McKenzie Creative Brands filed a data breach notice with the Massachusetts Attorney General after a cybersecurity incident that may have involved personal information. The company says it determined this on or about September 14, 2026.
McKenzie Creative Brands’s Data Breach Investigation
In a notice filed with the Massachusetts Attorney General’s office, the company told affected people that it had experienced a recent cybersecurity incident that potentially involved their personal information. The company says the privacy and security of the personal information it maintains is of the utmost importance and that it wrote to explain what happened and what precautions people can take.
The filed copy of the notice is a sample letter and several lines in it are blank. It does not give the date the incident began, the date it was discovered, how the information was accessed, how many people were notified, or the contact information for the company’s assistance line. The line that should list the categories of personal information involved is also missing from the filed copy, so those categories have not been publicly described. No public count of affected people has been published so far. We are not guessing at what the missing details might be.
What the notice does say is that the company reviewed the impacted information and, on or about September 14, 2026, determined that certain personal information may have been involved. It says it is committed to maintaining the privacy of personal information entrusted to it, and that it continually evaluates and modifies its practices and internal controls to improve the security and privacy of personal information. The notice does not describe any specific new security measures.
The letter suggests that, as a best practice, people who see suspicious transactions should call their bank or card issuer and ask whether a new card should be issued. That advice hints at payment card or financial account information, but the notice does not actually confirm which categories were involved, so readers should not assume either way.
A consumer-facing brand typically holds customer names, shipping and billing addresses, order histories and payment details, and may also hold employee and vendor records. The notice does not say whether any of those records were involved. We mention them only as general background on what retailers and brands commonly keep.
The notice includes standard guidance on protecting yourself. It recommends placing a one-year fraud alert on your credit files at no charge, and it explains that a security freeze can be requested for free with each of the three major credit bureaus. It reminds people that they can get a free credit report from each bureau every 12 months through annualcreditreport.com, and it encourages regular review of financial statements and credit reports for irregular activity.
The notice also explains the rights of Massachusetts residents, including the right to obtain a police report about the incident and, if they are a victim of identity theft, to file a police report and obtain a copy. It notes that anyone who finds suspicious activity can file a complaint with the Federal Trade Commission.
The notice does not say whether the company hired outside cybersecurity specialists, notified law enforcement, or is offering free credit monitoring or identity protection. We will update this page if McKenzie Creative Brands or a regulator publishes more detail, including the dates of the incident, the categories of information involved and the number of people notified.
Months can pass between an incident and the letter that tells people about it, because a company has to work out which records were touched and whose information they contain. If you have bought from, worked for, or done business with the company, watch your mail for a letter and keep it with your records.
When Did This Breach Occur?
McKenzie Creative Brands says it determined on or about September 14, 2026 that certain personal information may have been involved in a cybersecurity incident. The company has not publicly stated when the incident began or when it was first discovered.
What Information Was Breached?
The filed sample notice does not list the categories of personal information involved, and the company has not published a list. It does suggest contacting a bank or card issuer about suspicious transactions, but it does not confirm which types of information were affected.
What You Can Do
If you received a notice from McKenzie Creative Brands, consider these steps:
- Review your bank and card statements for anything you do not recognize, and report it to your bank or card issuer right away.
- Ask your card issuer whether you should get a replacement card.
- Place a free one-year fraud alert on your credit files, and consider a security freeze with Equifax, Experian and TransUnion.
- Check your credit reports for free at annualcreditreport.com and look for accounts or inquiries you do not recognize.
- Report suspected identity theft to the Federal Trade Commission and your state Attorney General.
File a Data Breach Lawsuit Against McKenzie Creative Brands
If you received a notice that your information may have been involved in a McKenzie Creative Brands data breach, or you believe your information was put at risk, you may be entitled to compensation. Companies that collect personal information are expected to take reasonable steps to protect it, and people affected by a breach can face fraud, lost time and ongoing worry about misuse.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.