Friesen Group, a Redding, California-based company that provides accounting, human resources, marketing, and IT support to a family of affiliated businesses, has begun notifying individuals about a cyber security incident affecting its network. Companies entrusted with personal data, whether directly or through affiliated healthcare, real estate, and pharmacy services operations, have a responsibility to keep that information secure.
Friesen Group’s Data Breach Investigation
According to a notice filed with the California Attorney General, Friesen Group received a suspicious email on May 19, 2025, that indicated data stored on its network may have been at risk. The company says it immediately activated its incident response protocols and engaged independent computer forensic specialists to investigate. That investigation determined on July 15, 2025 that an unauthorized party had gained access to Friesen Group’s network for a limited period of time and may have accessed certain data. Friesen Group has stated it then worked with a data review team to determine which individuals were affected before beginning notifications.
The specific data elements involved were not filled in on the sample notice Friesen Group filed with the California Attorney General’s office, so the company’s own notice does not identify a confirmed universal list of the information exposed. Separately, firms investigating the incident on behalf of potentially affected individuals have referenced categories that could be at risk in an incident of this kind, including names, addresses, dates of birth, Social Security numbers, driver’s license or state identification numbers, health insurance information, medical records, and financial information, though Friesen Group’s own filed notice does not confirm which of these categories actually applied to any given individual.
Incidents like this one are common across small and mid-sized businesses that provide back-office services, such as accounting, human resources, and IT support, to other companies. These service providers often hold sensitive personal and financial data on behalf of multiple client organizations at once, which can make them an attractive target for hackers looking to access a large volume of records through a single point of entry. A breach at a business-services company can therefore expose the personal information of individuals connected not just to that company, but to the clients and affiliated organizations it supports.
The combination of data types potentially involved in a breach like this, including Social Security numbers, driver’s license numbers, and health insurance details, is particularly valuable to criminals because it can be used to open new credit accounts, file fraudulent tax returns, or submit false insurance claims in a victim’s name. Notification timelines for incidents like this can also vary widely. Friesen Group’s investigation reportedly determined unauthorized access occurred in mid-2025, with individual notification letters going out more than a year later in September 2026, a gap that is not unusual when forensic investigators must first determine the scope of an incident and identify exactly which individuals had their information involved before notices can be sent.
Business-services firms like Friesen Group occupy a sensitive middle position in the data security landscape. Because they act as a hub connecting multiple client organizations, a single vulnerability in their systems can create a much wider blast radius than a breach at any one of the individual client companies. Regulators and cybersecurity professionals have increasingly flagged vendors, contractors, and shared-services providers as a common weak point in an otherwise well-defended supply chain, since attackers understand that compromising one back-office provider can yield data belonging to dozens of downstream organizations at once. This dynamic has made robust vendor risk management, including regular security audits and encryption of data at rest and in transit, an important part of how companies in this position are expected to safeguard the information entrusted to them.
Anyone who receives a letter from Friesen Group regarding this incident should read it carefully and take advantage of any complimentary credit monitoring or identity protection services offered, since these services can help detect unauthorized use of personal information early.
When Did This Breach Occur?
Friesen Group’s notice states that a suspicious email first raised concern on May 19, 2025, and that its forensic investigation confirmed unauthorized network access as of July 15, 2025. Affected individuals were being notified in September 2026.
What Information Was Breached?
Friesen Group’s own filed notice does not specify a confirmed list of exposed data elements for the individuals it is notifying. Parties investigating the incident have referenced categories that could potentially be involved, including names, Social Security numbers, driver’s license or state ID numbers, health insurance information, medical records, and financial information, but individuals should refer to their own notification letter for the specific information that applied to them.
What You Can Do
If you received a notice from Friesen Group, consider taking the following steps:
- Enroll in any complimentary credit monitoring or identity protection service offered in your notification letter.
- Review your financial account statements and credit reports regularly for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus.
- Request a free annual credit report from each of the three major credit bureaus at annualcreditreport.com.
- Watch for phishing attempts referencing this incident, and never provide personal information in response to an unsolicited email or call.
File a Data Breach Lawsuit Against Friesen Group
If you received a notice that your personal information may have been exposed in the Friesen Group data breach, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.