U.S. 1031 Exchange Services, Inc. (“1031”), a Florida-based exchange services company, recently disclosed a cybersecurity incident involving unauthorized access to sensitive personal information. The breach affected approximately 2,090 individuals, including 5 Maine residents. Although the company states it has not identified any confirmed misuse of the exposed information, affected individuals are being offered complimentary credit monitoring and identity restoration services through Cyberscout.
U.S. 1031 Exchange Services, Inc.’s Data Breach Investigation
According to the company’s supplemental notice, U.S. 1031 Exchange Services first became aware of suspicious activity within its network environment on October 16, 2025. Upon discovery of the incident, the company promptly shut down workstations, contacted IT personnel, and engaged an external cybersecurity firm to conduct a forensic investigation into the nature and scope of the attack.
The forensic investigation concluded on November 11, 2025, and determined that unauthorized actors had accessed certain files stored within the company’s systems. Following the investigation, the company reviewed the affected data to identify impacted individuals and determine what personal information may have been exposed.
The company stated that the compromised information may have included individuals’:
- First and last names
- Addresses
- Social Security numbers
- Bank account and routing numbers
Although the company reported that it had not received any reports of fraud or identity theft connected to the breach as of the notice date, the exposure of banking and Social Security information creates serious risks related to identity theft, financial fraud, and unauthorized account activity.
As part of its response efforts, U.S. 1031 Exchange Services implemented additional cybersecurity safeguards, including password resets, mandatory multi-factor authentication (MFA), and updates to its internal security policies and procedures. The company also began notifying affected individuals on May 8, 2026.
When Did This Breach Occur?
The breach activity occurred on or around October 16, 2025. The incident was discovered the same day, and the forensic investigation concluded on November 11, 2025.
Affected individuals received written notification letters beginning on May 8, 2026.
What Information Was Breached?
According to the notice issued by U.S. 1031 Exchange Services, the potentially exposed information may have included:
- Names
- Addresses
- Social Security numbers
- Bank account numbers
- Routing numbers
This information could potentially be used for identity theft, tax fraud, financial fraud, or unauthorized banking transactions.
What You Can Do
If you received a notice regarding this breach, there are several important steps you can take to help protect yourself:
- Enroll in the complimentary identity protection services offered through Cyberscout, a TransUnion company.
- Monitor your bank accounts and financial statements closely for suspicious activity.
- Review your credit reports regularly through AnnualCreditReport.com.
- Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
- Change passwords associated with financial accounts and enable multi-factor authentication where available.
- Remain cautious of phishing emails, calls, or text messages requesting personal information.
- Report any suspicious activity immediately to your financial institutions and law enforcement.
The complimentary services offered reportedly include 12 months of credit monitoring and identity theft restoration services designed to help individuals respond quickly if fraud occurs.
File a Data Breach Lawsuit Against U.S. 1031 Exchange Services, Inc.
Individuals affected by the U.S. 1031 Exchange Services data breach may have legal rights and could qualify to pursue compensation related to the exposure of their sensitive personal and financial information. Data breach lawsuits often seek compensation for damages such as identity theft risks, financial losses, time spent addressing fraud concerns, and loss of privacy.
Companies that collect and store highly sensitive personal and banking information are expected to maintain reasonable cybersecurity protections. When those protections fail, affected individuals may face long-term risks associated with identity theft and financial fraud.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.