USA DeBusk LLC, an industrial cleaning and infrastructure maintenance company headquartered in Deer Park, Texas, has notified individuals that a cybersecurity incident resulted in unauthorized access to personal information stored on its systems. Companies that manage sensitive personal, financial, and health-related data have a responsibility to safeguard it, and when that duty is not met, the people affected deserve clear answers and a path toward protecting themselves.
USA DeBusk’s Data Breach Investigation
According to a notification letter filed with the California Attorney General’s Office, USA DeBusk experienced a cybersecurity incident on or around September 5, 2025, involving unauthorized access to certain of its computer systems. The company states that it launched an investigation with the assistance of outside cybersecurity experts to determine the nature and scope of the incident, and on July 6, 2026, USA DeBusk determined that an unauthorized third party had obtained certain personal information belonging to individuals in its systems.
USA DeBusk has not publicly disclosed the specific method the unauthorized party used to gain access, nor has it published a total count of individuals affected. The company reports that after discovering the intrusion, it blocked the unauthorized party’s access, took additional steps intended to strengthen its security safeguards, and reported the incident to law enforcement.
Industrial services and infrastructure companies like USA DeBusk are frequent targets for cybercriminals because they typically maintain large databases of employee and client records that include some of the most sensitive categories of personal data, including Social Security numbers, financial account numbers, and health-related information. A single successful intrusion into these systems can expose years of accumulated records at once, making the resulting fallout more severe than a breach limited to a narrower slice of information.
The nearly ten-month gap between the reported intrusion date and the company’s determination that data was actually taken is not unusual in incidents of this kind. Forensic investigations into unauthorized network access can take months to complete, particularly when a company must first determine which systems were touched, what data those systems contained, and whether any of that data was actually exfiltrated rather than merely accessed. Notification laws in most states require companies to notify affected individuals and regulators within a reasonable time after that determination is made, not from the date the intrusion itself occurred.
The combination of data types reportedly involved in this incident, including Social Security numbers, driver’s license and passport numbers, financial account and payment card information, and medical and health insurance information, is especially attractive to identity thieves. That combination can be used to open new lines of credit, file fraudulent tax returns, submit fraudulent insurance claims, or impersonate an individual with a financial institution or medical provider. Affected individuals should treat any unexpected account activity, unfamiliar medical bills, or unsolicited communications referencing this incident with heightened caution in the months following notification.
When Did This Breach Occur?
USA DeBusk’s notification letter states that the cybersecurity incident occurred on or around September 5, 2025. The company determined on July 6, 2026 that personal information had been obtained by an unauthorized third party in connection with this incident, and notification letters to affected individuals followed shortly after that determination.
What Information Was Breached?
USA DeBusk’s notification letter indicates that the categories of information involved varied by individual and could include full name, contact information such as postal address, email address, and telephone number, date of birth, government-issued identification numbers such as a Social Security number, driver’s license number, or passport number, financial account information such as a bank account or payment card number, and medical, health-related, and health insurance information, along with usernames and passwords.
What You Can Do
USA DeBusk is offering affected individuals two years of complimentary identity monitoring services through Kroll, including single-bureau credit monitoring, fraud consultation, and identity theft restoration assistance. If you received a notification letter from USA DeBusk, consider taking the following steps:
- Enroll in the identity monitoring services offered in your notification letter before any stated deadline.
- Request and carefully review your free credit reports from Equifax, Experian, and TransUnion at annualcreditreport.com.
- Consider placing a fraud alert or security freeze on your credit files with each of the three major credit bureaus.
- Monitor your financial and medical insurance statements closely for any unfamiliar activity.
- Report any suspected identity theft to the Federal Trade Commission and your local law enforcement agency.
File a Data Breach Lawsuit Against USA DeBusk
If you received a notice that your personal information was exposed in the USA DeBusk data breach, you may have legal options. Companies that collect and store sensitive personal, financial, and medical information are expected to maintain reasonable safeguards to protect that data, and a failure to do so can leave affected individuals facing a lasting risk of identity theft and fraud.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.