All Breaches
September 16, 2025 Verified Sensitive Record Transportation

Virginia Transportation 2025 Data Breach

The Virginia Transportation 2025 data breach was a confirmed data-security event identified through unauthorized activity on the network of a Rhode Island-based automobile carrier and logistics company. The company discovered the activity on or about September 16, 2025; its forensic investigation found unauthorized network access on that date and concluded that files were likely copied.

Virginia Transportation Corporation completed a comprehensive review of the impacted files on July 6, 2026 and confirmed that personal information was affected. Public sources do not disclose a deduplicated nationwide total, so LeakData does not invent an affected-person figure: pwnCount and totalRecords are zero. importedRecordCount is also zero, and no person rows were imported.

How Was the Virginia Transportation Breach Confirmed?

The primary source is the “Notice of Data Breach” PDF published on the company's own domain. It directly states the discovery date, forensic work with external cybersecurity professionals, likely file copying, completion date of the file review, confirmed data categories, and the company's dedicated response line.

A Massachusetts Office of Consumer Affairs and Business Regulation record provides a sample individual notice and confirms the Kroll identity-monitoring offer. Claim Depot connects the official company and state disclosures and corroborates the timeline, data classes, and partial state counts. All three sources align on the core facts of the event.

What Happened on September 16, 2025?

The company became aware of unauthorized activity on its network on or about September 16 and immediately began an investigation. Extensive forensic work with external cybersecurity professionals determined that unauthorized network access occurred on that date and that files were likely copied from the network. The official notice does not provide a longer access window.

Virginia Transportation then notified affected affiliates and worked to obtain current mailing addresses. A person-by-person review of information in the files concluded on July 6, 2026, when the company determined that personal data had been impacted. The initial access method, actor identity, and tools used were not disclosed in the public notice.

What Identity and Financial Information Was Affected?

The official list includes full names in combination with financial information, taxpayer identification numbers, dates of birth, driver's license or state ID numbers, passport numbers, social insurance numbers, and Social security numbers. The company expressly says not every field was affected for every individual, so file contents may differ from person to person.

“Financial information” appears as a general category in the source; no specific bank account, payment-card number, balance, or transaction record is disclosed. The notice also does not list addresses, email addresses, phone numbers, passwords, or login credentials as confirmed fields. LeakData does not infer narrower data elements or add fields absent from the source.

What Health Information Was Involved?

The company notice expressly names health-insurance information and medical information among the possible affected fields. The public text does not separately identify diagnoses, treatments, prescriptions, medical-record numbers, dates of service, or provider names. This entry therefore uses only the two broad health categories confirmed by the source.

The possible presence of identity, financial, and health information in the same group of files may raise risks beyond identity theft, including medical-identity impersonation and fraudulent insurance claims. It does not mean every class was combined for every person. The official notice says there was no evidence of identity theft or fraud related to the incident.

How Many People Were Affected and How Did the Company Respond?

An appendix to the company's public notice states that 268 Rhode Island residents were affected; Claim Depot also reports 119 Massachusetts residents and two Vermont residents. These are partial counts for specific states. Because no deduplicated nationwide final total was published, adding the state values and presenting them as a U.S. total would be misleading.

Virginia Transportation said it continually evaluates its practices and internal controls, worked with affected affiliates, and established a dedicated response line. The Massachusetts letter confirms complimentary Kroll identity monitoring for eligible recipients. Because the membership number and activation deadline are redacted from the public sample, LeakData does not guess a service term or deadline.

What Should Affected People Do?

Notice recipients should monitor financial statements, credit reports, tax records, and health-insurance explanation-of-benefits statements for unfamiliar transactions, accounts, claims, or services. When Social Security and other government identifiers are involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate safeguards.

Identity details, health data, verification codes, or payments should not be shared in unexpected email, text messages, or calls claiming to represent Virginia Transportation. Eligibility should be confirmed only through the 1-844-858-8919 line in the official notice. LeakData does not host, distribute, or make searchable the impacted files, financial details, health data, or person records.

0
Affected Accounts
13
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

13
Personal information
Protected health information
Names
Financial information
Taxpayer identification numbers
Dates of birth
Driver’s license numbers
State identification numbers
Health insurance information
Medical information
Passport numbers
Social insurance numbers
Social security numbers

Additional Information

Added DateJuly 27, 2026
Breach DateSeptember 16, 2025
Domainvirginiatransportation.com
SourceOfficial Virginia Transportation notice confirming unauthorized access and likely copying of files containing PII, financial information, and health information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information