The Bernard Group Data Breach Exposes Personal Information

Retail data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the The Bernard Group Data Breach?

The Bernard Group, a Chanhassen, Minnesota firm that builds visual displays, packaging, and printed materials for major retail chains, recently sent notification letters to individuals about a data security event. The company, also known as TBG, confirmed that personal information may have been involved. This notice went out through a formal letter dated July 2026.

The filing submitted to the Massachusetts Attorney General’s office serves as a template copy used for mass mailing. As a result, it doesn’t spell out how intruders got in, whether through phishing, ransomware, or a compromised vendor connection. It also skips over the exact month the incident began or when internal teams first spotted it.

Because the public version of this letter lacks specifics, the personalized notice mailed to each individual likely carries more detail. That letter typically includes a unique engagement number and activation code tied to a person’s own record. In addition, TBG has stated that it currently has no evidence of actual identity theft or fraud connected to the event.

Even without a full public accounting of the incident, the company still moved to notify affected people and file with state regulators. This step reflects a legal obligation that follows once a business identifies a security event touching personal data. The Bernard Group’s investigation into the underlying cause has not been made public at this time.

Who was affected?

The notification identifies affected individuals as clients of The Bernard Group. Because TBG works with major national retailers on packaging and in-store displays, its client relationships often involve exchanging sensitive business and personal contact information. However, the exact number of people affected has not been publicly disclosed.

It also remains unclear whether employees, contractors, or business partners were swept into this incident alongside clients. Companies in the visual merchandising and printing space frequently maintain records tied to multiple types of relationships. Consequently, individuals who worked with TBG in any capacity should stay alert for a letter, even if they don’t consider themselves a typical customer.

The geographic scope of those affected also hasn’t been shared publicly. Because the notification was filed with the Massachusetts Attorney General, it’s likely that at least some Massachusetts residents received letters. That said, TBG’s retail client base spans the country, so affected individuals could live well beyond that state.

What Information Was Potentially Exposed?

The publicly filed version of The Bernard Group’s notification letter does not list which specific categories of personal information were involved. This is common with template letters submitted for regulatory record-keeping, since the detailed version goes only to the individual it concerns. Still, breaches involving business and client records commonly touch on a few recognizable categories.

  • Full names
  • Contact information such as addresses, phone numbers, or email addresses
  • Potentially financial account details
  • Potentially Social Security numbers
  • Other identifying details tied to a client or business relationship

Without a confirmed list, affected individuals must rely on their personal letter to know exactly what was involved in their case. This uncertainty is frustrating for consumers who want clarity, but it doesn’t change the practical risk. If sensitive identifiers like Social Security numbers or financial account numbers were part of the exposure, the danger of identity theft and fraud rises considerably.

Even when only names and contact information are exposed, scammers can use that data to craft convincing phishing messages. For example, a fraudster might reference a real interaction with TBG to trick someone into giving up more sensitive details later. This makes vigilance important regardless of which exact data categories applied to any single person.

What is the company doing?

The Bernard Group has responded by mailing individual notification letters and filing a copy with the Massachusetts Attorney General’s office, satisfying its regulatory disclosure duties. As part of this response, the company is offering 24 months of complimentary credit monitoring and identity theft protection through Experian IdentityWorks. This service is available to affected individuals who enroll using the activation code found in their personal letter.

Beyond the immediate notification, TBG has indicated there’s currently no evidence that the exposed information has led to fraud or identity theft. Even so, offering monitoring services reflects an added precaution while the company continues to assess the incident. As more facts emerge, additional details about the root cause and scope may become available to the public.

What Should Affected Individuals Do?

Enroll in the Free Credit Monitoring Offer

Affected individuals should sign up for the complimentary Experian IdentityWorks membership before any enrollment deadline listed in their personal letter. This service can alert you to new accounts opened in your name or unusual credit inquiries. Because it’s offered at no cost for 24 months, there’s little reason to skip it if you received a notice.

To enroll, you’ll typically need the engagement number and activation code printed in your personalized letter. Therefore, it’s important to keep that letter somewhere safe rather than discarding it. If you’ve misplaced your letter, contacting The Bernard Group directly may help you recover the codes needed to verify eligibility.

Consider a Fraud Alert or Credit Freeze

Because the specific data types exposed in this incident haven’t been confirmed publicly, placing a fraud alert or credit freeze offers a strong layer of protection regardless of what was taken. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further, blocking new credit applications entirely until you lift it.

You can request either protection through Equifax, Experian, or TransUnion, and by law they must share fraud alert requests with the other two bureaus. This process is free and can be reversed later if you need to apply for credit yourself. Given the uncertainty around what data was involved here, this extra step is a reasonable precaution.

Monitor Your Accounts and Credit Reports Closely

Regularly reviewing your bank statements, credit card activity, and credit reports helps catch fraud early, before it spirals into a larger problem. Look for unfamiliar charges, new accounts you didn’t open, or hard inquiries you don’t recognize. Federal law entitles you to a free credit report from each major bureau every year through AnnualCreditReport.com.

In addition to bureau reports, many banks and credit card companies offer free transaction alerts by text or email. Setting these up gives you real-time notice of activity on your accounts. This kind of ongoing awareness matters even after your free monitoring period through Experian eventually ends.

Stay Alert for Phishing Attempts Referencing This Breach

Scammers often exploit news of a data breach by sending fake emails, texts, or phone calls pretending to represent the breached company. Because The Bernard Group has not disclosed a full list of exposed information, be especially cautious of any message asking you to confirm personal details. Legitimate companies will not ask you to provide sensitive information over an unsolicited call or email.

If you receive a suspicious message referencing this incident, avoid clicking any links or providing information. Instead, contact The Bernard Group directly using a verified phone number or website. This simple habit can prevent scammers from turning a notification letter into a second, more damaging breach of your information.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

See the latest data breaches we're tracking →