[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcz2hfu9bjep5":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":31,"seoTitle":32,"seoTitleEn":8,"seoDescription":32,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a702375ee7bfa8e395c509a","NorthAtlanticStatesCarpentersBenefitFunds2025","North Atlantic States Carpenters Benefit Funds 2025 Data Breach","north-atlantic-states-carpenters-benefit-funds-2025","carpentersfund.org","2025-08-18T00:00:00.000Z","2026-08-03T05:13:25.994Z","North Atlantic States Carpenters Benefit Funds","https:\u002F\u002Fwww.in.gov\u002Fattorneygeneral\u002Fconsumer-protection-division\u002Fid-theft-prevention\u002Ffiles\u002FDB-Year-to-Date-Report-7_2026.pdf",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2026-205-north-atlantic-states-carpenters-benefit-funds\u002Fdownload",110435,"known",null,"people","High",[24,25,26,27,28,29,30],"Names","Physical addresses","Social security numbers","Government issued IDs","Financial account information","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2025 North Atlantic States Carpenters Benefit Funds data breach\u003C\u002Fstrong> was a security incident that may have affected personal information associated with employee and participant benefit funds and required notice to 110,435 people.\u003C\u002Fp>\u003Cp>The Indiana Attorney General's official report records August 18, 2025 as the incident date and February 11, 2026 as the notification date. Records published by Massachusetts and Texas authorities align with the same organization and February 2026 notification process.\u003C\u002Fp>\u003Ch2>How was the incident documented?\u003C\u002Fh2>\u003Cp>Massachusetts sample notice 2026-205 states that North Atlantic States Carpenters Benefit Funds investigated a data event that may involve personal information, notified law enforcement, and would notify appropriate regulators as required.\u003C\u002Fp>\u003Cp>Public official documents do not disclose the precise start and end of unauthorized access, the method used, or the responsible actor. August 18 should therefore be treated as the regulator-reported incident reference, not as a confirmed first-access date.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record lists names, addresses, Social Security numbers, government identification such as passports or state IDs, financial account information, medical information, and health insurance information among the possible data types.\u003C\u002Fp>\u003Cp>The information involved may have varied by person. The full list should not be assumed to apply to every affected individual or to have been accessed together.\u003C\u002Fp>\u003Ch2>What does the 110,435 figure mean?\u003C\u002Fh2>\u003Cp>The Indiana Attorney General's 2026 report lists 110,435 affected people nationwide for this incident. It separately identifies 149 affected Indiana residents.\u003C\u002Fp>\u003Cp>The 567 people in the Texas record are a state-resident subset and should not be added to the national total. The 110,435 figure is the broadest published affected-person total.\u003C\u002Fp>\u003Ch2>Why do these data types matter?\u003C\u002Fh2>\u003Cp>A Social Security number, government identifier, or financial account detail combined with a name and address can be used in identity theft, fraudulent account opening, and financial fraud attempts.\u003C\u002Fp>\u003Cp>Medical and health insurance information can make messages impersonating a benefit fund, healthcare provider, or insurer appear more convincing. An accurate membership or health detail does not prove that the sender is legitimate.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports, bank accounts, benefit statements, and health insurance explanation-of-benefits records and report transactions or services they do not recognize.\u003C\u002Fp>\u003Cp>The sample notice published in Massachusetts offers eligible recipients 24 months of credit and identity monitoring through Epiq. Use only the enrollment code and deadline in the letter sent directly to you.\u003C\u002Fp>\u003Cp>Never provide a Social Security number, bank detail, password, or verification code during an unsolicited call or message. Open carpentersfund.org independently instead of following a suspicious link.\u003C\u002Fp>\u003Ch2>Confirmed scope\u003C\u002Fh2>\u003Cp>The confirmed scope consists of the August 18, 2025 incident reference, 110,435 affected people, and recipient-variable identity, financial, and health information. The sample notice says no funds were taken, benefit and account balances remained intact, and no misuse evidence had been found at notice time; the exact access period, method, and responsible actor were not disclosed.\u003C\u002Fp>","","The North Atlantic States Carpenters Benefit Funds data breach affected 110,435 people. Review the confirmed scope and practical safety steps.","\u002Fuploads\u002Flogo\u002Fnascbf-official.png",false,{"name":13,"sector":37,"country":38,"website":10,"websiteArchiveUrl":32,"websiteStatus":39,"websiteCheckedAt":12},"Finance","United States","active"]