Families United Network, a Pennsylvania child welfare nonprofit, says an unauthorized person accessed and downloaded one employee’s email account between December 19 and December 22, 2025. Exposed data may include names, Social Security numbers, driver’s license numbers, financial account information and medical records. Clients, families and possibly employees are affected, though the total number has not been disclosed. Affected individuals should watch for a notice letter and consider a credit freeze right away.
| Company | Families United Network |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Names, Dates of Birth, Driver’s License Numbers, State Identification Numbers, Social Security Numbers, Financial Account Information, Health Insurance Information, Medical Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Email Account Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Families United Network Data Breach?
Families United Network, a Pennsylvania nonprofit that supports children and families through foster care, adoption and related services, has disclosed a data security incident. The organization says an unauthorized party broke into a single employee’s email account and downloaded its contents. This Families United Network data breach raises serious concerns because email accounts at social service agencies often hold years of sensitive case files.
According to the organization’s notice, the unauthorized access happened between December 19 and December 22, 2025. In other words, unauthorized access to its network occurred in December 2025. The notice does not explain how the intruder got into the account, and it does not name any individual or group responsible for the intrusion.
Because the attacker downloaded the full contents of the mailbox, Families United Network then launched a review to figure out exactly what the account contained. This process took many months, which is common when a single mailbox holds forms, billing records, case documents and other paperwork tied to many different people. The organization only began notifying affected individuals around October 2026, long after the initial intrusion.
Families United Network says it has found no evidence that anyone has actually misused the exposed information. However, the review confirmed that sensitive personal and medical details were present in the account. As a result, the organization decided that formal notice letters were necessary for everyone whose data appeared in the files.
Who was affected?
The people connected to this incident include clients of Families United Network. This likely covers children and families involved in foster care, adoption or peer support programs, along with their caregivers. Because the organization works directly with minors, some of the exposed records may belong to children and teenagers rather than only adults.
The exact number of people affected has not been publicly disclosed. Families United Network’s notice does not include a total count, and no breakdown by state has been released either. The notice does include state-specific language for residents of the District of Columbia, Maryland, New Mexico, New York, North Carolina and Rhode Island, which suggests the breach may reach beyond Pennsylvania. This is a standard feature of multi-state breach notices, though, so it does not confirm exact numbers in each location.
Employees may also be affected, since the incident involved an internal email account that could have contained staff records as well as client information. Anyone who has had direct dealings with the organization, including foster parents, adoptive parents, and former clients, should watch for a notification letter in the mail.
What Information Was Potentially Exposed?
The specific data exposed in this breach can vary from person to person, based on what appeared in the compromised mailbox. Families United Network’s notice lists several categories of information that were present in the affected files. Because the content varies by individual, people should read their own letter carefully for the exact details that apply to them.
- Full names
- Dates of birth
- Driver’s license numbers
- State identification numbers
- Social Security numbers
- Financial account information
- Health insurance information
- Medical information
This combination of data is particularly concerning. For example, a Social Security number paired with a date of birth and driver’s license number gives criminals nearly everything needed to open new credit accounts in someone else’s name. Financial account details can additionally allow direct access to existing bank or payment accounts.
Medical and health insurance information adds another layer of risk. Criminals can use this data to file fraudulent insurance claims or obtain medical treatment under someone else’s identity. Because many of the people connected to Families United Network are children, any misuse of their information might not surface for years, until they apply for credit or loans as adults.
What is the company doing?
Once Families United Network discovered the suspicious activity, it says it moved to confirm the security of its systems. The organization then conducted an investigation to determine exactly what happened and which files were involved. This process included a detailed review of the downloaded email contents to identify whose information appeared in them.
Following the investigation, Families United Network reports that it reviewed its existing security policies. It also says it reinforced data-safeguarding practices with its staff. The organization has set up a dedicated assistance line for people with questions, available on weekdays during extended daytime hours Eastern Time.
The notice does not state whether Families United Network is offering credit monitoring or identity protection enrollment. Instead, it points affected individuals toward general protective steps, such as reviewing account statements and placing fraud alerts. Because the organization’s own notice is the basis for these facts, this response should be read as what the nonprofit itself has disclosed, rather than as independently confirmed outside reporting.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone connected to Families United Network should start checking their credit reports regularly. You can get free reports from all three bureaus at annualcreditreport.com. Look for accounts you do not recognize, unfamiliar inquiries, or sudden changes to your credit profile.
Because this breach included Social Security numbers and driver’s license numbers, the risk of someone opening new accounts in your name is real. Regular monitoring helps you catch fraudulent activity early, before it causes lasting financial damage. Consider checking reports from each bureau every few months instead of only once.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers and financial account information were involved, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before approving new credit. A credit freeze goes further and blocks new accounts from being opened entirely until you lift it.
You can set up a freeze directly with Equifax, Experian and TransUnion. Doing so is free and will not hurt your existing credit score. This step is especially important for children’s records, since fraud on a minor’s identity can go unnoticed for years.
Protect Against Medical and Insurance Fraud
Because health insurance and medical information were included in this breach, affected individuals should review their insurance statements carefully. Look for any services, prescriptions or claims you do not recognize. If you spot anything suspicious, contact your health plan immediately.
In addition, request an itemized statement from your insurer if you ever suspect a false claim was filed. Medical identity theft can be harder to untangle than financial fraud, since it can affect your medical records as well as your wallet. Acting quickly limits the damage and helps correct your records sooner.
Stay Alert for Phishing Attempts
Scammers often use breach information to craft convincing phishing emails, texts or phone calls. Because this incident involved an email account, affected individuals should be especially cautious of messages that reference Families United Network or related services. Never share personal details with unsolicited contacts.
Instead, verify any request by contacting the organization directly through a known phone number or website. If a message pressures you to act immediately, treat that as a warning sign. Taking a moment to confirm legitimacy can prevent a costly mistake.
Know Your Legal Options
If you received a notice confirming your Social Security number, medical information or financial details were involved, you may have legal options worth exploring. Organizations that hold sensitive data are expected to protect it, and failing to do so can lead to legal accountability. Consulting with a data breach attorney can help you understand whether you qualify for compensation.
Many attorneys offer free case evaluations, so there is little downside to asking questions. This is especially worth considering if you later discover unauthorized activity tied to your personal information. Acting sooner rather than later can also help preserve your legal rights under applicable deadlines.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
