What Happened in the WiredScore Data Breach?
WiredScore, the New York company that runs building certification programs under the WiredScore and SmartScore names, recently confirmed a data security incident. The company disclosed the event in a filing with the Texas Attorney General’s office. This filing revealed that unauthorized parties gained access to personal information tied to certain individuals connected to WiredScore’s operations.
According to the regulatory filing, WiredScore reported the incident on August 22, 2025. However, the exact date the intrusion itself took place has not been publicly disclosed. As a result, affected individuals currently have no clear picture of how long their information may have been exposed before the company detected it.
Because WiredScore has not released a detailed forensic timeline, many questions remain unanswered. For instance, the public record does not yet explain how the attacker gained access or whether the incident involved a vendor system. WiredScore has also not confirmed whether it completed a full forensic investigation before submitting its regulatory filing.
Notably, the filing indicated that direct notice to affected consumers had not yet been sent as of the filing date. This means many people whose data was involved may still be unaware that their information was part of this breach. Because notification timelines vary by state, individuals should not wait for a formal letter before taking action.
Who was affected?
WiredScore’s filing identifies at least 735 Texas residents as affected by this breach. These individuals appear to be connected to WiredScore through its certification and rating programs, which serve building owners, property managers, and corporate clients. It is possible that employees or other program participants were also involved, though the filing does not break down the population by category.
At this time, WiredScore has not publicly disclosed a nationwide total for how many people were affected. Because certification programs like WiredScore’s often involve interactions with clients across many states, the true scope of this incident could extend beyond Texas. Until WiredScore releases more detail, the full geographic reach of this breach remains unclear.
It is also worth noting that WiredScore works with commercial clients rather than individual consumers in most cases. Therefore, affected individuals may include employees of building management companies or corporate representatives whose contact details were stored in WiredScore’s systems as part of the certification process.
What Information Was Potentially Exposed?
Based on what WiredScore reported to Texas regulators, the breach involved several categories of personal data. The filing describes the exposed information in general terms, without a fully itemized breakdown.
- Full names
- Home or business addresses
- Other unspecified personal information
WiredScore has not confirmed whether more sensitive data, such as Social Security numbers or financial account numbers, was part of this exposure. Until the company releases additional detail, affected individuals should assume that at least their name and address were compromised.
Even without financial account numbers, exposed names and addresses carry real risk. Scammers frequently combine this type of data with information from other breaches to build detailed profiles of potential victims. As a result, affected individuals may become targets of convincing phishing emails, fraudulent mail offers, or phone scams designed to extract more sensitive details.
In addition, because addresses reveal where someone lives, this type of exposure can also enable physical-world risks, such as targeted mail fraud or impersonation schemes. Criminals sometimes use address data to file fraudulent change-of-address requests or open accounts using a victim’s real home address to intercept mail.
What is the company doing?
WiredScore reported this incident to the Texas Attorney General’s office, which is a required step under state breach notification law. This filing represents the company’s initial public acknowledgment of the incident. However, the filing does not detail specific remediation steps WiredScore has taken internally.
As of the filing date, WiredScore had not yet confirmed sending direct notice to affected individuals. This suggests that the company’s response is still in progress. Because full investigations often take time, additional details about WiredScore’s security improvements or consumer protections may emerge as the situation develops.
Meanwhile, individuals connected to WiredScore should watch for any official communication from the company. This could include information about credit monitoring services or other protective measures, though none have been confirmed publicly at this time.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone connected to WiredScore’s certification programs should review their credit reports regularly. This helps catch new accounts or inquiries that were not authorized. You can request free reports from each of the three major credit bureaus annually.
Because exposed names and addresses can support identity theft attempts, regular monitoring gives you an early warning system. If you spot an unfamiliar account or inquiry, you can act quickly to dispute it before further damage occurs.
Consider a Fraud Alert or Credit Freeze
If you notice any suspicious activity tied to your identity, consider placing a fraud alert with the credit bureaus. This step requires creditors to verify your identity before opening new accounts in your name.
For stronger protection, a credit freeze restricts access to your credit file entirely. This makes it much harder for a criminal to open new credit lines using your information. While a freeze requires a bit more effort to lift when you need credit yourself, it offers a higher level of protection against identity theft.
Watch for Phishing and Impersonation Attempts
Because your name and address may now be circulating among criminals, expect an increase in suspicious contact. This could include emails, calls, or mailed offers referencing WiredScore or claiming to help resolve the breach.
Never click links or share personal details in response to unsolicited messages. Instead, verify any communication by contacting WiredScore directly using a phone number or website you know to be legitimate, not one provided in the suspicious message itself.
Keep Records of Suspicious Activity
If you notice unusual contact or unauthorized activity connected to your identity, document it carefully. Save emails, note dates and times of phone calls, and keep copies of any letters you receive.
This documentation can prove valuable if you decide to pursue a legal claim later. Additionally, thorough records help credit bureaus and financial institutions investigate fraud more efficiently on your behalf.
Speak With a Data Breach Attorney
Because WiredScore had a responsibility to safeguard your personal information, you may have legal options if your data was exposed in this breach. Many individuals choose to consult an attorney who focuses on data breach cases to understand their rights.
A free case evaluation can help you determine whether you qualify to join a claim seeking compensation. This costs nothing upfront and can clarify what evidence you may need going forward.
