Were you recently affected by a data breach?

Suede Data Breach

Suede, formerly known as Merchant Industry, LLC, notified individuals that an unauthorized third party accessed its systems and may have obtained personal information including names and Social Security numbers.

Suede
Date of Breach: June 3, 2026
CAU logo

Who was affected:

Clients of Suede

Impacted Data:

Names, Social Security numbers

Suede, a payments technology and merchant services company formerly known as Merchant Industry, LLC, has notified individuals that a security incident may have exposed their personal information. Companies that process payments on behalf of merchants collect and store sensitive personal information as part of their operations, and have a responsibility to keep that information secure.

Suede’s Data Breach Investigation

Suede reported that on June 3, 2026, it identified suspicious activity related to one of its internal systems. The company stated it took prompt containment actions, including securing the affected systems, and launched an investigation to determine the nature and scope of the activity. Suede’s investigation determined that an unauthorized third party accessed the company’s system on June 3, 2026, and potentially accessed and copied certain files. Suede then conducted a detailed review of the affected data to identify whose information was involved and to locate current address information for those individuals, a process the company said it completed on July 27, 2026. Suede stated it is not aware of any fraud or identity theft occurring in connection with this incident.

Payments and merchant services companies like Suede are frequent targets for cybercriminals because they sit at the intersection of large volumes of personal and financial data flowing between merchants, processors, and financial institutions. A breach at a payments company can expose information belonging not just to direct customers, but to employees or contacts of the many merchants the company serves, which is part of why thorough post-incident reviews like the one Suede described can take weeks or months to complete.

The combination of names and Social Security numbers, which Suede identified as the data types involved here, is particularly valuable to identity thieves because it can be used to open new lines of credit, file fraudulent tax returns, or otherwise impersonate the affected individual. Individuals notified of this kind of exposure are generally encouraged to take proactive steps, such as enrolling in credit monitoring and placing fraud alerts, even in the absence of confirmed misuse, precisely because the risk of future fraud can persist well after the initial incident.

Suede’s timeline, from a June 3, 2026 detection date to a late July 2026 completion of its review and subsequent notification, reflects a common pattern for corporate data security incidents, where the investigation and identification of affected individuals often takes longer than the initial detection and containment of the incident itself.

When Did This Breach Occur?

Suede identified suspicious activity on June 3, 2026, and its investigation determined that unauthorized access to its system occurred on that same date. The company completed its review to identify affected individuals on July 27, 2026, after which notification letters were sent.

What Information Was Breached?

According to Suede’s notification, the information that could have been affected includes the recipient’s name and Social Security number.

What You Can Do

Suede is offering complimentary credit monitoring and identity theft protection services for 24 months through Cyberscout, a TransUnion company. If you received a notification letter from Suede, consider taking the following steps:

  • Enroll in the complimentary credit monitoring services described in your notification letter within 90 days of the letter’s date.
  • Review your credit reports and account statements regularly for the next 12 to 24 months for any suspicious activity.
  • Consider placing a fraud alert or credit freeze on your credit file with the three major credit bureaus.
  • Be alert to phishing attempts or unsolicited contacts referencing this incident.

File a Data Breach Lawsuit Against Suede

If you received a data breach notification letter from Suede (formerly Merchant Industry) or believe your personal information was compromised in this incident, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
SMG
Date of Breach: March 18 to April 7, 2026 (detected March 31, 2026)
Date of Breach: June 3, 2026
Date of Breach: Notification dated August 6, 2026; incident date not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.