The Computer Merchant, Ltd., a nationally recognized IT staffing and software engineering services firm based in Norwell, Massachusetts, has reported a data breach affecting nearly 3,000 individuals. Staffing firms handle large volumes of candidate and employee personal information, and a breach of that data can put job seekers and employees at real risk.
The Computer Merchant’s Data Breach Investigation
The Computer Merchant, headquartered in Norwell, Massachusetts, reported a data security incident to the Texas Attorney General’s office. The filing states that the breach affected approximately 2,981 individuals in Texas, and the true nationwide total is likely higher, since Texas is only one of the states where the company would be required to report. According to the filing, affected individuals were notified by U.S. mail, consistent with Texas’s data breach notification requirements.
The public filing does not disclose the specific cause of the breach, such as whether it resulted from a phishing attack, a ransomware incident, an unauthorized network intrusion, or some other cause. It also does not disclose when the breach was first detected internally or how long unauthorized access may have persisted before discovery. What is disclosed is that the compromised information included names, addresses, and Social Security numbers.
IT staffing firms like The Computer Merchant maintain detailed personal files on the candidates, contractors, and employees they place with client companies, often including Social Security numbers, tax documentation, and contact information collected as part of the hiring and payroll process. This makes staffing companies a valuable target for cybercriminals, since a single successful intrusion can expose the personal information of thousands of people who may have interacted with the company only briefly, such as candidates who submitted a resume years earlier and may not even remember providing their Social Security number.
When names, addresses, and Social Security numbers are exposed together, victims face an elevated risk of identity theft, including the opening of new credit accounts, fraudulent tax filings, and other forms of financial fraud carried out in the victim’s name. Social Security numbers in particular are difficult, if not impossible, to change, meaning the exposure can create risk that persists for years after the initial breach, long after any single credit card or account number could have been replaced. Victims of this kind of exposure are often advised to monitor their credit reports for new accounts they did not open and to remain alert for suspicious tax-related correspondence from the IRS.
The Texas Attorney General’s breach notification requirement, which applies to any company experiencing a breach affecting 250 or more Texas residents, is designed to give the public visibility into incidents that might not otherwise become widely known. Even so, the time between when a company first discovers a breach internally and when its public filing appears can leave a gap during which affected individuals have no way of knowing their information may already be at risk. This is one of the reasons that security professionals generally recommend taking protective steps as soon as a breach notification is received, rather than waiting to see whether fraud actually occurs.
Because a bare name, address, and Social Security number combination lacks a specific financial account attached to it, this type of breach is sometimes underestimated compared to incidents that also expose credit card numbers or bank account details. In practice, however, identity thieves often find this exact combination more useful for opening entirely new lines of credit, since it provides everything needed to pass a basic identity verification check at many lenders and service providers, without requiring the thief to bypass a bank’s own existing fraud controls on a specific account. Victims sometimes do not discover this kind of fraud until a debt collector contacts them about an account they never opened, or until a routine credit check reveals unfamiliar inquiries or accounts.
Staffing agencies also present a distinct challenge for breach response compared to a typical consumer-facing business, since their records often include individuals who are not current clients or employees at all, but rather candidates who applied years earlier and may have long since forgotten they ever shared personal information with the company. This can make it harder for affected individuals to recall why they are receiving a breach notification in the first place, and it underscores the importance of reading any notification letter carefully rather than dismissing it as a mistake or a scam.
When Did This Breach Occur?
The Computer Merchant’s filing with the Texas Attorney General was published on August 22, 2025. The filing does not publicly specify the exact date the underlying breach occurred or the date it was first detected internally. If you received a notification letter, it may include more specific dates that are not part of the public record.
What Information Was Breached?
According to the filing, the following categories of information were involved in the breach: names, addresses, and Social Security numbers. The filing does not indicate which individuals had which specific data types exposed, so anyone who received a notification letter should assume any combination of these categories could apply to their own information.
What You Can Do
If you received a data breach notification letter from The Computer Merchant, consider taking the following steps to protect yourself:
- Read any notification letter carefully and follow the specific instructions it provides.
- Enroll in any free credit monitoring or identity protection services offered in the notice.
- Place a fraud alert or credit freeze with the three major credit bureaus.
- Monitor your credit reports for accounts you did not open.
- Watch for suspicious tax-related correspondence, which could indicate tax identity theft.
- Report any suspected identity theft to the Federal Trade Commission at IdentityTheft.gov.
File a Data Breach Lawsuit Against The Computer Merchant
If your personal information was exposed in The Computer Merchant data breach, you may be entitled to compensation. Companies that collect and store sensitive personal data have a responsibility to protect it, and when that trust is broken, those responsible can be held accountable.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.