Rectory School Data Breach Notice (Massachusetts Attorney General)
If you received a notice from Rectory School, here’s what the filing says was exposed, and what to do about it.
Rectory School notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on July 21, 2026, and the notice lists social security numbers, financial account numbers and driver's license numbers among the information exposed.
The filing from Rectory School means that for 91 people, their Social Security numbers, financial account numbers, and driver's license numbers are now outside the school's control. These three categories together create a durable set of keys that do not expire and cannot be replaced the way a credit card or password can.
Social Security Numbers Cannot Be Reissued
A Social Security number is permanent. Once it leaves an organisation's systems, it remains a lifelong identifier that can be paired with other public or stolen data to open accounts, file fraudulent tax returns, or build synthetic identities. The Massachusetts filing lists Social Security numbers among the exposed data for this incident involving 91 individuals. That exposure does not fade with time.
Financial account numbers and driver's license numbers add immediate practical value to anyone who obtains the records. A driver's license supplies a verified name, address, date of birth, and unique ID number. When combined with a Social Security number, these details allow criminals to bypass many remote verification checks that rely on matching exactly this combination of government-issued identifiers.
What the Record Does Not Show
The filing does not list passwords, and no credential exposure occurred. This removes one common source of immediate account takeover risk. The record also does not name medical information, email addresses, or dates of birth as exposed categories. Only the three categories named above appear in the official notice submitted to the Massachusetts Office of Consumer Affairs on July 21, 2026.
Because the filing carries no separate incident date, it is not possible to calculate how long the information may have been accessible. The only reliable way to determine whether your records were included is the notification letter itself. Rectory School is required to contact affected Massachusetts residents directly, usually by mail. If you have not received such a letter at your last known address, it is likely your information was not part of the 91 records involved. Anyone who has moved since the events described in the filing should contact the school directly to confirm their status.
The Long-Term Risk Profile
The combination of a Social Security number and a driver's license number is particularly valuable for synthetic identity fraud. Criminals can use real identifiers from multiple victims to create a fictitious person who then applies for credit, government benefits, or employment. Because these identifiers never expire, the risk window remains open for years or decades.
Financial account numbers raise the possibility of fraudulent ACH transfers, wire instructions, or loan applications if the attacker also possesses matching personal details. While banks can reverse some unauthorized transactions, the process requires time, documentation, and vigilance. Early detection matters.
Why the Scale Matters
The breach affects 91 individuals according to the official filing. This is a contained but not trivial number for an educational institution. Each person whose records were exposed now carries a permanent increase in identity-theft exposure that cannot be undone by changing a password or canceling a single card.
Practical Steps That Address This Exposure
Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new credit accounts from being opened in your name without your explicit permission and is the single most effective control available when a Social Security number has been compromised.
Monitor your bank and credit-card statements weekly for the next twelve months. Look specifically for small test charges or unfamiliar ACH withdrawals that often precede larger fraud. Set up account alerts for any transaction above zero dollars if your bank offers that option.
File your taxes as early as possible each year. This reduces the window during which a criminal can submit a fraudulent return using your Social Security number. If you receive a notice from the IRS that a return has already been filed under your number, act immediately.
Review your annual credit reports from the three major bureaus for accounts you do not recognize. Dispute any suspicious entries in writing. Consider adding a fraud alert or extended fraud alert to your files, which forces creditors to take extra verification steps.
Contact Rectory School if you have not received a notification letter but believe you may have been a student, parent, or employee whose records could have been included. The filing does not state when the underlying events occurred, so the letter remains the clearest indicator of personal impact.
These exposures cannot be erased, but they can be managed. The combination of a credit freeze, close monitoring, and early tax filing addresses the specific permanent and semi-permanent identifiers named in the Rectory School filing. The absence of exposed passwords or login credentials means your existing online accounts with the school or other services are not directly at risk from this particular incident.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Rectory School.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…