Transport Workers Union Local 100 Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Transport Workers Union Local 100 notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on April 24, 2026, and the notice lists social security numbers, health records among the information exposed.
The Transport Workers Union Local 100 has notified one Vermont resident that their Social Security number and health records were exposed in a data breach. The filing, submitted to the Vermont Attorney General on April 24, 2026, lists these two categories and no others.
Your Social Security Number Cannot Be Replaced
A Social Security number does not expire and cannot be reissued on request the way a credit card or password can. Once it is in the hands of unauthorized parties, it remains a lifelong tool for identity theft, tax fraud, loan fraud, and government benefits fraud. The same permanence applies to the health records included in this incident. Medical information tied to your name and SSN can be used for insurance fraud, prescription fraud, or blackmail.
Because this filing names only these two categories, no passwords were exposed. That is genuine good news. You do not need to change any password connected to the union as a direct result of this breach.
What the Exposure Actually Enables
With a valid Social Security number and health records, someone can open accounts, file false tax returns, apply for medical services in your name, or combine the data with information from other breaches to build a more complete identity profile. Health records add sensitive personal context that makes social engineering attacks more convincing and can expose you to targeted medical identity theft.
The record does not state when the incident occurred, only that the filing reached the Vermont Attorney General on April 24, 2026. It also does not disclose whether the data was encrypted at rest or how the intrusion happened. Those details remain unknown to the public.
How to Determine If This Filing Concerns You
The union is required to notify affected individuals directly, usually by mail. If you receive a letter from Transport Workers Union Local 100 describing this incident, your information was included. Absence of a letter usually means you were not in the affected group of one. Anyone who has moved since the incident should contact the union directly to confirm their status, because mailed notices can miss changed addresses.
The Lifelong Nature of These Records
Unlike a compromised password or credit card number, neither a Social Security number nor health history can be cancelled or swapped for a new one. This is why regulators treat SSN breaches differently from credential-only incidents. The exposure creates a permanent risk that you must manage for years rather than months.
Health records add another permanent layer. Once medical details are linked to your identity outside the legitimate healthcare system, they can be used to request care, file claims, or pressure you personally. These risks do not diminish with time the way some digital credentials do.
What Remains Under Your Control
You cannot change the exposed data, but you can limit what thieves do with it. Monitoring for new accounts, tax filings, and medical claims in your name gives you the best chance of catching misuse early. Credit monitoring and fraud alerts create friction for anyone trying to open new lines of credit using your SSN.
Placing a freeze with the three major credit bureaus remains one of the strongest steps available. It prevents new credit accounts from being opened without your explicit permission. Because no passwords were involved, the focus stays on these identity-protection measures rather than credential hygiene.
Why This Filing Matters Despite Its Small Size
A breach affecting a single person still carries the full weight of the exposed categories. One record containing both an SSN and health information is enough to enable serious fraud. The small headcount does not reduce the value of the data to identity thieves or the potential harm to the individual named in the filing.
The union’s notice provides the only official confirmation available. No public detail exists on the root cause, the method of access, or whether any data was exfiltrated. The record limits itself to who filed, when they filed, what categories were listed, and how many Vermont residents were affected.
Stay alert for any communication from Transport Workers Union Local 100. If the letter arrives, follow the specific instructions it contains. In the absence of that letter, the filing indicates your information was not part of the exposed record. For those uncertain about address history, reaching out to the union directly is the only way to obtain certainty this record cannot provide.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Transport Workers Union Local 100.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…