AACN Data Breach Impacts its Payment System: 57,526 Individuals Affected

Published
September 1, 2025
Updated
September 1, 2025
AACN Data Breach Impacts its Payment System: 57,526 Individuals Affected
AACN
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

AACN

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On July 31, 2025, the American Association of Critical-Care Nurses (AACN) discovered a data breach affecting its website’s payment system. According to a notice filed with the Maine Attorney General, an unauthorized party accessed payment card information associated with certain transactions on the AACN website between March 8, 2025, and the date the breach was identified. While the investigation could not determine exactly which payment cards were compromised, AACN is notifying all individuals who made purchases during the affected period out of an abundance of caution.

The breach exposed a range of personally identifiable information (PII), including payment card information (card number, expiration date, CVV), name, contact information, shipping and billing addresses, phone number and email address.

A total of 57,526 individuals in the United States were affected by this breach, with 186 residents in Maine identified. The breach was formally disclosed to the Maine Attorney General on Aug. 29, 2025, and affected individuals were notified by written communication on the same date.

The severity of this breach is notable, as it involved direct access to payment card data and associated personal details, potentially putting thousands at risk for financial fraud and identity theft. The breach appears to have resulted from a compromise of AACN’s payment system by an unauthorized party, though the specific method of attack has not been detailed.

American Association of Critical-Care Nurses’s response

AACN is offering affected individuals two years of complimentary credit and identity monitoring services through IDX. Impacted individuals are encouraged to enroll in these services by Nov. 29, 2025, as detailed in the notification letter. The organization also advises all affected parties to remain vigilant by reviewing payment card and bank statements for suspicious activity and to promptly report any unauthorized transactions to their financial institution.

Given the nature of the breach, anyone who made a purchase on the AACN website between March 8, 2025, and July 31, 2025, should take the following steps:

  • Enroll in the offered credit and identity monitoring services
  • Monitor account statements and credit reports for unusual activity
  • Consider placing a fraud alert or security freeze on credit files
  • Report any suspected identity theft to law enforcement and the Federal Trade Commission

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image