Central National Gottesman Inc., a fifth-generation family-owned paper, pulp, and packaging company headquartered in Purchase, New York, has been named in class action lawsuits after a 2026 ransomware attack compromised the personal information of current and former employees. The lawsuits allege that Central National Gottesman failed to implement reasonable data security measures to protect the sensitive information entrusted to it by its workforce.
Central National Gottesman’s Data Breach Investigation
Central National Gottesman Inc. is a global sales and marketing organization in the pulp, paper, and packaging industry, founded in 1886 and headquartered in Purchase, New York. The company sells products including paper stock for books and catalogs, newsprint, towels, diapers, cleaning tissue, packaging materials, paper pulp, and cans, and it employs more than 4,200 people across 29 offices worldwide, making it one of the largest privately held paper merchants in the country.
On March 2, 2026, the ransomware group known as Payoutsking, also referred to as Payouts King, claimed responsibility for a cyberattack on Central National Gottesman’s computer systems. According to the group’s public claims, the attack resulted in unauthorized access to internal company data before the group threatened to publish the stolen files if the company did not begin negotiations. As of this writing, Central National Gottesman has not publicly confirmed the incident or issued a detailed statement acknowledging the full scope of the breach, leaving many current and former employees uncertain about exactly what happened to their information.
Roughly a month later, two former employees, Alexis Romero of Bayshore, New York, and Samantha Campbell of Tarpon Springs, Florida, filed separate class action lawsuits against Central National Gottesman on April 6, 2026, in the U.S. District Court for the Southern District of New York in White Plains. Both complaints allege that the ransomware attack exposed the names, Social Security numbers, dates of birth, home addresses, and contact information of current and former employees, and that Central National Gottesman was negligent in failing to secure this information despite knowing the risks associated with storing large volumes of sensitive employee data.
According to the complaints, there has been no acknowledgement yet by the defendant that the data breach occurred, nor any assurances that the defendant is taking steps to protect the private information going forward. The lawsuits argue that Central National Gottesman should have known the risks inherent in collecting and storing employees’ personal information and had a duty to use reasonable safeguards, including intrusion detection systems capable of identifying a breach as it happens, so that affected individuals and law enforcement could be notified quickly and any resulting harm could be mitigated. The complaints further note that stolen personal information of this kind is frequently sold on dark web marketplaces, where it can be used to open fraudulent accounts, file false tax returns, or otherwise commit identity theft against victims for years after the initial exposure.
On July 22, 2026, a federal magistrate judge granted an unopposed motion to consolidate the Romero and Campbell lawsuits into a single action, now captioned In re Central National Gottesman Inc., Data Privacy Incident, Case No. 7:26-cv-03747, and appointed interim co-lead class counsel to represent the putative class going forward. The court noted that both cases arose from the same alleged data breach and asserted essentially identical theories of liability, making consolidation appropriate to promote judicial efficiency, coordinate discovery, and avoid duplicative litigation and inconsistent rulings across the two related actions.
Separately, New York’s Office of the Attorney General has received a data breach notification identifying 843 New York residents whose information may have been affected, indicating that at least some individuals have already been formally notified of the incident even though the company has not made a broad public statement addressing the breach directly to consumers or the media.
The consolidated lawsuit seeks at least $5 million in damages on behalf of a nationwide class of individuals whose personal information was taken from Central National Gottesman’s systems, along with lifetime credit monitoring and identity theft insurance for every affected person. Attorneys continue to investigate the scope of the breach, and additional plaintiffs may join the litigation as more information becomes available about how many people were affected nationwide and precisely what data was compromised in the incident.
When Did This Breach Occur?
Available records indicate the underlying cyberattack occurred on or around March 2, 2026, based on the ransomware group Payoutsking’s claim of responsibility for the intrusion into Central National Gottesman’s systems. It is not publicly known exactly when the company itself discovered the breach or when it began notifying affected individuals, since Central National Gottesman has not issued its own detailed public statement about the timeline. The class action lawsuits filed on April 6, 2026, roughly five weeks after the claimed attack date, are currently the most detailed public account of when the incident is alleged to have taken place. Individuals who received a notification letter from Central National Gottesman should rely on the date listed in that letter as the most accurate information about when their own data may have been exposed.
What Information Was Breached?
According to the class action complaints filed against Central National Gottesman, the data compromised in this incident includes current and former employees’ full names, Social Security numbers, dates of birth, home addresses, and other contact information. This type of information is considered highly sensitive because, once exposed, it generally cannot be changed the way a password or account number can. New York’s Attorney General’s Office has also received a formal breach notification covering 843 residents of that state, though the total number of people affected nationwide has not been publicly disclosed. Anyone who worked for Central National Gottesman, whether currently or in the past, should treat any notification letter from the company as an indication that some portion of this information may have been exposed.
What You Can Do
If you have received a notice from Central National Gottesman about this data breach, or believe your information may have been affected, there are several steps you can take to protect yourself. Enroll in any free credit monitoring or identity theft protection services offered in the notification letter. Place a fraud alert or security freeze on your credit files with all three major credit bureaus. Regularly review your bank and credit card statements, as well as your credit reports, for any unfamiliar activity. Be cautious of phishing emails, texts, or phone calls that reference the breach or ask you to confirm personal details. Consider changing passwords for any accounts that used the same login credentials, and enable multi-factor authentication wherever it is available. Keep any notification letter you received, along with records of any suspicious activity, in case you need to demonstrate that your information was compromised.
File a Data Breach Lawsuit Against Central National Gottesman
If you are a current or former employee of Central National Gottesman and believe your personal information was exposed in this data breach, you may be entitled to compensation. A class action lawsuit can hold companies accountable for failing to safeguard the private data they were trusted to protect, and a successful case may also require Central National Gottesman to strengthen its data security practices going forward. To learn whether you qualify to join a data breach lawsuit against Central National Gottesman, contact Class Action U today for a free case review.