Were you recently affected by a data breach?

Sweetwater Development & Management Company Data Breach

Sweetwater Development & Management Company notified investors that a security incident at its third-party fund administrator, Ultimus Fund Solutions, may have exposed their personal information.

Sweetwater Development & Management Company
Date of Breach: Not publicly disclosed by Sweetwater; vendor incident first communicated July 30, 2026
CAU logo

Who was affected:

Clients of Sweetwater Development & Management Company

Impacted Data:

Certain information provided to Sweetwater by affected individuals; specific data elements not detailed in the public notice

Sweetwater Development & Management Company has notified individuals that a data security event at one of its third-party vendors, Ultimus Fund Solutions, may have involved their personal information. Companies that share sensitive investor and client data with outside vendors remain responsible for ensuring that information is properly protected, even when the underlying incident occurs outside their own network.

Sweetwater Development & Management Company’s Data Breach Investigation

According to a follow-up notification letter dated August 14, 2026, Sweetwater Development & Management Company informed affected individuals of additional details regarding a data security event that occurred at Ultimus Fund Solutions, a third-party vendor that provides fund administration services to Sweetwater. The company states that it first communicated with affected individuals about the incident on July 30, 2026, and that Ultimus subsequently made Sweetwater aware that the incident may affect certain information related to its investors.

Sweetwater states that the activity in question was not within its own network environment, but rather occurred at Ultimus. Upon learning of the incident, Sweetwater began working with Ultimus and engaged third-party cybersecurity specialists to confirm the scope and details of the event. Once Ultimus confirmed the relevant scope, Sweetwater worked to communicate with affected individuals and coordinated additional written notifications to those individuals and applicable regulatory authorities. Sweetwater has stated that it is evaluating its relationship with Ultimus going forward and has taken steps to further strengthen its own cybersecurity infrastructure in response to the incident.

Incidents involving third-party fund administrators and vendors have become an increasingly common source of data exposure for investment and real estate development firms, since these vendors often centralize large volumes of sensitive investor data, including personal and financial information, across many client relationships at once. A single vendor-side security failure can therefore affect the customers of numerous unrelated companies simultaneously, which is part of why regulators and courts have increasingly scrutinized how thoroughly companies vet and oversee the data-security practices of the vendors they rely on.

As a precaution, Sweetwater is offering affected individuals twenty-four months of complimentary credit monitoring and identity protection services through TransUnion. Investors and clients who receive this notification should take the incident seriously, even though the underlying event did not occur within Sweetwater’s own systems, because their personal information may still have been exposed as a result of Sweetwater’s business relationship with Ultimus.

When Did This Breach Occur?

Sweetwater states that it first communicated with affected individuals about the Ultimus incident on July 30, 2026, with this follow-up letter, providing additional information, dated August 14, 2026. The notice does not specify the exact date the underlying security incident at Ultimus occurred or was first discovered.

What Information Was Breached?

Sweetwater’s notification letter states that the information related to each individual is certain information that person provided to Sweetwater, to the extent that information was shared with Ultimus. The letter does not specify a single universal list of data categories affected, noting that the specific information involved varies by individual.

What You Can Do

If you received a notification letter from Sweetwater Development & Management Company, consider taking the following steps to help protect yourself:

  • Enroll in the complimentary 24-month credit monitoring and identity protection service offered through TransUnion within 90 days of your letter.
  • Request and review your free credit reports from Equifax, Experian, and TransUnion for unfamiliar accounts or inquiries.
  • Consider placing a fraud alert or credit freeze on your credit files.
  • Monitor your financial account statements closely for any unauthorized activity.
  • Report any suspected identity theft to your state Attorney General’s office, the Federal Trade Commission, or local law enforcement.

File a Data Breach Lawsuit Against Sweetwater Development & Management Company

If you received a data breach notification letter from Sweetwater Development & Management Company regarding the Ultimus Fund Solutions incident, you may have legal options available to you. Companies that share investor and client data with third-party vendors have a responsibility to ensure that data is properly protected, and affected individuals may be entitled to compensation when that responsibility is not met.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Alleged to have occurred on or around August 13, 2026 (unconfirmed by Carhartt)
Date of Breach: July 2, 2026 (disclosed August 12, 2026)
Date of Breach: Alleged to have occurred on or around August 17, 2026 (unconfirmed by ASU)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.