On June 13, 2025, The Hiller Companies, a provider of fire protection products and services, discovered a data security incident that impacted the personal information of individuals connected to its operations. According to disclosures made to the California, Massachusetts and Vermont Attorneys General, attackers copied certain files from Hiller’s systems without authorization on or around Dec. 18, 2024.
A detailed forensic investigation led by external cybersecurity experts revealed that the compromised files contained an array of sensitive information. The types of consumer information exposed include personally identifiable information (PII) such as names, Social Security numbers, driver’s license numbers, unique government-issued identification numbers, passport numbers, financial account information, and payment card numbers. In addition, protected health information (PHI) was also affected, including medical information and health insurance details.
For residents of Massachusetts, 123 individuals were confirmed to be affected, but the total number of impacted people may be broader, as notifications were also filed in Vermont and potentially other states. The breach was officially disclosed to the Massachusetts Attorney General’s office on Aug. 26, 2025, and to the Vermont Attorney General’s office on Aug. 27, 2025.
For those affected, Hiller Companies is offering complimentary identity protection services through Cyberscout, a TransUnion company specializing in fraud assistance and remediation. Impacted individuals are eligible for up to 24 months of single-bureau credit monitoring, credit reports, credit scores, and proactive fraud assistance. These services provide alerts when changes occur to a credit file, helping individuals respond quickly to potential misuse of their information.
Given the nature of the breach, those who receive a notification are encouraged to:
Affected individuals can contact the dedicated assistance line at 833-426-8016, Monday through Friday, 7 a.m. to 7 p.m. Central, for questions or support.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.