Were you recently affected by a data breach?

RTX Corporation Data Breach

RTX Corporation notified individuals that a June 2026 security incident exposed personal information including names, mailing addresses, and Social Security numbers. RTX is offering free credit monitoring to those affected. Individuals impacted should take steps to protect against identity theft and fraud.

RTX Corporation
Date of Breach: June 25, 2026
CAU logo

Who was affected:

Clients of RTX Corporation

Impacted Data:

Names, mailing addresses, Social Security numbers

RTX Corporation recently notified individuals that a security incident exposed personal information including Social Security numbers. When a company of RTX’s size and scope experiences a breach, the number of people whose sensitive data may be exposed can be significant, and the responsibility to protect that information falls squarely on the company that collected it.

RTX Corporation’s Data Breach Investigation

According to a notice of data breach filed with the Massachusetts Attorney General’s Office, RTX Corporation informed affected individuals that a security incident occurred on June 25, 2026, and involved some of their personal information. RTX’s investigation determined that the exposed data included full names, mailing addresses, and Social Security numbers. The notification letter, dated July 23, 2026, states that RTX is unaware of any instances in which the exposed information has actually been misused, but the company is nonetheless offering affected individuals free credit monitoring and identity protection services as a precaution.

RTX Corporation, formerly known as Raytheon Technologies, is one of the largest aerospace and defense contractors in the world, and the company has previously disclosed other, separate cybersecurity incidents affecting different parts of its business, including a 2025 ransomware attack that disrupted certain airport services. This latest incident, involving Social Security numbers and other personal information, appears to be a distinct event from that earlier disruption, based on the differing dates and the nature of the data described in each disclosure.

Large defense and aerospace contractors like RTX are attractive targets for cybercriminals not only because of the sheer volume of personal data they hold on employees, contractors, and other individuals, but also because a successful intrusion can potentially expose sensitive information tied to government contracts and national security work. While this particular breach notice concerns personal information rather than classified data, the scale of a company like RTX means that even an incident described in general terms can affect a substantial number of people.

Social Security numbers are among the most sensitive categories of personal data because they serve as a near-permanent identifier tied to a person’s financial and legal identity. Unlike a compromised password or credit card number, a Social Security number generally cannot simply be changed or reissued, which means that individuals whose numbers were exposed in this incident may face an elevated and long-term risk of identity theft, tax fraud, or fraudulent account openings, even if the credit monitoring services RTX is offering catch some fraudulent activity early.

The roughly one-month gap between the June 25, 2026 incident and the July 23, 2026 notification letter is consistent with the kind of investigation timeline typically required to determine the scope of a breach and identify which specific individuals were affected before notice can be sent. Companies are generally expected to move through this process without unreasonable delay, and a monthlong turnaround is on the faster end of what is often seen in large corporate data breaches, though it still leaves affected individuals without any way to protect themselves during that window.

Data breach notifications that involve Social Security numbers frequently lead to a secondary wave of targeted phishing attempts, in which scammers pose as the breached company, a credit monitoring provider, or a government agency to try to extract even more personal information from anxious recipients. Anyone contacted about the RTX incident should independently verify the source of any follow-up communication before clicking links, calling phone numbers, or providing additional personal details, rather than assuming a message referencing the breach is automatically legitimate.

Because the exposed information in this incident includes a full name, mailing address, and Social Security number for each affected individual, the risk extends well beyond simple account fraud. That combination of data is often enough for a bad actor to attempt to open new lines of credit, file a fraudulent tax return in someone else’s name, or apply for government benefits using a stolen identity. The free credit monitoring RTX is offering can help detect some of these attempts, but it does not prevent the underlying exposure or guarantee that misuse will be caught before damage occurs, which is why affected individuals are encouraged to take independent protective steps as well.

When Did This Breach Occur?

RTX Corporation states that the security incident occurred on June 25, 2026. The company’s notification letter, dated July 23, 2026, indicates that its investigation into the incident had been completed by that point, having identified which individuals were affected and which categories of their personal information were involved. RTX has not publicly disclosed how the unauthorized access occurred or whether a specific threat actor has been identified in connection with this particular incident.

What Information Was Breached?

RTX Corporation’s notification letter states that the investigation determined the following types of personal information were involved in the incident: first and last name, mailing address, and Social Security number. The combination of a full name with a Social Security number and home address is considered highly sensitive, since it provides much of what is needed to attempt identity theft, open fraudulent accounts, or file fraudulent tax returns in an affected individual’s name.

What You Can Do

If you received a notification letter from RTX Corporation or believe your information may have been affected by this incident, consider taking the following steps:

  • Enroll in the free Equifax Complete Premier credit monitoring service RTX is offering before the October 31, 2026 enrollment deadline.
  • Review your credit reports from Equifax, Experian, and TransUnion for accounts or inquiries you do not recognize.
  • Consider placing a credit freeze or fraud alert on your credit file with each of the three major credit bureaus.
  • File a police report if you believe you have been a victim of identity theft, which Massachusetts law entitles affected residents to do.
  • Monitor your financial accounts and tax filings closely for any signs of fraudulent activity.

File a Data Breach Lawsuit Against RTX Corporation

If RTX Corporation failed to adequately safeguard the personal information entrusted to it, affected individuals may have legal options to pursue compensation for the risk and inconvenience caused by this data breach. Companies that collect and store sensitive personal information, including Social Security numbers, have a responsibility to implement reasonable safeguards against unauthorized access, and when those safeguards fail, the people whose data is exposed can be left dealing with the fallout for years.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 31, 2025 (JLR's response date to the incident)
Date of Breach: Not publicly disclosed
Date of Breach: June 18, 2026 (learned of incident)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.