Natco Home Group Data Breach Exposes Social Security Numbers and Payroll Records

Manufacturing data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: August 2026

Natco Home Group, a Rhode Island home furnishings manufacturer, confirmed a data breach in which the aurora threat actor group stole decades of employee and financial records, including Social Security numbers dating back to 1979, payroll data, medical leave records, and financial statements. Affected current and former employees should place a credit freeze, monitor credit reports, and watch for phishing attempts immediately.

CompanyNatco Home Group
IndustryManufacturing
Data Types ExposedSocial Security Numbers, Payroll Records (Pay Stubs, W-2s, W-4s), 401k Records, Drug Test Results, Background Check Reports, Medical Leave Records, Financial Statements and Tax Records, Customer Credit Data
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Natco Home Group Data Breach?

Natco Home Group, a family-owned home furnishings manufacturer based in West Warwick, Rhode Island, confirmed that a threat actor group accessed and stole company data. The group behind the intrusion is known as aurora. This Natco Home Group data breach involved the theft of records spanning the company’s entire corporate history.

The exact discovery date has not been publicly disclosed. However, the company issued breach notifications in August 2026. Investigators found that the stolen dataset included an unencrypted legacy payroll database along with a decade of more recent payroll records. This means the exposure covered both very old and very recent employee information.

As a result, Natco Home Group launched a forensic investigation to determine the full scope of the intrusion. The investigation aimed to identify exactly which systems the attackers reached and which records they copied. Because the compromised data included files going back to 1979, the review process likely took considerable time. In addition, the company had to assess financial and operational records tied to acquisitions and retailer relationships.

Because ransomware groups like aurora often threaten to publish stolen files, the company also had to weigh the risk of public exposure. This is a common tactic among extortion-focused threat actors today. Therefore, understanding this breach requires looking closely at both what was taken and who is affected.

Who Was Affected?

The Natco Home Group data breach appears to primarily affect current and former employees of the company. This includes legacy staff whose records date back decades, as well as workers employed more recently. Because Natco operates facilities across seven US states, affected individuals could be spread across a wide geographic area.

The number of affected individuals has not been publicly confirmed in an official total. However, the stolen records reportedly include 100 to 120 legacy employees from an older payroll system. In addition, a separate payroll dataset covers roughly 700 to 1,000 current and former employees over a ten-year span. Given the timeframes involved, both younger and older workers could be impacted, though there is no indication minors were specifically involved.

Beyond employees, the breach also touched business records tied to major retail partners. This suggests that some third-party business contacts connected to Natco’s operations could also face indirect exposure. Consequently, the breach’s reach may extend beyond just Natco’s own workforce.

What Information Was Potentially Exposed?

The scope of exposed data in this incident is unusually broad. It spans personal employee records, sensitive workplace documentation, and internal financial materials. Below is a summary of the categories confirmed as part of the exfiltrated dataset.

  • Social Security numbers in plaintext for legacy employees dating back to 1979
  • Ten years of ADP payroll data, including pay stubs, W-2s, and W-4s
  • 401k retirement account records
  • Drug test results
  • Background check reports
  • Medical leave records
  • Divisional financial statements and income tax records
  • Customer credit data tied to major retailers
  • Eighteen years of bad-debt reserve calculations
  • Acquisition-related business materials

Given this range of information, the risk to affected individuals is significant. Social Security numbers combined with payroll details create a strong foundation for identity theft. For example, criminals could use this combination to open new credit accounts or file fraudulent tax returns in a victim’s name.

Moreover, the presence of medical leave records and drug test results raises separate privacy concerns. This type of sensitive personal history is not something most people expect to see exposed. As a result, some employees may face reputational or emotional harm, not just financial risk. Meanwhile, the exposure of retailer credit data and financial statements could create fraud risks for business partners as well.

What Is the Company Doing?

In response to the breach, Natco Home Group has acknowledged the incident and issued notifications to affected individuals. This step is a required part of responding to a confirmed data compromise involving personal information. Because the stolen data included Social Security numbers, notification obligations likely extend across multiple states where employees reside.

Following discovery, the company also appears to have undertaken efforts to assess the full scope of the intrusion. This includes reviewing which historical and current systems the attackers accessed. In addition, organizations facing this kind of breach typically work to secure their networks against further unauthorized access. Although specific protective service offerings have not been publicly detailed, affected individuals should watch for official notification letters that outline any credit monitoring or identity protection support.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should request copies of their credit reports and review them for unfamiliar activity. Because Social Security numbers were exposed, this step is especially important. You can request free credit reports from each of the three major credit bureaus.

In addition, consider checking your reports every few months rather than just once. This helps you catch new fraudulent accounts quickly. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Credit Freeze or Fraud Alert

Because plaintext Social Security numbers were involved, a credit freeze is a strong protective option. A freeze blocks new creditors from accessing your credit file, which makes it harder for identity thieves to open accounts in your name. Alternatively, a fraud alert requires businesses to verify your identity before extending credit.

To place a freeze, you must contact each of the three major credit bureaus separately. This process is free and can be lifted temporarily whenever you need to apply for credit yourself. Given the age range of exposed records, even individuals who left the company decades ago should consider this step.

Watch for Phishing and Scam Attempts

Following a breach like this, scammers often send phishing emails or texts pretending to be from the company involved. Therefore, be cautious of unexpected messages asking you to click links or confirm personal details. Legitimate breach notifications generally will not ask for sensitive information over email.

Instead, verify any suspicious communication by contacting the company directly through a known phone number or website. In addition, avoid downloading attachments from unfamiliar senders. This simple habit can prevent a second wave of harm following the original breach.

Review Health and Employment-Related Records

Because medical leave records, drug test results, and background checks were exposed, affected individuals should also monitor for unusual activity tied to their health or employment history. For example, watch for unexpected insurance claims or unfamiliar medical bills. This can be a sign of medical identity misuse.

Furthermore, keep an eye on any communications referencing employment verification requests you did not initiate. If something feels off, contact the relevant provider or agency to confirm. Taking these extra steps helps limit long-term harm from this deeply personal category of exposed data.

Consult a Data Breach Attorney

Given the scale and sensitivity of the data involved, affected individuals may want to speak with a data breach attorney. An attorney can help evaluate whether you qualify for compensation through a potential class action. Many offer free case evaluations, so there is little downside to asking questions.

Because deadlines for filing claims can vary by state, it is wise to act sooner rather than later. Waiting too long could limit your legal options. A quick consultation can clarify what steps make sense for your specific situation.



Related Data Breaches

Check other recent data breach notifications →