All Breaches
November 14, 2025 Verified Sensitive Record Healthcare

Center for Life Resources 2025 Data Breach

The Center for Life Resources 2025 data breach involved unauthorized access to the internal network of the community mental-health organization also known as Central Texas MHMR and the copying of files. The organization identified suspicious activity on November 17, 2025, and its investigation found that unauthorized access occurred on November 14 and 15.

Current Texas Attorney General record BR-0005197 reports that 26,055 people across the United States were affected, including 10,031 Texas residents. The possible scope includes identity, contact, financial, medical, and health-insurance information.

How Was the Center for Life Resources Breach Confirmed?

The primary incident source is the official notice published on Center for Life Resources' own domain. Issued by the organization, it describes discovery of unusual activity, steps to secure systems, an investigation with cybersecurity specialists, the November 14–15 access window, and files that were copied or potentially viewed.

The second official source is Texas Attorney General data security breach record BR-0005197. It identifies the organization as Central Texas MHMR dba Center for Life Resources at its Brownwood address and publishes the U.S. and Texas counts, notice method, and affected-data categories. ClaimDepot connects the company notice and regulatory records to the same event.

What Happened on November 14 and 15, 2025?

The organization detected unusual activity in its internal network on November 17, took steps to secure systems, and said services to clients were not disrupted. An investigation with outside cybersecurity specialists determined that an unauthorized actor accessed the network on November 14 and 15 and copied or may have viewed certain files.

The public official notice does not establish the initial entry method, exploited vulnerability, ransom demand, or actor identity. Secondary reporting says a ransomware group claimed the event in December 2025, but that claim has not been confirmed in official records and is not used as evidence for data fields or incident scope.

What Identity and Financial Information Was Affected?

The Texas Attorney General lists possible personal fields as names, addresses, Social security numbers, driver's license numbers, government-issued identifiers such as passports or state IDs, and dates of birth. The scope varied by person, and the sources do not say every file contained every category.

Financial information is also a confirmed broad category and can include account numbers or credit and debit card numbers. The official record does not specify which financial field applied to which individual. These data can raise the risks of identity theft, new-account fraud, payment fraud, and targeted social engineering.

What Health Information Was Affected?

Center for Life Resources provides mental-health, intellectual and developmental disability, substance-use, and related community services. The Texas record confirms medical information and health-insurance information within the incident scope. These categories are sensitive because they may reveal a care relationship or connection to a health plan.

Public sources do not separately publish diagnoses, treatments, prescriptions, laboratory results, physician names, medical-record numbers, or service dates as confirmed fields. Those details should not be assumed. People with health information involved should regularly review insurance explanations and provider records for unfamiliar services, claims, or changes.

How Many People Were Affected?

Texas Attorney General record BR-0005197 publishes an exact nationwide total of 26,055 people and a Texas subset of 10,031. The Texas figure is included in the nationwide population and has not been added on top of it. Older public summaries saying an exact total had not been disclosed are superseded by the current Texas record.

The organization's detailed notice gives November 14–15, 2025 as the unauthorized-access window. Because a broader date field in the Texas portal does not fully align with that narrative, the company's detailed forensic finding is used for the incident window. The Texas record is used for the affected-person total and data categories, while its conflicting end-date field is not interpreted as the duration of technical access.

What Should Affected People Do?

Notice recipients should check their letter for the data fields involved and review credit reports, bank and card activity, health-insurance explanations, and healthcare records for unfamiliar accounts, transactions, or services. When a Social Security number was involved, a free credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate.

Identification numbers, passwords, payments, and verification codes should not be shared through unexpected messages claiming to represent Center for Life Resources, a health plan, or a financial institution. Use known official channels instead of links in the message. An individual's authentic notification letter is the primary source for person-specific fields and protection options.

26.1 Thousand
Affected Accounts
11
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

11
Personal information
Protected health information
Names
Physical addresses
Social security numbers
Driver’s license numbers
Government-issued identification numbers
Financial information
Medical information
Health insurance information
Dates of birth

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 14, 2025
Domaincflr.us
SourceOfficial Center for Life Resources notice and Texas Attorney General record confirming network access, copied files, affected fields, and nationwide count
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information