Were you recently affected by a data breach?

Recovery Café Data Breach

Recovery Café, a Seattle nonprofit, notified current and former employees and contractors that their personal information, including Social Security numbers, was exposed in a network breach. The organization is offering complimentary identity theft protection through IDX.

Recovery Café
Date of Breach: June 26-30, 2026 (discovered June 30, 2026)
CAU logo

Who was affected:

Clients of Recovery Café

Impacted Data:

Names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, health insurance policy and identification numbers

Recovery Café, a Seattle-based nonprofit organization, recently notified current and former employees and contractors that their personal information was compromised after an unauthorized party gained access to its computer network. Recovery Café is offering complimentary identity theft protection services to affected individuals.

Organizations that maintain sensitive personal information about their employees and contractors, including Social Security numbers and health insurance details, have a responsibility to secure that data against unauthorized access and to promptly notify anyone whose information may have been compromised.

Recovery Café’s Data Breach Investigation

According to a notice sent to affected individuals dated August 6, 2026, Recovery Café discovered that an unauthorized party had accessed its computer network between approximately June 26 and June 30, 2026. The organization states it discovered the incident on June 30, 2026, and promptly took action to terminate the unauthorized party’s access and secure its network. Recovery Café then launched an investigation into the scope of the incident.

During that investigation, on or around July 15, 2026, Recovery Café determined that the incident had compromised a system storing personal information about the organization’s current and former employees and contractors. The organization has said it is not aware of any actual misuse of the affected information as of the date of its notification letter.

In response, Recovery Café says it has taken steps intended to reduce the likelihood of a similar incident occurring again, including implementing more advanced security monitoring tools and strengthening its access controls. The organization has not publicly detailed the specific technical vulnerability that allowed the unauthorized access to occur in the first place.

Nonprofit organizations, including community health and recovery-support organizations like Recovery Café, are frequent targets for cybercriminals because they often manage substantial amounts of sensitive personal and health-related data on staff, program participants, and contractors, while typically operating with more constrained cybersecurity budgets than larger corporations or healthcare systems. Unauthorized network access incidents, where an outside actor gains entry to internal systems, are among the most common breach types reported to state regulators and often go undetected for days or weeks before being identified and contained.

The roughly two-week gap between when Recovery Café says it discovered the unauthorized access (June 30) and when it completed its investigation into which systems and data were affected (around July 15) is a fairly typical timeline for this type of incident. Forensic investigations into network intrusions generally require specialized cybersecurity teams to trace how the intrusion occurred, determine what data was actually accessed or exfiltrated, and confirm which individuals were affected before an organization can issue accurate notification letters.

The combination of data types Recovery Café says was involved, including Social Security numbers, driver’s license numbers, passport numbers, and health insurance policy and identification numbers, is considered highly sensitive because it can enable multiple forms of fraud beyond ordinary credit card misuse, including new-account identity theft, fraudulent tax filings, and medical identity theft in which someone else’s health insurance benefits are used fraudulently. This is why Recovery Café is offering a broader identity protection package, including credit and dark web monitoring and a $1,000,000 insurance reimbursement policy, rather than credit monitoring alone.

Because the affected population includes both current and former employees and contractors, individuals who may have left Recovery Café’s employment or contracting relationship well before the June 2026 intrusion could still be impacted and may not be actively checking correspondence associated with the organization. Anyone who previously worked for or contracted with Recovery Café, even years ago, should be alert to the possibility that a notification letter addressed to them may arrive at a current or forwarding address, and should not assume the notice does not apply simply because the working relationship ended some time ago.

Data breaches involving payroll, human resources, and benefits-administration systems are particularly consequential because they frequently combine several high-value identifiers, such as a Social Security number, date of birth, and government-issued identification number, in a single record. Fraudsters value this kind of combined record considerably more than any one data point alone, since it is often sufficient by itself to open new financial accounts, file fraudulent tax returns, or apply for government benefits in a victim’s name without needing any additional information.

When Did This Breach Occur?

Recovery Café states that the unauthorized network access occurred between approximately June 26 and June 30, 2026. The organization says it discovered the incident on June 30, 2026, and completed its investigation into the scope of affected data on or around July 15, 2026. The notification letters to affected individuals are dated August 6, 2026.

What Information Was Breached?

Recovery Café’s notification letter states that the affected personal information varies by individual but generally includes first and last name, contact and demographic information such as address, phone number, email address, and age, date of birth, Social Security number, driver’s license number, passport number or other government-issued identification number, and, for individuals who participated in Recovery Café’s group health plan, health insurance policy and identification numbers.

What You Can Do

Individuals who received a notification letter from Recovery Café should consider taking the following steps:

  • Enroll in the complimentary identity theft protection services offered through IDX before the November 6, 2026 enrollment deadline.
  • Monitor bank, credit card, and health insurance statements closely for any unfamiliar activity.
  • Request free copies of credit reports from Equifax, Experian, and TransUnion and review them for unauthorized accounts.
  • Consider placing a fraud alert or security freeze on your credit files with each of the three major credit bureaus.
  • Report any suspected identity theft or fraud to local law enforcement, your state Attorney General, and the Federal Trade Commission.

File a Data Breach Lawsuit Against Recovery Café

If you received a notice from Recovery Café about this data breach, you may have legal options available to help protect yourself and hold the organization accountable for failing to secure your personal information. An experienced data breach attorney can help evaluate whether you may be entitled to compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Disruption began August 3, 2026; investigation ongoing
Date of Breach: Suspicious activity detected June 5, 2026; unauthorized access determined June 8, 2026, tied to data acquired May 12, 2026
Date of Breach: Disclosed via SEC filing, 2026 (exact incident date not disclosed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.