USA DeBusk LLC Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what’s now in circulation.
USA DeBusk LLC notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on August 10, 2026, and the notice lists social security numbers, government id numbers, financial account codes, credit and debit account info, health records among the information exposed.
The filing from USA DeBusk LLC, reported to the Vermont Attorney General on August 10, 2026, states that one person’s records were exposed. Those records included Social Security numbers, government ID numbers, financial account codes, credit and debit account information, and health records.
A single affected individual changes the stakes
When a breach notice lists only one person, the organisation almost certainly knows exactly whose information was involved. That makes direct notification likely and the absence of a letter a strong signal that you were not affected. The filing does not state when the incident occurred, so the letter remains the only practical way to confirm your status. Anyone who has moved since receiving services from USA DeBusk LLC should contact the organisation directly rather than rely solely on mail sent to an old address.
What the exposed categories actually enable
A Social Security number combined with a government ID and basic personal details can be used to file fraudulent tax returns, open accounts in your name, or apply for government benefits. These identifiers cannot be changed like a credit card or password. Once they are out, they remain usable for identity theft for years.
Health records add another permanent risk. Medical identity theft can lead to incorrect information being added to your insurance file, denied claims, or bills sent to you for treatment you never received. Because health records are tied to your name and Social Security number in this incident, the two categories together make fraudulent medical activity easier to sustain.
Credit and debit account information and financial account codes can be used for immediate unauthorized charges. Unlike SSNs, these can usually be replaced, but the window between exposure and replacement matters. The filing does not indicate whether the data was merely viewed or actually taken, so the safest assumption is that it has left the organisation’s control.
No passwords or credentials were exposed
The notice lists no passwords, login details, or authentication information. This is genuinely good news. You do not need to change any password connected to USA DeBusk LLC because none was compromised. The lifelong risks in this incident come from the non-replaceable identifiers and health data, not from account takeover of this specific service.
The permanent versus the replaceable
Social Security numbers and government ID numbers cannot be reissued on request the way a compromised credit card can. Health records also cannot be “reset.” Financial account codes and credit or debit card numbers, however, can be canceled and replaced. The distinction is important: the first group creates lifelong monitoring needs, while the second group requires fast but temporary action.
Because only one Vermont resident is named in the filing, the breach appears tightly scoped. The record does not disclose the root cause, whether the data was exfiltrated, or any details about how access occurred. Those facts remain unknown to the public.
What this means for medical and tax fraud risk
Health records paired with a Social Security number give a fraudster the two pieces most insurers and government agencies use to verify identity. A criminal could file false medical claims, obtain prescription medications, or create fake tax filings that trigger refunds sent to addresses they control. These attacks can surface months or years later, which is why monitoring matters long after the initial breach notice.
Credit and debit account details allow quicker but shorter-lived abuse. Most banks will reverse fraudulent charges if reported promptly, but the SSN and health data create slower, harder-to-detect problems that require active vigilance rather than a single phone call.
How to determine whether this filing applies to you
USA DeBusk LLC is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, letters can go to outdated addresses. If you have ever been a patient or client of USA DeBusk LLC and have moved in recent years, reach out to them to confirm whether your records were part of this single-person incident.
Concrete steps that address the actual exposure
- Place a fraud alert or credit freeze with the three major credit bureaus immediately. This prevents new accounts from being opened with your Social Security number while you sort out the rest of your response.
- Contact your health insurer and request an audit of recent claims. Look for any treatment or services you did not receive. Early detection limits damage from medical identity theft.
- Review tax transcripts from the IRS each year. A fraudulent return filed with your SSN can delay your legitimate refund or trigger audits.
- Monitor credit reports weekly for the next six months. Free weekly reports are available from AnnualCreditReport.com. Focus on new accounts or inquiries you do not recognize.
- Keep the breach notice and any correspondence from USA DeBusk LLC. Documentation helps if you later need to dispute fraudulent activity tied to this specific incident.
The filing establishes that one person’s sensitive identifiers and health information left USA DeBusk LLC’s control. No passwords were involved. The non-replaceable nature of Social Security numbers and health records makes ongoing monitoring the central task, while credit and debit account details require faster but more contained action. The letter is the definitive check on whether this notice concerns you. Where a letter has not arrived, the risk is low but not zero for anyone who has changed addresses since interacting with the organisation.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on USA DeBusk LLC.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…