What Happened in the Schembre & Gannon Data Breach?
Schembre & Gannon, LLC, a firm that provides accounting services to individual and business clients, filed notice of a data security incident with the Vermont Attorney General’s Office. The filing confirms that unauthorized parties may have accessed sensitive client records held by the firm. This kind of regulatory filing typically happens only after a company has already begun its own internal review of what occurred.
As of now, the public record does not describe exactly how intruders got in. It also does not say when the firm first noticed anything wrong. Vermont’s breach notification law does not force companies to publish their full notification letters, so many operational details remain outside public view. What is confirmed is that the firm reported the matter to state regulators on July 30, 2026.
Because the filing represents an early snapshot, the firm’s investigation may still be ongoing. Additional details could surface as forensic specialists finish reviewing affected systems. In many similar cases, the initial victim count grows once a company completes its full audit of compromised files. For now, Schembre & Gannon has not shared a public timeline for when that fuller picture might emerge.
Who was affected?
The Vermont filing identifies at least three Vermont residents as affected individuals. However, this number reflects only the residents known at the time of the state filing. Since accounting firms often serve clients across multiple states, the true scope of impacted people could extend well beyond Vermont’s borders.
Anyone who has used Schembre & Gannon for tax preparation, bookkeeping, or related financial services could potentially be included. This may include individual taxpayers as well as small business owners who shared account records with the firm. Because tax and accounting relationships often span many years, the exposed data could include information collected across several filing seasons.
What Information Was Potentially Exposed?
According to the state filing, the compromised data includes highly sensitive categories that accounting firms routinely collect and store. This combination of information creates meaningful risk for anyone affected. Below is a summary of what was reportedly involved.
- Social Security numbers
- Financial account codes
- Credit and debit account information
When Social Security numbers appear alongside financial account details, the danger multiplies. As a result, criminals could potentially open new credit lines using a victim’s identity. They might also attempt to access existing bank or credit accounts directly, rather than needing to create new ones from scratch.
In addition, because accounting firms often hold years of tax filings, exposed records could include income history, dependent information, and other financial details. This means affected individuals may face risks that extend beyond typical credit fraud. Tax-related identity theft, where a criminal files a fraudulent return using someone else’s SSN, is a particular concern following this type of exposure.
What is the company doing?
Schembre & Gannon has taken the required step of notifying the Vermont Attorney General’s Office about the incident. This filing is a legal obligation under state breach notification law once a company confirms that residents’ data was compromised. The firm has not publicly detailed what technical remediation steps it has completed so far.
It also remains unclear whether Schembre & Gannon is offering credit monitoring or identity protection services to those affected. Firms in similar situations often provide complimentary monitoring once their investigation concludes. Clients who want clarity on this point should reach out to the firm directly, since public filings so far do not specify these details.
What Should Affected Individuals Do?
Contact Schembre & Gannon Directly
If you have ever used Schembre & Gannon for accounting or tax services, consider reaching out to the firm directly. Ask whether your specific information was involved in this incident. Also ask what protective services, such as credit monitoring, the firm may be offering to affected clients.
Getting direct confirmation matters because public filings only list the minimum number of confirmed victims at the time of reporting. Your own records may show a relationship with the firm even if you have not yet received a formal notification letter. Being proactive can help you respond faster if your data was indeed included.
Place a Fraud Alert or Credit Freeze
Because this incident involves Social Security numbers, placing a fraud alert or credit freeze is a strong protective step. A freeze restricts new creditors from accessing your credit file, which makes it much harder for criminals to open accounts in your name. You can freeze your credit for free with Equifax, Experian, and TransUnion.
A fraud alert is a lighter-weight option that requires lenders to verify your identity before extending new credit. Either step adds a meaningful layer of protection. Given that both Social Security numbers and account information were reportedly exposed together, taking one of these steps is a reasonable precaution.
Monitor Financial Accounts and Credit Reports
Review your bank and credit card statements regularly for unfamiliar transactions. Because account codes and credit or debit card information were reportedly included in this breach, direct account monitoring is especially important. Even small unauthorized charges can be an early warning sign of larger fraud attempts.
You should also request a free copy of your credit report from annualcreditreport.com. Check it carefully for accounts you don’t recognize. If you spot anything suspicious, report it right away to your bank, the credit bureaus, and your state Attorney General’s office.
Stay Alert to Phishing Attempts
Criminals who obtain real account details often use them to craft convincing phishing messages. For example, a scam email might reference your actual account number to appear legitimate. Because of this, treat any unexpected communication about this breach with caution.
Always verify the sender before clicking links or sharing information. If you receive a message claiming to be from Schembre & Gannon, call the firm directly using a phone number you already trust, rather than one listed in the suspicious message. This simple habit can prevent a second wave of fraud following the original breach.
Consider Consulting a Data Breach Attorney
If your Social Security number or financial account information was exposed, you may have legal options worth exploring. Accounting firms are expected to maintain reasonable safeguards over the sensitive financial and tax data they collect. When those safeguards fail, affected clients sometimes have grounds to pursue compensation.
Speaking with a data breach attorney can help you understand whether you qualify to join a claim. Many consultations are free and carry no obligation. This can be a useful first step if you want to understand your rights following this incident.
