Were you recently affected by a data breach?

Corpay Data Breach

Corpay (Cambridge Mercantile Corp.) notified individuals that an unauthorized third party may have accessed personal information, including names and contact details, held in connection with its payment and foreign exchange services.

Corpay
Date of Breach: Not publicly disclosed; review completed August 28, 2026
CAU logo

Who was affected:

Clients of Corpay

Impacted Data:

Names, contact details (email or physical address)

Corpay, the trading name used by Cambridge Mercantile Corp. (U.S.A.), has notified individuals that some of their personal information may have been accessed without authorization. Corpay provides cross-border payment and foreign exchange services to businesses and their employees or associates, and companies that manage this kind of financial data have a responsibility to keep it secure.

Corpay’s Data Breach Investigation

Corpay reported that it identified a data security incident affecting personal information related to individuals connected to the company through a business relationship, either directly or through an employer. Corpay stated that it performed a comprehensive review to identify potentially affected individuals, an effort that was substantially completed on August 28, 2026. The company said an unauthorized third party may have accessed certain personal information as a result of the incident. Corpay reported no evidence to date of fraud, identity theft, or other misuse of the information involved, and said the incident has not affected customer funds, payment processing, transaction execution, or the availability of its services.

Data breaches involving financial services and payment processing companies like Corpay are a common target for cybercriminals because these companies routinely handle large volumes of sensitive personal and financial information as part of processing cross-border transactions. Companies in the payments space are attractive targets precisely because a single compromised system can expose records tied to many individuals and business relationships at once.

Following incidents like this, affected individuals are often at increased risk of follow-up phishing attempts, where scammers pose as the breached company, a bank, or a credit monitoring service in order to extract additional personal information. Corpay’s response, which included engaging third-party security experts, enhancing its security and monitoring practices, and offering complimentary identity monitoring services through Kroll, reflects steps companies are increasingly expected to take once a security incident affecting personal data is confirmed.

Notification timelines for incidents like this can vary considerably depending on the complexity of the investigation and the scope of the review needed to identify every individual whose information may have been affected. In Corpay’s case, the company indicated its review process concluded in late August 2026, after which notification letters were prepared and sent to potentially impacted individuals, including the Massachusetts Attorney General filing that made this notice public.

When Did This Breach Occur?

Corpay has not publicly disclosed the specific date the unauthorized access occurred. The company reported that its review to identify affected individuals was substantially completed on August 28, 2026, and notification letters, including the filing with the Massachusetts Attorney General, followed shortly after.

What Information Was Breached?

According to Corpay’s notification, the information involved may have included an individual’s name, contact details such as an email address or physical address, and other categories of information tied to the individual’s specific relationship with the company. Corpay stated that no passwords or authentication credentials were involved in the incident.

What You Can Do

Corpay is offering complimentary identity monitoring services through Kroll, including credit monitoring, fraud consultation, and identity theft restoration, to individuals affected by this incident. If you received a notification letter from Corpay, consider taking the following steps:

  • Enroll in the complimentary Kroll identity monitoring services described in your notification letter before the enrollment deadline.
  • Review your financial account statements regularly for any unauthorized or suspicious activity.
  • Consider placing a fraud alert or security freeze on your credit file with the three major credit bureaus.
  • Remain cautious of unsolicited phone calls, emails, or texts referencing this incident, as scammers sometimes use news of a breach to attempt further fraud.

File a Data Breach Lawsuit Against Corpay

If you received a data breach notification letter from Corpay or believe your personal information was compromised in this incident, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
SMG
Date of Breach: March 18 to April 7, 2026 (detected March 31, 2026)
Date of Breach: June 3, 2026
Date of Breach: Notification dated August 6, 2026; incident date not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.