Were you recently affected by a data breach?

The Bernard Group Data Breach

The Bernard Group, a Chanhassen, Minnesota visual merchandising and retail services company, notified individuals of a data security event involving their personal information. The company is offering 24 months of complimentary credit monitoring through Experian. Affected individuals should understand their rights and available protections.

The Bernard Group
Date of Breach: Notification letter dated July 20, 2026 (underlying incident date not publicly disclosed)
CAU logo

Who was affected:

Clients of The Bernard Group

Impacted Data:

Specific data elements not publicly disclosed in the filed notice

The Bernard Group, known as TBG, is a Chanhassen, Minnesota company that provides visual merchandising, printing, and retail display solutions for major retailers. The company recently notified individuals that a data security event may have involved some of their personal information.

Companies that handle personal data on behalf of clients, employees, or business partners have a responsibility to protect that information and to notify affected individuals when a security incident occurs.

The Bernard Group’s Data Breach Investigation

According to a notification letter dated July 20, 2026, The Bernard Group, Inc. wrote to inform affected individuals of an event involving some of their information. The letter states that the company has no indication that identity theft or fraud has occurred as a result of the event, but as an added precaution, TBG is offering 24 months of complimentary credit monitoring and identity theft protection services through Experian IdentityWorks.

The notification letter filed with the Massachusetts Attorney General’s Office is a template used for the mail-merge process and does not specify, in the copy made publicly available, precisely which categories of personal information were involved for any given recipient, nor does it disclose the cause of the incident, such as whether it stemmed from a phishing attack, ransomware, or a vendor compromise. This is a common pattern with notification letters filed as sample Exhibit A documents with a state attorney general, where the substantive details specific to each individual recipient are contained in the personalized version of the letter actually mailed, rather than in the generic template filed for public record.

TBG operates in the retail visual merchandising and printing industry, working with major national retailers on packaging, in-store displays, and marketing materials. Companies in this space often maintain databases containing personal information belonging to employees, contractors, and business partners as part of their day-to-day operations, making them, like companies in many other industries, potential targets for cyberattacks aimed at extracting sensitive data.

When a data breach notification does not specify the underlying cause of an incident or provide a complete accounting of which data types were exposed, affected individuals are often left to rely on the personalized letter they receive directly from the company for more complete detail. Consumers who receive a notice referencing an engagement number and a specific activation code, as described in TBG’s letter, should retain that letter and use the provided codes to verify their eligibility for the free credit monitoring services being offered.

Because the full circumstances of this incident, including the specific data elements involved and the initial cause, have not been made publicly available, individuals affected by this notification should treat their personal letter as the authoritative source of detail regarding what happened and how their particular information may have been involved. As more information becomes available, this page will be updated to reflect additional confirmed facts about the incident.

Data breach notification letters that reach the level of state attorney general filings, while not always publicly detailed, still trigger meaningful legal obligations and consumer protections. Even when full technical detail about an incident is not available, individuals who receive notice of exposure are entitled to take protective action and, where appropriate, seek legal recourse.

When Did This Breach Occur?

The Bernard Group’s notification letter is dated July 20, 2026, but does not specify the exact date the underlying security incident occurred or when it was first detected internally by the company. The letter also does not disclose when TBG’s investigation into the incident concluded.

Individuals who receive a personalized version of this letter should check it for a specific engagement number and activation code, which may correspond to more detailed information about their individual case that is not reflected in the general template filed with the Massachusetts Attorney General.

What Information Was Breached?

The version of The Bernard Group’s notification letter filed with the Massachusetts Attorney General does not specify which categories of personal information were involved in the incident. The letter references the affected individual’s information generally without listing specific data elements such as Social Security numbers, financial account numbers, or health information.

Individuals who receive the personalized version of this letter directly from The Bernard Group should review it carefully, as it may identify the specific data elements involved in their individual case that are not disclosed in the generic template version filed for public record.

What You Can Do

If you were notified that your information was involved in this breach, there are several steps you can take to help protect yourself:

  • Enroll in the complimentary 24-month Experian IdentityWorks credit monitoring and identity theft protection membership offered by The Bernard Group before the enrollment deadline in your personalized letter.
  • Place a fraud alert or credit freeze with the three major credit bureaus, Equifax, Experian, and TransUnion.
  • Regularly review your financial account statements and credit reports for unfamiliar activity.
  • Be cautious of unsolicited calls, emails, or text messages referencing this breach, and never provide personal information in response to a message you did not initiate.
  • Keep your notification letter and any engagement or activation numbers in a safe place in case you need them to verify eligibility for identity protection services.

File a Data Breach Lawsuit Against The Bernard Group

If you were affected by this breach, you may have legal options available to you. Individuals whose personal information is exposed due to a company’s failure to reasonably secure it may be entitled to pursue compensation through a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to the Vermont Attorney General on August 25, 2026
Date of Breach: Reported to the Vermont Attorney General on August 26, 2026
Date of Breach: Reported to the Vermont Attorney General on August 26, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.