Rich Products Discloses Phishing Breach Impacting ~200
If you are a customer of Rich Products Corporation, here’s what is being claimed, and what it would mean for you.
Rich Products Corporation disclosed a data breach originating from a phishing attack on a third-party vendor (First Advantage) employee account. The incident exposed sensitive personal information including Social Security numbers and driver's license data for approximately 200 individuals associated with the company. Notifications were issued following the vendor's investigation.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Rich Products Corporation customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
A phishing attack on a third-party vendor employee account at First Advantage has led Rich Products Corporation to notify approximately 200 individuals that their names, Social Security numbers, and driver's license data may have been exposed.
Public reporting indicates the breach originated when attackers compromised an employee account at the background-check provider First Advantage through phishing. Rich Products Corporation, a major food manufacturer, disclosed the incident on May 29, 2026, after the vendor completed its investigation. Notifications were sent directly to the affected individuals, who appear to be current or former employees or contractors associated with the company. The compromised data includes full names, Social Security numbers, and driver's license information. No evidence has surfaced suggesting the data was misused at the time of disclosure.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
For executives and high-net-worth families, this incident underscores how supply-chain vulnerabilities at seemingly routine service providers can expose core identity documents. A single vendor breach can place high-value targets at immediate risk of identity theft, fraudulent loan applications, tax fraud, or targeted social engineering. When the affected individuals include senior leaders or family members whose personal details are linked to corporate travel, executive benefits, or household staff, the downstream operational and reputational exposure increases significantly.
The doxxing and identity-chain implications are particularly concerning. Once Social Security numbers and driver's license data enter criminal ecosystems, they frequently serve as anchor points for linking disparate online handles, email addresses, phone numbers, and family relationships. Available reporting describes how such records accelerate doxxing campaigns that can cascade into account takeovers across email, financial services, and gaming platforms. Credential leaks of this nature often become the starting point for broader exposure chains that reveal home addresses, family member names, and children's online accounts.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real-world identity, followed by cleanup of exposed records.
- Rotate any password used at First Advantage or related vendor portals wherever it has been reused, and immediately enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 15B+ breach records and 100+ platforms so the next exposure of your information is detected and addressed within hours rather than months.
- Cover the entire household with DoxxScan family protection that extends to dependents and children's gaming accounts, which frequently chain back to the same addresses and parent credentials.
- For executives and family offices, layer on hands-on remediation specialists who manage takedown requests across data brokers and high-risk platforms.
Organizations and families that treat vendor-related breaches as isolated events miss the larger pattern of accelerating identity exposure. A structured, ongoing defense that combines rapid detection with expert intervention remains the most practical way to limit damage. DoxxScan by GalaxyWarden delivers continuous monitoring across 15B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and family coverage that explicitly includes children's gaming accounts vulnerable to the same credential-stuffing and doxxing chains seen in incidents like the Rich Products breach.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Rich Products Corporation.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Betterment Robo-Advisor 1.4M Customers — January 2026
Robo-advisor Betterment disclosed a breach affecting ~1.4 million customers in January 2026 via a fa…
Everest ransomware claims breach of Liberty Mutual insurance data
The Everest ransomware group listed Liberty Mutual on its leak site, claiming theft of over 100 GB o…
Instructure Canvas LMS suffers massive data theft affecting 275M users
Education technology company Instructure confirmed a breach of its Canvas learning management system…