Were you recently affected by a data breach?

CSC Data Breach

CSC, the corporate registered agent and compliance services firm formally known as Corporation Service Company, disclosed a data breach exposing Social Security numbers after ransomware group CL0P claimed responsibility for an October 2025 dark web leak, reported to the Vermont Attorney General in August 2026.

CSC
Date of Breach: Not yet publicly disclosed by CSC (CL0P dark web claim dated October 21, 2025; reported to Vermont AG August 13, 2026)
CAU logo

Who was affected:

Clients of CSC

Impacted Data:

Social Security numbers

CSC, formally known as Corporation Service Company, is a Wilmington, Delaware-based firm that provides registered agent, business compliance, tax, and legal support services to corporations across the country. Companies like CSC are entrusted with sensitive business and personal information belonging to their corporate clients and, by extension, the individuals those clients represent, so when a cyberattack is claimed against a company handling this volume of sensitive data, those potentially affected deserve a clear account of what is known so far.

CSC’s Data Breach Investigation

On October 21, 2025, the ransomware and data-extortion group CL0P posted a claim on a dark web leak site asserting that it had obtained data belonging to CSC. The claim, made nearly ten months before CSC’s incident was formally reported to state regulators, is one of the ways cybercriminal groups apply pressure on corporate victims: by threatening to publish stolen files unless a ransom is paid. CSC reported the breach to the Vermont Attorney General’s office on August 13, 2026, along with several other state regulators, though as of this writing the company has not issued a detailed public statement confirming the full scope, method of intrusion, or root cause of the incident.

CL0P is a well-known, financially motivated ransomware and extortion group that has been linked to some of the largest and most consequential data breaches of the past several years, including mass attacks that exploited vulnerabilities in third-party file-transfer software used by hundreds of companies simultaneously. Rather than encrypting a victim’s systems outright, CL0P and similar groups increasingly favor a double-extortion model: they infiltrate a target’s network, quietly copy or exfiltrate files containing sensitive information, and then threaten to publish that stolen data on a dark web leak site unless the victim pays. This approach lets the attackers apply pressure even when a company has strong backups and can restore its own systems without paying a ransom, because the threat centers on the exposure of confidential information rather than system availability.

As a company at the intersection of the corporate compliance and legal-services industries, CSC handles registered agent filings, corporate formation documents, UCC lien searches, and related compliance work for businesses ranging from small startups to Fortune 500 companies. This role means CSC’s systems can potentially hold not only its own employees’ personal information but also sensitive records tied to its corporate clients and, in some cases, individuals connected to those clients. Companies that serve as a centralized repository of this kind of information are attractive targets for ransomware and extortion groups precisely because a single successful intrusion can expose data belonging to a wide and varied set of victims.

According to CSC’s notification, the personal information exposed in the breach included Social Security numbers. Beyond this specific confirmation, CSC has not publicly detailed the exact number of individuals affected, the specific method the attackers used to gain access to its network, or the full extent of the data that may have been copied. The roughly ten-month gap between CL0P’s initial October 2025 dark web claim and the company’s August 2026 regulatory notifications is not unusual for incidents of this kind, since companies frequently spend months conducting a forensic investigation, determining the scope of a possible compromise, and preparing legally required notifications before they can share information publicly, even after a claim first surfaces from a hacking group.

State data breach notification laws generally require companies to notify affected individuals and regulators once an investigation has determined that personal information was likely compromised, but that determination itself can take a substantial amount of time. A company must typically first confirm that unauthorized access occurred, work with forensic investigators and outside counsel to determine what categories of data were involved, identify which individuals were affected, and prepare notification letters and regulatory filings consistent with each applicable state’s specific legal requirements. When a claim originates from a hacking group’s own dark web post rather than internal detection, a company may also need extra time to verify whether the claim is credible and accurate before it can respond publicly with confidence.

When a Social Security number is exposed in a data breach, the risk to affected individuals extends well beyond the immediate incident. Social Security numbers are a key piece of identifying information used across financial institutions, government agencies, and other services, and once exposed they can be used by criminals to open new lines of credit, file fraudulent tax returns, or otherwise impersonate the victim in ways that can be difficult and time-consuming to unwind. Because Social Security numbers cannot be changed as easily as a password or account number, individuals whose SSNs are compromised in an incident like this one are often encouraged to take precautionary steps for an extended period following any notification, not just in the immediate aftermath.

When Did This Breach Occur?

The exact date CSC’s systems were first compromised has not been publicly disclosed. What is known is that the ransomware group CL0P posted a claim on the dark web on October 21, 2025, asserting it had obtained CSC’s data, meaning the underlying intrusion likely occurred at or before that date, though CSC has not independently confirmed a specific breach date. CSC reported the incident to the Vermont Attorney General’s office on August 13, 2026, and appears to have notified several other state attorneys general and federal agencies around the same time, based on publicly available breach-tracking records. CSC has not published a specific breach-discovery date or notification-mailing date distinct from the regulatory filing date. This page will be updated if CSC or a state regulator releases additional information clarifying the breach, discovery, or notification timeline.

What Information Was Breached?

CSC has confirmed that Social Security numbers were among the personal information exposed in this breach. The company has not published a complete, itemized list of every category of information involved, and it is not yet publicly known how many individuals were affected or whether the exposed data also included other personal details such as names, addresses, dates of birth, or financial account information. Given CSC’s role providing registered agent, compliance, and related business services, information at risk in an incident like this can extend to records tied to corporate clients as well as the company’s own employees. This page will be updated if CSC or a state regulator discloses additional detail about the specific data types or number of individuals involved.

What You Can Do

Anyone concerned that their personal information may have been exposed in the CSC breach should consider the following steps while more details become available:

  • Monitor bank and credit card statements closely for unfamiliar or unauthorized activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus, particularly given the confirmed exposure of Social Security numbers.
  • Watch for phishing emails, calls, or letters that reference CSC or claim to offer breach-related assistance.
  • Keep any official notification letter you receive, since it can serve as evidence that you were affected by this specific incident.

File a Data Breach Lawsuit Against CSC

If it is confirmed that CSC failed to adequately protect the personal information entrusted to it, affected individuals may be entitled to pursue compensation through a class action lawsuit. A successful case could also require the company to strengthen its data security practices going forward.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: April 11-13, 2026 (discovered April 12, 2026)
Date of Breach: Not publicly disclosed (reported via Massachusetts Attorney General filing, August 2026)
Date of Breach: June 11-17, 2026 (discovered June 15, 2026; notification began after a review completed July 30, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.