Were you recently affected by a data breach?

COMHAR Data Breach

COMHAR, a Philadelphia-based nonprofit behavioral health and human services provider, disclosed that a threat actor accessed files containing patients’ Social Security numbers, treatment records, and other sensitive information. Affected individuals should watch for identity theft and consider a data breach lawsuit against COMHAR.

COMHAR
Date of Breach: Discovered on or before July 17, 2026 (threat actor claim posted July 1, 2026); notice issued September 4, 2026
CAU logo

Who was affected:

Clients of COMHAR

Impacted Data:

Names, addresses, dates of birth, Social Security numbers, treatment notes, diagnoses, medications, health insurance information

COMHAR, Inc., a Philadelphia-based nonprofit that provides behavioral health, intellectual disability, HIV/AIDS support, and home health services, has disclosed a data breach affecting current and former clients. The organization determined that an unauthorized actor copied files containing sensitive personal and health information.

Organizations that handle Social Security numbers and protected health information carry a heightened duty to secure that data, and a breach of this kind can expose affected individuals to a lasting risk of identity theft and fraud.

COMHAR’s Data Breach Investigation

Founded in 1975, COMHAR Inc. is a nonprofit organization based in Philadelphia that provides integrated behavioral health, intellectual disability, HIV/AIDS support, and home health care services throughout the region. On July 1, 2026, a threat actor identifying itself as Worldleaks posted on the dark web that it had obtained data belonging to COMHAR and threatened to publish the information within one to two days. COMHAR identified unusual activity on its network and retained third-party cybersecurity specialists to investigate the incident and determine what had happened. Working with these specialists, COMHAR determined on July 17, 2026 that certain files and folders had been copied from its systems by an unauthorized actor on or before that date. COMHAR then undertook a comprehensive review of the affected files to determine the full scope of the information involved, a process the organization said was still ongoing at the time it issued notice.

COMHAR published notice of the data event on September 4, 2026. Because the file review remained in progress when notice went out, the complete picture of who was affected and precisely what data belonging to each individual was involved may not be fully known even now. The organization has said it is continuing to notify individuals as its review identifies them. This kind of staged disclosure, where a company first confirms an intrusion and only later completes the harder work of mapping exactly which files were touched, is common after cyberattacks. Investigations into extortion-style incidents in particular can take weeks or months to fully resolve, since threat actors may exfiltrate large volumes of unstructured files that have to be reviewed individually before an organization can say with confidence whose information is included.

Nonprofit health and human services providers like COMHAR are attractive targets for cybercriminals because they routinely store some of the most sensitive categories of personal data in one place, including Social Security numbers, government identification, and detailed medical and behavioral health records, often while operating with more limited cybersecurity budgets than large hospital systems or insurers. Dark web extortion groups such as Worldleaks typically use a two-stage playbook: quietly copying data from a victim’s network, then publicly threatening to leak or sell it unless a ransom is paid. Even when a company refuses to pay, the underlying exposure of client data already occurred at the moment of the intrusion, which is why regulators require notice regardless of whether stolen data is ultimately published.

The combination of data potentially exposed in the COMHAR breach, including Social Security numbers, dates of birth, and health insurance information alongside treatment notes and diagnoses, is especially valuable to fraudsters. Social Security numbers and dates of birth are often enough on their own to open new lines of credit or file fraudulent tax returns in a victim’s name, while medical and behavioral health details can be used to commit health insurance fraud, target victims with tailored phishing schemes, or, given the sensitivity of behavioral health and HIV/AIDS-related records, expose individuals to embarrassment or discrimination if the information becomes public. Because this class of data does not expire the way a stolen credit card number does, individuals affected by breaches like this one often face an elevated risk of misuse for years after the incident.

Notification laws generally require organizations to disclose a data breach within a reasonable window once the scope of the incident is understood, but that timeline can be complicated when, as here, a threat actor’s initial dark web claim comes weeks before an organization’s own internal investigation confirms exactly what was taken. Individuals whose information is caught up in this kind of extended investigation often face a longer period of uncertainty about their own exposure, since a company may only be able to confirm the full extent of who was affected after the underlying forensic review concludes. In the meantime, prompt account monitoring and credit monitoring remain the most effective steps individuals can take to limit the damage a delayed or staged disclosure can cause.

When Did This Breach Occur?

COMHAR has disclosed several key dates related to this incident. A threat actor calling itself Worldleaks posted about the breach on the dark web on July 1, 2026, claiming to have obtained COMHAR’s data and threatening to publish it. COMHAR says its investigation determined that files and folders were copied from its network by an unknown actor on or before July 17, 2026, though the breach itself may have begun earlier; forensic investigations of this kind frequently identify a period of unauthorized access that started well before it was detected. COMHAR published formal notice of the data event on September 4, 2026. The organization has stated that its review of the affected files was still ongoing at that time, meaning some individuals may be notified after this initial round of letters as the investigation continues to identify additional affected files and individuals.

What Information Was Breached?

COMHAR has said the information potentially exposed in this breach includes personally identifiable information and protected health information. According to the notice, the data at risk may include names, addresses, dates of birth, Social Security numbers, treatment notes, diagnoses, medications, and health insurance information. Because COMHAR’s review of the affected files was still ongoing at the time of notice, the organization has not disclosed a total number of individuals affected, and it is possible that not every affected person’s exact combination of exposed data has been identified yet. Given the range of services COMHAR provides, including behavioral health, intellectual disability, HIV/AIDS support, and home health care, the records involved may include especially sensitive clinical details tied to those services.

What You Can Do

If you received a notice from COMHAR, or believe you may have been affected by this breach, there are steps you can take to protect yourself:

  • Review the notice letter carefully and follow any specific instructions COMHAR has provided.
  • Monitor your financial accounts, insurance statements, and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus.
  • Watch for phishing emails, calls, or letters that reference the breach or COMHAR by name.
  • Contact COMHAR’s dedicated phone line, 1-888-941-5180, Monday through Friday from 8 a.m. to 8 p.m. ET, with questions about the incident.

Because this breach may involve protected health information in addition to Social Security numbers, affected individuals should also review any insurance explanation-of-benefits statements for services they do not recognize, which can be an early sign of medical identity theft.

File a Data Breach Lawsuit Against COMHAR

If your personal or health information was exposed in the COMHAR data breach, you may have legal options. Companies and organizations that collect sensitive data are expected to maintain reasonable safeguards to protect it, and when that data is compromised, affected individuals can face real and lasting harm, from the time and expense of monitoring accounts to the ongoing risk of identity theft.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: On or around September 7, 2026 (unconfirmed)
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.