Knights of Columbus Data Breach Lawsuit (August 2026)

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Knights of Columbus
Active investigation Data breach · Consumer Notices mailed Aug 3, 2026

Received an August 2026 breach notice from Knights of Columbus?

Dapeer Law, P.A. is investigating a potential class action against Knights of Columbus, the Connecticut-based Catholic fraternal service organization and member insurer, on behalf of members whose personal information may have been exposed in a December 2025 cybersecurity incident at a third-party hosting vendor. Knights of Columbus disclosed the incident to the Massachusetts Attorney General on August 3, 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
Dec 25, 2025
Suspicious activity detected at hosting vendor
Notification delay
About 7 months
Detected Dec 2025, notice filed Aug 2026
Credit monitoring
IDX offered
Credit and CyberScan monitoring, $1M insurance
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Knights of Columbus dated August 2026.
  • Your letter offered enrollment in complimentary IDX identity protection services, including credit monitoring and CyberScan dark web monitoring.
  • You are a current or former Knights of Columbus member, insurance applicant, or policyholder whose personal, medical, or Social Security information was held by the organization or its vendors.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

According to a breach notice filed with the Massachusetts Attorney General on August 3, 2026, a third-party vendor that hosts data for Knights of Columbus detected suspicious activity on its network on December 25, 2025. The vendor reports that it began containment steps immediately and retained a cybersecurity firm to conduct a forensic investigation. Knights of Columbus states that it was notified of the incident on May 4, 2026, roughly four months after the vendor detected the activity.

Knights of Columbus then conducted a detailed data review to determine what information could have been involved and began notifying affected individuals. The Massachusetts filing reports that the categories of data varied by individual and may have included medical information and Social Security numbers. The organization is offering complimentary identity protection services through IDX, which include credit monitoring, CyberScan dark web monitoring, identity theft recovery support, and up to $1,000,000 in reimbursement insurance. The Massachusetts notice lists 5 Massachusetts residents, but Knights of Columbus reports more than 2.2 million members worldwide, and the nationwide total has not been publicly confirmed.

Medical information and Social Security numbers are among the most sensitive categories of personal data. Unlike a payment card, a Social Security number cannot be reissued on request, and health information can support medical identity theft, fraudulent insurance claims, and targeted phishing for years after a breach. The roughly seven month gap between the vendor's detection of suspicious activity in December 2025 and the August 2026 regulator filing is one of the issues our investigation is evaluating, along with what security controls were in place at the vendor and what contractual oversight Knights of Columbus exercised over it.

Third-party vendor incident Social Security numbers Medical information Massachusetts Attorney General filing IDX identity protection Notification delay
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the IDX identity protection services and is important evidence if you decide to participate in a lawsuit. Note the categories of data listed in your specific letter, because the notice states that the information involved varied by individual.

2

Enroll in the free IDX identity protection services

Activate the complimentary IDX services offered in your letter before the enrollment deadline printed on it. The package is described as including credit monitoring, CyberScan dark web monitoring, identity theft recovery support, and up to $1,000,000 in reimbursement insurance. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because medical information may have been involved, also review Explanation of Benefits statements and insurance correspondence for services or claims you did not receive.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We will review your notice, explain your options under state data breach and consumer protection laws, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

Dec 25, 2025 Passed
Third-party hosting vendor detects suspicious network activity
Dec 2025 to May 2026 Passed
Vendor containment and forensic investigation
May 4, 2026 Passed
Knights of Columbus notified of the incident
Aug 3, 2026 Passed
Notice filed with the Massachusetts Attorney General, letters mailed
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. If medical information covered by HIPAA was involved, additional federal notification obligations may also apply. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, medical-claim and insurance fraud, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Knights of Columbus to implement stronger data security practices going forward, including tighter vetting and contractual oversight of the third-party vendors that host member data.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Knights of Columbus. What should I do? +

Keep your notice letter, activate the complimentary IDX identity protection services as soon as possible, and monitor your financial, credit, and medical statements for unfamiliar activity. Consider placing a fraud alert or a security freeze on your credit files. Because medical information may have been involved, also watch for Explanation of Benefits statements describing care you did not receive. Then speak with a data breach attorney about your potential claims.

Am I eligible to join a class action against Knights of Columbus? +

If you received a security incident letter from Knights of Columbus, you may be eligible. Eligibility generally depends on your state of residence, the categories of information listed in your individual letter, and whether you have experienced any documented losses or misuse. A free case review is the fastest way to find out where you stand.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The Massachusetts Attorney General filing reports that the information involved varied by individual and may have included medical information and Social Security numbers. Your individual letter should list the categories that apply to you, so check it closely and keep it. Our investigation is still working to confirm whether other categories of data were affected.

Did Knights of Columbus offer free credit monitoring? +

Yes. Knights of Columbus is offering complimentary identity protection services through IDX, described as including credit monitoring, CyberScan dark web monitoring, identity theft recovery support, and up to $1,000,000 in reimbursement insurance. The exact term of the offering is stated in your letter. Enrolling does not waive your right to pursue a legal claim.

How many people were affected by the Knights of Columbus breach? +

The Massachusetts breach notice lists 5 Massachusetts residents. Knights of Columbus reports more than 2.2 million members worldwide, and the total number of people affected nationwide has not been publicly confirmed. This page will be updated as additional regulator filings become available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The breach notice is publicly available from the Massachusetts Attorney General, and you can download it using the link in the Sources and References section of this page. If you cannot locate your own letter, Dapeer Law can help you obtain a copy during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Knights of Columbus, IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on August 3, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Etnyre International, Ltd. Data Breach Lawsuit Investigation

Next
Next

Corporate Travel Service Data Breach Lawsuit Investigation