Corpay, the trading name used by Cambridge Mercantile Corp. (U.S.A.), has notified individuals that some of their personal information may have been accessed without authorization. Corpay provides cross-border payment and foreign exchange services to businesses and their employees or associates, and companies that manage this kind of financial data have a responsibility to keep it secure.
Corpay’s Data Breach Investigation
Corpay reported that it identified a data security incident affecting personal information related to individuals connected to the company through a business relationship, either directly or through an employer. Corpay stated that it performed a comprehensive review to identify potentially affected individuals, an effort that was substantially completed on August 28, 2026. The company said an unauthorized third party may have accessed certain personal information as a result of the incident. Corpay reported no evidence to date of fraud, identity theft, or other misuse of the information involved, and said the incident has not affected customer funds, payment processing, transaction execution, or the availability of its services.
Data breaches involving financial services and payment processing companies like Corpay are a common target for cybercriminals because these companies routinely handle large volumes of sensitive personal and financial information as part of processing cross-border transactions. Companies in the payments space are attractive targets precisely because a single compromised system can expose records tied to many individuals and business relationships at once.
Following incidents like this, affected individuals are often at increased risk of follow-up phishing attempts, where scammers pose as the breached company, a bank, or a credit monitoring service in order to extract additional personal information. Corpay’s response, which included engaging third-party security experts, enhancing its security and monitoring practices, and offering complimentary identity monitoring services through Kroll, reflects steps companies are increasingly expected to take once a security incident affecting personal data is confirmed.
Notification timelines for incidents like this can vary considerably depending on the complexity of the investigation and the scope of the review needed to identify every individual whose information may have been affected. In Corpay’s case, the company indicated its review process concluded in late August 2026, after which notification letters were prepared and sent to potentially impacted individuals, including the Massachusetts Attorney General filing that made this notice public.
When Did This Breach Occur?
Corpay has not publicly disclosed the specific date the unauthorized access occurred. The company reported that its review to identify affected individuals was substantially completed on August 28, 2026, and notification letters, including the filing with the Massachusetts Attorney General, followed shortly after.
What Information Was Breached?
According to Corpay’s notification, the information involved may have included an individual’s name, contact details such as an email address or physical address, and other categories of information tied to the individual’s specific relationship with the company. Corpay stated that no passwords or authentication credentials were involved in the incident.
What You Can Do
Corpay is offering complimentary identity monitoring services through Kroll, including credit monitoring, fraud consultation, and identity theft restoration, to individuals affected by this incident. If you received a notification letter from Corpay, consider taking the following steps:
- Enroll in the complimentary Kroll identity monitoring services described in your notification letter before the enrollment deadline.
- Review your financial account statements regularly for any unauthorized or suspicious activity.
- Consider placing a fraud alert or security freeze on your credit file with the three major credit bureaus.
- Remain cautious of unsolicited phone calls, emails, or texts referencing this incident, as scammers sometimes use news of a breach to attempt further fraud.
File a Data Breach Lawsuit Against Corpay
If you received a data breach notification letter from Corpay or believe your personal information was compromised in this incident, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.