The Credit Acceptance 2026 data breach was a confirmed incident in which the U.S. automobile-finance company determined that personal information belonging to certain consumers had been affected by a data-security event. According to the official notice filed in Massachusetts, the company determined on June 4, 2026 that certain personal information was impacted.
The confirmed fields are an individual's first and last name together with a Social Security number. The Massachusetts record does not disclose a nationwide total, and no deduplicated final count across other states is public. LeakData does not invent an affected-person figure: pwnCount and totalRecords are zero, importedRecordCount is zero, and no consumer rows were imported.
How Was the Credit Acceptance Breach Confirmed?
The primary source is official Massachusetts Office of Consumer Affairs and Business Regulation record 2026-1067. Its Credit Acceptance consumer letter directly states the company name, June 4 determination date, two affected data fields, law-enforcement contact, engagement of outside cybersecurity firms, and complimentary identity-monitoring offer.
Claim Depot links the official Massachusetts file and independently summarizes that the event was disclosed to the regulator on June 30, 2026, that names and SSNs were involved, and that Kroll services were offered. The sources align on these core facts. LeakData does not add an attacker, ransomware, or data-sale claim absent from the public documents.
What Was Determined on June 4, 2026?
The Credit Acceptance letter says the company determined on June 4 that certain personal information was impacted by the incident. This is the earliest definite public event date; the notice does not call it the attacker's initial-access date. The technical access window, entry method, affected systems, and manner of discovery are not disclosed.
The official text says the incident was contained, law enforcement was contacted, and leading cybersecurity firms were engaged to assess its scope and cause. It does not expressly say files were copied, downloaded, or published on the dark web. LeakData therefore does not manufacture access or exfiltration details.
What Personal Information Was Affected?
The precise statement in the consumer letter says the involved information included the recipient's first and last name along with a Social Security number. That combination may enable fraudulent credit applications, tax-identity fraud, new-account opening, and targeted social engineering. The source presents those fields as applicable to the notice recipient.
The notice does not list dates of birth, postal or email addresses, phone numbers, driver's licenses, passports, bank accounts, payment cards, credit balances, passwords, health-insurance details, or medical information. Documents requested to place a freeze in the general resource section are not incident fields. LeakData records only the expressly confirmed name and SSN classes.
How Many People Were Affected?
The public Massachusetts file provides the sample consumer letter but does not visibly publish an affected-person total for the state or the entire United States. Claim Depot does not report a numerical total. With the source scope unknown, assuming only one state, counting notice recipients, or estimating from the company's customer base would be unreliable.
A zero figure on LeakData does not mean nobody was affected; it indicates that no verified nationwide total was publicly disclosed. This entry contains no SSN, name list, customer account, finance agreement, or contact detail. It publishes only incident metadata, source-confirmed data classes, and protective steps that readers can take.
How Did Credit Acceptance Respond?
The company said it contained the incident, contacted law enforcement, and worked with cybersecurity firms to assess the scope and cause. Affected individuals were offered 24 months of complimentary identity monitoring through Kroll. The package includes single-bureau credit monitoring, fraud consultation, and identity-theft restoration.
Enrollment requires the membership number in the recipient's letter; the membership number and activation deadline are masked with placeholders in the public sample. LeakData therefore does not guess a code or deadline. For questions about the incident and services, the notice lists 1-844-959-7145 on weekdays from 8:00 a.m. to 5:30 p.m. Central Time.
What Should Affected People Do?
Notice recipients should activate Kroll only through the official enrollment address with the membership number in their letter, then regularly review credit reports, account statements, tax records, and new-credit inquiries for unfamiliar activity. When an SSN is affected, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate safeguards.
SSNs, membership numbers, verification codes, or payments should not be shared in unexpected email, text messages, or calls claiming to represent Credit Acceptance or Kroll. Contact details should be independently verified against the official letter. LeakData does not host, distribute, or make searchable the impacted files, Social security numbers, customer names, or person records.