What Happened in the Operation PAR Data Breach?
Operation PAR, a Pinellas Park, Florida-based provider of addiction treatment and mental health services, has confirmed a major data breach. The organization discovered unauthorized activity within its computer network in June 2025. As a result, sensitive personal and medical information belonging to current and former clients was exposed.
According to the notification, Operation PAR identified suspicious activity on its systems and moved quickly to secure its network. However, determining the full scope of the intrusion took considerable time. It took a full year, until June 2026, for the organization to confirm that the compromised files actually contained personal and protected health information.
The delay suggests a lengthy and complex forensic investigation. Because health records often sit alongside financial and identifying data, investigators typically must review enormous volumes of files before confirming exactly whose information was affected. This process explains why notification did not happen until roughly a year after discovery.
Although Operation PAR’s notification letters do not name an attacker, evidence points to the Worldleaks threat group as being responsible. This group added Operation PAR to its dark web leak site in July 2025 and later published the stolen data online. This pattern is consistent with extortion-style attacks, where hackers steal files and threaten public release unless a ransom is paid.
Who Was Affected?
The breach affected 145,714 individuals, based on the notification issued by Operation PAR. These individuals include both current and former clients who received addiction treatment or mental health services through the organization.
Because Operation PAR provides substance use disorder treatment, this breach carries an added layer of sensitivity. Records tied to addiction treatment can be more damaging if exposed than typical medical records, given the stigma some individuals still face. In addition, the population affected likely spans a wide age range and geographic area within Florida and possibly beyond, since treatment providers often serve clients from multiple regions.
What Information Was Potentially Exposed?
The data compromised in this breach is extensive and touches on some of the most sensitive categories of personal information. Operation PAR confirmed that the exposed files included a broad mix of identifying, financial, and medical details.
- First and last names
- Dates of birth
- Social Security numbers
- Driver’s license numbers
- Financial account information
- Medical information
- Health insurance information
This combination of data creates serious risk for identity theft. When a Social Security number is paired with a full name, date of birth, and driver’s license number, criminals have nearly everything they need to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name.
The exposure of medical and health insurance information adds another layer of concern. Fraudsters can use stolen health insurance details to receive medical treatment under someone else’s identity, which can corrupt medical records and cause billing disputes. Because this breach involves an addiction treatment provider, affected individuals may also face unwanted disclosure of sensitive treatment history, which could lead to discrimination or personal harm if misused.
What Is the Company Doing?
Once Operation PAR identified the suspicious activity, it took immediate steps to secure its network and prevent further unauthorized access. The organization then launched a detailed investigation to determine exactly what happened and which records were affected.
Following the investigation, Operation PAR implemented additional security measures aimed at preventing similar incidents going forward. The organization began mailing notification letters to affected individuals in June 2026, more than a year after the initial discovery. These letters included guidance on best practices for protecting personal information and preventing fraud.
Notably, Operation PAR does not appear to have offered credit monitoring or identity theft protection services to affected individuals. This means those impacted must take proactive steps on their own to guard against misuse of their data.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Affected individuals should request copies of their credit reports and review them carefully for unfamiliar accounts or inquiries. Because Social Security numbers were exposed, criminals could attempt to open new lines of credit using stolen identities.
You can obtain free credit reports from each of the three major credit bureaus. Checking reports regularly over the coming months, rather than just once, gives you a better chance of catching fraud early before serious damage occurs.
Consider a Credit Freeze or Fraud Alert
Because Social Security numbers and driver’s license numbers were both exposed, placing a credit freeze is a strong protective step. A freeze blocks lenders from accessing your credit file, which stops most attempts to open new accounts in your name.
Alternatively, a fraud alert requires creditors to verify your identity before extending new credit. This option is less restrictive than a freeze but still adds a meaningful layer of protection. Given the sensitivity of this breach, many individuals may prefer the stronger safeguard a freeze provides.
Watch for Medical and Insurance Fraud
Since health insurance information was exposed, affected individuals should review their explanation of benefits statements from their insurer. Unfamiliar charges or services could indicate someone else has used your insurance identity.
If you notice suspicious medical claims, contact your insurance provider immediately. Correcting fraudulent medical records early can prevent long-term complications with future treatment or insurance coverage.
Stay Alert for Phishing Attempts
Because this breach exposed names, dates of birth, and other identifying details, scammers may use this information to craft convincing phishing emails or phone calls. These messages often pretend to be from Operation PAR, a bank, or a government agency.
As a result, you should avoid clicking links or providing personal information in response to unsolicited messages. Instead, verify any request by contacting the organization directly through a known, official phone number or website.
Seek Legal Guidance if You Were Affected
Given the scope and sensitivity of this breach, affected individuals may want to consult a data breach attorney to understand their legal options. An attorney can help evaluate whether you qualify for compensation related to the exposure of your personal and health information.
Many attorneys offer free case evaluations, so there is little downside to exploring your options. This step is especially worth considering since Operation PAR does not appear to be offering credit monitoring services to those affected.
