Berkeley Research Group Data Breach Exposes Social Security Numbers and Health Records

Published: 31 August 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

Berkeley Research Group, LLC confirmed that unauthorized parties accessed sensitive personal data, including Social Security numbers, government ID numbers, financial account codes, and health records. The company notified affected individuals and regulators in August 2026. The exact number of people affected has not been disclosed. Anyone who receives a notification letter should place a credit freeze and monitor their accounts immediately.

CompanyBerkeley Research Group, LLC
IndustryOther Commercial
Data Types ExposedSocial Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Information, Health Records
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedVermont Attorney General, Iowa Attorney General

What Happened in the Berkeley Research Group Data Breach?

Berkeley Research Group, LLC recently filed formal notice confirming that unauthorized individuals accessed sensitive personal information belonging to people connected to the firm. The company reported the incident to the Vermont Attorney General’s office in August 2026. This filing revealed that intruders had gained access to data containing some of the most sensitive categories of personal information a company can hold.

According to the notification, the exposed information includes Social Security numbers, government identification numbers, financial account codes, credit and debit account details, and health records. The exact date the breach was discovered has not been publicly disclosed. However, the timing of the notification suggests the company spent time investigating the scope of the incident before notifying affected individuals and regulators.

As is typical in these situations, Berkeley Research Group likely brought in forensic specialists to determine how attackers got in and what data they touched. This process usually involves reviewing network logs, identifying compromised systems, and confirming exactly which files were accessed or taken. Because the firm handles complex data on behalf of clients, the investigation may have required extra time to sort out exactly whose information was involved.

The company has not released a detailed public account of the attack method. Still, the breadth of data categories involved points to a significant compromise of internal systems. This kind of exposure often results from unauthorized network access rather than a simple isolated error.

Who was affected?

Berkeley Research Group, LLC provides consulting and advisory services, which means the individuals affected could include current or former employees, clients, or people connected to the firm’s casework. Because the firm works across many industries, the affected population may span multiple states and sectors. The exact relationship between the breach victims and the company has not been fully detailed in the public notice.

The total number of individuals affected has not been publicly disclosed. Regulatory filings in states like Vermont and Iowa often don’t require a company to state precise victim counts at the state level. As a result, the true scope of this incident may only become clear as more notifications are issued or as further details emerge.

Given that health records were among the exposed data types, it’s possible that individuals connected to litigation, healthcare consulting engagements, or related casework are included. This raises the possibility that both business associates and private individuals were affected. Because Berkeley Research Group serves clients broadly, the population impacted could include people who never had a direct relationship with the firm itself.

What Information Was Potentially Exposed?

The categories of data confirmed in the breach notification are notably sensitive. This combination of financial, identity, and health-related information creates meaningful risk for anyone affected. Understanding exactly what was exposed helps clarify the level of caution needed going forward.

  • Social Security numbers
  • Government ID numbers
  • Financial account codes
  • Credit and debit account information
  • Health records

Social Security numbers and government ID numbers are especially valuable to criminals because they can be used to open new accounts, file fraudulent tax returns, or impersonate victims in other ways. When this data is combined with financial account details, the risk multiplies. Fraudsters can potentially access existing accounts or use stolen numbers to apply for new credit lines.

Health records add another layer of concern. Medical identity theft can lead to fraudulent insurance claims or incorrect information being added to a victim’s health history. This type of fraud can be especially difficult to detect and correct, because it may not show up on a standard credit report. Because of this, affected individuals should watch for unusual medical bills or insurance statements in addition to standard financial account activity.

What is the company doing?

In response to the breach, Berkeley Research Group filed official notifications with state regulators, including the Vermont Attorney General. This step is a legal requirement in many states when personal data is compromised. The filing process typically also triggers direct notification letters to affected individuals explaining what happened and what protective steps are available.

In addition to the Vermont filing, the company also notified the Vermont Attorney General and the Iowa Attorney General as part of its broader regulatory compliance efforts. These filings help ensure that consumers across multiple states receive appropriate notice. Companies are generally required to detail the nature of the breach and the categories of data involved when submitting these notices.

Beyond notification, organizations that experience this kind of breach typically strengthen their network security to prevent future intrusions. This can include tightening access controls, patching vulnerabilities, and increasing monitoring of sensitive systems. Because Berkeley Research Group has not released a full account of its remediation steps, affected individuals should watch for direct correspondence for more specific guidance, including any offer of credit monitoring or identity protection services.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone affected by this breach should begin checking their credit reports regularly. You can request a free copy from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports helps you catch new accounts or inquiries you didn’t authorize.

Because Social Security numbers were involved, this step is especially important. Identity thieves often wait months or even years before using stolen information. As a result, ongoing monitoring is more effective than a single check right after receiving a notification letter.

Consider a Credit Freeze or Fraud Alert

Given that Social Security numbers and financial account data were exposed, placing a credit freeze is a strong protective step. A freeze blocks new creditors from accessing your credit file, which makes it much harder for someone to open accounts in your name. You can request a freeze for free with each credit bureau individually.

Alternatively, a fraud alert requires lenders to take extra verification steps before approving new credit. This option is less restrictive than a freeze but still adds a layer of protection. Either way, acting quickly reduces the window of opportunity for criminals to misuse your information.

Protect Yourself Against Medical Identity Theft

Because health records were part of this breach, affected individuals should also review their medical statements and insurance explanations of benefits. Look for any services or treatments listed that you did not receive. This type of fraud can affect both your finances and your medical history.

If you notice anything unusual, contact your healthcare provider or insurer immediately. In addition, request a copy of your medical records to confirm their accuracy. Correcting fraudulent medical entries early can prevent complications with future care or insurance claims.

Stay Alert for Phishing Attempts

After a breach involving personal data, scammers often follow up with phishing emails or phone calls pretending to be legitimate companies. Be cautious of any message asking you to confirm personal details or click on unfamiliar links. Berkeley Research Group will not ask for sensitive information through unsolicited contact.

Instead, verify any communication by contacting the company directly through official channels. If something feels off, it’s safer to delete the message or hang up the phone. This simple habit can prevent a second wave of harm following the initial breach.

Consult a Data Breach Attorney

Because this breach involves highly sensitive categories of data, affected individuals may want to speak with an attorney who focuses on data breach cases. A consultation can help clarify whether you qualify for compensation or participation in a potential class action. Many attorneys offer free initial case evaluations.

Taking this step costs nothing upfront and can help you understand your legal options. Given the sensitivity of the data involved, including Social Security numbers and health records, exploring legal recourse may provide additional peace of mind. It also ensures you don’t miss any applicable deadlines for filing a claim.



More Information

View the public data breach notification listing from Vermont Attorney General

Official data breach notification from Iowa Attorney General

Related Data Breaches

View the full list of tracked data breaches →