
In September 2025, the Public Relations Society of America was the victim of a ransomware attack carried out by the Sinobi group, who claimed responsibility for infiltrating PRSA’s computer systems and exfiltrating approximately 800 GB of sensitive organizational data. The attackers announced their intent to publish the stolen data within a week on a dark web forum.
Upon discovering suspicious activity in their computer systems, PRSA began an investigation and took steps to contain the situation. It was determined that an unauthorized actor had gained access to PRSA’s server environment and copied a limited but sensitive amount of data.
According to the notice posted on PRSA's website, the breach exposed names, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account information, health insurance information, medical condition or treatment information, usernames and access information, and student identification card numbers.
The total number of affected individuals nationwide was determined to be 873, including nine residents of Massachusetts and one of Maine.
PRSA reported the breach to the Maine Attorney General and to the Massachusetts Office of Consumer Affairs and Business Regulation.
For those impacted, PRSA has arranged complimentary identity monitoring services through Kroll, a global leader in risk mitigation and response. These services include credit monitoring, fraud consultation and identity theft restoration for a specified period.
Affected individuals are encouraged to activate their monitoring services by following the instructions provided in their notification letter.
Recommended steps include:
Given the nature of the breach, PRSA strongly recommends that all affected individuals remain vigilant against potential identity theft and fraud.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)