Empower Group, a New York-based alternative financing provider, is reported to have experienced a data breach allegedly carried out by the threat actor DragonForce. Sensitive information, including Social Security numbers, names, and contact details, may have been exposed to unauthorized parties.
Empower Group’s Data Breach Investigation
Empower Group, known for offering alternative financing solutions to small- and medium-sized businesses, is currently under scrutiny following reports of a significant data breach. On April 16, 2026, the dark web monitoring site Ransomware.Live discovered that a cybercriminal group identified as DragonForce claimed to have exfiltrated approximately 316 GB of data from the company’s systems.
Subsequently, on May 26, 2026, DataBreach.com published what it described as an indexed database allegedly containing the compromised information. According to this post, the breach may have affected 6,691,415 rows of data, including highly sensitive personal information such as Social Security numbers, names, addresses, phone numbers, email addresses, and dates of birth. This volume of data, if accurate, represents a massive potential impact affecting Empower Group employees, investors, and clients.
At the time of reporting, Empower Group had not publicly confirmed the breach. The lack of official acknowledgment, however, does not diminish the potential risk to those whose information may have been exposed. Cybersecurity experts note that the scale of the claimed exfiltration by DragonForce indicates a serious compromise of systems that could leave individuals vulnerable to identity theft, financial fraud, and other cybercrimes.
Investigations into the breach are ongoing, and legal professionals are urging anyone affiliated with Empower Group who suspects their information could be at risk to come forward. Providing information to investigators can help identify the scope of the exposure and strengthen potential claims in legal proceedings. Cybersecurity specialists emphasize monitoring accounts, securing sensitive data, and being vigilant for phishing attempts or other suspicious communications in the aftermath of such breaches.
When Did This Breach Occur?
The alleged Empower Group data breach was first identified on April 16, 2026, by dark web monitoring site Ransomware.Live, with the exposed data reportedly posted online on May 26, 2026.
What Information Was Breached?
- Social Security numbers
- Names
- Addresses
- Phone numbers
- Email addresses
- Dates of birth
What You Can Do
If you are affiliated with Empower Group and believe your information may have been compromised, take the following steps:
- Monitor your accounts: Regularly review financial statements, banking, and credit accounts for unusual activity.
- Set up fraud alerts or credit freezes: This prevents new accounts from being opened in your name without authorization.
- Secure personal and professional emails: Change passwords and enable multi-factor authentication.
- Keep detailed records: Document any costs, time, or effort spent addressing potential impacts of the breach.
- Seek legal advice: Contact Class Action U to explore the possibility of joining a class action lawsuit to recover compensation for damages.
Prompt action can help protect your identity, mitigate financial harm, and support potential legal claims.
File a Data Breach Lawsuit Against Empower Group
Individuals affected by the Empower Group breach may be entitled to compensation for loss of privacy, time, and related costs. Filing a class action lawsuit can also help ensure Empower Group strengthens its data security measures.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or believe you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.