Catalyst Brands LLC Data Breach Exposes Social Security Numbers and Government ID Data

Published: 7 September 2026 · Last Updated: 8 September 2026
HR Technology data breach illustration
Breach Discovery: May 2026Breach Notification: August 2026

Catalyst Brands LLC discovered in May 2026 that a vendor supporting its HR and payroll services suffered unauthorized network access, and confirmed in August 2026 that personal data including Social Security numbers, government ID numbers, and financial account details was taken. Employees and former employees may be affected. If you received a notice, enroll in the free Experian identity monitoring and check your credit reports immediately.

CompanyCatalyst Brands LLC
IndustryHR Technology
Data Types ExposedSocial Security Numbers, Date of Birth, Driver’s License Number, Passport Number, Government-Issued ID Numbers, Financial Account Numbers, Email/Username with Password, Digital Signature
People AffectedNot Publicly Disclosed
Attack MethodThird-Party Vendor Breach
Regulators NotifiedCalifornia Attorney General

What Happened in the Catalyst Brands Data Breach?

Catalyst Brands LLC recently notified affected individuals about a cybersecurity incident tied to its human resources and payroll operations. The company explained that an unauthorized party gained access to servers managed by a third-party vendor. This vendor supports Catalyst Brands’ HR and payroll-related services, which means the exposure touched systems handling sensitive workforce data.

According to the notification, unauthorized access to the network occurred in May 2026. Catalyst Brands has not disclosed exactly how the intruder got in, though the incident centered on a third-party service provider rather than the company’s own internal systems. This distinction matters because it shows the exposure originated outside Catalyst Brands’ direct control, even though the data belonged to its workforce.

After discovering the incident, Catalyst Brands launched a formal investigation with outside cybersecurity experts. As a result of that work, the company confirmed in August 2026 that an unauthorized third party had actually obtained personal information. This gap between discovery and confirmation reflects the time it often takes forensic teams to determine exactly whose data was taken and what categories were involved.

Because the breach involved a vendor’s servers, Catalyst Brands also had to coordinate closely with that provider during its review. The company has stated it blocked further unauthorized access once the issue was identified. It also alerted law enforcement and strengthened its security measures going forward.

Who was affected?

The Catalyst Brands data breach appears to affect individuals connected to the company’s HR and payroll functions. This likely includes current and former employees whose information passed through the compromised vendor systems. Because payroll data was involved, the population affected may include people no longer employed by the company but still on file for tax or benefits purposes.

Catalyst Brands has not publicly disclosed the total number of individuals affected. As a result, the exact scope of this incident remains unclear at this time. The notification also does not specify particular states or regions, so the geographic reach isn’t fully known either. However, given that HR and payroll systems typically hold nationwide employee records, the impact could extend across multiple states.

What Information Was Potentially Exposed?

The breach notification lists an unusually broad range of personal data categories. Because the information varied by individual, not everyone affected had every data type exposed. Still, the scope described is serious and touches on some of the most sensitive identifiers a person can have stolen.

  • Full name
  • Social Security number
  • Date of birth
  • Driver’s license number
  • Passport number
  • Alien Registration number (A-number)
  • U.S. military identification number or other government-issued ID
  • Contact information
  • Financial account number (without access information)
  • Email or username with password or security answer
  • Digital signature

This combination of data creates significant risk. For example, a Social Security number paired with a date of birth and driver’s license number gives criminals nearly everything needed to open new credit accounts. In addition, government-issued identifiers like passport or military ID numbers can be used to impersonate victims in ways that are especially hard to reverse.

Financial account numbers, even without access credentials, can still support fraud when combined with other stolen identifiers. Meanwhile, exposed email addresses and passwords raise the risk of account takeover on other websites, especially if people reuse login credentials. Because so many different identity elements were involved, affected individuals face a wider range of potential fraud scenarios than a typical single-category breach.

What is the company doing?

Catalyst Brands responded by opening an investigation as soon as it learned of the incident. The company brought in outside cybersecurity specialists to determine what happened and how far the exposure reached. It also worked to cut off the unauthorized access and reported the matter to law enforcement.

In addition, Catalyst Brands says it has added new safeguards to help prevent similar incidents going forward. The company has also filed a formal notification with the California Attorney General. To help affected individuals, Catalyst Brands is offering two years of free identity protection and credit monitoring through Experian IdentityWorks.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone notified about this breach should check their credit reports right away. You’re entitled to a free credit report every year from each of the three nationwide credit bureaus. You can get these at annualcreditreport.com or by calling 1-877-322-8228.

Because Social Security numbers were involved, reviewing your reports regularly is especially important. Look for accounts you don’t recognize or credit inquiries you didn’t authorize. If you spot anything unusual, report it to the credit bureau immediately and consider contacting a data breach attorney to discuss your options.

Consider a Fraud Alert or Credit Freeze

Given the exposure of Social Security numbers, driver’s license numbers, and financial account information, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further by blocking access to your credit file entirely.

Both options are free and can be requested directly through Equifax, Experian, and TransUnion. Because this breach involved multiple forms of government identification, a credit freeze offers stronger protection against someone opening new accounts using your stolen identity.

Enroll in the Free Identity Protection Services

Catalyst Brands has arranged complimentary identity protection and credit monitoring through Experian IdentityWorks for 24 months. If you received a notification letter, it likely includes an enrollment code and engagement number needed to sign up.

This service can help detect suspicious activity tied to your identity early. In addition, if fraud does occur, Experian’s identity restoration support can help you work through resolving those issues. It’s worth enrolling promptly, since these protections are time-limited and tied to your specific notification.

Watch for Phishing and Suspicious Contact

Because email addresses and login credentials were part of this breach, affected individuals should be extra cautious about unexpected emails or texts. Scammers often use breach news as an opportunity to send convincing phishing messages. These messages may pretend to be from Catalyst Brands, Experian, or even a bank.

Never click links or download attachments from messages you weren’t expecting. Instead, go directly to the official website or call a verified phone number if you need to confirm something. This simple habit can prevent a data breach from turning into a second, self-inflicted compromise.

Protect Government-Issued Identification

Because passport numbers, driver’s license numbers, and other government IDs were exposed, some individuals may want to contact the issuing agencies. For example, the State Department can advise on passport-related concerns, while your state’s DMV can address driver’s license misuse.

If you notice signs that your identification has been misused, report it promptly to the relevant agency. Acting early can limit the damage and create a paper trail that helps if you need to dispute fraudulent activity later. Consulting with a data breach attorney can also help clarify your legal options given the sensitivity of this exposed data.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

View the full list of tracked data breaches →