Loop Capital Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Loop Capital, here’s what the filing says was exposed, and what to do about it.
Loop Capital notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 19, 2026, and the notice lists social security numbers among the information exposed.
A Social Security number belonging to one of just nine Massachusetts residents has been exposed in a data breach reported by Loop Capital. Because this identifier cannot be changed or replaced, the exposure creates a permanent risk of identity theft and tax fraud that will last for years.
The Exposure Is Small but Permanent
Loop Capital filed the notice with the Massachusetts Attorney General on May 19, 2026. The filing states that Social Security numbers were exposed for nine people. No other categories of information are listed in the record.
This is one of the smallest breaches reported in the state this year. Yet its impact on those nine individuals is outsized precisely because a Social Security number never expires. Unlike a credit card or password, it cannot be reissued on request. Once it is out of the organisation’s control, it remains usable for identity theft, fraudulent tax returns, loan applications in someone else’s name, and other long-term fraud schemes.
What This Means for Anyone Who Receives the Letter
If Loop Capital sends you a notification, your Social Security number is among the records included in this incident. The company is required by Massachusetts law to contact affected individuals directly, usually by mail. Absence of a letter almost always means your information was not part of the nine records exposed. However, if you have moved since the incident occurred, the letter may not have reached you. In that case you should contact Loop Capital directly to confirm whether your records were involved.
The filing does not state when the incident itself took place, only the date the notice was filed. This means the only reliable way to determine whether you are affected remains the letter from the firm.
Why Social Security Numbers Create Enduring Risk
A Social Security number combined with basic personal information is enough to file a fraudulent tax return, open new accounts, or claim government benefits. Because the number cannot be retired or replaced the way a compromised password or credit card can, the risk does not diminish over time. Credit monitoring helps detect some misuse, but it cannot prevent every form of identity theft that relies on this single unchanging identifier.
The record contains no indication that passwords, login credentials, or financial account numbers were exposed. That limitation is genuinely good news: it means the breach does not put your existing Loop Capital account or online credentials at direct risk. The sole lasting consequence is the permanent identifier itself.
The Gap Between Incident and Notification
Because the filing provides only the May 19, 2026 notification date and does not disclose a separate incident date, it is impossible to calculate how long the information may have been accessible. Massachusetts law sets deadlines for notification once an organisation becomes aware of a breach, but without an incident date the length of any delay cannot be determined from the public record.
What the Nine-Person Scale Actually Tells Us
The small number of affected individuals does not minimise the seriousness for those nine people. When a Social Security number is exposed, each record carries the same long-term danger regardless of how many others were involved. The filing simply establishes that Loop Capital determined these nine Massachusetts residents were the ones whose Social Security numbers were included.
Protecting Yourself When the Identifier Cannot Be Changed
Since the core exposed element cannot be replaced, the focus shifts to detection, freezing access, and vigilance. Place a freeze on your credit files with the three major bureaus so new accounts cannot be opened without your explicit permission. Monitor your tax filings closely each year and respond immediately to any IRS notice that appears inconsistent with your records. Consider placing an extended fraud alert that lasts for seven years, which forces creditors to take extra steps to verify your identity before issuing new credit.
Review every explanation of benefits or tax document you receive for unfamiliar activity. Even years from now, a fraudulent return filed under your number could trigger collection efforts aimed at you. Early detection remains one of the few practical controls available when the primary identifier is permanent.
The record does not establish how the information was accessed or whether it was exfiltrated. It simply confirms that Social Security numbers for nine people left Loop Capital’s control and must now be treated as permanently compromised.
For the vast majority of people who visit this page, no letter will arrive and no action will be required. For the small group who do receive notification, the exposure is limited but irreversible. The practical response is therefore narrow and specific: freeze your credit, watch your tax mail, and treat the number as public for the rest of your life.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Loop Capital.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…