Skip to content
Back to Blog
medium severity September 01, 2026 · 5 min read

BRG data breach: what the 2025 TRICARE incident means for you

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

In late February 2025 someone broke into systems at consulting firm Berkeley Research Group and copied files. About 96,000 TRICARE beneficiaries were later identified in those files; Social Security numbers were included for 38 of them. Affected people were mailed notices offering two years of free credit monitoring, and there are no reports of fraud from the incident.

BRG data breach: what the 2025 TRICARE incident means for you

Between the evening of 28 February 2025 and 2 March 2025, someone who should not have had access got into systems at Berkeley Research Group (BRG), a consulting firm, and copied data. BRG found the activity on 2 March 2025 and stopped it. BRG was doing work for Evernorth Federal Services (formerly Express Scripts), which administers TRICARE pharmacy benefits for the Defense Health Agency. Because of that work, about 96,000 TRICARE beneficiaries were later identified in the copied files.

What was copied varied by person. It could include names, dates of birth, contact information, health-plan names, member IDs, group numbers, medical record numbers, clinical, treatment or prescription information, and payment history. Social Security numbers were involved for 38 of those 96,000 people. BRG reported the incident to law enforcement and to state attorneys general — California’s listing shows a breach date of 28 February 2025 and a report date of 31 August 2026. People who were identified were mailed notices offering 24 months of free Kroll credit monitoring. BRG has said it is not aware of any fraud or identity theft from this. The same incident also affected other BRG clients; 96,000 is only the TRICARE group.

Most coverage is reassuring you about the wrong thing

Write-ups of this incident tend to lead with the same two points: Social Security numbers were taken for only 38 people, and nobody has reported identity theft. Both are true. They also quietly recast the story as a near-miss on credit fraud.

If you are one of the 96,000, that is probably not what actually changed for you. BRG is not TRICARE and not your pharmacy. It is a consulting firm that was holding files because the company that runs TRICARE pharmacy benefits had hired it. You did not choose BRG, and you had no reason to know it had anything about you. For most people, what left its systems was not a Social Security number. It was a named list of TRICARE beneficiaries — service members, retirees, and families — with dates of birth, contact details, plan and member identifiers, and in many cases clinical, treatment, or prescription information and payment history.

That mix is useful in a different way than a stolen Social Security number. It is enough for someone to write or call as if they already handle your pharmacy benefits. It is enough to know what you have been treated for or prescribed. Credit monitoring watches for new loans and credit cards. It does not tell you who has a copy of that file, and it does not take the copy back. BRG later settled with the attacker; paying does not erase a file that was already copied.

The wait was long, too. The intrusion was in early March 2025. Some notices to individuals went out in the autumn of 2025; the official TRICARE substitute notice was posted in May 2026, and the California filing is dated 31 August 2026. If you are only hearing about this now, the delay is part of what happened, not proof that it was minor.

What to actually expect

  • A mailed letter from BRG describing the incident and offering 24 months of free Kroll credit monitoring. That letter is the official channel. The Defense Health Agency also posted a substitute notice in May 2026 for the TRICARE group. Unexpected texts or emails about “your BRG notice” are not how this was communicated.
  • Contact that tries to sound like TRICARE, Express Scripts, Evernorth, a pharmacy, Kroll, or BRG, and that already knows a name, date of birth, member ID, or plan name. Those details were in the copied files, which is why a fake message can sound real. Nobody needs you to “confirm” that information over the phone or through a link.
  • Not a sudden wave of new credit cards or loans tied to this, based on what BRG and regulators have said. That is not the same as “nothing left the building.” For most of the 96,000, the live problem is a convincing health-plan or pharmacy impersonation, not a new account in your name.
  • If you never used TRICARE, you may still have been in a different BRG client file. Other BRG clients were affected by the same incident and people in those groups received separate notices. There is no single public list of everyone involved.

What you can and cannot fix

The copy cannot be pulled back. Names, dates of birth, and contact information that were taken are out. Health-plan names, member IDs, group numbers, medical record numbers, and any clinical, treatment, prescription, or payment details that were copied are out. For 38 people, Social Security numbers are out. A settlement with the attacker does not undo that, and no company can recall the file.

  • If a letter arrived, read what it says was in your file and enroll in the 24 months of Kroll monitoring named in that letter. That is the one protection already paid for, and the letter is the only document that tells you which of your fields were involved. There is no reliable public lookup that can answer that question for you.
  • For anything about your prescriptions, TRICARE, this incident, or your monitoring offer, use the phone number on your insurance card or a site you type yourself. Hang up on inbound calls that already seem to know your member ID. The useful move here is not a new password. It is refusing to treat a well-informed stranger as your health plan.
  • If your notice said a Social Security number was involved, a credit freeze at the major bureaus is the control that actually blocks new accounts. For everyone else in the 96,000, that is extra caution, not the main issue. The letter, not a guess, is what tells you which group you are in.
  • Reduce people-search listings that publish you. A bare leaked record — a name, a date of birth, contact details, maybe a member ID — becomes much more useful to a stranger when it can be matched to listings that add relatives, phone numbers, employers, and previous addresses. Those listings, unlike the BRG copy, can actually be taken down. That is the lever you still have.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on BRG.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Medium identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed September 01, 2026
Last reviewed September 1, 2026
Affected Unconfirmed
Data exposed Full namesDates of birthContact informationHealth plan namesMember IDsGroup numbersMedical record numbersClinical and prescription information +2 more
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email