Were you recently affected by a data breach?

McKenzie Creative Brands Data Breach

McKenzie Creative Brands filed a data breach notice with the Massachusetts Attorney General, saying it determined on or about September 14, 2026 that a cybersecurity incident may have involved personal information.

McKenzie Creative Brands
Date of Breach: Determined on or about September 14, 2026; incident dates not disclosed
CAU logo

Who was affected:

Clients of McKenzie Creative Brands

Impacted Data:

Categories of personal information have not been publicly disclosed

McKenzie Creative Brands filed a data breach notice with the Massachusetts Attorney General after a cybersecurity incident that may have involved personal information. The company says it determined this on or about September 14, 2026.

McKenzie Creative Brands’s Data Breach Investigation

In a notice filed with the Massachusetts Attorney General’s office, the company told affected people that it had experienced a recent cybersecurity incident that potentially involved their personal information. The company says the privacy and security of the personal information it maintains is of the utmost importance and that it wrote to explain what happened and what precautions people can take.

The filed copy of the notice is a sample letter and several lines in it are blank. It does not give the date the incident began, the date it was discovered, how the information was accessed, how many people were notified, or the contact information for the company’s assistance line. The line that should list the categories of personal information involved is also missing from the filed copy, so those categories have not been publicly described. No public count of affected people has been published so far. We are not guessing at what the missing details might be.

What the notice does say is that the company reviewed the impacted information and, on or about September 14, 2026, determined that certain personal information may have been involved. It says it is committed to maintaining the privacy of personal information entrusted to it, and that it continually evaluates and modifies its practices and internal controls to improve the security and privacy of personal information. The notice does not describe any specific new security measures.

The letter suggests that, as a best practice, people who see suspicious transactions should call their bank or card issuer and ask whether a new card should be issued. That advice hints at payment card or financial account information, but the notice does not actually confirm which categories were involved, so readers should not assume either way.

A consumer-facing brand typically holds customer names, shipping and billing addresses, order histories and payment details, and may also hold employee and vendor records. The notice does not say whether any of those records were involved. We mention them only as general background on what retailers and brands commonly keep.

The notice includes standard guidance on protecting yourself. It recommends placing a one-year fraud alert on your credit files at no charge, and it explains that a security freeze can be requested for free with each of the three major credit bureaus. It reminds people that they can get a free credit report from each bureau every 12 months through annualcreditreport.com, and it encourages regular review of financial statements and credit reports for irregular activity.

The notice also explains the rights of Massachusetts residents, including the right to obtain a police report about the incident and, if they are a victim of identity theft, to file a police report and obtain a copy. It notes that anyone who finds suspicious activity can file a complaint with the Federal Trade Commission.

The notice does not say whether the company hired outside cybersecurity specialists, notified law enforcement, or is offering free credit monitoring or identity protection. We will update this page if McKenzie Creative Brands or a regulator publishes more detail, including the dates of the incident, the categories of information involved and the number of people notified.

Months can pass between an incident and the letter that tells people about it, because a company has to work out which records were touched and whose information they contain. If you have bought from, worked for, or done business with the company, watch your mail for a letter and keep it with your records.

When Did This Breach Occur?

McKenzie Creative Brands says it determined on or about September 14, 2026 that certain personal information may have been involved in a cybersecurity incident. The company has not publicly stated when the incident began or when it was first discovered.

What Information Was Breached?

The filed sample notice does not list the categories of personal information involved, and the company has not published a list. It does suggest contacting a bank or card issuer about suspicious transactions, but it does not confirm which types of information were affected.

What You Can Do

If you received a notice from McKenzie Creative Brands, consider these steps:

  • Review your bank and card statements for anything you do not recognize, and report it to your bank or card issuer right away.
  • Ask your card issuer whether you should get a replacement card.
  • Place a free one-year fraud alert on your credit files, and consider a security freeze with Equifax, Experian and TransUnion.
  • Check your credit reports for free at annualcreditreport.com and look for accounts or inquiries you do not recognize.
  • Report suspected identity theft to the Federal Trade Commission and your state Attorney General.

File a Data Breach Lawsuit Against McKenzie Creative Brands

If you received a notice that your information may have been involved in a McKenzie Creative Brands data breach, or you believe your information was put at risk, you may be entitled to compensation. Companies that collect personal information are expected to take reasonable steps to protect it, and people affected by a breach can face fraud, lost time and ongoing worry about misuse.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Texas Attorney General on October 2, 2026; incident date not disclosed
Date of Breach: Determined on or about September 14, 2026; incident dates not disclosed
Date of Breach: Notice dated September 28, 2026; incident dates not disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.