Were you recently affected by a data breach?

Moorman, Harting & Co Data Breach

Moorman, Harting & Co, an Ohio accounting and financial services firm, has notified individuals of a data security incident involving suspicious activity on its computer network. The firm has not publicly itemized which personal information was exposed. Anyone who received a notice letter should understand their options.

Moorman, Harting & Co
Date of Breach: Not publicly disclosed (notification letters dated September 25, 2026)
CAU logo

Who was affected:

Clients of Moorman, Harting & Co

Impacted Data:

Names, and additional personal information that the company has not publicly itemized in its notification filing

Moorman, Harting & Co, an accounting, tax, and financial services firm based in Coldwater, Ohio, has begun notifying individuals that some of their personal information may have been affected by suspicious activity on its computer network. Firms that handle tax returns and financial records hold exactly the kind of information that criminals value most, so a notice from an accounting provider deserves a careful response.

Moorman, Harting & Co’s Data Breach Investigation

Moorman, Harting & Co, whose related financial services business is Moorman, Harting Financial Services, Ltd., sent notification letters dated September 25, 2026 to people whose information may have been involved in a network security incident. A sample of the letter was filed with the Massachusetts Attorney General’s office, which lists six Massachusetts residents among those affected. The total number of people notified nationwide has not been made public in the materials available.

According to the sample letter, the firm identified suspicious activity on its computer network and carried out an investigation to determine what happened and what information was involved. The investigation concluded that each recipient’s name, along with additional personal information specific to that individual, was potentially impacted. The sample letter filed with regulators is a mail-merge template, so the specific data elements for each person appear as a placeholder rather than a finished list. As a result, it is not publicly known exactly which categories of data were exposed for each affected person.

The letter does not describe how the intruder gained access, whether files were actually copied, or whether the incident involved ransomware. It also does not state when the suspicious activity began or when the firm discovered it. Those details matter, because they determine how long personal information may have been exposed and how much time passed before people were told. Until the firm or regulators release more information, those questions remain open.

Moorman, Harting & Co is offering affected individuals two years of complimentary credit monitoring and identity protection through IDX. Recipients must enroll using the code printed on their letter by December 25, 2026, and the letter notes that the firm cannot enroll people automatically because of privacy restrictions. The letter also encourages recipients to review account statements and monitor free credit reports over the next 12 to 24 months for signs of fraud.

Accounting and tax practices are frequent targets for cyberattacks for a simple reason: their files often combine many categories of sensitive data in one place. A single client folder can include a Social Security number, date of birth, home address, bank account details, employer information, and prior-year tax returns. Criminals can use that combination to file fraudulent tax returns, open new credit accounts, or craft convincing impersonation scams aimed at the firm’s clients. This is general context about the sector, not a confirmed statement about which files were involved in this incident.

Because the type of information involved in this incident has not been itemized, the safest assumption for anyone who received a letter is that the information could include identifying details commonly kept by a financial services firm. Taking the free monitoring offer, placing a fraud alert or credit freeze, and watching for unexpected tax-related mail or IRS notices are sensible precautions while more facts emerge. Fraud tied to stolen data can surface months or even years after an incident, which is why the letter’s guidance covers a 12 to 24 month window.

Notice timing is another area worth watching. State laws generally require organizations to notify affected people within a set period after discovering an incident, and regulators look at whether the delay between discovery and notice was reasonable. Because the firm has not said when it discovered the suspicious activity, outsiders cannot yet judge whether its notice came promptly, which is one reason people who received letters often want to understand their options early.

Individuals who think they may have been affected should keep their notification letter, record the date they received it, and save any related correspondence. Those documents can matter if the situation later leads to a legal claim. Anyone who did not receive a letter but has done business with the firm and has noticed suspicious activity involving their accounts or tax filings may also want to ask the firm directly whether their information was involved.

When Did This Breach Occur?

Moorman, Harting & Co has not publicly stated when the suspicious activity on its network began or when it was discovered. The only date available from the sample notice filed with Massachusetts regulators is September 25, 2026, which is the date printed on the notification letter. That is the date the firm began telling individuals about the matter, not necessarily the date of the incident itself.

The letter also sets a December 25, 2026 deadline to enroll in the complimentary credit monitoring offer, so anyone who received a notice should act well before that date. The letter says the notice was not delayed by law enforcement.

What Information Was Breached?

The letter states that each recipient’s name and additional personal data were potentially impacted, but the sample filed with regulators leaves the specific data elements as an unfilled placeholder. Moorman, Harting & Co has not publicly disclosed a universal list of what was exposed, and the information may differ from person to person.

Because the firm provides accounting, tax, and financial services, people who received a letter should consider the possibility that financial or tax-related details were involved, while recognizing that this has not been confirmed. Your own letter is the best source for what applies to you, and you can contact the firm’s assistance line listed on it to ask for specifics.

What You Can Do

Enroll in the two years of complimentary IDX credit monitoring before December 25, 2026, using the enrollment code on your letter. Review bank, credit card, and brokerage statements carefully, and check your free credit reports at annualcreditreport.com, which you can do through each of the three major bureaus.

Consider placing a fraud alert or a credit freeze with Equifax, Experian, and TransUnion at no cost. If you file taxes, consider requesting an IRS Identity Protection PIN to help block fraudulent returns filed in your name. Be cautious about unexpected emails, calls, or texts that mention your accountant or financial advisor, since scammers often reference a real breach to appear credible. Massachusetts residents also have the right to obtain any police report filed about this incident.

File a Data Breach Lawsuit Against Moorman, Harting & Co

If your personal information was exposed in the Moorman, Harting & Co incident, you may have legal options. Data breach class actions generally allege that an organization failed to use reasonable safeguards to protect sensitive information and failed to notify affected people promptly. Whether a claim is viable depends on facts that are still emerging in this matter, including what was taken and how the firm responded.

Speaking with a lawyer early can help you understand your rights, preserve your notice letter and related records, and learn whether a lawsuit is being organized for people in your position.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed (patient notifications began September 25, 2026)
Date of Breach: August 3, 2026
Date of Breach: Not publicly disclosed (notification letters dated September 25, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.