Cambridge Mercantile Corp. (U.S.A.) Data Breach Exposes Names and Contact Details

Published: 19 September 2026
Finance data breach illustration
Breach Discovery: June 2026Breach Notification: August 2026

Cambridge Mercantile Corp. (U.S.A.), also known as Corpay, notified customers that a vendor breach at Klue exposed names, email addresses, and physical addresses between June 11-12, 2026. No passwords or financial account access were involved. Affected individuals should enroll in the free Kroll identity monitoring offered and watch for phishing attempts referencing Corpay.

CompanyCambridge Mercantile Corp. (U.S.A.)
IndustryFinance
Data Types ExposedFull Name, Email Address, Physical Address, Additional Personal Information
People AffectedNot Publicly Disclosed
Attack MethodThird-Party Vendor Breach
Regulators NotifiedCalifornia Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Cambridge Mercantile Corp. (U.S.A.) Data Breach?

Cambridge Mercantile Corp. (U.S.A.), operating as Corpay, has notified customers about a data security incident tied to a vendor it relies on for market intelligence. The company explained that unauthorized access to its network did not occur directly. Instead, the breach happened at Klue, a third-party platform that connects to Corpay’s customer relationship management system.

According to the notice, an unauthorized third party compromised Klue’s integration infrastructure. As a result, the attacker accessed CRM data belonging to many of Klue’s customers, including Corpay. Corpay stated that this unauthorized access occurred between June 11 and June 12, 2026. Because Klue integrates directly with Corpay’s CRM, the intrusion reached records Corpay had shared through that connection.

Corpay learned about the incident after Klue informed the company. In response, Corpay engaged cybersecurity experts to investigate the scope of the exposure. The investigation also aimed to assess potential impact on affected individuals and to determine appropriate next steps.

Corpay also notified law enforcement as part of its response. Importantly, that notification did not delay the company’s outreach to affected individuals. Corpay confirmed that its own internal networks remained unaffected throughout the incident. The company also reported no disruption to its business operations as a result of the breach.

Who was affected?

The breach may affect individuals connected to Corpay through business relationships. This includes customers, employees of business partners, and individuals associated with companies that work with Corpay or its affiliates. Corpay collects personal information both from direct customers and from individuals tied to companies establishing commercial relationships with the firm.

Corpay has not publicly disclosed a specific number of affected individuals. The company completed its review of impacted individuals on August 28, 2026. Because Corpay operates across multiple business relationships, the affected population could span various industries and geographic locations. There is no indication in the notice that minors were specifically involved.

What Information Was Potentially Exposed?

Corpay’s notice outlines the categories of personal information believed to be involved in this breach. The company emphasized that its review focused on identifying exactly whose data may have been affected. Based on that investigation, certain types of information were confirmed as potentially exposed.

  • Full name
  • Email address
  • Physical address
  • Additional personal information specific to the individual’s relationship with Corpay

Corpay stated that no passwords or authentication credentials were involved in this incident. The company also reported no evidence that customer funds, payment processing, or transaction execution were affected. However, exposure of names and contact details still carries real risk for affected individuals.

For example, attackers often use stolen contact information to launch targeted phishing campaigns. These scams may impersonate Corpay or related companies to trick victims into revealing more sensitive data. In addition, exposed contact details can be combined with information from other breaches to build a more complete profile of a victim, increasing the risk of identity theft or fraud over time.

Because Corpay serves business clients, some affected individuals may not have a direct personal relationship with the company. This means some people could remain unaware they were affected until they receive a notification letter. As a result, staying alert to unexpected communications referencing Corpay or Klue is especially important right now.

What is the company doing?

After learning of the incident, Corpay acted quickly to contain further risk. The company brought in third-party cybersecurity experts to investigate the breach and support remediation efforts. Corpay also stated it took steps to help prevent additional unauthorized activity going forward.

As part of its ongoing response, Corpay reported implementing additional safeguards following the incident. The company also filed a formal notification with the California Attorney General. This filing reflects Corpay’s legal obligation to disclose the breach to state regulators.

In addition, Corpay is offering affected individuals complimentary identity monitoring services through Kroll. These services include credit monitoring, fraud consultation, and identity theft restoration support. Enrollment is available through a dedicated activation portal, and individuals have a limited window to sign up for the free service.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Affected individuals should check their credit reports for any unfamiliar activity. This is one of the simplest ways to catch identity theft early. You can request a free credit report from each of the three major credit bureaus through annualcreditreport.com.

Because fraud can take time to surface, checking your report periodically over the coming months is wise. Look specifically for new accounts, unfamiliar inquiries, or address changes you did not authorize. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Since contact information was exposed, placing a fraud alert on your credit file adds an extra layer of protection. An initial fraud alert lasts one year and requires creditors to verify your identity before opening new accounts. You can request this by contacting any one of the three major credit bureaus.

For stronger protection, you may also consider a credit freeze. This restricts access to your credit file entirely, making it harder for identity thieves to open accounts in your name. Keep in mind that you will need to lift the freeze temporarily whenever you apply for new credit yourself.

Enroll in the Free Kroll Identity Monitoring Services

Corpay is offering complimentary identity monitoring through Kroll to individuals affected by this breach. This service includes credit monitoring, fraud consultation, and identity theft restoration assistance. Because this offer is free, affected individuals should take advantage of it before any stated deadline passes.

To enroll, visit the activation portal referenced in your notification letter. You will need your unique membership number to complete registration. If you have not received a letter but believe you may be affected, contact Corpay directly to confirm your status.

Stay Alert to Phishing Attempts

Because names and contact details were exposed, affected individuals should watch closely for phishing emails or calls. Scammers often use breach events like this one to craft convincing, urgent-sounding messages. These messages may reference Corpay, Klue, or related business relationships to appear legitimate.

Therefore, avoid clicking links or providing personal information in response to unsolicited messages. Instead, verify any suspicious communication by contacting Corpay directly through official channels. When in doubt, it is always safer to independently confirm a request before responding.

Know Your Legal Options

If you received a breach notification letter, you may have options beyond the protective services offered. Many affected individuals choose to consult a data breach attorney to understand their rights. An attorney can help evaluate whether you qualify for compensation related to this incident.

Because data breach laws vary by state, a free case evaluation can clarify your specific situation. This step costs nothing and can provide peace of mind. It also ensures you do not miss any relevant deadlines for pursuing a claim.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Check other recent data breach notifications →