Were you recently affected by a data breach?

CAZ Investments Data Breach

CAZ Investments LP, a Houston-based alternative asset manager, notified the Texas Attorney General of a data breach affecting 3,824 people. Exposed data may include Social Security numbers, driver’s license numbers, and financial account information.

CAZ Investments
Date of Breach: Not publicly disclosed
CAU logo

Who was affected:

Clients of CAZ Investments

Impacted Data:

Names, addresses, Social Security numbers, driver’s license numbers, government-issued ID numbers, financial account information, dates of birth

CAZ Investments LP has disclosed a data breach that may have exposed sensitive personal and financial information belonging to thousands of individuals. Companies entrusted with Social Security numbers and financial account details carry a responsibility to protect that information from unauthorized access.

CAZ Investments’s Data Breach Investigation

CAZ Investments LP, a Houston, Texas-based alternative investment firm headquartered at 1360 Post Oak Blvd, filed a data breach notification with the Texas Attorney General’s Office reporting that 3,824 individuals were affected. The company notified affected individuals by U.S. Mail, and the notice was published to the Texas Attorney General’s data security breach report on September 29, 2026. CAZ Investments has not publicly disclosed the specific cause of the incident, the date the breach occurred, or the date it was discovered.

Financial services and asset management firms are frequent targets for cyberattacks because they maintain large repositories of client Social Security numbers, government-issued identification numbers, and account-level financial data in one place. A single successful intrusion at a firm like CAZ Investments can expose a wide range of sensitive identifiers that criminals can exploit for years afterward, not just at the moment of the breach itself.

The combination of data types reportedly involved in this incident, including Social Security numbers, driver’s license numbers, and financial account information, is considered especially high-risk. Criminals can combine these data elements to open new credit lines, file fraudulent tax returns, or gain access to existing financial accounts, making this type of breach more dangerous to victims than incidents involving names and email addresses alone.

State data breach notification laws, including the Texas Identity Theft Enforcement and Protection Act, generally require companies to notify affected residents and the Attorney General’s Office without unreasonable delay once a breach involving sensitive personal information is discovered. Firms that manage significant amounts of client wealth, like CAZ Investments, are often held to a heightened expectation of promptly identifying and disclosing security incidents given the scale of financial harm a delay could cause.

Investment management firms typically maintain extensive client onboarding records, including copies of government-issued identification and account funding documentation, in order to comply with anti-money-laundering and know-your-customer regulations. While these recordkeeping requirements serve a legitimate regulatory purpose, they also mean that a breach at a firm like CAZ Investments can expose a far more complete profile of an individual’s identity than a breach at a retailer or service provider that collects only limited contact information.

Victims of breaches involving Social Security numbers and driver’s license numbers often do not see the effects immediately. Stolen identity data is frequently held or sold on criminal marketplaces before being used, sometimes months or years after the original breach, which is why credit monitoring and account vigilance need to continue well beyond the initial notification period rather than stopping once the immediate news cycle passes.

The Texas Attorney General’s Office maintains a public data security breach report specifically so residents can check whether a company holding their information has experienced an incident, even when that company has not separately advertised the breach. CAZ Investments’s filing became part of that public record on September 29, 2026, listing 3,824 affected Texans and confirming that written notice was sent by U.S. Mail. Individuals who manage investment accounts, retirement funds, or other assets through firms like CAZ Investments are encouraged to periodically check that report, as well as their own account statements, for any indication their information has been misused.

Because CAZ Investments has not yet released a detailed public statement describing the root cause of the incident, affected individuals are left relying primarily on the brief description filed with regulators. This is a common pattern in early breach disclosures, and additional details, including the underlying cause and a more precise timeline, sometimes follow in later supplemental notices as a company’s own investigation continues.

When Did This Breach Occur?

CAZ Investments has not publicly disclosed the specific date or timeframe of the breach, nor when it was discovered. The company’s notification to the Texas Attorney General’s Office was published on September 29, 2026, and affected individuals were notified by U.S. Mail. As more information becomes available, this page will be updated with additional details about the timeline of the incident.

What Information Was Breached?

According to the notification filed with the Texas Attorney General’s Office, the information involved in this breach may include:

Names, addresses, Social Security numbers, driver’s license numbers, other government-issued identification numbers, financial account or payment card information, and dates of birth.

CAZ Investments has not publicly specified which categories of information applied to which individuals, or whether every affected person had all of the listed data types exposed.

What You Can Do

If you received a notification letter from CAZ Investments, or believe you may have been affected by this breach, consider taking the following steps to protect yourself:

  • Review your financial account and credit card statements closely for any unauthorized or unfamiliar activity.
  • Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to make it harder for identity thieves to open new accounts in your name.
  • Obtain and review your free credit reports at annualcreditreport.com for signs of identity theft.
  • Be cautious of unsolicited calls, emails, or letters asking you to confirm personal or financial details, as scammers sometimes exploit breach news to run follow-up phishing schemes.
  • Consider enrolling in identity theft protection or credit monitoring services if offered by CAZ Investments.

File a Data Breach Lawsuit Against CAZ Investments

If you were notified that your personal information was exposed in the CAZ Investments data breach, you may have legal options available to you. Companies that collect sensitive financial and personal data have a duty to protect it, and a breach affecting thousands of people raises serious questions about whether that duty was met.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: Not publicly disclosed
Date of Breach: August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.