Were you recently affected by a data breach?

Life Unlimited Data Breach

Life Unlimited, a Missouri nonprofit serving people with disabilities, discovered in 2026 that an unauthorized party accessed its network in early 2025, potentially exposing clients’ Social Security numbers, medical records, and financial information. Affected individuals are being notified and should act to protect their identity.

Life Unlimited
Date of Breach: January 20-25, 2025 (discovered/confirmed July 15, 2026; notification began September 4, 2026)
CAU logo

Who was affected:

Clients of Life Unlimited

Impacted Data:

Social Security numbers, dates of birth, driver’s license numbers, state identification numbers, financial account numbers (with or without password or routing number), health insurance application and claims information, patient account numbers, medical history, diagnosis, treatment information, dates of service, telephone numbers, email addresses, and names

Life Unlimited, a Missouri-based nonprofit that provides services and support to individuals with disabilities, recently began notifying certain clients that their personal information may have been exposed in a data security incident. The organization sent notification letters after determining that sensitive data was involved in the incident.

Organizations entrusted with sensitive personal, medical, and financial information, especially those serving vulnerable populations, have a responsibility to take reasonable steps to safeguard that data from unauthorized access.

Life Unlimited’s Data Breach Investigation

According to a notice posted to its website on September 4, 2026, Life Unlimited discovered that an unauthorized actor may have gained access to its network environment. Following an internal investigation and a manual review of the affected documents, the organization determined on July 15, 2026 that the impacted systems contained personal information belonging to clients and that this information had been accessed by an unauthorized party between approximately January 20 and January 25, 2025.

Life Unlimited began mailing notification letters to affected individuals on September 4, 2026. The organization also reported the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on September 5, 2026, as required by that state’s data breach notification law. As of this writing, Life Unlimited has not publicly disclosed how many individuals were affected nationwide, nor has it identified the specific method the unauthorized actor used to gain access to its systems.

The roughly eighteen-month gap between the initial unauthorized access and the notification to affected individuals is not unusual for incidents of this type. When a company or nonprofit detects suspicious activity on its network, it typically must first contain the intrusion, then conduct a forensic investigation to determine what actually happened, and finally undertake a document-by-document review to identify exactly whose information, and what categories of information, were present in the affected files. For an organization serving over a thousand individuals across multiple service lines, that review process alone can take many months, particularly when medical and financial records are involved and each file must be checked individually rather than through an automated search.

Nonprofits and human-services organizations like Life Unlimited are increasingly attractive targets for cybercriminals precisely because of the volume and sensitivity of the data they hold. Organizations that manage disability services, in-home care, and community support programs routinely collect and retain Social Security numbers, health insurance information, medical histories, and financial account details for the individuals and families they serve, often for years at a time. That combination of highly sensitive data, paired with the reality that many nonprofits operate with leaner IT security budgets than large corporations or hospital systems, can make them a comparatively soft target for hackers looking to harvest information that can be resold or used for identity theft and financial fraud.

The specific categories of information Life Unlimited says may have been exposed, Social Security numbers, driver’s license numbers, financial account numbers, health insurance claims information, and detailed medical history, together create a particularly high-risk profile for the people affected. Social Security numbers and driver’s license numbers can be used to open new lines of credit or file fraudulent tax returns, while financial account numbers can potentially be used to make unauthorized withdrawals or charges. Health insurance and medical information, meanwhile, can be exploited for medical identity theft, in which a criminal uses a victim’s insurance information to obtain treatment, equipment, or prescriptions in the victim’s name, potentially resulting in incorrect entries in the victim’s own medical records.

Data breach notification laws exist in all fifty states, and most require organizations to notify both affected individuals and the appropriate state regulator once the scope of an incident is understood. Massachusetts, where Life Unlimited reported this incident, is one of several states that also requires a description of the steps the organization has taken, or plans to take, in response to the breach. These laws are designed to give affected consumers timely, actionable information so they can take steps to protect themselves before their exposed information is misused, rather than learning about a breach only after fraud has already occurred.

Attorneys who represent consumers in data breach litigation are now reviewing whether Life Unlimited had reasonable security measures in place to protect this information and whether the delay between the unauthorized access and the eventual notification caused additional harm to those affected. A class action lawsuit, if filed, could seek to hold the organization accountable for any failure to adequately protect the data entrusted to it and to recover compensation for those whose information was compromised.

When Did This Breach Occur?

Life Unlimited says the unauthorized access to its network took place between approximately January 20 and January 25, 2025. The organization states it did not determine that personal information had actually been affected until July 15, 2026, following an investigation and a manual review of the impacted documents. Notification letters to affected individuals began going out on September 4, 2026, and the incident was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on September 5, 2026.

A lengthy interval between the date of unauthorized access and the date affected individuals are actually notified is common in breaches that require a document-level review to identify whose data was present in the compromised files, rather than a simple review of a database schema. State breach notification laws generally require notice to be sent without unreasonable delay once the scope of a breach is understood, but they typically allow additional time when a forensic investigation or law enforcement request is still underway.

What Information Was Breached?

According to Life Unlimited, the information that may have been exposed in the breach includes:

Names, Social Security numbers, dates of birth, driver’s license numbers, state identification numbers, financial account numbers (with or without an accompanying password or routing number), health insurance application and claims information, patient account numbers, medical histories, diagnoses, treatment information, dates of service, and telephone numbers and email addresses.

Life Unlimited has not publicly disclosed the total number of individuals affected by this incident.

What You Can Do

If you received a notification letter from Life Unlimited, or believe your information may have been affected by this breach, consider taking the following steps:

  • Carefully review the notification letter for any specific instructions or services Life Unlimited may be offering.
  • Monitor your bank and credit card statements for unfamiliar charges.
  • Request a free copy of your credit report from each of the three major credit bureaus and review it for accounts you did not open.
  • Consider placing a fraud alert or credit freeze on your credit file.
  • Review any Explanation of Benefits statements from your health insurer for services you did not receive.
  • Be alert to phishing emails, texts, or phone calls referencing the breach or asking you to confirm personal information.

File a Data Breach Lawsuit Against Life Unlimited

If your personal information was compromised in the Life Unlimited data breach, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: January 20-25, 2025 (discovered/confirmed July 15, 2026; notification began September 4, 2026)
Date of Breach: September 17 - October 9, 2025 (incident at vendor Mercadien, P.C., CPAs)
Date of Breach: November 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.