What Happened in the National Alliance for Direct Support Professionals Data Breach?
The National Alliance for Direct Support Professionals, known as NADSP, is a nonprofit group that works with direct support professionals across the country. In early 2026, the organization found that someone had broken into its email system without permission. This NADSP data breach put sensitive personal records at risk for an unknown number of people connected to the organization.
According to a filing with the New Hampshire Attorney General’s Office, NADSP found the intrusion in its email environment in January 2026. As soon as staff spotted the problem, they cut off the compromised accounts. They then brought in outside cybersecurity specialists to help contain the damage and shore up their systems against further attacks.
Because email inboxes often hold years of scattered attachments and messages, figuring out exactly whose information sat inside the compromised accounts took a long time. NADSP hired a forensic firm to dig through the affected mailboxes. That firm concluded that an intruder had likely viewed or copied files stored within the email environment.
The review process dragged on for months. NADSP did not finish identifying every affected person until July 2026, nearly six months after the initial discovery. Only then could the organization put together a final list of who needed to be told their information may have been exposed.
This kind of delay is common after email-based break-ins. Investigators must trace every message and attachment that passed through a hacked account. As a result, notification often lags well behind the moment a breach is first discovered.
Who was affected?
NADSP’s notice describes the affected group broadly as clients connected to the organization. Because NADSP serves direct support professionals and related programs nationwide, the exposed data likely touches people across several states, not just one region.
The New Hampshire filing named just a single resident of that state as impacted. However, this number only reflects New Hampshire’s portion of the incident. The full nationwide count of affected individuals has not been publicly disclosed, so the true scope may be considerably larger.
Given that NADSP works with direct support professionals, program participants and staff records may also be part of the exposed data. Nonprofits like this often store financial and identity records for a mix of members, employees, and program participants, meaning the population affected could span multiple categories of people.
What Information Was Potentially Exposed?
NADSP’s breach notice lists several categories of sensitive data that may have been accessed. This is exactly the kind of information identity thieves look for, because it can be used to open new accounts or drain existing ones.
- Social Security numbers
- Driver’s license numbers
- Financial account information
Because Social Security numbers were involved, affected individuals face a heightened risk of long-term identity theft. Criminals can use a stolen Social Security number to open credit cards, file fraudulent tax returns, or apply for loans in someone else’s name. This kind of fraud can be difficult to detect right away and even harder to fully undo.
In addition, the exposure of driver’s license numbers and financial account details raises the risk of direct financial fraud. Thieves could use financial account information to attempt unauthorized withdrawals or transfers. Meanwhile, a stolen driver’s license number can support fraudulent identification, making it easier for a criminal to impersonate the victim in other schemes.
What is the company doing?
Once NADSP discovered the unauthorized access, it moved to isolate the affected email environment right away. Internal IT staff worked alongside outside cybersecurity experts to secure the systems and stop any ongoing access by the intruder.
After containment, NADSP shifted its focus to figuring out exactly what happened and who was affected. The organization brought in a third-party forensic firm to investigate the scope of the intrusion in detail. This investigation ultimately confirmed that an unauthorized party had likely viewed or downloaded certain files.
Following the investigation, NADSP notified state regulators, including the New Hampshire Attorney General’s Office, as required by law. The organization also mailed notification letters to affected individuals in July 2026. As part of its response, NADSP is offering 12 months of complimentary credit monitoring and identity theft protection through Cyberscout, a TransUnion company.
What Should Affected Individuals Do?
Enroll in Credit Monitoring Promptly
If you received a letter from NADSP, sign up for the free credit monitoring and identity theft protection services as soon as possible. These services can flag suspicious activity on your credit file before it spirals into a bigger problem.
Because enrollment deadlines often apply, check your letter carefully for the exact cutoff date. Waiting too long could mean missing out on this protection entirely, so it’s worth acting within the first few weeks after you receive notice.
Consider a Fraud Alert or Credit Freeze
Since Social Security numbers and financial account information were exposed, placing a fraud alert or credit freeze is a smart precaution. A freeze blocks new creditors from accessing your credit file, which makes it much harder for a thief to open accounts in your name.
You can contact Equifax, Experian, and TransUnion directly to request either option. A fraud alert is easier to set up and lasts about a year, while a freeze offers stronger protection but requires you to lift it temporarily whenever you apply for new credit yourself.
Watch Your Financial Accounts Closely
Because financial account information may have been exposed, review your bank and credit card statements regularly for unfamiliar charges or withdrawals. Catching fraud early often makes it easier to reverse the damage.
In addition, consider setting up account alerts through your bank’s mobile app or website. These alerts can notify you instantly of new transactions, so you don’t have to rely solely on remembering to check your statements manually.
Stay Alert for Phishing Attempts
After a breach like this, scammers sometimes use the stolen information to craft convincing phishing emails or phone calls. Be cautious of any message claiming to be from NADSP, your bank, or a government agency that asks for personal details.
Instead of clicking links in unexpected messages, go directly to the official website or phone number you already trust. This simple habit can prevent you from handing over even more information to a scammer posing as a legitimate organization.
Request Your Free Credit Reports
You’re entitled to a free copy of your credit report from each of the three major bureaus through annualcreditreport.com. Reviewing these reports lets you spot accounts or inquiries you don’t recognize.
If you notice anything suspicious, report it right away to the FTC and your state Attorney General’s office. Documenting any signs of fraud early can also help if you later decide to pursue legal action related to this breach.
