What Happened in the Perrigo Company Data Breach?
Perrigo Company, a manufacturer of consumer health and pharmaceutical products, recently disclosed a data breach that exposed sensitive personal information belonging to consumers. The company filed a formal notification with the Vermont Attorney General’s office confirming the incident. This filing revealed that Social Security numbers were among the data categories involved.
According to the notification, Perrigo Company identified that unauthorized parties may have accessed or obtained personal data tied to individuals connected with the company. The exact method used to gain access has not been publicly disclosed in available records. As a result, many details about the timeline of the intrusion itself remain unclear at this time.
Following discovery, Perrigo Company appears to have conducted an internal review to determine which records were affected. This process typically involves forensic specialists who examine network activity and data logs. Because the notification to Vermont regulators confirms Social Security numbers were involved, the company evidently completed enough of this investigation to identify the specific data types exposed before notifying affected individuals and regulators.
Who was affected?
The notification does not specify an exact number of individuals affected by this breach. Therefore, it hasn’t been publicly disclosed how many consumers, employees, or other individuals had their information exposed. However, filing with a state attorney general typically indicates that at least one resident of that state was impacted.
Because Perrigo Company operates broadly across the consumer health and pharmaceutical sector, the population affected could include customers, employees, or business partners. In addition, the scope may extend beyond Vermont, since companies generally file similar notices in multiple states when a breach affects residents nationwide. Until more information becomes available, the full geographic and demographic scope of this incident remains uncertain.
What Information Was Potentially Exposed?
The Vermont filing specifically confirms that Social Security numbers were part of the exposed data. This is one of the most sensitive categories of personal information that a breach can involve. Because Social Security numbers are often used to verify identity, their exposure carries significant risk.
- Social Security numbers
Beyond the confirmed exposure of Social Security numbers, other personal details often accompany this type of record, though the filing does not list additional categories. As a result, affected individuals should assume that names or contact details may also have been involved, even though this hasn’t been officially confirmed.
When Social Security numbers fall into the wrong hands, the risk of identity theft rises sharply. Criminals can use this information to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. Because these numbers rarely change, the risk can persist for years after a breach occurs.
In addition to identity theft, exposed Social Security numbers can enable synthetic identity fraud. This occurs when criminals combine a real number with fabricated details to create a new, fraudulent identity. Consequently, victims may not notice the misuse immediately, since the fraudulent activity may not appear directly on their own credit file right away.
What is the company doing?
In response to discovering the breach, Perrigo Company took the step of notifying the Vermont Attorney General, as required under state breach notification law. This filing indicates that the company recognized its legal obligation to inform regulators once it confirmed sensitive data had been compromised. Such notifications are generally required within a specific window after discovery.
Beyond the regulatory filing, further public details about Perrigo Company’s remediation efforts have not been disclosed. Companies in similar situations often work to secure affected systems, reset credentials, and review security protocols going forward. However, whether Perrigo Company is offering credit monitoring or identity protection services to affected individuals has not been confirmed in available records.
What Should Affected Individuals Do?
Place a Fraud Alert or Credit Freeze
Because Social Security numbers were exposed, affected individuals should strongly consider placing a fraud alert or credit freeze on their credit files. A fraud alert warns lenders to verify your identity before approving new credit. A credit freeze goes further by blocking access to your credit report entirely.
To set this up, contact one of the three major credit bureaus: Equifax, Experian, or TransUnion. Any one of them must alert the other two once you place a fraud alert. This step is free and can meaningfully reduce the chances of someone opening fraudulent accounts in your name.
Monitor Your Credit Reports Closely
Affected individuals should also review their credit reports regularly for suspicious activity. You are entitled to a free credit report from each of the three major bureaus once a year, and you can request additional free reports during periods of heightened fraud risk. Checking these reports frequently helps catch unauthorized accounts early.
If you notice unfamiliar accounts or hard inquiries you didn’t authorize, report them immediately. Early detection often makes it easier to dispute fraudulent charges and limit damage. In addition, consider setting up account alerts through your bank or credit card provider for extra visibility.
Stay Alert for Phishing Attempts
Following a data breach, scammers often use exposed information to craft convincing phishing emails or phone calls. Because your Social Security number may have been exposed, be cautious of any communication asking you to verify personal details. Legitimate companies rarely request sensitive information through unsolicited emails or texts.
Before clicking links or providing information, verify the sender’s identity independently. For example, call the company directly using a number from its official website, rather than one provided in a suspicious message. This simple habit can prevent scammers from tricking you into handing over even more personal data.
Consider Filing an IRS Identity Protection PIN
Because Social Security numbers can be used to file fraudulent tax returns, affected individuals should consider requesting an Identity Protection PIN from the IRS. This PIN adds another layer of verification before a tax return can be processed under your Social Security number. As a result, it becomes much harder for criminals to file a fraudulent return in your name.
You can apply for this PIN directly through the IRS website. Once issued, you’ll need to use it every tax season going forward. This extra step takes only a few minutes but can prevent significant headaches during tax filing season.
Consult a Data Breach Attorney
Given the sensitivity of Social Security numbers, affected individuals may want to speak with an attorney who focuses on data breach cases. An attorney can help you understand whether you qualify for compensation through a potential class action or settlement. Many offer free consultations to evaluate your situation.
Because breach notification laws and consumer protection rules vary by state, professional guidance can clarify your specific rights. Additionally, an attorney can help you track deadlines for filing claims. Acting sooner rather than later often preserves more options for pursuing compensation.
More Information
Official data breach notification from Vermont Attorney General
