Southern California Telephone Company Data Breach Exposes Passports and W-9 Tax Forms

Published: 15 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Southern California Telephone Company suffered a ransomware attack by the Akira group, which claims to have stolen 34GB of corporate data including employee passports, W-9 tax forms, and customer phone numbers. The breach notification date is September 2026. Affected employees and customers should monitor their credit reports and consider a credit freeze immediately.

CompanySouthern California Telephone Company
IndustryOther Commercial
Data Types ExposedPassport Information, W-9 Tax Forms, Customer Phone Numbers, Contracts and Agreements, Non-Disclosure Agreements, Confidential Corporate Certificates
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Southern California Telephone Company Data Breach?

Southern California Telephone Company, a telecom provider serving residential and business customers, has confirmed a data breach linked to the Akira ransomware group. The Southern California Telephone Company data breach came to light after the attackers publicly claimed responsibility and threatened to release stolen files. As a result, current and former employees, along with customers, now face real exposure risks.

According to available information, the attackers say they obtained roughly 34 gigabytes of corporate data. This reportedly includes employee passports, W-9 tax forms, customer phone numbers, contracts, non-disclosure agreements, and confidential certificates. The breach notification date associated with this incident is September 2026, though the exact discovery date has not been publicly disclosed.

Akira is a known ransomware group that typically gains unauthorized access to corporate networks before exfiltrating sensitive files. Once inside, these groups often threaten to publish stolen data unless a ransom is paid. In this case, the threat actors stated they planned to release the stolen files, which suggests the company either declined payment or negotiations remain unresolved.

Because ransomware investigations take time, forensic review of the full scope of this incident is likely still underway. Companies facing this type of attack typically work with cybersecurity specialists to determine exactly which systems were accessed. Until that work concludes, the full extent of the exposure may not be entirely clear to the public.

Who was affected?

The breach appears to affect two distinct groups: employees of Southern California Telephone Company and its customers. Employee records reportedly include passport copies and W-9 forms, which are typically used for identity verification and tax reporting purposes. This means current and former staff members could be at heightened risk of identity theft.

Customers are also implicated, since the attackers claim to have accessed phone numbers and other sensitive account information. The exact number of affected individuals has not been publicly disclosed. Given the company’s residential and business client base, the affected population could span a wide range of individuals across Southern California and potentially beyond.

Because business clients often submit their own W-9 forms and contract details when signing up for telecom services, business owners and their staff may also be caught up in this incident. In addition, the presence of NDAs and confidential certificates suggests that vendor and partner information may have been included in the exposed files.

What Information Was Potentially Exposed?

Based on the attacker’s own claims, several categories of sensitive personal and corporate data may have been compromised in this breach. The following list reflects the types of information reportedly included in the stolen files.

  • Passport information (employees)
  • W-9 tax forms, which typically include Social Security numbers or tax ID numbers
  • Customer phone numbers and account details
  • Contracts and business agreements
  • Non-disclosure agreements (NDAs)
  • Confidential certificates and corporate documents

This combination of data is particularly concerning because it mixes government identification documents with tax information. When passport numbers and W-9 forms are exposed together, criminals can potentially use them to open fraudulent accounts, file false tax returns, or apply for loans in someone else’s name. This risk applies mainly to affected employees whose personal records were part of the stolen files.

For customers, exposed phone numbers can enable targeted phishing and smishing attempts. Scammers frequently use stolen phone numbers to impersonate trusted companies, tricking victims into revealing further personal details. Meanwhile, exposed contracts and NDAs could expose competitively sensitive business information, which may create secondary risks for corporate partners and vendors connected to the company.

What is the company doing?

Southern California Telephone Company has not publicly detailed every step of its incident response. However, ransomware incidents of this nature typically prompt an internal investigation alongside outside cybersecurity experts. This usually includes efforts to contain the intrusion, assess which systems were compromised, and determine whether the ransomware group’s data claims are accurate.

In response to threats like this, affected organizations often begin notifying impacted employees and customers as more details become confirmed. Companies in this situation also frequently strengthen network defenses, reset credentials, and review vendor access to prevent further unauthorized activity. As the investigation continues, additional notifications or protective service offers, such as credit monitoring, may follow for those confirmed to be impacted.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who worked for or did business with Southern California Telephone Company should check their credit reports regularly. This is especially important given that W-9 forms and passport data may have been exposed. Look for unfamiliar accounts, inquiries, or changes to your personal information.

You can request a free credit report from each of the three major bureaus through AnnualCreditReport.com. Because fraud can appear months after a breach, it helps to check reports periodically rather than just once. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers may be embedded in the leaked W-9 forms, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. A credit freeze goes further, blocking access to your credit file entirely until you lift it.

Both options are free and can be requested directly through Equifax, Experian, and TransUnion. Setting up a freeze takes only a few minutes, but it can prevent significant financial damage. This step is particularly worthwhile for employees whose passport and tax information may have been stolen.

Stay Alert for Phishing and Impersonation Attempts

Because customer phone numbers were reportedly exposed, scammers may attempt to contact victims directly. These messages often pretend to come from the telephone company itself or from a related financial institution. Be cautious of unexpected calls or texts asking for personal information or payment.

Never click links or share codes sent through unsolicited messages, even if they appear urgent. Instead, contact the company directly using a verified phone number from its official website. This simple habit can prevent scammers from tricking you into revealing further sensitive details.

Protect Yourself Against Tax and Identity Fraud

Since W-9 forms often contain Social Security or tax identification numbers, affected employees should watch for signs of tax-related fraud. This includes unexpected IRS notices about tax returns you did not file. If this happens, contact the IRS Identity Protection Specialized Unit right away.

You may also want to request an Identity Protection PIN from the IRS, which adds an extra layer of security to your tax filings. This step specifically helps prevent criminals from filing fraudulent returns using your stolen information. Taking action early can reduce the time and stress needed to resolve any resulting tax issues.

Consult a Data Breach Attorney

If you believe your information was part of this breach, it may help to speak with a data breach attorney. Many offer free case evaluations and can explain whether you qualify for compensation. This is especially relevant given the sensitive nature of the passport and tax data reportedly involved.

An attorney can also help you understand your legal options if a class action lawsuit develops related to this incident. Because deadlines for filing claims can be limited, reaching out sooner rather than later is generally a good idea. This step costs nothing upfront and can provide clarity about your rights.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →