USA DeBusk Data Breach: PHI and PII Exposed

Published
August 11, 2026
Updated
August 11, 2026
USA DeBusk Data Breach: PHI and PII Exposed
DeBusk Services
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

USA DeBusk LLC, a leading provider of industrial cleaning and infrastructure services in the oil and energy sector, disclosed a data breach involving a ransomware attack that compromised its computer systems. USA DeBusk has not disclosed the total number of individuals affected by the breach.

USA DeBusk fell victim to a ransomware attack that involved unauthorized access to its computer systems on or around Sept. 5, 2025.

On Sept. 20, 2025, a ransomware group known as Embargo claimed responsibility for the attack on the Tor network. The group stated it had obtained 2 TB of the organization's sensitive data, including contracts, client records, employee personal data and incident reports. The group threatened to publish the stolen data within two to three days.

After an investigation and review of the affected files, which concluded on July 6, 2026, the company determined that the files contained sensitive personal and protected health information of certain individuals.

The types of information exposed varied by individual but included names, contact information (such as postal addresses, email addresses and telephone numbers), dates of birth and government-issued identification numbers (such as Social Security numbers, driver's license numbers and passport numbers), financial data (such as bank account numbers, payment card numbers and other financial account information), usernames and passwords, medical information, health-related information and health insurance details.

The breach was reported to the California Attorney General on Aug. 10, 2026.

USA DeBusk's response to the breach

The company is offering affected individuals two years of free identity monitoring services through Kroll. Affected individuals can activate their identity monitoring services by visiting Kroll's enrollment page and entering the membership number included in their notification letter.

Enrollment must be completed by the activation deadline listed in each person's letter.

For questions about the breach, affected individuals can contact USA DeBusk at 844-958-8959, toll-free, Monday through Friday from 8 a.m. to 5:30 p.m. Central Time, excluding major U.S. holidays.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
DeBusk Services
Consumers Notification date
Date of Breach
August 14, 2025
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Social Security number
  • bank account number
  • contact information
  • date of birth
  • driver’s license number
  • email address
  • financial account information
  • government-issued identification number
  • health insurance information
  • health-related information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image