Were you recently affected by a data breach?

Central National Gottesman Data Breach

Central National Gottesman, a paper and packaging company based in Purchase, New York, faces lawsuits after a 2026 ransomware attack exposed employees’ Social Security numbers, dates of birth, and other personal information.

Central National Gottesman
Date of Breach: March 2, 2026
CAU logo

Who was affected:

Clients of Central National Gottesman

Impacted Data:

Full names, Social Security numbers, dates of birth, home addresses, and other contact information belonging to current and former employees.

Central National Gottesman Inc., a fifth-generation family-owned paper, pulp, and packaging company headquartered in Purchase, New York, has been named in class action lawsuits after a 2026 ransomware attack compromised the personal information of current and former employees. The lawsuits allege that Central National Gottesman failed to implement reasonable data security measures to protect the sensitive information entrusted to it by its workforce.

Central National Gottesman’s Data Breach Investigation

Central National Gottesman Inc. is a global sales and marketing organization in the pulp, paper, and packaging industry, founded in 1886 and headquartered in Purchase, New York. The company sells products including paper stock for books and catalogs, newsprint, towels, diapers, cleaning tissue, packaging materials, paper pulp, and cans, and it employs more than 4,200 people across 29 offices worldwide, making it one of the largest privately held paper merchants in the country.

On March 2, 2026, the ransomware group known as Payoutsking, also referred to as Payouts King, claimed responsibility for a cyberattack on Central National Gottesman’s computer systems. According to the group’s public claims, the attack resulted in unauthorized access to internal company data before the group threatened to publish the stolen files if the company did not begin negotiations. As of this writing, Central National Gottesman has not publicly confirmed the incident or issued a detailed statement acknowledging the full scope of the breach, leaving many current and former employees uncertain about exactly what happened to their information.

Roughly a month later, two former employees, Alexis Romero of Bayshore, New York, and Samantha Campbell of Tarpon Springs, Florida, filed separate class action lawsuits against Central National Gottesman on April 6, 2026, in the U.S. District Court for the Southern District of New York in White Plains. Both complaints allege that the ransomware attack exposed the names, Social Security numbers, dates of birth, home addresses, and contact information of current and former employees, and that Central National Gottesman was negligent in failing to secure this information despite knowing the risks associated with storing large volumes of sensitive employee data.

According to the complaints, there has been no acknowledgement yet by the defendant that the data breach occurred, nor any assurances that the defendant is taking steps to protect the private information going forward. The lawsuits argue that Central National Gottesman should have known the risks inherent in collecting and storing employees’ personal information and had a duty to use reasonable safeguards, including intrusion detection systems capable of identifying a breach as it happens, so that affected individuals and law enforcement could be notified quickly and any resulting harm could be mitigated. The complaints further note that stolen personal information of this kind is frequently sold on dark web marketplaces, where it can be used to open fraudulent accounts, file false tax returns, or otherwise commit identity theft against victims for years after the initial exposure.

On July 22, 2026, a federal magistrate judge granted an unopposed motion to consolidate the Romero and Campbell lawsuits into a single action, now captioned In re Central National Gottesman Inc., Data Privacy Incident, Case No. 7:26-cv-03747, and appointed interim co-lead class counsel to represent the putative class going forward. The court noted that both cases arose from the same alleged data breach and asserted essentially identical theories of liability, making consolidation appropriate to promote judicial efficiency, coordinate discovery, and avoid duplicative litigation and inconsistent rulings across the two related actions.

Separately, New York’s Office of the Attorney General has received a data breach notification identifying 843 New York residents whose information may have been affected, indicating that at least some individuals have already been formally notified of the incident even though the company has not made a broad public statement addressing the breach directly to consumers or the media.

The consolidated lawsuit seeks at least $5 million in damages on behalf of a nationwide class of individuals whose personal information was taken from Central National Gottesman’s systems, along with lifetime credit monitoring and identity theft insurance for every affected person. Attorneys continue to investigate the scope of the breach, and additional plaintiffs may join the litigation as more information becomes available about how many people were affected nationwide and precisely what data was compromised in the incident.

When Did This Breach Occur?

Available records indicate the underlying cyberattack occurred on or around March 2, 2026, based on the ransomware group Payoutsking’s claim of responsibility for the intrusion into Central National Gottesman’s systems. It is not publicly known exactly when the company itself discovered the breach or when it began notifying affected individuals, since Central National Gottesman has not issued its own detailed public statement about the timeline. The class action lawsuits filed on April 6, 2026, roughly five weeks after the claimed attack date, are currently the most detailed public account of when the incident is alleged to have taken place. Individuals who received a notification letter from Central National Gottesman should rely on the date listed in that letter as the most accurate information about when their own data may have been exposed.

What Information Was Breached?

According to the class action complaints filed against Central National Gottesman, the data compromised in this incident includes current and former employees’ full names, Social Security numbers, dates of birth, home addresses, and other contact information. This type of information is considered highly sensitive because, once exposed, it generally cannot be changed the way a password or account number can. New York’s Attorney General’s Office has also received a formal breach notification covering 843 residents of that state, though the total number of people affected nationwide has not been publicly disclosed. Anyone who worked for Central National Gottesman, whether currently or in the past, should treat any notification letter from the company as an indication that some portion of this information may have been exposed.

What You Can Do

If you have received a notice from Central National Gottesman about this data breach, or believe your information may have been affected, there are several steps you can take to protect yourself. Enroll in any free credit monitoring or identity theft protection services offered in the notification letter. Place a fraud alert or security freeze on your credit files with all three major credit bureaus. Regularly review your bank and credit card statements, as well as your credit reports, for any unfamiliar activity. Be cautious of phishing emails, texts, or phone calls that reference the breach or ask you to confirm personal details. Consider changing passwords for any accounts that used the same login credentials, and enable multi-factor authentication wherever it is available. Keep any notification letter you received, along with records of any suspicious activity, in case you need to demonstrate that your information was compromised.

File a Data Breach Lawsuit Against Central National Gottesman

If you are a current or former employee of Central National Gottesman and believe your personal information was exposed in this data breach, you may be entitled to compensation. A class action lawsuit can hold companies accountable for failing to safeguard the private data they were trusted to protect, and a successful case may also require Central National Gottesman to strengthen its data security practices going forward. To learn whether you qualify to join a data breach lawsuit against Central National Gottesman, contact Class Action U today for a free case review.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General's office in August 2026
Date of Breach: August 2026
Date of Breach: August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.