NFI North, Inc. confirmed a data breach discovered in September 2025 that exposed the names, Social Security numbers, driver’s license numbers, financial account information, and medical records of 49,540 individuals. The nonprofit serves clients in New Hampshire and Maine. Affected individuals should place a credit freeze and monitor their accounts for suspicious activity immediately.
| Company | NFI North, Inc. |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Names, Home Addresses, Dates of Birth, Social Security Numbers, Driver’s License Numbers, Financial Account Information, Medical Information, Health Insurance Information |
| People Affected | 49,540 individuals |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the NFI North Data Breach?
NFI North, Inc. has confirmed a data breach that compromised the personal and health information of tens of thousands of people. The nonprofit organization delivers mental health, behavioral, and educational support services across New Hampshire and Maine. This NFI North data breach ranks among the larger healthcare-related incidents reported this year.
According to the organization’s breach notice, suspicious activity was first identified within its computer network in September 2025. NFI North then brought in outside cybersecurity professionals to investigate the scope of the intrusion. As a result, the review process took many months to complete.
The investigation and data review did not conclude until July 2026. At that point, NFI North confirmed which data elements had actually been accessed or acquired by the unauthorized party. Because the forensic process was so lengthy, affected individuals were not notified until nearly a year after the initial intrusion.
NFI North has since implemented additional technical safeguards to prevent a similar incident from happening again. However, the organization’s public notice does not name the attacker or describe the specific method used to breach the network. This means many details about how the intrusion occurred remain unknown to the public.
Who was affected?
The breach affects 49,540 individuals, according to NFI North’s substitute notice filed with federal regulators. This group likely includes current and former clients who received mental health, behavioral, or educational services through the organization. It may also include employees whose personal records were stored on the affected systems.
Because NFI North operates programs in both New Hampshire and Maine, the affected population is likely spread across both states. Given the nature of the services provided, some affected individuals could be minors who received educational or behavioral support through the organization’s programs. This raises additional concerns, since stolen data belonging to children can go undetected for years before misuse is discovered.
NFI North has not broken down the affected population by category, such as clients versus staff. Therefore, anyone who received services from or worked with the organization should assume they could be included until they receive official confirmation.
What Information Was Potentially Exposed?
The data review confirmed that a wide range of sensitive personal and health information was compromised in this incident. This combination of data types makes the exposure particularly serious for those affected.
- Full names
- Home addresses
- Dates of birth
- Social Security numbers
- Driver’s license numbers
- Financial account information
- Medical information
- Health insurance information
This mix of identifiers creates significant risk for identity theft. For example, a criminal armed with a Social Security number, birth date, and address has enough information to open new credit accounts or file fraudulent tax returns. Financial account details could also allow direct access to existing bank or credit accounts.
In addition, the exposure of medical and health insurance information raises the risk of medical identity theft. Someone could use stolen health insurance details to obtain treatment or prescriptions under another person’s name. As a result, victims might later find inaccurate information in their own medical records, which can complicate future care.
What is the company doing?
In response to the breach, NFI North engaged third-party cybersecurity professionals to investigate the incident thoroughly. The organization also implemented additional technical safeguards designed to reduce the chance of a repeat incident. Notification letters have been sent to individuals whose information was confirmed to be involved.
NFI North also filed a formal breach report with the U.S. Department of Health and Human Services Office for Civil Rights, as required under federal health privacy law. This filing is what first made details of the incident public. Going forward, affected individuals should watch for any additional updates from NFI North regarding protective services or further findings.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Anyone whose Social Security number was exposed in this breach should strongly consider placing a fraud alert or credit freeze. A credit freeze restricts access to your credit file, which makes it much harder for criminals to open new accounts in your name. This is one of the strongest protections available to consumers.
To set up a freeze, you must contact each of the three major credit bureaus separately. Because freezes are free and can be lifted temporarily when needed, there is little downside to using this protection. A fraud alert offers a lighter form of protection and only requires contacting one bureau, which will notify the others.
Monitor Your Credit Reports Closely
Affected individuals should also review their credit reports regularly for signs of unauthorized activity. You can request a free copy of your report from each major bureau through AnnualCreditReport.com. Checking these reports periodically helps catch fraudulent accounts before they cause lasting damage.
If you notice unfamiliar accounts, inquiries, or addresses on your report, dispute them immediately. In addition, consider signing up for a credit monitoring service if one is offered, since it can alert you to changes in real time. Acting quickly after spotting suspicious activity often limits the financial harm.
Watch for Phishing and Scam Attempts
Because your personal information may now be in criminal hands, expect an increase in phishing emails, texts, and phone calls. Scammers often use details from breaches like this one to make their messages seem more convincing. For example, they may reference your real name or address to gain your trust.
Never click on links or share personal information in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website. This simple habit can prevent many follow-on scams that target breach victims specifically.
Protect Against Medical Identity Theft
Since medical and health insurance information was exposed, affected individuals should also review their medical records and insurance statements closely. Look for any services, prescriptions, or claims that you do not recognize. If something looks unfamiliar, contact your insurance provider or medical facility right away.
Correcting fraudulent medical records can be a slow and frustrating process. However, catching errors early makes the correction process much easier. Consider requesting a copy of your medical records periodically to confirm their accuracy going forward.
Consider Consulting a Data Breach Attorney
Given the scope and sensitivity of the information exposed, affected individuals may want to speak with an attorney who focuses on data breach cases. A free consultation can help you understand your legal options. This is especially worth exploring if you experience financial losses connected to this incident.
An attorney can also help you determine whether you qualify to join any legal action related to the NFI North data breach. Because deadlines for filing claims can be limited, it’s wise to seek guidance sooner rather than later. This step costs nothing to explore and may help you recover losses down the road.
