All Breaches
November 6, 2025 Verified Sensitive Record Healthcare

Devereux Foundation 2025 Data Breach

The Devereux Foundation 2025 data breach involved unauthorized access to certain systems on the behavioral-health and human-services organization's network and the copying of files without permission. Devereux identified suspicious activity on November 9, 2025. According to its official notice, an unauthorized actor accessed specified systems from November 6 through November 9, 2025.

Texas Attorney General record BR-0005199 reports that 86,958 people across the United States were affected, including 5,341 Texas residents. The affected population may include current and former employees, clients, donors, people connected with payors, and individuals associated with business partners.

How Was the Devereux Breach Confirmed?

The primary incident source is the “Notice of Data Event” published on Devereux's own domain. Issued in the organization's name, it directly describes the discovery date, unauthorized-access window, copying of files, reviewed data categories, law-enforcement notification, and complimentary credit monitoring.

The second official source is Texas Attorney General data security breach record BR-0005199. It identifies The Devereux Foundation at its Villanova, Pennsylvania address and publishes the U.S. total of 86,958 people, the Texas subset of 5,341, notification methods, and principal data categories. The two sources agree on the organization and the incident's starting date.

What Happened From November 6 Through November 9, 2025?

Devereux detected suspicious activity in certain computer-network systems on November 9. It began isolating systems, assessing network security, and investigating the nature and scope of the event. The review, supported by third-party specialists, determined that an actor accessed certain systems from November 6 through November 9 and copied files without permission.

The organization then conducted a detailed review to determine whether sensitive information appeared in the copied files and the individuals to whom it related. The public notice does not identify the initial access method, exploited vulnerability, malware, ransom demand, or actor. The event therefore has not been attributed to a particular group or attack technique.

What Personal Information Was Affected?

According to Devereux's official notice, the information varied by individual. Possible fields included names, dates of birth, Social security numbers, driver's license or state identification numbers, U.s. alien registration numbers, taxpayer identification numbers, and digital or electronic signatures.

The copied files could also contain financial-account information, payment-card information, medical information, and health-insurance information. The notice does not say that every affected person had every category involved. Passwords, email contents, and biometric data were not listed among affected categories in the official incident notice and are not included in this record.

How Many People Were Affected?

Texas Attorney General record BR-0005199 gives an exact nationwide affected-person total of 86,958. The same record separately identifies 5,341 Texas residents. The Texas figure is a subset of the national population and has not been added on top of the total.

The Texas portal records November 6, 2025 as the breach start and says notice was provided by posting on a company or special website and by U.S. mail. Devereux's notice states that access continued through November 9 and that notification began on January 8, 2026. The sources' different date fields have been read as incident, review, and notification milestones rather than combined into one date.

How Did Devereux Respond?

Devereux said it isolated systems, engaged third-party specialists to support network security and operations, and reported the event to law enforcement. The organization also reviewed policies and procedures, began additional employee training intended to reduce the chance of a similar event, and notified relevant regulators.

Affected individuals were offered complimentary credit monitoring through Experian. The official notice says there were no indications of actual or attempted identity theft or fraud resulting from the incident. That statement reflects the situation at the time of notice; continued monitoring remains prudent because copying of files was confirmed.

What Should Affected People Do?

Notice recipients should review the data types identified in their letter and enroll with Experian only through the verified code supplied there. Credit reports, bank and card activity, health-insurance explanations of benefits, and medical-service records should be checked for unfamiliar accounts, transactions, or services. If a Social Security number was involved, a free credit freeze and fraud alert may be appropriate.

Passwords, full identification numbers, payments, or verification codes should not be provided in unexpected messages claiming to represent Devereux, Experian, a health plan, or a financial institution. Use a known official channel instead of links in the message. Questions about the event may be directed to the 833-745-1528 line in Devereux's notice; an individual's notification letter is the primary source for the specific data fields involved.

87 Thousand
Affected Accounts
14
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

14
Personal information
Protected health information
Names
Dates of birth
Social security numbers
Driver’s license numbers
State identification numbers
U.s. alien registration numbers
Taxpayer identification numbers
Digital or electronic signatures
Financial account information
Payment card information
Medical information
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 6, 2025
Domaindevereux.org
SourceOfficial Devereux notice and Texas Attorney General record confirming unauthorized access, file copying, affected fields, and nationwide count
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information