Empower The User Inc, dba Skillwell Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Empower The User Inc, here’s what the filing says was exposed, and what to do about it.
Empower The User Inc, dba Skillwell notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 12, 2026, and the notice lists financial account numbers and driver's license numbers among the information exposed.
The filing from Empower The User Inc, doing business as Skillwell, reports that one Massachusetts resident’s financial account numbers and driver’s license numbers were exposed. With only a single person named in the state record, this is the narrowest breach notification Massachusetts has seen in some time.
A single affected record still carries permanent risk
When a driver’s license number and financial account details leave an organization’s control, the exposure does not expire. A driver’s license number combined with an account number gives fraudsters durable building blocks for identity theft, loan applications, and account takeover attempts that can surface months or years later. Unlike a credit card, neither piece of information can be cancelled or reissued on demand.
The record contains no indication that passwords were exposed. That absence is genuine good news. You do not need to change any Skillwell password because of this incident, and you should treat any advice telling you otherwise as incorrect.
What the two exposed categories actually enable
A driver’s license number is a government-issued identifier that many financial institutions still accept as primary proof of identity. Once it is loose, it can be paired with publicly available information to answer knowledge-based authentication questions or to impersonate you during remote verification processes.
Financial account numbers, when paired with the driver’s license, give a fraudster enough detail to attempt unauthorized transfers, open new accounts in your name, or file fraudulent tax returns. These two categories together remain usable for identity crimes long after the filing date of August 12, 2026.
The filing does not state when the incident itself occurred. Because no incident date is given, there is no reliable way to calculate how long the information may have been accessible. The only practical test available to you is the notification itself.
How to determine whether this record concerns you
Skillwell is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely that your information was not included in the single record reported to Massachusetts. However, letters can go to outdated addresses. Anyone who has moved since the time the data was held by Skillwell should contact the company directly to confirm whether their records were part of this filing.
The Massachusetts Attorney General’s office lists this as a one-person breach. The small scale does not reduce the seriousness of the categories involved; it simply means the exposure was tightly limited to one individual’s file.
Why these specific fields matter more than volume
Most people measure breach severity by the total number of records. In this case the number is one. What matters is that the two categories listed cannot be rotated or replaced the way a compromised password or credit card can. A driver’s license number stays with you for decades. A financial account number can be used to create long-term financial entanglement in your name.
This is why the organization-posture lens is the clearest way to view the event. The filing itself reveals nothing about how the data left Skillwell’s control, whether encryption was in place, or what access controls existed. Those details remain undisclosed. What the record does establish is that two high-value, non-resettable identifiers left the company’s custody and reached at least one Massachusetts resident.
The limits of what this filing can tell us
The notification does not disclose a root cause. It does not say whether the data was encrypted at rest or how the threat actor obtained it. Those uncertainties are common in attorney general filings, which are designed to document the fact of exposure and the categories involved rather than to provide a forensic summary.
Because the record names only financial account numbers and driver’s license numbers, you can be certain that no passwords were included. The remedy steps generated elsewhere on this page therefore do not include password changes for Skillwell. Focus instead on the two categories that were named.
Practical steps that address exactly these exposures
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This is the single most effective barrier against new accounts opened with your driver’s license and financial details.
- Monitor your bank and credit-card statements for any transactions you do not recognize. Set up account alerts for transfers or changes to contact information.
- Respond promptly to any verification requests from financial institutions that reference your driver’s license. Fraudsters may attempt to preemptively answer security questions using the exposed data.
- Keep the notification letter and note the exact date you received it. If suspicious activity appears later, regulators and banks will ask when you first learned of the breach.
- Contact Skillwell directly if you have moved or believe you should have received a letter but did not. Only the company can confirm whether your specific record was the one reported.
The exposure of one person’s financial account numbers and driver’s license numbers is limited in scope but not in consequence. These identifiers do not lose their value over time. The actions above give you the practical control that the original record can no longer provide.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Empower The User Inc.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.