Skip to content
Back to Blog
high severity May 18, 2026 · 4 min read

Perrigo Data Breach Notice (Vermont Attorney General)

If you received a notice from Perrigo, here’s what the filing says was exposed, and what to do about it.

Perrigo notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on May 18, 2026, and the notice lists social security numbers among the information exposed.

Perrigo Data Breach Notice (Vermont Attorney General)

A Social Security number belonging to one of the 54 affected individuals is now in unknown hands and cannot be replaced. That single fact defines what comes next for anyone notified in this incident.

The filing submitted to the Vermont Attorney General on May 18, 2026 states that Perrigo exposed Social Security numbers of 54 Vermont residents. No other categories of information are listed in the record. This means the breach carries permanent risk that cannot be eliminated the way a compromised password or credit card can.

Social Security Numbers Create Lifelong Identity Theft Exposure

Unlike passwords, credit cards, or even driver's licenses, a Social Security number never expires and cannot be reissued on request. Once it leaves the organisation's control, it remains a valid key to tax accounts, government benefits, credit applications, and employment records for the rest of the person's life.

Thieves who obtain an SSN can file fraudulent tax returns to claim refunds before the rightful owner does, open new lines of credit in the victim's name, or apply for government services using the number as proof of identity. These attacks do not require the thief to have any other details from this specific breach. The SSN alone is often enough to pass initial automated checks.

Because the record lists only Social Security numbers, this incident does not involve exposed passwords, financial account numbers, or medical records. That limitation matters. It narrows the immediate damage compared with breaches that dump dozens of data types at once.

What the 54-Person Filing Actually Tells You

The Vermont filing is required when a company discovers that protected resident data has been exposed. Perrigo's submission confirms that 54 people were affected and that Social Security numbers were included. The record does not state how the exposure occurred, when it began, or whether the data was stolen, accidentally published, or accessed by an unauthorised party.

What it does establish is that the organisation is now legally required to notify the affected Vermont residents directly, usually by mail. If you have not received a letter from Perrigo, it is likely that your information was not part of this incident. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact Perrigo directly to confirm whether they were included.

Why This Exposure Is Different From Most Breaches

Many data incidents involve information that can be changed or cancelled. A leaked password can be updated within minutes. A compromised credit card can be replaced the same day. A Social Security number offers no such remedy. Its permanence is why regulators treat SSN exposures as especially serious even when the total number of people affected is relatively small.

The scale here — 54 individuals — is modest by breach standards. The significance lies entirely in the type of data lost rather than the headcount. Each of those 54 SSNs retains its full value to identity thieves years from now.

How to Determine Whether This Affects You

The only reliable way to know is the notification letter itself. State law requires Perrigo to contact each affected person directly. Absence of a letter from Perrigo almost always means your records were not in the group of 54. If you have changed addresses since the incident occurred, reach out to Perrigo's privacy or customer service team to verify your status. Do not rely on the public filing alone.

Practical Steps That Address This Specific Risk

Place a freeze on your credit reports with Equifax, Experian, and TransUnion. This prevents new credit accounts from being opened in your name without your explicit permission. It is the single most effective step available when an SSN has been exposed.

Monitor your tax account with the IRS through their online portal and set up alerts for any unexpected filings. Fraudulent tax returns filed with your SSN are one of the fastest ways thieves monetise stolen numbers.

Review your annual Social Security earnings statement each year to ensure no one is using your number for employment elsewhere. Discrepancies here can reveal identity theft that credit monitoring might miss.

Consider placing an extended fraud alert on your credit files, which lasts for seven years and requires creditors to take extra steps to verify your identity before issuing new credit.

Be extremely cautious with any unsolicited calls, texts, or emails claiming to be from government agencies, banks, or tax authorities that ask you to confirm your Social Security number. Legitimate organisations already have it and will not request it over the phone or by email.

The exposure of these 54 Social Security numbers creates a permanent risk that requires ongoing vigilance rather than a one-time fix. While the breach itself is limited in scope, the data involved has no expiration date. The steps above reduce what thieves can do with the information but cannot make the numbers themselves safe again.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Perrigo.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity High includes at least one identifier that cannot be reissued
Disclosed May 18, 2026
Last reviewed July 22, 2026
Affected 54
Data exposed Social Security Numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email