ProCamps Data Breach Exposes Camp Enrollment Information

Published: 1 October 2026
Other Commercial data breach illustration
Breach Discovery: March 2026Breach Notification: September 2026

ProCamps, a Cincinnati-based youth sports camp organizer, discovered in March 2026 that an unauthorized party accessed cloud-stored camp enrollment data, affecting names combined with enrollment details but not Social Security or financial information. The company confirmed the scope in September 2026 and began notifying affected individuals. Anyone who received a letter should monitor their credit reports and watch closely for phishing attempts referencing camp payments or refunds.

CompanyProCamps
IndustryOther Commercial
Data Types ExposedFull Name, Camp Enrollment Information
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Cloud Access
Regulators NotifiedCalifornia Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the ProCamps Data Breach?

ProCamps runs athletic camps and training programs for young athletes and coaches across the country. The Cincinnati-based organizer recently disclosed a data security incident involving camp enrollment records. According to its notification filing, an unauthorized party gained access to information stored in the company’s cloud systems.

The company says it first became aware of the issue in March 2026. At that point, ProCamps brought in outside cybersecurity specialists to look into what had happened. Investigators later determined that an unknown actor had pulled certain camp enrollment data without permission at some point before that discovery date.

The notification does not say exactly how the intruder got into the cloud environment. It also does not identify any group or individual claiming responsibility. This means the specific attack method remains unclear, though the incident is best described as unauthorized access to cloud-stored data.

After the initial discovery, ProCamps hired a third-party vendor to comb through the affected records. This review aimed to determine whether the exposed files actually contained personal information. The company says it finished confirming the scope of the incident in September 2026, roughly five and a half months after first learning of the problem.

That gap between discovery and confirmation is not unusual for incidents involving large volumes of stored records. However, it does mean affected individuals went a long stretch without knowing their information might be at risk. Shortly after confirming the scope, ProCamps formally reported the incident to regulators and began sending notification letters.

Who was affected?

The individuals affected by this incident appear to be people who enrolled in ProCamps programs. Because these camps serve young athletes, it is reasonable to expect that both participants and their parents or guardians could be involved. However, the notification does not specify which categories of people are covered.

ProCamps has not publicly disclosed the total number of people affected by this breach. The notification letter does list several states whose attorneys general were informed, including California, Florida, Illinois, New York, and Texas, among others. This suggests the affected population spans multiple states rather than a single region.

Because the filing is a generic template rather than an individualized letter, it does not break down the affected group by role or age. As a result, this article does not assume whether minors, adults, or both were impacted. Anyone who received a direct letter from ProCamps should treat that notice as the most accurate source of information about their own situation.

What Information Was Potentially Exposed?

According to the notification, the exposed data centered on each person’s name combined with information they submitted during camp enrollment. The filing does not break down exactly which enrollment details were included. ProCamps did confirm that certain especially sensitive categories were not part of this incident.

  • Full name
  • Information provided during the camp enrollment process (not individually itemized in the notice)

The company specifically states that Social Security numbers, driver’s license numbers, and financial account information were not involved. This distinguishes the incident from many larger breaches that expose highly sensitive identifiers. Still, the fact that core financial identifiers were spared does not mean the exposure carries no risk.

Even basic enrollment data can be valuable to scammers when combined with a name. For example, a fraudster could use these details to send a convincing fake message about a camp refund or payment request. Because many enrollment records likely involve children, parents may be especially quick to respond to messages that reference their child’s activities.

In addition, enrollment information often includes contact details, which can fuel targeted phishing attempts. As a result, affected families should stay alert for unexpected communications that reference ProCamps, a specific camp session, or a child’s participation. While the risk of direct financial account fraud appears lower here, social engineering risks remain real.

What is the company doing?

ProCamps says it engaged cybersecurity experts to investigate as soon as it learned of the incident. The company also hired a separate third-party vendor to conduct a detailed review of the affected data. This review was intended to confirm exactly what information had been involved and who needed to be notified.

In response to the incident, ProCamps states it has added further security measures to better protect camp enrollment data going forward. The company also filed a formal notification with the California Attorney General in late September 2026. This filing is what made details about the incident publicly available.

Notably, the letter does not mention any offer of free credit monitoring or identity theft protection services. This sets the response apart from many other breach notifications, which often include such offers as a standard precaution. Instead, ProCamps has set up a dedicated help line for affected individuals.

That help line is available for 90 days from the date of the notification letter. It operates on weekdays from 8:00 a.m. to 8:00 p.m. Eastern time, excluding major U.S. holidays. Anyone who received a letter can use this number to ask specific questions about their own exposure.

What Should Affected Individuals Do?

Review Your Notification Letter Carefully

If you received a letter from ProCamps, start by reading it in full. The letter should confirm whether your information was involved and may include details specific to your account or enrollment record.

Because the publicly available copy is a generic template, your personal letter may contain information not found in the general notice. Pay close attention to any instructions or reference numbers included, since these can help if you need to contact the company’s help line later.

Monitor Your Credit Reports

Since ProCamps is not offering free credit monitoring, it falls on affected individuals to check their own credit activity. You can pull a free credit report from each major bureau through annualcreditreport.com.

Doing this regularly over the coming months can help you catch suspicious new accounts or inquiries early. If you notice anything unfamiliar, you can dispute it directly with the credit bureau involved. This step matters even though Social Security numbers were not exposed, because proactive monitoring costs nothing and provides peace of mind.

Consider a Fraud Alert or Credit Freeze

Although ProCamps states that financial account numbers were not involved, placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion is still a reasonable precaution. This is especially true if you are concerned about how enrollment data might be combined with other information already available about you online.

A fraud alert requires creditors to take extra steps to verify your identity before opening new accounts in your name. A credit freeze goes further by restricting access to your credit file entirely. Both options are free and can be lifted later if you need to apply for credit.

Watch for Phishing Attempts Tied to Camp Activities

Because the exposed data includes enrollment details, affected families should be cautious about messages referencing camps, payments, or refunds. Scammers often use context like this to make fraudulent messages feel legitimate.

Before responding to any unexpected email, text, or phone call, confirm the request through contact information you already know and trust. For example, call ProCamps directly using a number from its official website rather than one provided in a suspicious message. If you believe you have been targeted, you can report the attempt at identitytheft.gov.

Know Your Legal Options

Affected individuals may have legal options if they believe ProCamps did not adequately protect their information or delayed notification unreasonably. Data breach claims often examine whether an organization used reasonable security safeguards and whether notice was given promptly.

Whether you can pursue a claim depends on your specific circumstances, including whether you received a notice and what that notice says. Consulting a data breach attorney for a free case evaluation can help clarify whether you qualify and what next steps make sense for your situation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Check other recent data breach notifications →