PAMCAH-UA Local 675 Health and Welfare Fund Data Breach Exposes Social Security Numbers and Personal Data

Non-profit data breach illustration
Breach Discovery: October 2025Breach Notification: August 2026

What Happened in the PAMCAH-UA Local 675 Data Breach?

PAMCAH-UA Local 675 Health and Welfare Fund has disclosed a data security incident tied to unauthorized access of its email systems. The fund provides health and welfare benefits to plumbers and their families in Hawaii. Its recent notice to affected individuals outlines how outside intruders reached certain employee inboxes without permission.

According to the fund’s filing with the Massachusetts Attorney General, an unknown party accessed employee email accounts between September 2025 and October 2025. During that window, the intruder may have viewed or copied messages and attachments stored in those accounts. Because the exposure spanned more than two weeks, the scope of what the attacker actually saw is difficult to pin down with precision.

After spotting the intrusion, the fund launched a forensic investigation to determine what happened and which accounts were touched. That review took many months to complete, which is common in email-based breaches since investigators must manually examine each affected mailbox. The fund ultimately filed formal notice with Massachusetts regulators in August 2026, nearly a year after the access window closed.

Importantly, the fund has stated it found no evidence so far that the exposed information has been misused for fraud or identity theft. However, it chose to notify affected individuals anyway, out of caution. This approach reflects a common pattern in breach response: informing people before any confirmed harm occurs, rather than waiting for fraud reports to surface.

Who was affected?

The breach affects individuals connected to PAMCAH-UA Local 675 Health and Welfare Fund, including plan participants and their family members. Because the fund manages benefits for plumbers and their households, both workers and dependents could be impacted. The notice does not specify whether minors are among those affected, though family health plans often include children.

The fund has not publicly disclosed a specific number of affected individuals. What is known is that the exposed information varied by person, meaning not everyone had the same data type compromised. Some individuals may have had only their name exposed, while others may have had more sensitive details like Social Security numbers included in the affected email content.

What Information Was Potentially Exposed?

The fund reviewed the contents of the compromised email accounts to determine what personal information was present. Because the exposure came from email correspondence rather than a structured database, the specific data varies from person to person. Still, the categories identified so far include some highly sensitive information.

  • Full names
  • Dates of birth
  • Social Security numbers

This combination of data is particularly concerning because it gives criminals nearly everything needed to impersonate someone. A name paired with a date of birth and Social Security number can be used to open new credit accounts, file fraudulent tax returns, or apply for loans in the victim’s name. As a result, affected individuals face a real risk of identity theft even without confirmed misuse yet.

In addition to financial fraud, this type of data can fuel more targeted scams. For example, criminals sometimes use stolen personal details to craft convincing phishing messages that reference real information, making them harder to spot. Because health and welfare fund data often connects to medical benefits, there is also a possibility that some exposed messages touched on health-related matters, though the fund’s notice focuses on the three data categories above.

What is the company doing?

Once the fund discovered the unauthorized access, it moved to investigate the incident and determine its scope. This involved reviewing which accounts were compromised and what specific information those accounts contained. The fund also states it has taken steps to secure the affected email accounts going forward.

In response to the incident, PAMCAH-UA Local 675 is offering a complimentary two-year membership in Experian IdentityWorks credit monitoring to affected individuals. This service can help detect unusual account activity or new credit inquiries. The fund is also notifying regulators, including the Massachusetts Attorney General, as required under state breach notification laws.

What Should Affected Individuals Do?

Enroll in Credit Monitoring

If you received a notice from PAMCAH-UA Local 675, sign up for the free Experian IdentityWorks membership right away. This service can alert you quickly if someone tries to open new accounts using your information.

Because credit monitoring only flags activity after it happens, it works best when paired with your own regular checks. Reviewing your accounts often gives you an extra layer of protection beyond what any single service can catch alone.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers were potentially exposed, consider placing a fraud alert or a full credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new creditors from accessing your credit file, which makes it much harder for someone to open accounts in your name.

While a freeze adds an extra step when you apply for credit yourself, it is one of the strongest protections available. You can lift it temporarily whenever you need to apply for a loan or new account, then reinstate it afterward.

Watch for Phishing Attempts

Because your name and personal details may now be in criminal hands, watch closely for phishing emails or calls that reference this breach. Scammers often use real breach details to make their messages appear legitimate.

Never click links or provide information in response to unexpected messages, even if they mention the fund by name. Instead, contact the organization directly using a verified phone number or website if you have questions about your account.

Monitor Your Financial Accounts and Credit Reports

Check your bank and credit card statements regularly for charges you don’t recognize. In addition, request your free credit report from annualcreditreport.com and review it for accounts you didn’t open.

If you spot anything suspicious, report it immediately to your financial institution and to the Federal Trade Commission at ftc.gov/idtheft. Acting quickly can limit the damage and help you dispute fraudulent activity before it spreads further.



More Information

Official data breach notification from Oregon Department of Justice

Related Data Breaches

See the latest data breaches we're tracking →