TouchSource, LLC, a provider of digital signage, kiosk, and wayfinding technology used by businesses and healthcare facilities, has notified individuals that their personal information was exposed in a network security incident. Any company that stores Social Security numbers as part of its business operations has a heightened responsibility to secure that information against unauthorized access.
TouchSource’s Data Breach Investigation
According to a notification letter filed with the Massachusetts Attorney General’s Office, TouchSource discovered that an unauthorized party gained access to its network in March 2026. The company retained outside cybersecurity professionals to investigate the extent of the compromise, and that investigation, along with a subsequent document review, concluded in early July 2026. TouchSource determined that affected individuals’ full names and Social Security numbers were removed from its network as part of the incident.
Unlike many breach notifications that describe generic data categories, TouchSource’s letter is specific: names paired with Social Security numbers were confirmed to have been taken. This combination of data is considered one of the most sensitive and dangerous pairings in a data breach, because it is sufficient on its own to open new lines of credit, file fraudulent tax returns, or apply for loans in a victim’s name without any additional information. Unlike a stolen credit card number, which can be canceled and reissued, a Social Security number is effectively permanent — victims of this kind of exposure often need to remain vigilant for fraud attempts for years, not months, after the incident.
Companies that build technology products, such as digital signage and kiosk platforms, are not always the first business type consumers associate with large-scale data breaches, but many of these companies retain substantial amounts of personal information for billing, account management, or client-facing services, making them just as attractive a target to cybercriminals as traditional financial institutions. A roughly four-month gap between the March intrusion and the July notification is consistent with the kind of thorough forensic review that responsible companies undertake to confirm the exact scope of what was accessed, though it also means the exposed data could have been available to bad actors for a meaningful period before affected individuals were able to take protective steps.
Individuals whose names and Social Security numbers have been exposed together should treat this as a high-priority situation. Beyond the credit monitoring services being offered, taking proactive steps like placing an extended fraud alert or a full credit freeze — rather than relying on monitoring alone, which only flags fraud after it happens — offers stronger protection against the kind of new-account fraud this specific data combination is known to enable.
When Did This Breach Occur?
TouchSource states that unauthorized access to its network occurred on or around March 13, 2026. The company’s investigation and document review concluded on July 6, 2026, after which notification letters were sent to affected individuals.
What Information Was Breached?
TouchSource’s notification letter confirms that affected individuals’ full names and Social Security numbers were removed from the company’s network in connection with this incident.
What You Can Do
TouchSource is offering complimentary Equifax Credit Watch Gold membership to affected individuals for a specified enrollment period. Given that Social Security numbers were involved, affected individuals should strongly consider placing an extended fraud alert or a security freeze with all three major credit bureaus, monitor financial and tax accounts closely, and request free credit reports at annualcreditreport.com to check for unauthorized activity.
File a Data Breach Lawsuit Against TouchSource
If you received a notification letter from TouchSource, or believe your Social Security number or other personal information may have been compromised in this incident, you may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.