Cardinal Services Data Breach Exposes Social Security Numbers and Personal Information

HR Technology data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: May 2026

What Happened in the Cardinal Services Data Breach?

Cardinal Services, Inc., along with its affiliated organizations Cardinal Employer Organization and Preferred Employer Solutions, recently notified California residents about a data breach involving sensitive personal information. The Cardinal Services data breach exposed personal records that the companies held as part of their employer services operations. This notification was filed with the California Attorney General’s office, a required step whenever personal data of state residents is compromised.

The notification letter sent to affected individuals does not specify the exact method attackers used to gain access. However, it confirms that unauthorized parties accessed systems containing personal information. As a result, the company began an internal review to determine the scope of the intrusion and which records were involved.

Because Cardinal Services operates as an employer organization, it likely maintains records tied to payroll, benefits, and human resources functions for client businesses. This means the breach may have touched systems that process highly sensitive employee data. The notification indicates that the company took steps to assess the incident once it became aware of the unauthorized access.

Following discovery, Cardinal Services engaged in a review process to identify affected individuals and determine what specific data elements were compromised. This process ultimately led to formal notification letters being sent to those impacted. The company also arranged credit monitoring services in response to the breach, which suggests the exposed data included financial or identity-related information.

Who was affected?

The notification is addressed to individuals whose personal information was stored within Cardinal Services’ systems, or those of its affiliated companies, Cardinal Employer Organization and Preferred Employer Solutions. Because these entities function as employer service providers, the affected population likely includes current and former employees of client businesses, as well as possibly job applicants or dependents whose data was collected for benefits administration.

The source does not provide a specific count of how many individuals were affected. Therefore, the exact number of impacted people has not been publicly disclosed. What is clear is that the company determined the breach was significant enough to warrant formal notification under California law, along with an offer of credit monitoring services.

Because employer organizations often manage data across multiple client companies, the breach could span numerous workplaces and industries. This broadens the potential pool of affected individuals beyond a single employer’s direct workforce. In addition, the involvement of benefits administration functions raises the possibility that dependents or family members included in benefits plans could also be affected.

What Information Was Potentially Exposed?

While the notification letter itself focuses heavily on remedial steps, the offer of credit monitoring and identity restoration services strongly indicates that sensitive personal and financial data was involved. Employer organizations like Cardinal Services typically store a range of data points needed for payroll and benefits processing.

  • Full names
  • Social Security numbers
  • Dates of birth
  • Financial account information tied to payroll or benefits
  • Other personal identifiers used for identity verification

Because the company is offering dark web monitoring that specifically covers Social Security numbers, email addresses, phone numbers, names, and dates of birth, these categories are the most likely types of data exposed. This combination of information is particularly valuable to identity thieves.

When Social Security numbers are exposed alongside names and birth dates, the risk of identity theft rises sharply. Criminals can use this data to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. As a result, affected individuals should treat this incident seriously, even without an official list of every data type involved.

In addition to identity theft, exposed financial account details could lead to unauthorized transactions or attempts to redirect payroll deposits. Because employer-related data often includes banking information for direct deposit, this creates an additional layer of financial risk. Individuals should therefore monitor both credit activity and any accounts linked to payroll.

What is the company doing?

In response to the breach, Cardinal Services arranged complimentary credit monitoring services through Epiq’s Privacy Solutions ID platform for affected individuals. This service includes single-bureau credit monitoring, dark web monitoring, credit protection assistance, change of address monitoring, and identity restoration support. The company set an enrollment deadline for affected individuals to activate these protections using a unique code provided in their notification letters.

Beyond offering these services, Cardinal Services stated that it continually evaluates and updates its internal security practices to better protect personal information going forward. The company also established a dedicated toll-free response line, staffed on weekdays, so affected individuals can ask questions about the incident. This ongoing communication channel suggests the company anticipated follow-up concerns from those notified.

What Should Affected Individuals Do?

Enroll in the Offered Credit Monitoring

Affected individuals should activate the complimentary credit monitoring service using the activation code included in their notification letter. This service can alert you quickly if someone opens a new account or if suspicious activity appears in your credit file.

To enroll, visit the designated website, enter your activation code, and complete the identity verification steps. Because enrollment deadlines apply, it’s important to act promptly rather than setting the letter aside for later.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers may have been exposed, placing a fraud alert or a credit freeze offers strong protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name, while a credit freeze blocks access to your credit file entirely.

You can request either protection for free by contacting Equifax, Experian, or TransUnion. Because confirming a fraud alert with one bureau typically triggers notification to the others, this process is relatively quick. However, a freeze may need to be requested separately at each bureau for full coverage.

Review Your Credit Reports Regularly

Under federal law, you can request a free credit report from each major bureau once every twelve months. Reviewing these reports allows you to spot unfamiliar accounts or inquiries you didn’t authorize.

If you notice anything suspicious, contact the credit bureau immediately to dispute the entry. This step is especially important in the months following a breach, since fraudulent activity doesn’t always appear right away.

Stay Alert for Phishing Attempts

After a data breach, scammers often use exposed contact information to send phishing emails or text messages designed to look official. These messages may impersonate Cardinal Services, a credit bureau, or even a government agency.

Because of this, you should avoid clicking links or providing personal details in response to unsolicited messages. Instead, verify any communication by contacting the company directly through a known, official phone number or website.

Monitor Financial and Payroll Accounts Closely

Since payroll-related data may have been involved, affected individuals should also review bank statements and payroll deposit records for unauthorized changes. Even small, unexplained transactions can be an early warning sign of fraud.

If you notice any irregularities, report them to your bank and employer right away. Acting quickly can limit financial losses and help stop further misuse of your information.



More Information

Official data breach notification from Washington State Attorney General

Official data breach notification from California Attorney General

Related Data Breaches