc-sunsource\u002Fdownload",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.sun-source.com\u002FAbout-Us",12463,"known",null,"people","Medium",[24,25,26,27,28,29,30,31,32],"Names","Physical addresses","Dates of birth","Social security numbers","Driver's licenses","Government-issued identification","Financial information","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The SunSource data breach\u003C\u002Fstrong> was a security incident in which an unauthorised party gained access to a limited part of the industrial equipment distributor's network and exposed certain files on a file server. SunSource's official notice places the access between 31 March and 5 April 2026.\u003C\u002Fp>\u003Cp>The Texas Attorney General record reports that the incident affected 12,463 people across the United States, including 2,142 Texas residents. The Massachusetts Attorney General also published SunSource's consumer notification letter.\u003C\u002Fp>\u003Ch2>How was the incident confirmed?\u003C\u002Fh2>\u003Cp>SunSource's letter published in Massachusetts confirms that an unauthorised third party briefly accessed a limited part of the company's network. SunSource engaged an outside forensic expert after discovering the incident.\u003C\u002Fp>\u003Cp>The Texas record identifies the same organisation, the same access period and the nationwide affected-person total. SunSource's official website also confirms the Addison, Illinois industrial distributor identified in the notice.\u003C\u002Fp>\u003Ch2>When did the breach occur?\u003C\u002Fh2>\u003Cp>The investigation determined that the third party had access to the network and certain files on part of a file server between 31 March and 5 April 2026. The catalog event date is the beginning of that period.\u003C\u002Fp>\u003Cp>SunSource said it determined whose information was present in the files on 4 May 2026. The Texas and Massachusetts records were published on 18 June 2026; that publication date is not the date access began.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record lists names, addresses, dates of birth, Social Security numbers, driver's licence details and other government identification. Financial information, medical information and health insurance information are also among the reported categories.\u003C\u002Fp>\u003Cp>The fields involved varied by person. SunSource's sample letter leaves the specific data elements as a recipient-specific field, so the published categories should not be interpreted as applying to all 12,463 people.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports a total of 12,463 affected people. This is the stated United States-wide scope, not only the 2,142 Texas residents.\u003C\u002Fp>\u003Cp>Resident counts published for individual states are subsets of that total. Those state figures were not added to the nationwide count again.\u003C\u002Fp>\u003Ch2>What risks do these data types create?\u003C\u002Fh2>\u003Cp>A Social Security number combined with a date of birth and government identification may be used in fraudulent account applications or attempts to bypass identity checks. Financial information may also make account- or payment-themed messages more convincing.\u003C\u002Fp>\u003Cp>Medical and health insurance details can be used in scams disguised as healthcare or benefits assistance. A message containing personal details does not prove that the sender is authorised by SunSource.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>SunSource offered eligible notice recipients two years of identity monitoring through Kroll. Enrollment links and membership details should be checked only against the recipient's official notification letter.\u003C\u002Fp>\u003Cp>Recipients can review credit reports, bank accounts, insurance statements and new-account alerts for unfamiliar activity. If suspicious activity appears, they can contact the relevant institution directly and consider placing a security freeze on their credit file.\u003C\u002Fp>","","SunSource Data Breach (12.5 Thousand People Affected)","Review the verified SunSource breach date, the 12,463 people affected, the information involved and practical protective steps.","https:\u002F\u002Fd36z6dgmsq8u8z.cloudfront.net\u002Fuserfiles\u002Fsunsource_logo_soft-gradient.svg",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":34,"websiteStatus":43,"websiteCheckedAt":12},"SunSource","Industrial Distribution","United States","active"]