Were you recently affected by a data breach?

Knights of Columbus Data Breach

Knights of Columbus recently notified individuals that a security incident at a third-party vendor used for insurance underwriting record retrieval may have exposed some of their personal information. Contact Class Action U to learn about your legal options.

Knights of Columbus
Date of Breach: Vendor incident detected December 25, 2025; Knights of Columbus notified May 4, 2026; consumer notice filed with the Massachusetts Attorney General in early August 2026
CAU logo

Who was affected:

Clients of Knights of Columbus

Impacted Data:

Specific data types not clearly disclosed in the filed notice; the information involved reportedly varied by document and individual

Knights of Columbus recently notified individuals that their personal information may have been affected by a data security incident that occurred at AutoAPS, LLC, a vendor that performs medical record retrieval services in connection with underwriting solutions provided to Knights of Columbus. Organizations that rely on third-party vendors to process sensitive information as part of an insurance underwriting process still bear responsibility for making sure that data is properly protected, and affected individuals deserve clear answers when a vendor incident puts their information at risk.

Knights of Columbus’s Data Breach Investigation

According to a notification letter filed with the Massachusetts Attorney General’s office, AutoAPS’s third-party hosting vendor identified suspicious activity in its network on December 25, 2025. Upon discovering the activity, the hosting vendor says it took immediate steps to contain and remediate the incident and initiated a forensic investigation with the assistance of a cybersecurity firm. That forensic investigation was ultimately unable to determine conclusively whether any data was actually accessed or acquired by an unauthorized person. As a result, AutoAPS conducted its own comprehensive review of the data present in the affected environment at the time of the incident to determine what information could have been exposed. Knights of Columbus was formally notified of the incident on May 4, 2026.

This kind of vendor-chain breach, where the entity whose name appears on a consumer notice is not the same organization whose systems were actually compromised, has become increasingly common as insurers and membership organizations outsource specialized functions like medical record retrieval to third-party service providers. A security incident at any vendor in that chain, including a hosting provider one step further removed from the original company, can put the personal information of the ultimate policyholders or applicants at risk even though those individuals never directly interacted with the vendor.

Insurance underwriting records are a particularly sensitive category of data because they routinely combine identifying information with medical history, making a breach involving this type of vendor more consequential than one involving purely administrative records. Offering identity protection services and encouraging affected individuals to monitor their accounts, as described in this notice, is a standard response even when a forensic investigation cannot conclusively confirm that data was accessed, since the potential exposure alone is treated as reason enough to notify and protect those affected.

The roughly four-month gap between the vendor’s discovery of the incident in late December 2025 and Knights of Columbus’s own notification in May 2026 is not unusual in vendor-chain incidents, where a forensic review and a comprehensive document-level analysis must typically be completed before the ultimate client organization can determine which of its own members or applicants were affected and begin the notification process.

When Did This Breach Occur?

AutoAPS’s third-party hosting vendor identified suspicious network activity on December 25, 2025. Knights of Columbus was notified of the incident on May 4, 2026, and the consumer notification letter was filed with the Massachusetts Attorney General’s office in early August 2026.

What Information Was Breached?

The notice states that the information involved varied by document and individual, but does not provide a single universal list of data types in the publicly filed version available. Individuals who received a personalized letter directly may have more specific information about what data was involved in their particular case.

What You Can Do

If you received a notice regarding this Knights of Columbus / AutoAPS incident, consider taking the following steps to protect yourself:

  • Enroll in the complimentary IDX identity protection membership described in the notification letter, including credit and CyberScan monitoring.
  • Regularly review your account statements and free credit reports for any unauthorized activity.
  • Consider placing a fraud alert or a security freeze on your credit file with Equifax, Experian, and TransUnion.
  • Request a free copy of your credit report at annualcreditreport.com.
  • Report any signs of identity theft to your state Attorney General and the Federal Trade Commission at identitytheft.gov.

File a Data Breach Lawsuit Against Knights of Columbus

If you received a notice about this data security incident affecting Knights of Columbus applicants or members, you may have legal options available to you. Organizations that collect sensitive personal and medical information, whether directly or through a vendor, are expected to ensure that information is properly secured, and when a breach occurs, affected individuals may be entitled to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported August 2026 (unconfirmed)
Date of Breach: Discovered and disclosed August 24, 2026
Date of Breach: Reported to HHS OCR on June 23, 2026 (exact breach date not yet public)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.