Central National Gottesman Data Breach Exposes Sensitive Personal and Health Data

Published
September 2, 2026
Updated
September 2, 2026
Central National Gottesman Data Breach Exposes Sensitive Personal and Health Data
Central National Gottesman
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Central National Gottesman Inc., a private, family-owned global distributor of pulp, paper, packaging and related products, disclosed a data breach that exposed a wide range of sensitive personal information.

So far, 843 Texas residents, 568 Massachusetts residents and 22 Vermont residents were identified as affected.

On March 12, 2026, Payouts King, a ransomware group, posted on the Tor network, stating it had stolen 726 gigabytes of Central National Gottesman's internal data and intended to publish the information within six to seven days.

The compromised data allegedly covered a wide range of corporate and personal files including corporate confidential correspondence, executive email exports (described as Outlook exports), employee and customer personally identifiable information, credit card records, corporate confidential documents, contracts, nondisclosure agreements, legal documents, compliance and litigation records, financial data, budgets, payroll records, invoices, employee personal folders and database backups.

According to official filings, the types of personal information exposed in the breach included names, addresses, contact information, email addresses, phone numbers, dates of birth, Social Security numbers, driver's license numbers, government-issued identification numbers (such as passports and state ID cards), financial information (such as account numbers and credit or debit card numbers), medical information, health insurance information and payroll-related information.

Central National Gottesman's response to the breach

Central National Gottesman is offering affected individuals two years of complimentary credit monitoring and identity protection services through Experian.

Affected individuals who receive a notification letter should review it promptly, as it is expected to contain details specific to each person about which types of information were involved in their case. The letter may also include information about credit monitoring, identity theft protection or other services the company is offering, along with enrollment instructions and contact information for additional support.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Name of individual
  • Address
  • Contact information
  • Email address
  • Phone number
  • Date of Birth
  • Social Security Number Information
  • Driver’s License number
  • Government-issued ID number (e.g. passport, state ID
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image