What Happened in the CB Squared Services Data Breach?
CB Squared Services, Inc. runs a group of Jiffy Lube franchise locations spread across Virginia and Maryland from its base in Fredericksburg, Virginia. The company has told regulators that an intruder broke into its computer network and walked away with files containing sensitive customer information. This CB Squared Services data breach centers on stolen names and Social Security numbers, a combination that creates serious identity theft risk for anyone affected.
Records filed with the New Hampshire Attorney General show that the unauthorized network access happened between April 2026 and May 2026. During that window, someone outside the company copied files off CB Squared’s systems without permission. The company has not said publicly how the intruder first broke in, and it has not released a nationwide total of how many people were affected beyond the single New Hampshire resident named in its state filing.
Once CB Squared spotted unusual activity on its network, it moved to lock down its systems and started an internal review. The company then brought in outside cybersecurity specialists who focus on incidents like this one. That forensic team spent weeks combing through the stolen files before confirming, in June 2026, exactly whose information had been taken and what it contained.
This lag between the original intrusion and the final confirmation of exposed data is fairly typical in breach investigations. Forensic teams often need to sort through large volumes of files before they can say with confidence which records were touched. As a result, affected individuals sometimes wait weeks or months to learn the full scope of what happened to their personal data.
Who was affected?
The people affected by this breach are customers of CB Squared’s Jiffy Lube service locations. Because the company runs multiple stores under one centralized computer system, a single network intrusion can reach customer records tied to many different physical locations at once. This is a common risk for franchise operators that rely on shared back-end systems across a regional footprint.
CB Squared has not disclosed a total victim count covering its full customer base. Its regulatory filing in New Hampshire addressed only one resident of that state, which suggests the company is filing separate notices as required in each state where affected individuals live. Therefore, the true nationwide number could be considerably higher than what has been made public so far. Anyone who used a CB Squared-operated Jiffy Lube location in Virginia or Maryland during the relevant period should watch their mail for a notification letter.
What Information Was Potentially Exposed?
According to CB Squared’s own notification, the files taken during the intrusion contained two specific categories of personal data. Both were confirmed by the company’s forensic investigation rather than assumed from the nature of the attack.
- Full names
- Social Security numbers
This pairing of data is especially dangerous because a name combined with a Social Security number is often all a criminal needs to commit serious fraud. With these two pieces of information, someone could open new credit card accounts, apply for loans, or file a fraudulent tax return in a victim’s name. Financial institutions and government agencies frequently treat this combination as sufficient proof of identity, which is exactly what makes it so valuable to criminals.
In addition to immediate financial fraud, stolen Social Security numbers carry a long tail of risk. Criminals often sell this kind of data on dark web marketplaces, where other bad actors can buy and misuse it years after the original breach. Because a Social Security number cannot simply be changed like a password, victims may need to stay alert for suspicious activity for a long time after receiving their notification letter.
What is the company doing?
After discovering the suspicious activity, CB Squared secured its network and brought in a specialized cybersecurity firm to investigate. This response allowed the company to determine both the timeline of the intrusion and exactly what data the intruder had copied. CB Squared has also stated that it has taken additional steps to strengthen its network security since the breach occurred.
For affected individuals, CB Squared is offering a complimentary membership to Epiq Privacy Solutions ID 3B Credit Monitoring. The company has also set up a dedicated, toll-free call center so people can ask questions and learn about the protective resources available to them. These measures mirror standard practice for companies responding to a confirmed exposure of Social Security numbers.
What Should Affected Individuals Do?
Monitor Your Credit Reports
If you received a notification letter from CB Squared, start by requesting your free credit reports from Equifax, Experian, and TransUnion through annualcreditreport.com. Reviewing these reports lets you spot new accounts or inquiries you did not authorize. Because Social Security numbers were involved, this step deserves your immediate attention rather than being put off.
In addition, consider checking your reports every few months going forward rather than just once. Identity thieves sometimes wait months or even years before using stolen data, so a single check right after notification is not enough. Staying consistent with this habit makes it far more likely you will catch fraudulent activity early.
Consider a Fraud Alert or Credit Freeze
Because your Social Security number may have been exposed, placing a fraud alert or credit freeze on your credit files is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name, while a credit freeze blocks new accounts from being opened altogether. Both options are free to set up with each of the three major credit bureaus.
A credit freeze offers stronger protection but requires you to lift it temporarily whenever you apply for new credit yourself. For most people dealing with a breach involving Social Security numbers, the extra step is worth the added security. You can request a freeze online, by phone, or by mail with each bureau separately.
Enroll in Credit Monitoring and Watch for Phishing
Since CB Squared is offering a complimentary membership to Epiq Privacy Solutions ID 3B Credit Monitoring, affected individuals should take advantage of this free service right away. Credit monitoring can alert you quickly if someone tries to open an account using your information. This early warning gives you a chance to act before serious damage occurs.
At the same time, stay alert for phishing attempts that may follow a breach like this one. Scammers often send emails or texts pretending to be from the breached company, asking victims to click a link or share personal details. Always verify unexpected messages directly through a company’s official phone number instead of clicking links in an email.
Report Suspected Identity Theft Promptly
If you notice unfamiliar charges, unexpected credit inquiries, or any other sign of misuse, report it to the Federal Trade Commission at identitytheft.gov without delay. This site helps you create a personalized recovery plan based on your specific situation. Acting quickly can limit the financial and credit damage that identity theft causes.
You should also consider speaking with a data breach attorney about your legal options. Many attorneys offer free case evaluations and can help you understand whether you qualify for compensation. Because deadlines for filing claims can be limited, reaching out sooner rather than later is generally the safer choice.
