Mungo Homes Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Mungo Homes
Active investigation Data breach · Construction Notices mailed Aug 14, 2026

Received a May 2026 breach notice from Mungo Homes?

Dapeer Law, P.A. is investigating a potential class action against Clayton Properties Group, Inc. d/b/a Mungo Homes, a South Carolina based homebuilder, on behalf of individuals whose names, Social Security numbers, financial account numbers, driver's license numbers, and medical or insurance information may have been exposed when an unauthorized third party accessed an employee's cloud accounts in May 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
May 6 to 11, 2026
Files downloaded from an employee's cloud accounts
Notification delay
About 3 months
Access May 2026, discovered Jul 2026, notices Aug 2026
Credit monitoring
12 months
Identity theft monitoring named in the letter
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Mungo Homes dated May 2026.
  • Your letter offered enrollment in a complimentary 12-month membership to an identity theft monitoring product.
  • You had personal, financial, or insurance information held by the company in its capacity as a homebuilder, employer, or contracting party.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Clayton Properties Group, Inc. d/b/a Mungo Homes, a homebuilder headquartered in Irmo, South Carolina, disclosed a data security incident involving unauthorized access to the cloud accounts of one of its employees. According to the notice, on or around May 6, 2026 an unauthorized third party used social engineering techniques to register a new multifactor authentication device and obtain that employee's login credentials. The actor then accessed the employee's OneDrive, SharePoint, and email accounts and downloaded files between May 6 and May 11, 2026. Mungo Homes states that its investigation did not identify evidence of further movement beyond the identified accounts. Notice was filed with the Massachusetts Attorney General's Office and reported publicly on August 14, 2026.

The company reports that a forensic investigation confirmed on July 1, 2026 that certain personal information contained in the downloaded files may have been compromised. The categories of information identified in the filing are name, Social Security number or Individual Taxpayer Identification Number, financial account number, date of birth, driver's license number, physical address, and medical, prescription, or insurance information, with the specific elements varying by individual. The regulator filing reports one affected Massachusetts resident, and the company has not publicly stated a nationwide total. The interval between the incident and notification is one issue this investigation is evaluating. Roughly three months passed between the May 2026 access window and the August 2026 notice, and roughly six weeks passed between the July 1, 2026 forensic confirmation and the reported notification date. Several state breach notification statutes set outer limits on how long a company may take to notify affected individuals after a breach is discovered. Mungo Homes is offering a complimentary 12-month membership in an identity theft monitoring product, with enrollment instructions and a deadline printed in the mailed letter.

The combination of data elements reported here is unusually broad for a construction industry incident. A Social Security number or ITIN cannot be changed on request the way a payment card number can, and it supports new-account fraud, tax refund fraud, and fraudulent benefit claims for years after a breach. A financial account number paired with a name and address raises the risk of unauthorized transfers and account takeover, and a driver's license number can be used to obtain identification documents in another person's name. Medical, prescription, or insurance information can support medical identity theft, in which treatment or prescriptions are obtained in someone else's name. How the multifactor authentication enrollment was compromised, why a single set of credentials permitted bulk download of files containing Social Security numbers and medical information, what monitoring was in place on the affected cloud tenant, why the review took until July 1 to complete, and whether individuals outside Massachusetts were also affected are among the questions being evaluated.

Multifactor authentication bypass Social engineering attack Cloud account compromise Social Security number exposure Massachusetts AG filing Homebuilder data breach
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the identity theft monitoring offer and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 12-month identity theft monitoring

Enroll in the identity theft monitoring product named in your letter before the deadline printed in the notice, using the enrollment code provided. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because a Social Security number or Individual Taxpayer Identification Number was reported as involved, consider requesting an IRS Identity Protection PIN and reviewing your Social Security earnings statement for employment you do not recognize. Because a driver's license number and a financial account number were also reported, contact your state motor vehicle agency about a note on your license record and ask your bank about account alerts or a new account number. Because medical, prescription, or insurance information may have been involved, review the explanation of benefits statements from your health insurer for treatment or prescriptions you did not receive.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

On or about May 6, 2026 Passed
Unauthorized third party registers a new multifactor authentication device and obtains an employee's credentials
May 6 to 11, 2026 Passed
Files downloaded from the employee's OneDrive, SharePoint, and email accounts
Jul 1, 2026 Passed
Forensic investigation confirms the downloaded files contained personal information
Aug 14, 2026 Passed
Notice reported to the Massachusetts Attorney General, letters mailed
Deadline printed in your letter Active
Identity theft monitoring enrollment deadline
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Roughly three months elapsed between the May 2026 access window and the public notice, and roughly six weeks passed between the July 1, 2026 forensic confirmation and notification. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, fraudulent credit accounts or tax filings opened in your name, unauthorized withdrawals or transfers from your financial accounts, medical services or prescriptions billed in your name, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Clayton Properties Group, Inc. d/b/a Mungo Homes to implement stronger data security practices going forward, including phishing resistant multifactor authentication and monitoring for bulk downloads from employee cloud accounts.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Mungo Homes. What should I do? +

Keep the letter, enroll in the complimentary 12-month identity theft monitoring described in your notice before the deadline printed there, order and review your free credit reports at AnnualCreditReport.com or by calling 1-877-322-8228, and consider placing a security freeze or fraud alert with Equifax, Experian, and TransUnion. A freeze is free and blocks new credit from being opened in your name without your authorization. Because a Social Security number or ITIN was reported as involved, requesting an IRS Identity Protection PIN is also worth considering. Because a financial account number was reported, review your bank and card statements and ask your bank about alerts or a new account number. Because medical, prescription, or insurance information may have been involved, review your health insurer's explanation of benefits statements for treatment you did not receive. If you find fraud, file a police report, keep a copy, and use the FTC's recovery guidance at IdentityTheft.gov or 1-877-438-4338. Accepting the monitoring offer does not waive your right to sue.

Am I eligible to join a class action against Mungo Homes? +

If you received a breach notice from Mungo Homes, you may be eligible for a free case evaluation. Eligibility depends on your state of residence, the categories of your data that were exposed, and any losses or out-of-pocket costs you have incurred. The interval between the May 2026 access window, the July 1, 2026 forensic confirmation, and the August 2026 notice may also be relevant, because several state breach notification statutes impose outer time limits on notifying affected individuals. Dapeer Law will review your notice at no cost.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The filing with the Massachusetts Attorney General identifies the categories of information involved as name, Social Security number or Individual Taxpayer Identification Number, financial account number, date of birth, driver's license number, physical address, and medical, prescription, or insurance information, and states that the specific elements varied by individual. The notice does not itemize which files were downloaded, and does not identify how the attacker obtained the employee's credentials beyond describing social engineering techniques used to register a new multifactor authentication device. Your individual letter should specify the categories of your data that were affected. If you no longer have it, Dapeer Law can help you obtain a copy.

Did Mungo Homes offer free credit monitoring? +

Yes. Mungo Homes is offering a complimentary 12-month membership in an identity theft monitoring product. The public filing does not name the provider, and the enrollment code and the enrollment deadline appear in the mailed letter rather than in the regulator filing. Check your notice for the product name, activation instructions, and the date by which you must enroll. Enrolling is separate from, and does not waive, your right to pursue a claim.

How many people were affected by the Mungo Homes breach? +

The filing with the Massachusetts Attorney General reports one affected Massachusetts resident. Because Mungo Homes builds homes across South Carolina, North Carolina, Georgia, and Virginia, the nationwide total is likely higher, but the company has not publicly disclosed it and filings in other states had not been published as of this update. This page will be updated as additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

A copy of the notice is available through the Massachusetts Attorney General's public data breach records, linked in Sources below. If you received a letter but no longer have it, Dapeer Law can assist you in obtaining a copy during your free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Clayton Properties Group, Inc. d/b/a Mungo Homes, the identity theft monitoring provider named in your letter, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on August 14, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Rockwood Retirement Communities Data Breach Lawsuit Investigation

Next
Next

Bloom's Bus Lines Data Breach Lawsuit Investigation