Were you recently affected by a data breach?

Alkegen Data Breach

ASP Unifrax Holdings, Inc., operating as Alkegen, began notifying individuals on July 17, 2026 that a data security incident exposed personal information, including Social Security numbers and health records. The Dallas-based materials manufacturer disclosed the breach to regulators in Massachusetts and Vermont. Affected individuals should act quickly to protect themselves.

Alkegen
Date of Breach: Notifications began July 17, 2026
CAU logo

Who was affected:

Clients of Alkegen

Impacted Data:

Social Security numbers, health information

Alkegen, the parent brand of ASP Unifrax Holdings, Inc., recently notified individuals that their personal information may have been exposed in a data security incident. The company began sending notification letters on July 17, 2026, alerting people that some of their sensitive information had been affected. Companies that manufacture and supply materials used across critical industries handle large volumes of personal and workforce data, and they carry a responsibility to keep that information secure from unauthorized access.

Alkegen’s Data Breach Investigation

ASP Unifrax Holdings, Inc., doing business as Alkegen, is a global materials manufacturer headquartered in Dallas, Texas. The company designs and produces specialty materials used in thermal management, filtration, fire protection, and battery applications, serving customers across a wide range of industrial sectors including automotive, aerospace, and energy storage. Alkegen has notified individuals that a data security incident has resulted in the exposure of personal information stored on its systems.

According to notifications filed with state regulators, including the Massachusetts Office of Consumer Affairs and Business Regulation and the Vermont Attorney General’s Office, Alkegen began mailing letters to affected individuals on July 17, 2026. The notification letter distributed by the company states that personal information was involved in the incident, and that Kroll identity monitoring services are being made available to affected individuals at no cost. The specific number of people affected, and the precise dates during which the unauthorized access occurred, have not yet been publicly disclosed in detail beyond the notification date itself.

The letter itself references that certain personal information was accessed, and public reporting on the incident by consumer-advocacy investigators has stated that the exposed information may include Social Security numbers and health-related records. Alkegen has arranged complimentary identity monitoring, fraud consultation, and identity theft restoration services through Kroll for individuals who received notice, with membership numbers and activation deadlines specified individually in each notification letter.

Manufacturing and industrial companies like Alkegen are common targets for cyberattacks because they often maintain large volumes of employee and business-partner data alongside proprietary operational systems, while historically investing less in cybersecurity infrastructure than sectors like finance or healthcare. Threat actors increasingly recognize that breaching an industrial supplier can expose not only the company’s own employees, but also sensitive information tied to a much wider network of business relationships and supply-chain partners.

When Social Security numbers and health information are exposed together, the risk to affected individuals is elevated substantially. Social Security numbers form the backbone of identity verification for banks, lenders, and government agencies, meaning a compromised number can be used to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. When paired with health-related information, criminals can also attempt medical identity theft, using a victim’s identity to obtain prescription medications, medical equipment, or healthcare services, which can corrupt a person’s own medical records and lead to billing complications that take months or years to fully unwind.

Notification timelines for data breaches can vary considerably depending on the complexity of the forensic investigation, the number of states involved, and applicable state and federal reporting requirements. Massachusetts, for example, requires notification to its Office of Consumer Affairs and Business Regulation as soon as practicable once a breach affecting Massachusetts residents is discovered, while other states allow longer windows. Because Alkegen’s notice was filed simultaneously across multiple states, the company appears to be treating this as a multi-state incident requiring coordinated regulatory disclosure.

Individuals who receive a notification letter from Alkegen should treat it seriously and take advantage of the credit monitoring services offered, even if they do not notice any signs of misuse right away. Identity thieves frequently wait months after obtaining stolen data before attempting to use it, in part to avoid triggering the kind of immediate fraud alerts that often accompany a publicized breach.

When Did This Breach Occur?

Alkegen has not publicly disclosed the specific dates on which the unauthorized access to its systems began or ended. What is known is that the company started notifying affected individuals on July 17, 2026, and disclosed the incident to state regulators, including Massachusetts and Vermont, around the same time. The notification letter sent to affected individuals references a recent data security incident but does not specify an exact breach window in the portions of the notice available to the public.

Companies are often required to complete a forensic investigation before determining the full scope of an incident, which can take weeks or months after unauthorized access is first detected. This process typically involves working with third-party cybersecurity firms to determine what systems were accessed, what data was involved, and which individuals need to be notified. Until that investigation is complete, exact incident dates are sometimes withheld from public notices even after individual notification letters have been mailed. If more specific information about the timeline of the Alkegen data breach becomes available, this page will be updated accordingly.

What Information Was Breached?

Alkegen’s notification letter confirms that personal information belonging to affected individuals was involved in the data security incident. Public reporting on the breach indicates that the exposed information may include Social Security numbers and health-related records, though the company’s own notification letter does not provide an itemized public list of every data element involved.

Because Alkegen has arranged complimentary Kroll identity monitoring services specifically for affected individuals, and because those services include triple-bureau credit monitoring, it is reasonable to infer that at least some individuals’ Social Security numbers were involved in the incident. Kroll’s identity monitoring services are most commonly offered following breaches that expose Social Security numbers or other information capable of supporting new-account fraud.

If you received a notification letter from Alkegen, review it carefully, as it should specify exactly which categories of your personal information were affected. Not every recipient of a breach notification necessarily had the same categories of information exposed, since notification letters are often customized based on what specific data was found to be at risk for each individual.

What You Can Do

If you received a data breach notification letter from Alkegen, there are several steps you can take to protect yourself:

  • Enroll in the complimentary Kroll identity monitoring services referenced in your notification letter before the enrollment deadline.
  • Review your credit reports from Equifax, Experian, and TransUnion for any unfamiliar accounts or inquiries.
  • Consider placing a fraud alert or credit freeze on your credit files with the three major credit bureaus.
  • Monitor your financial and healthcare accounts closely for any unauthorized activity.
  • Keep your notification letter and any related correspondence in a safe place in case you need to reference it later.

Taking these steps promptly can help reduce your risk of identity theft and make it easier to catch any fraudulent activity early.

File a Data Breach Lawsuit Against Alkegen

If your personal information was exposed in the Alkegen data breach, you may have legal options available to you. Companies that collect and store sensitive personal information, including Social Security numbers and health-related data, have a legal and ethical responsibility to protect it from unauthorized access. When that data is compromised, affected individuals can be left vulnerable to identity theft, financial fraud, and years of ongoing monitoring and cleanup.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May 8, 2026
Date of Breach: January 28, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.