Society of Tribologists and Lubrication Engineers Data Breach Exposes Names and Payment Card Information

Published: 9 October 2026
Non-profit data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: October 2026

The Society of Tribologists and Lubrication Engineers notified individuals that names and payment card information may have been exposed in a data incident. The exact breach date has not been disclosed, and the total number affected nationwide is unknown. If you received a notice, replace your payment card, monitor statements closely, and watch for phishing attempts referencing the incident.

CompanySociety of Tribologists and Lubrication Engineers
IndustryNon-profit
Data Types ExposedNames, Payment Card Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Society of Tribologists and Lubrication Engineers Data Breach?

The Society of Tribologists and Lubrication Engineers, a professional group known as STLE and based in Downers Grove, Illinois, has notified individuals about a data security incident. The organization reported that names and payment card information may have been accessed without permission. This STLE data breach raises concerns for anyone who made a purchase or paid dues through the group’s systems.

According to the notification letter, STLE has not shared exactly when the incident took place. It also has not disclosed when its team first discovered the problem. As a result, the timeline between the intrusion and the public notice remains unclear to those affected.

The letter does state that STLE took immediate steps to secure its network once it learned of the issue. However, it does not explain how an unauthorized party gained access to the payment information in the first place. Because the notice was filed under Massachusetts breach notification rules, state law limited how much detail STLE could include. This is why the letter describes the event only in broad terms rather than specifics.

Membership organizations like STLE often rely on outside vendors to handle online payments and registrations. Therefore, investigators looking into incidents like this one typically examine both internal systems and third-party payment processors. At this time, STLE has not publicly described which part of its payment process may have been affected.

Who was affected?

The individuals affected by this incident appear to be customers or members who used payment cards with STLE. This could include people who paid for memberships, conference registrations, training programs, or publications through the organization’s payment systems.

The notification letter filed with Massachusetts regulators reports 6 affected residents in that state alone. However, this number does not reflect the full scope of the incident. Because STLE operates as a national or even international professional society, individuals in other states may also have received notice. The total number of people affected nationwide has not been publicly disclosed.

It is also unclear whether the affected group includes only individual members or also staff, vendors, or event attendees. Since the letter focuses on payment card use, it likely centers on anyone who completed a financial transaction with the organization. Anyone unsure about their status should contact STLE directly for clarification.

What Information Was Potentially Exposed?

Based on the notification letter, the categories of information involved in this incident are limited but still sensitive. The letter specifically names two types of data that could have been affected.

  • Names
  • Payment card information

The letter does not clarify whether the payment card details included expiration dates or security codes. It also does not mention any other categories, such as Social Security numbers or account passwords. Even so, payment card data combined with a name creates real risk for consumers.

Stolen card numbers can be used for unauthorized purchases within hours of being taken. In addition, criminals sometimes run small test charges first to confirm a card still works before attempting larger fraudulent transactions. Because a cardholder’s name is attached to the data, scammers can also craft convincing phishing messages that appear to come from a bank or from STLE itself.

Unlike a Social Security number, a payment card can be canceled and replaced relatively easily. This limits some long-term harm compared to other types of breaches. Still, affected individuals should not assume they are safe simply because a card can be swapped. Fraudulent charges can slip by unnoticed, especially small amounts mixed in with regular purchases.

What is the company doing?

After discovering the incident, STLE says it took immediate action to secure its network and strengthen its security practices. This suggests the organization made changes to prevent further unauthorized access once the issue came to light.

STLE also sent written notification letters to affected individuals, informing them of the incident and the type of data involved. The organization has set up a dedicated assistance line, available Monday through Friday from 9:00 a.m. to 6:30 p.m. Eastern Time, to answer questions. In addition to its Massachusetts filing, STLE filed a formal notification with the Vermont Attorney General, as required under that state’s breach notification law.

Notably, the letter does not mention any offer of free credit monitoring or identity protection services. Instead, STLE directs recipients toward general guidance, such as reviewing account statements and requesting free credit reports. This means affected individuals may need to take extra protective steps on their own.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Anyone who received a notice from STLE should begin checking their credit reports for unfamiliar activity. You can request a free annual credit report from each of the three major bureaus. Reviewing these reports regularly helps catch new accounts or inquiries you did not authorize.

In addition, pay close attention to your existing account statements for the next 12 to 24 months, as STLE itself recommends. Because fraud does not always appear immediately, ongoing vigilance matters more than a single check right after receiving the letter.

Consider a Fraud Alert or Credit Freeze

Since payment card information was involved, placing a fraud alert with Equifax, Experian, or TransUnion can add a layer of protection. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit in your name.

For stronger protection, you may also consider a full credit freeze. This restricts access to your credit file entirely until you choose to lift it. While a freeze takes a bit more effort to manage, it offers one of the most effective defenses against new-account fraud.

Replace Your Payment Card and Watch for Fraud

If you used a payment card with STLE, contact your card issuer and ask about replacing it. This step prevents criminals from continuing to use a compromised card number for unauthorized purchases.

Also, consider setting up transaction alerts through your bank or card provider. These alerts notify you immediately of new charges, so you can catch suspicious activity before it grows into a larger problem. Report any unauthorized charges to your bank right away.

Stay Alert for Phishing Attempts

Because scammers often use breach notices as cover for follow-up scams, be cautious about unexpected emails, texts, or phone calls referencing this incident. Legitimate organizations will not ask you to confirm your full card number or password over email.

If you receive a suspicious message claiming to be from STLE or a financial institution, do not click on links or provide personal details. Instead, contact the organization directly using a verified phone number or website to confirm whether the message is genuine.

Know Your Legal Options

If your name and payment card information were exposed in this incident, you may have legal options worth exploring. Organizations that accept card payments are generally expected to maintain reasonable security measures to protect that data.

Consulting with a data breach attorney can help you understand whether you qualify for compensation. Many consultations are free, and an attorney can clarify what evidence you may need and what deadlines could apply to your situation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

See the latest data breaches we're tracking →