[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1fo13xva3sj9v":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a7009c69f154ca2476ebe5c","AlcottHR2025","Alcott HR 2025 Data Breach","alcott-hr-2025","alcotthr.com","2025-02-12T00:00:00.000Z","2026-08-03T03:23:50.483Z","2026-08-03T03:26:47.083Z","Alcott HR","https:\u002F\u002Falcotthr.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FUntitled-1.jpg",[15,17,18],"https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-625037","https:\u002F\u002Fwww.in.gov\u002Fattorneygeneral\u002Fconsumer-protection-division\u002Fid-theft-prevention\u002Ffiles\u002FDB-Year-to-Date-Report-7_2026.pdf",76098,"known",null,"people","Medium",[25,26,27,28,29],"Names","Dates of birth","Social security numbers","Driver's licenses","Medical information","\u003Cp>The Alcott HR data breach concerns unauthorized access connected to unusual activity the company identified on February 12, 2025. Official records state that \u003Cstrong>76,098 people\u003C\u002Fstrong> were affected nationwide, with notifications issued in June 2026.\u003C\u002Fp>\u003Cp>Alcott said the incident may have affected information held in certain systems used for its human resources services. The company specifically stated that its iSolved platform, which stores employee data such as tax forms, benefit enrollment and banking information, was not affected.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>After detecting unusual activity in February 2025, the company activated its incident response process, notified law enforcement and engaged independent forensic specialists. The investigation found that an unauthorized person gained access to some Alcott systems where personal information was stored.\u003C\u002Fp>\u003Cp>Alcott completed its review of the affected information in March 2026. Public notices and state regulator records followed in June 2026; the published documents do not identify the method used to gain initial access.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Alcott’s official notice says the potentially affected categories could include names, dates of birth, Social Security numbers, driver’s license information and health information. The fields can vary by person, so an individual notice remains the best source for a recipient’s specific exposure.\u003C\u002Fp>\u003Cp>The company said the iSolved human capital management platform was not affected. This distinction matters: the incident was limited to certain Alcott systems and should not be interpreted as confirmation that all tax, benefit or banking data held in that platform was compromised.\u003C\u002Fp>\u003Ch2>Why do these data types matter?\u003C\u002Fh2>\u003Cp>A name combined with a date of birth and Social Security number can increase the risk of identity theft, fraudulent account opening and credit fraud. Driver’s license information may also be used in attempted identity verification fraud.\u003C\u002Fp>\u003Cp>Health information is privacy-sensitive even when no financial loss occurs. Personal details can also make phishing messages more convincing, so unexpected calls or messages claiming to concern this incident deserve careful verification.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Recipients should first review their own letter to identify the data types listed for them. In the United States, regularly checking credit reports, investigating unfamiliar accounts or applications, and considering a fraud alert or credit freeze may be appropriate.\u003C\u002Fp>\u003Cp>Alcott’s official notice offers 24 months of identity protection and lists September 15, 2026 as the enrollment deadline. Anyone enrolling should use only the official company notice or contact details in the letter sent directly to them.\u003C\u002Fp>\u003Cp>Monitoring new credit inquiries and identity-verification alerts is useful in addition to reviewing bank and card activity. If something unfamiliar appears, contact the relevant organization through a known official channel and keep a record of the report.\u003C\u002Fp>\u003Ch2>Password and communication security\u003C\u002Fh2>\u003Cp>Passwords are not among the data types disclosed in the public notice. The incident does not by itself establish a password leak, but enabling multi-factor authentication on email can still help defend against convincing messages built from exposed personal details.\u003C\u002Fp>\u003Cp>It is safer to verify the address independently instead of following links in messages claiming to come from Alcott, a credit bureau or an identity-protection provider. Never disclose a full Social Security number, verification code or account password during an unexpected call.\u003C\u002Fp>\u003Ch2>Confirmed scope\u003C\u002Fh2>\u003Cp>The confirmed scope consists of the February 12, 2025 incident date, the nationwide total of 76,098 people, and the categories of names, dates of birth, Social Security numbers, driver’s license information and health information. Alcott said it had found no evidence of misuse; that statement does not guarantee that misuse will never occur.\u003C\u002Fp>","","Alcott HR 2025 Data Breach (76.1 Thousand People Affected)","The Alcott HR data breach affected 76,098 people. Review the confirmed February 12, 2025 timeline, exposed data types and practical safety steps.","\u002Fuploads\u002Flogo\u002Falcott-hr-official.jpg",false,{"name":14,"sector":37,"country":38,"website":10,"websiteArchiveUrl":31,"websiteStatus":39,"websiteCheckedAt":12},"Business Services","United States","active"]