Were you recently affected by a data breach?

Aprio Advisory Group Data Breach

Aprio Advisory Group, LLC, a national business advisory and accounting firm, notified state regulators of a data security incident affecting 500 individuals. The breach involved names, Social Security numbers, financial account information, and medical information, and the company has since notified affected individuals by mail.

Aprio Advisory Group
Date of Breach: Not publicly disclosed
CAU logo

Who was affected:

Clients of Aprio Advisory Group

Impacted Data:

Names, Social Security numbers, financial account information, medical information

Aprio Advisory Group, LLC, a large business advisory, tax, and accounting firm headquartered in Atlanta, Georgia, has notified state regulators of a data security incident affecting 500 individuals. The company reported the incident to the Kansas Attorney General’s office and has notified affected individuals by mail.

Companies that handle sensitive financial and personal information as part of their advisory and accounting services have a heightened responsibility to protect that data, given the range of harm that can follow when Social Security numbers, financial account details, and medical information fall into the wrong hands.

Aprio Advisory Group, LLC’s Data Breach Investigation

According to a filing with the Kansas Attorney General’s office, Aprio Advisory Group notified regulators of a data security incident affecting 500 individuals whose information may have been exposed. The filing indicates the affected data included names, Social Security numbers, financial account information, and medical information. Affected individuals have been notified by U.S. Mail, and the filing was published at the Kansas Attorney General’s office on September 21, 2026.

Aprio’s own public notification does not disclose the specific cause of the incident, when it occurred, or when the company first detected it. As a large, multi-service business advisory firm providing tax, audit, wealth management, and legal-adjacent services to clients across the country, Aprio would have collected exactly the kind of client and employee financial and personal data that makes accounting and advisory firms attractive targets for cybercriminals seeking Social Security numbers and financial account details in one place.

Accounting, tax, and financial advisory firms have increasingly become targets of data breaches and cyberattacks in recent years, largely because these firms function as centralized repositories of exactly the kind of sensitive financial data, Social Security numbers, bank account and routing numbers, tax identification numbers, that criminals can use to commit identity theft, file fraudulent tax returns, or open unauthorized credit accounts. A single firm serving thousands of individual and business clients can represent a much larger trove of exploitable data than any single client’s own records, making these firms high-value targets even when they are not household names to the general public.

When a breach involves a combination of Social Security numbers, financial account information, and medical information, as this filing indicates, the resulting risk to affected individuals is often broader than a typical breach involving only one category of data. Financial information can enable direct account takeover or fraudulent transactions, Social Security numbers can be used to open new credit lines or file fraudulent tax returns, and medical information can be used to commit medical identity theft, such as fraudulently obtaining prescription medications or medical services under a victim’s identity. Because these different types of fraud can surface on different timelines, sometimes months or years after a breach, affected individuals are generally advised to monitor their accounts and records well beyond any free credit monitoring period a company may offer.

State attorney general notification filings like the one Aprio submitted to Kansas are often the only public source of information about a breach’s scope in its early stages, particularly when a company has not yet issued its own detailed public statement. These filings can also understate the true reach of an incident, since a company may be required to separately notify regulators in every state where affected individuals reside, and the filing referenced here reflects only what has been reported to Kansas regulators to date.

Under most state data breach notification laws, a business is generally required to notify affected residents and the relevant state attorney general within a specific timeframe after discovering that personal information has been compromised, often somewhere between 30 and 60 days depending on the state. Some states additionally require notification to consumer reporting agencies when the number of affected residents exceeds a certain threshold. Because Aprio serves clients across dozens of states through its accounting, tax, and advisory practices, additional state filings beyond the Kansas notice referenced here may exist or may still be forthcoming as the company works through its notification obligations in each jurisdiction where affected individuals reside.

Regardless of a company’s size or reputation, a data breach affecting client financial and medical records can carry real consequences for the individuals whose information was exposed, even when the company itself faces limited direct financial harm. Clients of accounting and advisory firms often have little visibility into, or control over, how securely their sensitive information is stored once it leaves their hands, which is part of why courts and regulators increasingly hold firms handling this kind of data to a high standard of care.

When Did This Breach Occur?

The exact date of the breach and when it was discovered have not been publicly disclosed. The incident was reported to the Kansas Attorney General’s office, with the filing published September 21, 2026, and affected individuals have been notified by mail.

What Information Was Breached?

Names, Social Security numbers, financial account information, and medical information were affected, according to the state filing.

What You Can Do

If you received a breach notification letter from Aprio Advisory Group, consider taking the following steps:

  • Monitor your credit reports and any free credit monitoring service offered in the notification letter
  • Place a fraud alert or credit freeze with the three major credit bureaus
  • Watch for unauthorized financial transactions or unfamiliar medical bills
  • Report any suspected identity theft to the FTC at identitytheft.gov

File a Data Breach Lawsuit Against Aprio Advisory Group, LLC

If your personal, financial, or medical information was exposed in this data security incident, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: March 6, 2026
Date of Breach: June 5, 2026 - July 24, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.