All Breaches
November 13, 2025 Verified Sensitive Record Technology

First Advantage 2025 Data Breach

The First Advantage 2025 data breach involved unauthorized access to Profile Advantage accounts using valid login credentials at the background-screening provider for employers and housing organizations. Official notices place the access from November 13 through November 17, 2025, and say the company identified the activity on November 17.

Current Texas Attorney General record BR-0005194 reports that 40,596 people across the United States were affected, including 3,608 Texas residents. Lower figures assembled from earlier state notices are below the current official nationwide total and have not been treated as the final scope.

How Was the First Advantage Breach Confirmed?

The primary count source is Texas Attorney General data security breach record BR-0005194. It identifies First Advantage Corporation at its Atlanta address and publishes the November 13–17 incident window, November 17 discovery date, U.S. and Texas affected-person counts, and confirmed principal data categories in separate fields.

First Advantage consumer notice 2026-705 in Massachusetts' official archive supports the event's connection to Profile Advantage accounts and the organization's response details. ClaimDepot connects the Massachusetts, Indiana, New Hampshire, Vermont, Maine, and Montana notices under the same dates. The sources agree on the company, account product, access window, and core identity fields.

What Happened From November 13 Through November 17, 2025?

An unauthorized person used valid login credentials to access a limited number of accounts in Profile Advantage, the system consumers use to manage their background-screening process. First Advantage detected the unauthorized activity on November 17, activated its incident-response process, and investigated the nature and scope of the access.

The company said there was no evidence that the login credentials were obtained from First Advantage systems. That statement suggests credentials exposed elsewhere or reused across services may have been tried, but the notice does not establish the original source. Malware, a ransom demand, and a specific threat actor have not been confirmed in the official records.

What Personal Information Was Affected?

The Texas Attorney General lists names, Social security numbers, driver's license numbers, and dates of birth among affected categories. State consumer notices also indicate that email addresses and passwords associated with Profile Advantage accounts could be involved. The combination of fields varied by individual.

Names, birth dates, Social security numbers, and driver's license data in a background-screening context can increase the risk of impersonation, new-account fraud, tax fraud, and fraudulent job applications. Bank accounts, payment cards, medical information, health-insurance information, and passports are not listed as confirmed fields for this event in the official sources.

How Many People Were Affected?

Texas Attorney General record BR-0005194 publishes a nationwide affected-person total of 40,596 and a Texas subset of 3,608. The Texas figure is included in the nationwide population and has not been added on top of it. The record was published through the Texas portal on July 23, 2026.

ClaimDepot's summary of earlier regulatory notices reported 4,669 people in total and 2,784 Texas residents. Because the company, Profile Advantage product, and November 13–17 dates match, these are not separate breaches. The newer Texas record indicates that the known scope later expanded, so the current official total of 40,596 is used.

How Did First Advantage Respond?

First Advantage activated its incident-response process, investigated the unauthorized access, and sent notice to affected people. The company recommended changing passwords on other accounts that use the same email address and password combination. Reusing a password across services allows compromise of one account to place other accounts at risk.

Affected people were offered two years of complimentary credit monitoring and identity-restoration services through Experian IdentityWorks. Features include an Experian credit report at enrollment, ongoing monitoring, access to identity-restoration specialists, ExtendCare support after membership expires, and up to $1 million in identity-theft insurance. Eligibility and the activation code are provided in the recipient's letter.

What Should Affected People Do?

If a Profile Advantage password was reused elsewhere, create a unique strong password for every account and enable multifactor authentication where available. Email-account security should be checked first because password-reset links arrive by email and a compromised mailbox can make additional account takeover easier.

Notice recipients should enroll with Experian only through the code in their authentic letter and review credit reports for unfamiliar accounts or inquiries. When a Social Security number was involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate. Identification numbers, passwords, payments, and verification codes should not be shared through unexpected messages claiming to represent First Advantage or Experian.

40.6 Thousand
Affected Accounts
7
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

7
Personal information
Names
Social security numbers
Driver’s license numbers
Dates of birth
Email addresses
Passwords

Additional Information

Added DateJuly 27, 2026
Breach DateNovember 13, 2025
Domainfadv.com
SourceTexas Attorney General and official state notices confirming Profile Advantage account access, dates, identity fields, and nationwide count
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information