Were you recently affected by a data breach?

Knowledge Research Center Data Breach

Knowledge Research Center, a clinical research organization, disclosed that a former employee shared certain company files outside the organization without authorization, exposing clients’ personal information.

Knowledge Research Center
Date of Breach: Discovered August 3, 2026
CAU logo

Who was affected:

Clients of Knowledge Research Center

Impacted Data:

Names, dates of birth, gender, telephone numbers, email addresses, and in some cases certain medical diagnoses

Knowledge Research Center, a clinical research organization that works with individuals considering or participating in clinical trials, has notified affected individuals of a data security incident involving a former employee. The company says the incident did not involve unauthorized access to its internal network or systems, but rather the unauthorized disclosure of certain company files outside the organization.

Companies that manage clinical trial participant information, including health and contact details, have a responsibility to safeguard that data and to promptly notify affected individuals when something goes wrong.

Knowledge Research Center’s Data Breach Investigation

According to a notice filed with the California Attorney General’s office, Knowledge Research Center determined on August 3, 2026 that personal information had been impacted by an incident involving a former employee who disclosed certain company files outside the organization in an unauthorized manner on July 8, 2026. The company states it immediately launched an investigation to determine the scope of the incident and reports that it found no evidence of unauthorized access to its internal network or systems, distinguishing this from a typical external hacking event.

Clinical research organizations like Knowledge Research Center are entrusted with especially sensitive information, since prospective and enrolled trial participants often share personal health details, including medical diagnoses, in order to determine eligibility for a study. When that kind of data is exposed, even through an insider’s actions rather than an external attack, affected individuals can face real risks ranging from unwanted contact to more serious identity-theft-adjacent harms if the information is combined with other data circulating from unrelated sources.

The company has not publicly disclosed exactly how many individuals were affected or precisely what the former employee did with the files after disclosing them outside the organization. It reports that it has notified law enforcement and has continued to implement privacy and security measures, including staff training, aimed at preventing a similar incident in the future. Insider-related data incidents like this one underscore why access controls and employee offboarding procedures are treated as a critical layer of data security, not just external network defenses.

Notification letters for incidents like this are often sent out weeks or months after the underlying event is discovered, as the company works to determine the scope of what happened and prepares required regulatory filings. Affected individuals should treat the notification date, rather than the date of the underlying incident, as the point from which to start monitoring their accounts and any identity-protection services offered.

Insider-caused data incidents, where a current or former employee removes or discloses information rather than an outside hacker breaking in, are a recognized and persistent category of data security risk across every industry that handles sensitive personal or health information. Unlike a network intrusion, an insider incident often does not trigger the same technical alarms, which is one reason organizations frequently rely on internal audits, exit-interview procedures, and post-departure access reviews to catch this kind of activity after the fact. The fact that Knowledge Research Center says it found no evidence of unauthorized network access does not lessen the exposure to the individuals whose information was actually taken and shared outside the organization, it simply describes a different pathway than the more commonly reported external cyberattack.

The combination of data types involved here, names, dates of birth, contact information, and in some cases medical diagnoses, is particularly attractive to bad actors because it can be used to craft convincing phishing messages or fraudulent medical-billing schemes. A person’s date of birth paired with their name and a real medical diagnosis can lend false credibility to a scam call or email purporting to be from a clinic, insurer, or research coordinator, even without a Social Security number or financial account number attached. This is why organizations in the clinical research and healthcare space are generally held to a heightened duty of care when handling this category of information, regardless of whether the eventual leak occurred through an external attacker or an insider.

Clinical trial recruitment and eligibility screening in particular requires participants to disclose health information they might not otherwise share with a company they have limited ongoing interaction with, which increases the reputational and legal exposure a research organization faces when that data is mishandled. Regulators and plaintiffs attorneys alike frequently scrutinize how quickly a company detects and contains an insider incident, what access controls were in place before the departure of the employee involved, and whether the organizations data-retention practices unnecessarily prolonged the window during which the information was vulnerable.

When Did This Breach Occur?

Knowledge Research Center states that the unauthorized disclosure of company files by a former employee occurred on July 8, 2026, and that the company determined affected individuals’ information had been impacted on August 3, 2026.

What Information Was Breached?

The personal information involved may have included each individual’s name, date of birth, gender, telephone number, email address, and in some cases, certain medical diagnoses. The company states the incident did not involve Social Security numbers or financial information, including credit or debit card numbers, bank account information, or account passwords.

What You Can Do

Knowledge Research Center is offering 12 months of identity monitoring services through Kroll at no cost to affected individuals, including credit monitoring, fraud consultation, and identity theft restoration. Affected individuals who received a notice should also consider these general precautions:

  • Enroll in any complimentary credit monitoring or identity protection services offered in the notification letter.
  • Review financial and medical account statements regularly for any unfamiliar activity.
  • Consider placing a fraud alert or security freeze on your credit file with the three major credit bureaus.
  • Be cautious of unexpected calls, texts, or emails referencing this incident, medical diagnoses, or clinical trial participation, since exposed contact and health details can be used for targeted phishing attempts.

File a Data Breach Lawsuit Against Knowledge Research Center

If you received a notice that your information was affected by this incident, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: September 17, 2025 to October 8, 2025
Date of Breach: August 18, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.