Lawson Roofing, a fourth-generation San Francisco roofing and waterproofing company, has notified individuals that a network security incident may have exposed some of their personal information. The notice was filed with the California Attorney General’s office on July 22, 2026.
Companies that collect and store personal information, whether from customers, clients, or employees, have a legal and ethical responsibility to keep that information secure.
Lawson Roofing’s Data Breach Investigation
According to the notice, Lawson Roofing became aware of unusual activity in its network environment on or about April 28, 2026. The company promptly began an investigation and retained legal counsel and third-party forensic specialists to determine the scope and nature of the activity. That investigation determined that certain information may have been accessed and copied without authorization between April 23 and April 28, 2026. Lawson Roofing then conducted a comprehensive review of the affected data set to determine exactly what information was involved and whose it was, completing that review on July 8, 2026.
The version of the notice filed with the California Attorney General does not specify which categories of personal information were involved for the individuals it covers, and Lawson Roofing has not publicly disclosed how the unauthorized access occurred. The company is offering affected individuals single-bureau credit monitoring, credit report, and credit score services at no charge through Cyberscout, a TransUnion company, for twelve months from the date of enrollment.
Small and mid-sized contracting and service businesses like roofing companies are increasingly common targets for cyberattacks. These businesses often store sensitive customer and employee records, including Social Security numbers, payment information, and contact details, but may not always have the same level of dedicated cybersecurity infrastructure as larger enterprises, making them attractive targets for criminals seeking an easier point of entry into valuable personal data.
When unauthorized parties gain access to a company’s network for several days, as described in this notice, the risk is not limited to the specific files that were copied. Attackers who gain a foothold in a network environment can potentially view a wide range of stored records, and the true scope of what was accessed is not always fully knowable, which is one reason notification letters like this one often take weeks or months to finalize after an intrusion is first detected.
Regardless of the specific categories of information ultimately confirmed as affected, individuals who receive a notice like this one should treat it seriously. Unauthorized access to personal information, even when the exact data types are not yet disclosed publicly, can be used by criminals for identity theft, fraudulent account openings, phishing attempts, or other scams that specifically reference the breached company by name to appear more credible.
The nearly three-month gap between when Lawson Roofing first detected the unusual network activity in late April 2026 and when it finished reviewing exactly which records were affected in early July 2026 is not unusual for incidents of this kind. Determining precisely which files were accessed, and matching those files to specific individuals, often requires a lengthy forensic review, particularly when a company’s records include years of accumulated customer and employee data spread across multiple systems. Regulatory notification laws in California and other states generally require notice to affected individuals without unreasonable delay once the scope of a breach is known, which is why companies often wait until the investigation is substantially complete before sending letters, even though the underlying security incident happened months earlier.
Individuals who receive this kind of notice should also be alert to a secondary risk: follow-up phishing attempts that exploit public knowledge of the breach itself. Scammers sometimes send fake update or claim emails referencing a real, reported data breach in order to trick recipients into providing additional personal information or clicking malicious links. Anyone contacted about the Lawson Roofing incident should verify any follow-up communication directly through the official contact information provided in the notice itself, rather than clicking links in unsolicited messages.
When Did This Breach Occur?
Lawson Roofing states that unauthorized access to its network occurred between April 23 and April 28, 2026. The company says it became aware of unusual activity on or about April 28, 2026, and completed its review of the affected data on July 8, 2026, before notifying individuals and filing notice with the California Attorney General on July 22, 2026.
What Information Was Breached?
The notice filed with the California Attorney General does not specify which categories of personal information were involved. Lawson Roofing has not publicly disclosed additional detail beyond confirming that certain personal information may have been accessed and copied without authorization during the incident window.
What You Can Do
Lawson Roofing is offering affected individuals free single-bureau credit monitoring, credit report, and credit score services through Cyberscout, a TransUnion company, for twelve months from the date of enrollment. Affected individuals should consider taking the following steps:
- Enroll in the free credit monitoring services offered in the notice
- Review account statements and monitor credit reports for unauthorized activity
- Consider placing a fraud alert or security freeze on your credit file
- Watch for phishing emails, calls, or texts referencing this incident
- Report any suspected identity theft to your financial institutions and local law enforcement
File a Data Breach Lawsuit Against Lawson Roofing
If you received a notice about this incident, you may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.