Indico Data Solutions Data Breach: Social Security Numbers Exposed

Published
July 30, 2026
Updated
September 3, 2026
Indico Data Solutions Data Breach: Social Security Numbers Exposed
Indico
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Indico Data Solutions, a Boston-based AI software company, disclosed a data breach that may have exposed personal information stored in its online repositories. Indico serves as a data processing vendor for companies in various industries, providing data ingestion and workflow organization services.

On May 7, 2026, Indico Data Solutions determined that it had suffered a cybersecurity incident. The incident may have involved unauthorized access to various online repositories containing corporate customer information.

The company implemented its incident response protocols, took steps to secure its environment and worked with external cybersecurity specialists to investigate the scope of the breach. Indico then notified its corporate customers whose data may have been affected and worked with those customers to identify any individuals whose personal information was present in the compromised repositories.

For certain customers, this identification process was completed on June 17, 2026. At those customers' request, Indico is providing notice to affected individuals and to the Nebraska Attorney General on their behalf.

The types of personal information that may have been exposed include names, addresses, dates of birth, Social Security numbers and medical and health information.

The breach was reported to the California Attorney General, Nebraska Attorney General and the Texas Attorney General. The company also posted a notice of the data security incident on its website.

Indico began notifying consumers on July 16, 2026. The total number of individuals affected across the United States was not disclosed, although so far 2,128 residents of Texas were impacted.

Indico Data Solutions' response to the breach

The company is offering affected individuals 12 months of free single-bureau credit monitoring, credit report and credit score services through Cyberscout, a TransUnion company.

To enroll in the services, affected individuals can visit Cyberscout's activation page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the date of the letter.

The company has also set up a dedicated phone line for questions about the incident. Representatives are available Monday through Friday, from 8 a.m. to 8 p.m. Eastern time, excluding holidays, by calling 1-800-405-6108. This phone line will be available for 90 days from the date of the notification letter.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Indico
Consumers Notification date
July 16, 2026
Date of Breach
May 7, 2026
Breach Discovered Date
May 7, 2024
Total People Affected
4840
Information Types Exposed
  • Name of individual
  • Address
  • Social Security Number Information
  • Driver’s License number
  • Government-issued ID number (e.g. passport, state ID card)
  • Financial Information (e.g. account number, credit or debit card number
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image