Were you recently affected by a data breach?

North Dallas Shared Ministries Data Breach

North Dallas Shared Ministries, a Dallas nonprofit operating as Now-Forward, has notified the Texas Attorney General of a data breach exposing names, Social Security numbers, driver’s license numbers, financial account information, and medical information for individuals it has served.

North Dallas Shared Ministries
Date of Breach: Reported to be around May 25, 2026; formally reported to the Texas Attorney General on September 11, 2026
CAU logo

Who was affected:

Clients of North Dallas Shared Ministries

Impacted Data:

Names, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, medical information, health insurance information

North Dallas Shared Ministries, a Dallas, Texas nonprofit that operates as Now-Forward and provides financial aid, medical and dental care, food, clothing, and other essential services to low-income families, has reported a data security incident to the Texas Attorney General. Nonprofit organizations that serve vulnerable populations and collect sensitive personal information as part of delivering aid have a responsibility to protect that information, and the individuals affected deserve a clear account of what happened.

North Dallas Shared Ministries’s Data Breach Investigation

According to a filing submitted to the Texas Attorney General’s Data Security Breach Reports portal, published on September 11, 2026, North Dallas Shared Ministries, doing business as Now-Forward, disclosed a data security incident affecting 250 Texas residents. The filing lists the categories of information involved as names, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, medical information, and health insurance information. The filing indicates notice has not yet been provided to affected consumers as of the filing date. Separately, public reporting indicates the organization appeared on the leak site of a ransomware group in May 2026, though North Dallas Shared Ministries has not publicly confirmed a connection between that reported incident and the information described in its Texas Attorney General filing, and this article relies only on the state filing’s own disclosed facts for the specific figures cited below.

Nonprofit organizations that provide essential services such as financial aid, medical care, and food assistance to low-income families routinely collect some of the most sensitive categories of personal information that exist, including Social Security numbers, government identification, and medical and financial records, often from individuals who are already in a vulnerable position. This combination of sensitive data and a population that may have fewer resources to respond to identity theft makes nonprofit service organizations a particularly consequential target for cybercriminals, even though these organizations frequently operate with far smaller cybersecurity budgets than private companies handling comparable information.

Texas law generally requires organizations to notify affected residents and the Attorney General within a reasonable window once a breach is discovered and its scope understood, though the precise discovery and containment dates for this particular incident were not included in the public filing reviewed for this article. The gap between when an incident actually occurs and when the public becomes aware of it, and even the fact that consumer notice may still be pending as of this filing, reflects the practical realities of investigating and documenting a breach’s full scope, not evidence that anything was mishandled.

The specific combination of data types reportedly involved, Social Security numbers, driver’s license numbers, government-issued identification numbers, and financial and medical information, is highly valuable to identity thieves. Social Security numbers and government IDs can be used to open new lines of credit, file fraudulent tax returns, or apply for government benefits in a victim’s name. Financial account information can enable direct unauthorized transactions, while medical and health insurance information can be used to commit medical identity theft. Because North Dallas Shared Ministries serves a large number of families across many years of operation, an incident like this one has the potential to affect not just current clients but also individuals who received services from the organization some time ago.

Given the sensitivity of the information reportedly involved, security experts generally recommend that anyone who has received services from North Dallas Shared Ministries take proactive steps to monitor their financial accounts, credit files, and medical or insurance statements for signs of misuse, rather than waiting for a specific instance of fraud to occur before acting.

When Did This Breach Occur?

North Dallas Shared Ministries’s data breach notification was published to the Texas Attorney General’s Data Security Breach Reports portal on September 11, 2026. Public reporting separately indicates the organization appeared on a ransomware group’s leak site around May 25, 2026, though the state filing itself did not specify the exact date the breach occurred or was discovered.

What Information Was Breached?

Per the filing, the categories of information involved include names, Social Security numbers, driver’s license numbers, government-issued identification numbers, financial account information, medical information, and health insurance information for 250 Texas residents.

What You Can Do

If you have received services from North Dallas Shared Ministries or Now-Forward and believe you may have been affected by this breach, consider taking the following steps:

  • Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus.
  • Monitor your bank and credit card statements closely for any unauthorized transactions.
  • Watch for suspicious activity related to your health insurance, including unfamiliar claims or explanation-of-benefits statements.
  • File your taxes as early as possible to reduce the risk of tax-related identity fraud.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, as scammers sometimes exploit public breach notices to run phishing schemes.

File a Data Breach Lawsuit Against North Dallas Shared Ministries

If your personal information was exposed in the North Dallas Shared Ministries data breach, you may have legal options available to you. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Suspicious activity detected December 30, 2025; notice filed with the New Hampshire Attorney General on September 1, 2026
Date of Breach: Reported to the Texas Attorney General on September 11, 2026
Date of Breach: Reported to be around May 25, 2026; formally reported to the Texas Attorney General on September 11, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.