What Happened in the Knights of Columbus Data Breach?
Knights of Columbus has begun notifying members and applicants that their personal information may have been exposed through a security incident tied to a vendor used for its insurance underwriting process. The organization relies on AutoAPS, LLC to retrieve medical records in support of underwriting decisions. A separate hosting vendor used by AutoAPS is where the trouble actually started.
According to a notice filed with the Massachusetts Attorney General’s office, that hosting vendor spotted unusual network activity in December 2025. As a result, the vendor moved to contain the situation and brought in outside cybersecurity specialists to investigate further. This means the breach did not originate inside Knights of Columbus’s own systems, but within a vendor two steps removed from the organization.
The forensic review could not definitively confirm whether anyone actually viewed or took data during the intrusion. Because of that uncertainty, AutoAPS conducted its own detailed review of the files stored in the affected environment. This document-by-document analysis was necessary to figure out which individuals might have had information involved, since the initial investigation left that question unresolved.
Knights of Columbus says it first learned of the incident in May 2026, months after the hosting vendor’s initial discovery. That gap reflects how long a multi-layered vendor investigation can take before the ultimate client organization can identify affected members. The notice was then filed with Massachusetts regulators in early August 2026, marking the point at which the public first learned key details of the incident.
Who was affected?
The individuals affected by this incident are described as clients of Knights of Columbus, which likely includes both current members and insurance applicants whose underwriting files passed through AutoAPS. Because underwriting often involves collecting medical history from applicants, this population may include people who never had direct contact with either AutoAPS or its hosting vendor.
The notice does not include a specific total count of affected individuals. Therefore, the true scope of this breach has not been publicly disclosed at this time. Given that Knights of Columbus operates across the country, the affected group could span multiple states, though the notification referenced here was filed specifically with Massachusetts regulators.
What Information Was Potentially Exposed?
The notification letter states that the specific data involved varied depending on the document and the individual. This means not every affected person had the same categories of information exposed. However, because the incident touched underwriting-related files, the data at risk likely included a mix of identifying and medical details.
- Full names
- Medical history or health-related records used in underwriting
- Other application or underwriting-related documentation
- Additional personal identifiers that may vary by individual, as described in the notice
Because underwriting files often combine identity information with medical history, this type of breach carries more risk than a breach involving only basic contact details. Medical data mixed with personal identifiers can be used to commit both identity theft and medical fraud, which can be harder to detect and unwind than ordinary credit card fraud.
In addition, exposed medical information can lead to consequences beyond financial loss, such as inaccurate entries in a victim’s medical records if someone else uses their identity to obtain treatment. As a result, affected individuals should treat this incident seriously even though the exact data exposed has not been fully itemized in the public notice.
What is the company doing?
In response to the incident, Knights of Columbus is notifying individuals whose information may have been involved and is offering a complimentary membership in IDX identity protection services. This includes credit monitoring and CyberScan monitoring, which is designed to look for a person’s information circulating on the dark web.
Beyond notification, the organization is relying on the forensic work already completed by AutoAPS and its hosting vendor to understand the scope of the incident. Because the investigation could not conclusively rule out unauthorized access, Knights of Columbus chose to notify affected individuals out of caution. This approach reflects a broader trend where organizations treat potential exposure as sufficient reason to act, even without absolute confirmation that data was viewed or taken.
Ongoing vendor oversight
Since this incident originated with a vendor’s vendor, Knights of Columbus will likely need to reassess how it monitors the security practices of every company in its underwriting supply chain. This kind of layered vendor relationship can make it harder to quickly identify a breach’s true scope, which is exactly what happened here.
What Should Affected Individuals Do?
Enroll in the Offered Identity Protection Service
Individuals who received a notice should sign up for the complimentary IDX identity protection membership described in the letter. This service includes both credit monitoring and CyberScan monitoring, which can flag suspicious activity involving your personal details.
Because this monitoring is offered at no cost, there is little downside to enrolling promptly. Signing up early gives the service more time to detect unusual activity before it turns into a larger problem.
Place a Fraud Alert or Credit Freeze
Given that underwriting records often include sensitive personal details, affected individuals should consider placing a fraud alert or a full security freeze with Equifax, Experian, and TransUnion. A freeze restricts new accounts from being opened in your name without your explicit approval.
This step is especially important when there is uncertainty about exactly what was exposed. Because the notice indicates that the data involved varied by individual, a freeze offers broad protection regardless of which specific details were part of your file.
Watch for Signs of Medical Fraud
Because the breach involved a vendor that retrieves medical records for underwriting, affected individuals should review any health insurance statements or medical bills for unfamiliar charges. Medical identity theft can be harder to spot than financial fraud since it may not show up on a standard credit report.
If you notice unfamiliar providers, treatments, or claims on your insurance statements, contact your insurer immediately. Reporting these issues quickly can help prevent inaccurate information from becoming part of your permanent medical record.
Monitor Accounts and Credit Reports Regularly
Regularly reviewing your bank and credit card statements can help you catch unauthorized activity early. In addition, you can request a free copy of your credit report at annualcreditreport.com to check for accounts you don’t recognize.
Doing this consistently, rather than just once, matters because fraudulent activity tied to a breach can surface months or even years later. If you spot anything suspicious, report it to your state Attorney General and to the Federal Trade Commission through identitytheft.gov.
Stay Alert for Phishing Attempts
Scammers often use news of a data breach to send convincing phishing emails or text messages pretending to be from the breached organization. Be cautious of any message asking you to click a link or provide personal information related to this incident.
Instead of clicking links in unsolicited messages, go directly to the official Knights of Columbus website or contact them through a verified phone number. This simple habit can prevent you from accidentally handing over information to a scammer posing as a legitimate representative.
