StrataDx Data Breach Notice (Massachusetts Attorney General)
If you received a notice from StrataDx, here’s what the filing says was exposed, and what to do about it.
StrataDx notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on July 14, 2026, and the notice lists social security numbers and financial account numbers among the information exposed.
The exposure of your Social Security number and financial account numbers in the StrataDx breach means those two permanent identifiers are now outside the organisation’s control. A Social Security number cannot be replaced like a lost credit card, and a financial account number can be used immediately for fraud if the attacker also holds supporting details. With 84 Massachusetts residents named in the filing, this is a small but precise incident that leaves each affected person with long-term identity risks that do not fade.
Social Security Numbers Retain Full Value Years Later
The Massachusetts Attorney General’s filing lists Social Security numbers as exposed. Because these numbers are permanent and cannot be reissued on request, their value to identity thieves does not expire. Criminals can use them to open new accounts, file fraudulent tax returns, or claim government benefits in your name. Unlike passwords or credit cards, there is no simple reset. The risk remains for as long as the number stays valuable to fraudsters, which is effectively forever.
Financial account numbers were also exposed. These can enable direct account takeovers, unauthorized transfers, or new fraudulent accounts opened in combination with the Social Security number. The combination of the two data types significantly raises the practical risk of both tax fraud and financial fraud.
No Passwords or Credentials Were Exposed
The filing does not list passwords, login credentials, or any authentication data. This is genuinely good news. You do not need to change any StrataDx password because none was compromised. The breach centers on the non-changeable identifiers that matter most for identity theft rather than account access. This narrows the immediate threat to the permanent records instead of every online account you hold.
What the 84-Person Filing Actually Tells You
The record shows that StrataDx notified the Massachusetts Office of Consumer Affairs on July 14, 2026. It names exactly 84 affected Massachusetts residents. The filing does not disclose when the incident occurred, whether the data was copied or simply viewed, or the root cause. Those details remain unknown. What is known is limited to the two categories listed and the exact headcount printed beside this article.
Because the filing lists only Social Security numbers and financial account numbers, no medical records, driver’s license numbers, or other categories were named. This matters. Many breach notices include broader data sets; this one does not. The absence of passwords is also explicit in what the record omits.
How to Determine Whether You Are Affected
StrataDx is required to notify affected individuals directly, usually by mail. If you received a letter from them, your information was included. If you have not received any notice, it is likely you were not among the 84 people named. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact StrataDx directly to confirm whether their records were involved. The filing does not state when the incident took place, so the letter itself remains the only practical check available.
The Long-Term Reality of Permanent Identifiers
A Social Security number is the cornerstone of most identity theft schemes precisely because it cannot be changed at will. Once it is loose, the prudent assumption is that it may surface in criminal markets or private databases for years. The same applies to the financial account numbers. Monitoring and early detection therefore become ongoing responsibilities rather than one-time tasks.
Credit reports and tax records are the two places where misuse most often appears first. New accounts opened with your Social Security number will show on your credit file. Fraudulent tax filings are usually discovered when your legitimate return is rejected. Both events can be spotted through regular checks rather than waiting for damage to accumulate.
Concrete Monitoring Steps That Match This Exposure
Place a fraud alert or credit freeze with the three major credit bureaus. A freeze stops new accounts from being opened in your name and is the strongest single control available when a Social Security number is exposed. It is free and reversible.
Review your credit reports from Equifax, Experian, and TransUnion every four months. Look for accounts you did not open. The combination of the exposed Social Security number and financial account numbers makes this review more urgent than in breaches that lack those two fields.
File your taxes early each year. This reduces the window in which a fraudster can submit a fake return using your Social Security number. If someone else files first, the IRS will reject your legitimate return and you will need to submit an identity theft affidavit.
Monitor bank and credit-card statements for unfamiliar transactions linked to the exposed financial account numbers. Set up account alerts for any movement above a low dollar threshold. Early detection limits losses and simplifies disputes.
Contact StrataDx if you have changed addresses since the incident. Confirm directly whether your records were part of the 84 named in the Massachusetts filing. This step removes uncertainty that mailed letters cannot resolve.
The exposure is serious because the compromised data cannot be revoked. Yet the small scope, the absence of credentials, and the narrow list of categories give you a clearer picture than many larger breaches provide. Focus on the controls that still work—freezes, monitoring, early tax filing, and direct confirmation—rather than on what cannot be undone.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on StrataDx.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…