Cornick Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Cornick, here’s what the filing says was exposed, and what to do about it.
Cornick notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 14, 2026, and the notice lists social security numbers among the information exposed.
A Social Security number cannot be replaced the way a credit card or password can. For the five Massachusetts residents named in this filing, that single fact now defines the practical outcome of the breach reported on May 14, 2026.
Cornick’s notice to the Massachusetts Office of Consumer Affairs lists Social Security numbers as exposed. No other categories appear in the record. The filing does not state how the numbers were accessed, whether any additional information was taken, or when the incident itself occurred. What it does establish is that five people’s permanent identifiers are now outside the organisation’s control.
What a Social Security Number Actually Enables
An SSN combined with a name and date of birth is enough to open new accounts, request tax transcripts, file fraudulent returns, or apply for government benefits in someone else’s name. Because the number never expires and cannot be reissued on demand, the exposure does not fade with time the way a compromised password or temporary credit card number does.
This is the core difference between this incident and breaches that involve only changeable credentials. The record shows no passwords were exposed. That limitation matters: you do not need to worry about someone logging into a Cornick account with stolen login details. The risk sits entirely with identity theft and fraud that can be attempted years from now using the SSN.
The Scale Is Small, the Impact Is Personal
Only five individuals are listed in the Massachusetts filing. Small numbers do not reduce the seriousness for those affected. When a permanent identifier leaves an organisation, the consequences belong to the person whose number it is, not to the size of the group.
The record contains no information about the method of access. It does not say whether the exposure resulted from a cyber attack, an insider incident, lost media, or something else. Speculation on those points is not supported by the filing and does not change what you must now manage.
How to Determine Whether This Filing Concerns You
The organisation is required to notify affected individuals directly, usually by mail. If you received a letter from Cornick about a data breach, this filing refers to you. If you have not received such a letter, it is likely you were not among the five people named. However, anyone who has moved since the incident should contact Cornick directly to confirm whether their records were included.
Absence of a letter is usually meaningful, but it is not absolute proof. Letters can be delayed, misdelivered, or sent to an old address. The only authoritative answer comes from the organisation that holds the records.
Why This Exposure Lasts Decades
Unlike a password that can be changed in minutes or a credit card that can be cancelled and reissued, a Social Security number stays with you for life. Credit bureaus, tax agencies, employers, and government programs continue to accept it as proof of identity long after this breach is forgotten by everyone except the people whose numbers were taken.
This permanence is why regulators treat SSN exposures differently from other data breaches. The filing’s limited scope does not reduce the duration of the risk it creates for the individuals involved.
What Remains Under Your Control
You cannot change the number, but you can reduce what criminals can do with it. The most effective steps focus on early detection and blocking new-account fraud rather than attempting to make the SSN unusable.
Place a freeze with each of the three major credit bureaus. This prevents new creditors from accessing your credit file without your explicit permission. A freeze does not affect your existing accounts or credit score, but it stops most attempts to open loans, credit cards, or services in your name using the exposed SSN.
Monitor your annual tax transcript. Identity thieves sometimes file fraudulent returns early in the year. Requesting a transcript each year lets you see whether a return was filed under your SSN that you did not submit.
Consider an identity theft protection service that includes dark-web monitoring for your SSN and assistance filing disputes if fraud appears. While not a guarantee, these services can reduce the time between when fraudulent activity occurs and when you learn about it.
Review every explanation of benefits and tax document you receive. Even a single unfamiliar entry can signal that someone is using your number. Early detection remains one of the few practical advantages you retain when a permanent identifier is exposed.
The record is narrow. Five people. Social Security numbers. No passwords. No other categories listed. The filing does not support broader conclusions about Cornick’s security practices or the root cause. What it does support is clear: the five affected individuals now carry a lifelong risk that did not exist before May 14, 2026. Managing that risk starts with confirming you are one of them and then placing the controls that are still available.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Cornick.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…