Neon One, LLC, a Chicago, Illinois-based technology company that provides fundraising tools, donor management systems, and operational software for nonprofit organizations, has begun notifying individuals that their personal information may have been exposed in a recent cybersecurity incident tied to a third-party software vendor. Nonprofits and the vendors that serve them handle large volumes of donor and constituent data, and a breach at any point in that chain can affect people who never directly interacted with the vendor itself.
Neon One’s Data Breach Investigation
According to a notification letter sent to affected individuals dated July 31, 2026, Neon One became aware on June 16, 2026 of a cybersecurity incident experienced by Klue, a software vendor that provides an integration service for Neon One’s Salesforce customer relationship management software. The incident resulted in unauthorized access to certain personal information between June 11 and June 12, 2026. Neon One states it conducted an investigation with the support of cybersecurity experts, notified law enforcement, and that the incident has been contained with no further impact identified.
This incident illustrates a broader trend in data security: breaches increasingly originate not from a company’s own systems, but from third-party vendors and software integrations that have access to a company’s data. Nonprofit-sector technology providers like Neon One often integrate with numerous third-party tools to manage donor relationships, payment processing, and marketing, and each integration represents a potential point of vulnerability outside the primary company’s direct control.
Neon One’s notification letter states that the specific data elements affected in this incident have not yet been finalized in the version of the letter that has become public, though the company has committed to offering affected individuals 24 months of complimentary Experian IdentityWorks credit monitoring, fraud resolution services, and identity theft insurance. Regulatory filings, including one submitted to the Nebraska Attorney General’s office, confirm the incident and the company’s notification obligations.
Even when a breach originates at a third-party vendor rather than at the primary company, affected individuals face the same practical risks: exposure to identity theft, unauthorized account access, and an increased volume of phishing attempts referencing the incident. Anyone who receives a notice like this should treat it with the same seriousness as a direct breach notification from the company itself.
When Did This Breach Occur?
The unauthorized access occurred between June 11 and June 12, 2026. Neon One became aware of the incident on June 16, 2026, and began notifying affected individuals on July 31, 2026.
What Information Was Breached?
Neon One’s notification letter indicates that personal information was accessed as a result of the incident at its vendor Klue. The company has not publicly specified the full list of data elements involved beyond confirming that personal information was affected. Neon One is offering 24 months of Experian IdentityWorks credit monitoring, fraud resolution services, and $1 million in identity theft insurance to affected individuals, which suggests the exposed data may include the kind of sensitive information typically covered by such protections.
What You Can Do
If you received a notice from Neon One about this data breach, consider taking the following steps:
- Enroll in the complimentary Experian IdentityWorks credit monitoring offered in your notification letter before the enrollment deadline.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Monitor your financial accounts closely for unauthorized activity.
- Be alert to phishing emails, calls, or text messages referencing this breach.
- Report any suspected identity theft to local law enforcement, the FTC, and your state Attorney General.
File a Data Breach Lawsuit Against Neon One
If your personal information was exposed in the Neon One data breach, you may be entitled to compensation. Companies that collect and store sensitive personal information, whether directly or through third-party vendors, have a legal responsibility to protect it, and when that information is compromised, affected individuals may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.