Impact Melanoma Inc. Data Breach Exposes Names and Social Security Numbers

Published: 2 October 2026
Non-profit data breach illustration
Breach Discovery: May 2026Breach Notification: September 2026

Impact Melanoma Inc. discovered unauthorized access to employee email accounts in May 2026 and confirmed in September 2026 that one individual’s name and Social Security number may have been exposed. The nonprofit has only publicly confirmed one affected person, via a New Hampshire filing, though more notices may exist elsewhere. Affected individuals should enroll in the offered credit monitoring immediately and consider a credit freeze.

CompanyImpact Melanoma Inc.
IndustryNon-profit
Data Types ExposedFull Name, Social Security Number
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Email Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Impact Melanoma Data Breach?

Impact Melanoma Inc. has disclosed a data security incident tied to unauthorized access of employee email accounts. The organization, which focuses on melanoma prevention and patient support nationwide, said the intrusion gave an unknown party the ability to view messages and attachments inside two employee inboxes. As a result, at least one person’s full name and Social Security number may have been exposed.

According to the regulatory filing, unauthorized access to its network occurred in May 2026. Impact Melanoma says it detected the activity and moved to contain it quickly. However, the organization has not explained how the intruder got into the accounts in the first place. It is unclear whether phishing, a stolen password, or another method was used, and no attacker has been publicly identified.

Because email inboxes often contain years of messages, figuring out exactly whose data was affected took considerable time. Impact Melanoma brought in outside cybersecurity professionals to review the contents of the compromised accounts. That manual document review concluded in September 2026, when the organization confirmed that one individual’s personal information had likely been accessed or acquired before the breach was detected.

The gap between detection and confirmation spanned roughly four months. This kind of delay is common in email compromise cases, since every file and message has to be checked individually. Still, the timeline means affected individuals went a long stretch without knowing their information might be at risk.

Who was affected?

The people affected by this incident could include Impact Melanoma employees, donors, volunteers, or vendors whose information was stored in the two compromised inboxes. Nonprofit organizations frequently keep a mix of personnel records, donor files, and vendor paperwork inside email systems, which makes any single mailbox compromise potentially far-reaching.

So far, Impact Melanoma has only confirmed one affected individual, based on a filing submitted to the New Hampshire Attorney General. That number reflects a single state notification, not a nationwide total. The organization has not published how many people, if any, were notified in other states.

Because Impact Melanoma operates on a national scale, it is possible additional people outside New Hampshire received similar notices or will receive them later. The affected individual’s age and relationship to the organization have not been publicly disclosed. As a result, it remains unclear whether minors or other vulnerable groups are involved.

What Information Was Potentially Exposed?

The regulatory notice identifies a narrow but sensitive combination of data tied to the one confirmed individual. This pairing is often enough on its own to cause serious harm if misused.

  • Full name
  • Social Security number

Impact Melanoma has not stated that financial account numbers, medical records, or login credentials were included in the exposure. No other data categories should be assumed at this time. The organization has limited its public disclosure strictly to the two categories above.

Even so, a name paired with a Social Security number creates real risk. This combination is frequently used by criminals to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Because Social Security numbers rarely change, the exposure window for misuse can last for years rather than months.

In addition, stolen data is not always used right away. Criminals sometimes hold onto information or sell it on dark web marketplaces long after a breach occurs. This means the absence of confirmed fraud today does not guarantee safety in the future, so ongoing vigilance matters even if nothing suspicious has happened yet.

What is the company doing?

Impact Melanoma says it contained the unauthorized email activity after detecting it and launched an investigation with outside cybersecurity specialists. The organization also conducted the lengthy manual review needed to determine whose information was involved. Written notice to the affected individual was scheduled to go out in September 2026.

As part of its response, Impact Melanoma filed formal notification with the New Hampshire Attorney General’s Consumer Protection Bureau. This filing is the source of the only publicly confirmed detail about the breach’s scope. Other state regulators may have received similar notices that are not yet publicly available.

Impact Melanoma is offering the affected individual 12 months of complimentary credit monitoring and identity protection services through IDX. The organization also says it continues to evaluate and strengthen its data security practices going forward. Affected individuals are encouraged to review financial statements regularly and use the resources outlined in their notification letter.

What Should Affected Individuals Do?

Enroll in Credit Monitoring Right Away

If you received a notice from Impact Melanoma, sign up for the complimentary credit monitoring and identity protection services as soon as possible. These services can alert you to new accounts or inquiries made in your name. Enrolling early gives you the longest possible window of protection.

Keep a copy of your notification letter in a safe place. You may need it later if you have to prove you were affected by this specific incident. This documentation can also support any future legal claim related to the breach.

Place a Fraud Alert or Credit Freeze

Because a Social Security number was involved, consider placing a one-year fraud alert or a credit freeze on your file. Both options are free and can be requested through any of the three nationwide credit bureaus. A freeze blocks most new credit applications until you choose to lift it.

This step matters because Social Security numbers do not expire or reset. As a result, the risk of misuse can stretch far beyond the 12-month monitoring period offered by the organization. Many affected individuals choose to renew a fraud alert annually for extra peace of mind.

Monitor Your Accounts and Credit Reports Closely

Review your bank, credit card, and insurance statements regularly for charges or accounts you do not recognize. You are entitled to a free credit report from each nationwide bureau every 12 months through annualcreditreport.com. Checking these reports can help you catch unauthorized activity early.

In addition, watch for new accounts, hard inquiries, or address changes you did not make. If you spot anything suspicious, report it immediately to the credit bureau and consider filing a report with the Federal Trade Commission at identitytheft.gov.

Stay Alert for Phishing Attempts

Scammers often follow data breaches with phishing emails, calls, or texts designed to look like they come from the breached organization. Be cautious of any message referencing Impact Melanoma, your Social Security number, or your credit standing. Never click links or share information in response to unexpected outreach.

Instead, contact the organization directly using a phone number or website you find independently. This protects you from secondary scams that piggyback on real breach notifications. Because phishing attempts can arrive months after a breach, staying alert should become a long-term habit, not a one-time check.

Consider Speaking With a Data Breach Attorney

If your Social Security number was exposed, you may have legal options, especially if the organization took an extended time to notify you. A data breach attorney can review your notification letter and explain what rights may apply to your situation. Many offer free consultations with no upfront cost.

Because claims like this are often pursued collectively, joining a group of affected individuals can reduce the burden on any one person. This approach can also increase leverage in holding an organization accountable for its data security practices. Consulting an attorney costs nothing and can clarify your options quickly.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Browse all recent data breaches →