Skip to content
Back to Blog
high severity June 26, 2026 · 4 min read

New Apostolic Church USA Data Breach Notice (Vermont Attorney General)

If you received a notice from New Apostolic Church USA, here’s what the filing says was exposed, and what to do about it.

New Apostolic Church USA notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on June 26, 2026, and the notice lists social security numbers among the information exposed.

New Apostolic Church USA Data Breach Notice (Vermont Attorney General)

A Social Security number belonging to one of just six Vermont residents has been exposed in a data breach involving the New Apostolic Church USA. The organization filed notice with the Vermont Attorney General on June 26, 2026, confirming that Social Security numbers were included in the incident.

This is a small breach by any standard, yet the information lost carries outsized risk. Unlike passwords or credit card numbers, a Social Security number cannot be replaced. Once it is out of the organization’s control, it remains a permanent key to your identity and financial life for decades.

The Permanent Nature of a Social Security Number

The filing lists Social Security numbers as the exposed data category. No other categories are named. This means the core risk is identity theft and fraudulent use of your number rather than immediate account takeover or password-related threats.

Because no passwords were exposed, there is no need to change any login credentials for the New Apostolic Church USA. That particular worry does not apply here. The real concern is what criminals can build over time using a valid SSN combined with publicly available or later-acquired personal details.

Thieves can use a stolen Social Security number to file fraudulent tax returns, open new credit accounts, obtain government benefits, or create synthetic identities. These crimes can go undetected for years, damaging credit scores and creating years of paperwork to resolve.

What the Small Scale Actually Tells Us

Only six people are named in the Vermont filing. The record does not state when the incident occurred, only the filing date of June 26, 2026. It also does not disclose whether the data was stolen by an outside party, accidentally exposed, or accessed improperly by someone with internal access.

The limited number of affected individuals does not reduce the seriousness for those six people. Each person whose Social Security number was exposed now carries the same lifelong risk. The filing does not indicate that the data was encrypted or otherwise protected at the time of the incident.

How to Determine Whether You Are One of the Six

The New Apostolic Church USA is required to notify affected individuals directly, usually by mail. If you receive a letter from the organization, read it carefully. It will confirm whether your information was included and provide any additional details they are legally required to share.

Absence of a letter usually means your records were not part of this incident. However, if you have moved since the time the incident occurred, the notification may have gone to an old address. In that case, contact the organization directly to confirm your status. The filing does not provide an incident date, so the letter itself remains the clearest indicator available.

Why This Exposure Remains Valuable Years Later

A Social Security number does not expire and cannot be reissued on request the way a compromised card or password can. This single piece of information, when paired with a name and date of birth, allows criminals to impersonate you with government agencies, banks, and employers.

Even if the breach itself was limited, the value of the exposed numbers does not diminish quickly. Identity thieves often sit on stolen SSNs for months or years until they can combine them with additional data from other sources.

Protecting Yourself After This Breach

Place a freeze on your credit reports with Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name without your explicit permission. The freeze is free, reversible, and one of the most effective steps you can take.

Monitor your credit reports and tax filings closely for the next several years. Look for unfamiliar accounts, unexpected tax documents, or inquiries you did not authorize. Consider requesting an identity theft protection PIN from the IRS to block fraudulent tax returns.

Be extremely cautious with any unsolicited calls, emails, or messages that ask for your Social Security number or use it to “verify” your identity. Criminals who already possess the number will sound legitimate.

If you ever become a victim of tax-related identity theft, immediately file Form 14039 with the IRS and maintain detailed records of every fraudulent activity tied to your number. Recovery is possible but time-consuming.

The exposure of even a small number of Social Security numbers creates a permanent change in risk for the people affected. While the organization has fulfilled its legal duty to notify the state, the practical burden of protection now rests with you. Acting quickly on credit freezes and ongoing monitoring remains the most practical defense against the long-term consequences of this incident.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on New Apostolic Church USA.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity High includes at least one identifier that cannot be reissued
Disclosed June 26, 2026
Last reviewed July 22, 2026
Affected 6
Data exposed Social Security Numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email