Were you recently affected by a data breach?

USA DeBusk Data Breach

USA DeBusk, an industrial services company, discovered that an unauthorized party accessed its systems and obtained personal information, including Social Security numbers and financial account details, belonging to affected individuals.

USA DeBusk
Date of Breach: September 5, 2025 (discovered July 6, 2026)
CAU logo

Who was affected:

Clients of USA DeBusk

Impacted Data:

Names, contact information, dates of birth, government-issued identification numbers, financial account information, medical and health-related information, health insurance information, usernames and passwords

USA DeBusk LLC, an industrial cleaning and infrastructure maintenance company headquartered in Deer Park, Texas, has notified individuals that a cybersecurity incident resulted in unauthorized access to personal information stored on its systems. Companies that manage sensitive personal, financial, and health-related data have a responsibility to safeguard it, and when that duty is not met, the people affected deserve clear answers and a path toward protecting themselves.

USA DeBusk’s Data Breach Investigation

According to a notification letter filed with the California Attorney General’s Office, USA DeBusk experienced a cybersecurity incident on or around September 5, 2025, involving unauthorized access to certain of its computer systems. The company states that it launched an investigation with the assistance of outside cybersecurity experts to determine the nature and scope of the incident, and on July 6, 2026, USA DeBusk determined that an unauthorized third party had obtained certain personal information belonging to individuals in its systems.

USA DeBusk has not publicly disclosed the specific method the unauthorized party used to gain access, nor has it published a total count of individuals affected. The company reports that after discovering the intrusion, it blocked the unauthorized party’s access, took additional steps intended to strengthen its security safeguards, and reported the incident to law enforcement.

Industrial services and infrastructure companies like USA DeBusk are frequent targets for cybercriminals because they typically maintain large databases of employee and client records that include some of the most sensitive categories of personal data, including Social Security numbers, financial account numbers, and health-related information. A single successful intrusion into these systems can expose years of accumulated records at once, making the resulting fallout more severe than a breach limited to a narrower slice of information.

The nearly ten-month gap between the reported intrusion date and the company’s determination that data was actually taken is not unusual in incidents of this kind. Forensic investigations into unauthorized network access can take months to complete, particularly when a company must first determine which systems were touched, what data those systems contained, and whether any of that data was actually exfiltrated rather than merely accessed. Notification laws in most states require companies to notify affected individuals and regulators within a reasonable time after that determination is made, not from the date the intrusion itself occurred.

The combination of data types reportedly involved in this incident, including Social Security numbers, driver’s license and passport numbers, financial account and payment card information, and medical and health insurance information, is especially attractive to identity thieves. That combination can be used to open new lines of credit, file fraudulent tax returns, submit fraudulent insurance claims, or impersonate an individual with a financial institution or medical provider. Affected individuals should treat any unexpected account activity, unfamiliar medical bills, or unsolicited communications referencing this incident with heightened caution in the months following notification.

When Did This Breach Occur?

USA DeBusk’s notification letter states that the cybersecurity incident occurred on or around September 5, 2025. The company determined on July 6, 2026 that personal information had been obtained by an unauthorized third party in connection with this incident, and notification letters to affected individuals followed shortly after that determination.

What Information Was Breached?

USA DeBusk’s notification letter indicates that the categories of information involved varied by individual and could include full name, contact information such as postal address, email address, and telephone number, date of birth, government-issued identification numbers such as a Social Security number, driver’s license number, or passport number, financial account information such as a bank account or payment card number, and medical, health-related, and health insurance information, along with usernames and passwords.

What You Can Do

USA DeBusk is offering affected individuals two years of complimentary identity monitoring services through Kroll, including single-bureau credit monitoring, fraud consultation, and identity theft restoration assistance. If you received a notification letter from USA DeBusk, consider taking the following steps:

  • Enroll in the identity monitoring services offered in your notification letter before any stated deadline.
  • Request and carefully review your free credit reports from Equifax, Experian, and TransUnion at annualcreditreport.com.
  • Consider placing a fraud alert or security freeze on your credit files with each of the three major credit bureaus.
  • Monitor your financial and medical insurance statements closely for any unfamiliar activity.
  • Report any suspected identity theft to the Federal Trade Commission and your local law enforcement agency.

File a Data Breach Lawsuit Against USA DeBusk

If you received a notice that your personal information was exposed in the USA DeBusk data breach, you may have legal options. Companies that collect and store sensitive personal, financial, and medical information are expected to maintain reasonable safeguards to protect that data, and a failure to do so can leave affected individuals facing a lasting risk of identity theft and fraud.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 8, 2025 to August 27, 2025 (discovered July 16, 2026)
Date of Breach: September 5, 2025 (discovered July 6, 2026)
Date of Breach: On or about April 7, 2026 (ransomware detected)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.