The International Code Council, Inc. Data Breach Notice (Massachusetts Attorney General)
If you received a notice from The International Code Council, Inc., here’s what the filing says was exposed, and what to do about it.
The International Code Council, Inc. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 18, 2026, and the notice lists credit or debit card numbers among the information exposed.
The International Code Council, Inc. has notified Massachusetts authorities that the credit or debit card numbers of eight people were exposed in a data breach. The filing, submitted on August 18, 2026, lists only this category of information.
Credit and debit card numbers remain immediately usable
If your card number was among those exposed, it can still be used for fraudulent purchases until you cancel the card and receive a replacement. Unlike passwords or account credentials, which were not exposed here, a card number combined with its expiration date and CVV (often stored alongside in the same systems) lets someone make online or phone purchases right away. The record does not state whether expiration dates or security codes were also taken, but the exposure of the card numbers themselves creates real, short-term fraud risk.
This is the only category named in the filing. No Social Security numbers, no dates of birth, no addresses, and no passwords were listed as exposed. That limits the long-term identity theft potential. A stolen card number can be canceled and reissued. The absence of permanent identifiers means this incident does not create the kind of lifelong monitoring burden that many larger breaches impose.
What the small scale actually tells you
Only eight Massachusetts residents appear in this notification. When so few people are affected, it often points to a targeted or narrowly contained incident rather than a broad compromise of an entire customer database. The filing does not disclose how the card numbers were accessed, whether the data was encrypted, or the root cause. Those details remain unknown.
Because the record names only credit and debit card numbers, the primary concern is immediate financial fraud, not the slow-building identity theft that comes with biographic data. Card issuers can usually reverse fraudulent charges, but the process still requires your time and attention. The faster you act, the smaller the chance that unauthorized transactions appear on your statement.
How to determine whether this notice concerns you
The International Code Council, Inc. is required to notify affected individuals directly, usually by mail. If you received a letter from them, this filing almost certainly refers to you. If you have not received any communication, your information was likely not included. However, if you have moved since the incident occurred, the letter may have gone to an old address. In that case, contact the organization directly to confirm whether your records were involved. The filing does not state when the incident took place, so the letter itself remains the clearest indicator available.
Why this exposure still matters even without permanent identifiers
A single exposed card number can lead to months of monitoring statements, disputing charges, and requesting new cards. When the organization holds payment information for services or memberships, that card is often linked to an active account. Fraudsters test stolen card details quickly. Even though no passwords were exposed and you do not need to change any login credentials for this incident, the card itself must be treated as compromised.
The fact that only card numbers appear in the record is genuinely good news compared with breaches that release Social Security numbers or driver’s license data. Those cannot be replaced. Your card can. The limited scope reduces the overall risk profile, but it does not eliminate the need for prompt action on the cards that may have been affected.
Replacing the exposed payment method
Contact the bank or card issuer listed on the back of your card. Tell them you need a replacement because the number was exposed in a breach. Most issuers will send a new card within a few business days and can backdate protection so you are not responsible for fraudulent charges. Ask them to flag the old number for fraud monitoring in the meantime.
Review every statement that arrives over the next several months. Set up transaction alerts if your bank offers them. Even a small test charge is worth disputing immediately. Because the filing involves only eight people, the organization may be able to tell you which specific card was affected once you reach the right person. Have your membership or customer number ready when you call.
Update any automatic payments or subscriptions that used the old card. The new card number will need to be re-entered with every merchant that stored the previous details. Doing this promptly prevents service interruptions and reduces the chance that a merchant attempts to charge the now-invalid number.
Keep records of every conversation with your bank and with the International Code Council. If any fraudulent activity does appear, these notes will help when disputing charges or requesting reimbursement.
The record shows a narrow exposure limited to payment card data affecting a very small group of Massachusetts residents. While the precise method and timing remain undisclosed, the practical consequence is clear: the affected cards must be replaced, the statements watched, and the organization contacted if you believe you should have received notice but have not. Beyond that, this incident does not create the permanent identity risks that accompany many other types of breaches.
Report details & sourcing
Related breaches
ActionAid International Ransomware Claim — May 2026
NGO ActionAid International appeared on a ransomware victim list in early May 2026, with the threat …
Cybersecurity firm Trellix discloses source code repository breach
Trellix revealed that attackers gained unauthorized access to a portion of its source code repositor…
el-group Listed by Inc Ransom Ransomware Group
el-group was listed on the Inc Ransom ransomware leak site. The group claims to have stolen internal…