Alkegen, the parent brand of ASP Unifrax Holdings, Inc., recently notified individuals that their personal information may have been exposed in a data security incident. The company began sending notification letters on July 17, 2026, alerting people that some of their sensitive information had been affected. Companies that manufacture and supply materials used across critical industries handle large volumes of personal and workforce data, and they carry a responsibility to keep that information secure from unauthorized access.
Alkegen’s Data Breach Investigation
ASP Unifrax Holdings, Inc., doing business as Alkegen, is a global materials manufacturer headquartered in Dallas, Texas. The company designs and produces specialty materials used in thermal management, filtration, fire protection, and battery applications, serving customers across a wide range of industrial sectors including automotive, aerospace, and energy storage. Alkegen has notified individuals that a data security incident has resulted in the exposure of personal information stored on its systems.
According to notifications filed with state regulators, including the Massachusetts Office of Consumer Affairs and Business Regulation and the Vermont Attorney General’s Office, Alkegen began mailing letters to affected individuals on July 17, 2026. The notification letter distributed by the company states that personal information was involved in the incident, and that Kroll identity monitoring services are being made available to affected individuals at no cost. The specific number of people affected, and the precise dates during which the unauthorized access occurred, have not yet been publicly disclosed in detail beyond the notification date itself.
The letter itself references that certain personal information was accessed, and public reporting on the incident by consumer-advocacy investigators has stated that the exposed information may include Social Security numbers and health-related records. Alkegen has arranged complimentary identity monitoring, fraud consultation, and identity theft restoration services through Kroll for individuals who received notice, with membership numbers and activation deadlines specified individually in each notification letter.
Manufacturing and industrial companies like Alkegen are common targets for cyberattacks because they often maintain large volumes of employee and business-partner data alongside proprietary operational systems, while historically investing less in cybersecurity infrastructure than sectors like finance or healthcare. Threat actors increasingly recognize that breaching an industrial supplier can expose not only the company’s own employees, but also sensitive information tied to a much wider network of business relationships and supply-chain partners.
When Social Security numbers and health information are exposed together, the risk to affected individuals is elevated substantially. Social Security numbers form the backbone of identity verification for banks, lenders, and government agencies, meaning a compromised number can be used to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. When paired with health-related information, criminals can also attempt medical identity theft, using a victim’s identity to obtain prescription medications, medical equipment, or healthcare services, which can corrupt a person’s own medical records and lead to billing complications that take months or years to fully unwind.
Notification timelines for data breaches can vary considerably depending on the complexity of the forensic investigation, the number of states involved, and applicable state and federal reporting requirements. Massachusetts, for example, requires notification to its Office of Consumer Affairs and Business Regulation as soon as practicable once a breach affecting Massachusetts residents is discovered, while other states allow longer windows. Because Alkegen’s notice was filed simultaneously across multiple states, the company appears to be treating this as a multi-state incident requiring coordinated regulatory disclosure.
Individuals who receive a notification letter from Alkegen should treat it seriously and take advantage of the credit monitoring services offered, even if they do not notice any signs of misuse right away. Identity thieves frequently wait months after obtaining stolen data before attempting to use it, in part to avoid triggering the kind of immediate fraud alerts that often accompany a publicized breach.
When Did This Breach Occur?
Alkegen has not publicly disclosed the specific dates on which the unauthorized access to its systems began or ended. What is known is that the company started notifying affected individuals on July 17, 2026, and disclosed the incident to state regulators, including Massachusetts and Vermont, around the same time. The notification letter sent to affected individuals references a recent data security incident but does not specify an exact breach window in the portions of the notice available to the public.
Companies are often required to complete a forensic investigation before determining the full scope of an incident, which can take weeks or months after unauthorized access is first detected. This process typically involves working with third-party cybersecurity firms to determine what systems were accessed, what data was involved, and which individuals need to be notified. Until that investigation is complete, exact incident dates are sometimes withheld from public notices even after individual notification letters have been mailed. If more specific information about the timeline of the Alkegen data breach becomes available, this page will be updated accordingly.
What Information Was Breached?
Alkegen’s notification letter confirms that personal information belonging to affected individuals was involved in the data security incident. Public reporting on the breach indicates that the exposed information may include Social Security numbers and health-related records, though the company’s own notification letter does not provide an itemized public list of every data element involved.
Because Alkegen has arranged complimentary Kroll identity monitoring services specifically for affected individuals, and because those services include triple-bureau credit monitoring, it is reasonable to infer that at least some individuals’ Social Security numbers were involved in the incident. Kroll’s identity monitoring services are most commonly offered following breaches that expose Social Security numbers or other information capable of supporting new-account fraud.
If you received a notification letter from Alkegen, review it carefully, as it should specify exactly which categories of your personal information were affected. Not every recipient of a breach notification necessarily had the same categories of information exposed, since notification letters are often customized based on what specific data was found to be at risk for each individual.
What You Can Do
If you received a data breach notification letter from Alkegen, there are several steps you can take to protect yourself:
- Enroll in the complimentary Kroll identity monitoring services referenced in your notification letter before the enrollment deadline.
- Review your credit reports from Equifax, Experian, and TransUnion for any unfamiliar accounts or inquiries.
- Consider placing a fraud alert or credit freeze on your credit files with the three major credit bureaus.
- Monitor your financial and healthcare accounts closely for any unauthorized activity.
- Keep your notification letter and any related correspondence in a safe place in case you need to reference it later.
Taking these steps promptly can help reduce your risk of identity theft and make it easier to catch any fraudulent activity early.
File a Data Breach Lawsuit Against Alkegen
If your personal information was exposed in the Alkegen data breach, you may have legal options available to you. Companies that collect and store sensitive personal information, including Social Security numbers and health-related data, have a legal and ethical responsibility to protect it from unauthorized access. When that data is compromised, affected individuals can be left vulnerable to identity theft, financial fraud, and years of ongoing monitoring and cleanup.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.