Commonwealth Trust Data Breach Exposes Social Security Numbers

Published
September 19, 2025
Updated
September 19, 2025
Commonwealth Trust Data Breach Exposes Social Security Numbers
Commonwealth Trust Company
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Commonwealth Trust Company

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

Earlier this year, Commonwealth Trust Company experienced a data breach involving unauthorized access to a company email account. On May 13, 2025, an unauthorized actor gained access to an employee’s email account for a limited period and obtained emails from the account. An investigation was launched immediately after suspicious activity was detected, focusing on the nature and scope of the incident.

After reviewing the compromised email account, the company determined that sensitive information was present in the affected emails.

The information exposed included both personally identifiable information (PII) and protected health information (PHI): name, treating or referring physician, patient account number, account number, treatment information, prescription or medication information, individual insurance or subscriber number, account number with bank name, Social Security number, medical record number, medical billing or claims information, other health insurance information and date of birth.

The breach was officially reported to the Massachusetts Attorney General on Sept. 19, 2025. According to the disclosure, seven Massachusetts residents were affected. Commonwealth Trust Company completed its review of the incident on Aug. 4, 2025, and has since worked to verify the information involved and confirm current address information for notification purposes.

Commonwealth Trust Company's response

In response to the breach, Commonwealth Trust Company took immediate steps to secure the compromised email account and launched a comprehensive investigation to determine the extent of the incident. The company also implemented additional technical and administrative security measures to further protect its systems and the information in its care.

To assist those affected, Commonwealth Trust Company is offering complimentary credit monitoring, a single bureau credit report, and a single bureau credit score for 24 months through Cyberscout, a TransUnion company specializing in fraud assistance and remediation services. Impacted individuals are encouraged to enroll in these services within 90 days of receiving their notification letter. The company has provided detailed instructions for enrollment and established a dedicated phone line for questions about the breach or the credit monitoring services.

Given the nature of the breach, which involved access to both PII and PHI, affected individuals should remain vigilant for signs of identity theft or fraud. It is recommended to regularly review account statements, monitor free credit reports for suspicious activity and consider placing a fraud alert or credit freeze with the major credit bureaus if necessary. The company also provided guidance on how to contact the Federal Trade Commission and state attorneys general for further information on protecting personal information.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • name
  • treating/referring physician
  • patient account number
  • account number
  • treatment information
  • prescription/medication information
  • individual insurance/subscriber number
  • account number with bank name
  • Social Security number
  • medical
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image