AVL Growth Partners, an Ampleo Company Data Breach Exposes Social Security Numbers and Financial Account Information

Published: 17 September 2026
HR Technology data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

AVL Growth Partners, an Ampleo Company, notified Vermont regulators in September 2026 that a data breach exposed Social Security numbers, financial account codes, and credit and debit account information. The number of affected individuals has not been publicly disclosed. Anyone who receives a notification letter should place a credit freeze or fraud alert immediately to reduce the risk of identity theft.

CompanyAVL Growth Partners, an Ampleo Company
IndustryHR Technology
Data Types ExposedSocial Security Numbers, Financial Account Codes, Credit and Debit Account Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the AVL Growth Partners Data Breach?

AVL Growth Partners, an Ampleo Company, recently disclosed a data breach that exposed sensitive personal information belonging to individuals connected to the firm. The company filed a formal notification describing the incident in September 2026. This filing confirmed that unauthorized parties had accessed data containing highly sensitive financial and identity information.

The exact discovery date of the breach has not been publicly disclosed. However, the notification itself came in September 2026, which suggests the company had completed at least an initial review of the incident before alerting regulators. As a result, affected individuals are only now learning the scope of what happened.

Details about the specific attack method have not been made public. In many similar cases, companies conduct forensic investigations with outside cybersecurity specialists to determine how attackers gained entry. Because AVL Growth Partners has not released additional technical details, it remains unclear whether this incident involved ransomware, a phishing attack, or another form of unauthorized network access. Nonetheless, the company’s decision to notify a state regulator confirms that real exposure of personal data occurred.

Who was affected?

AVL Growth Partners provides services connected to Ampleo, and the breach likely affects individuals whose personal or financial records passed through the company’s systems. This may include clients, employees, or other individuals whose information was stored or processed by the firm.

The exact number of affected individuals has not been publicly disclosed. Because the notification was filed with the Vermont Attorney General, at least one Vermont resident was impacted. However, breaches involving corporate service providers often affect people across multiple states, since business relationships frequently span state lines.

At this time, there is no indication of whether minors were involved. Similarly, it is unclear whether the exposure was limited to current relationships or also included former clients or employees. Individuals who have interacted with AVL Growth Partners or Ampleo in any capacity should consider themselves potentially affected until they receive more specific information.

What Information Was Potentially Exposed?

According to the breach notification, several categories of highly sensitive data were involved in this incident. This type of information is especially valuable to criminals because it can be used to commit financial fraud or open new accounts in a victim’s name.

  • Social Security Numbers
  • Financial Account Codes
  • Credit and Debit Account Information

The combination of Social Security numbers with financial account details creates a heightened risk profile. For example, criminals who obtain both a Social Security number and account codes can potentially bypass identity verification steps used by banks and lenders. This makes it easier for them to open new lines of credit or attempt fraudulent transactions.

In addition, exposed credit and debit account information can lead to direct financial theft. Fraudsters may use stolen card details to make unauthorized purchases before a victim even notices. Because these details are still valid until canceled, the window for misuse can be significant if account holders are not notified quickly.

What is the company doing?

In response to the incident, AVL Growth Partners submitted a formal notification to the Vermont Attorney General’s office. This step is a legal requirement under Vermont’s breach notification law. It ensures that regulators are aware of incidents involving residents’ sensitive personal data.

The company also filed formal notification with the Vermont Attorney General, consistent with state breach reporting requirements. Beyond this filing, the source material does not specify additional remediation steps such as system upgrades or third-party security audits. It is common, however, for companies in this position to strengthen network defenses following an investigation.

The notification does not confirm whether AVL Growth Partners is offering credit monitoring or identity protection services to affected individuals. If such services are made available, they typically come with instructions on how to enroll. Affected individuals should watch for official correspondence from the company outlining any protective offerings.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Because Social Security numbers were involved in this breach, affected individuals should check their credit reports regularly. This can help catch new accounts opened without permission before significant damage occurs. Consumers can request free credit reports from each of the three major bureaus.

In addition, reviewing your credit report every few months for the next year is a smart precaution. Look for unfamiliar accounts, inquiries you did not authorize, or address changes you did not make. If you spot anything suspicious, report it to the credit bureau immediately.

Consider a Credit Freeze or Fraud Alert

Given that financial account codes and Social Security numbers were exposed, placing a credit freeze is a strong protective step. A freeze restricts access to your credit file, making it much harder for identity thieves to open new accounts in your name. This is one of the most effective tools available to consumers.

Alternatively, a fraud alert requires creditors to take extra steps to verify your identity before extending credit. This option is less restrictive than a freeze but still offers meaningful protection. Either measure can be requested directly through the credit bureaus at no cost.

Watch for Phishing Attempts

After a data breach, criminals often use stolen information to craft convincing phishing emails or phone calls. Because your personal details were exposed, you may become a target for these scams. Be cautious of unexpected messages asking you to confirm account information.

As a rule, never click on links or provide personal details in response to unsolicited messages. Instead, contact your bank or service provider directly using a verified phone number. This simple habit can prevent many follow-up scams tied to data breaches.

Review Financial and Bank Statements

Since credit and debit account information was potentially exposed, reviewing recent statements is essential. Look closely for unauthorized charges, even small ones, since criminals sometimes test stolen card details with minor purchases first. Report any suspicious activity to your bank immediately.

Furthermore, consider setting up transaction alerts through your bank’s mobile app or website. These alerts notify you in real time whenever a purchase is made. This added visibility can help you respond quickly if fraud occurs.

Consult a Data Breach Attorney

If you received a notification about this breach, it may be worth speaking with an attorney who focuses on data breach cases. They can help you understand whether you qualify for compensation. Many offer free consultations to evaluate your situation.

Because laws around data breach liability vary by state, professional guidance can clarify your specific rights. An attorney can also help determine whether a class action lawsuit related to this incident may be appropriate for your circumstances.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

See the latest data breaches we're tracking →