Rhodes, Young, Black & Duncan Data Breach Exposes Financial Info

Published
August 27, 2026
Updated
August 27, 2026
Rhodes, Young, Black & Duncan Data Breach Exposes Financial Info
Rhodes, Young, Black, and
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Rhodes, Young, Black & Duncan, a private accounting and advisory firm based in Duluth, Georgia, disclosed a data breach involving unauthorized access to one of its backup servers.

The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on Aug. 21, 2026. Rhodes, Young, Black & Duncan also posted a notice on its website. The firm began notifying affected consumers on or around Aug. 21, 2026.

The firm discovered the breach on Oct. 12, 2025. Unauthorized parties gained access to one of the firm's backup servers and exfiltrated data. The firm's investigation determined that the intruders first accessed the network on Sept. 17, 2025, and removed data before the unauthorized activity was detected.

On or about May 27, 2026, Rhodes, Young, Black & Duncan notified the employers of affected individuals that personal information may have been accessed or acquired by the unauthorized parties.

The types of personally identifiable information exposed included first and last names, Social Security numbers, taxpayer identification numbers, driver's license or state identification numbers and passport numbers.

The financial information exposed included financial account numbers, routing numbers, payment card numbers, payment card expiration dates and current PINs.

The breach also potentially exposed protected health information, including health insurance information and medical information.

Rhodes, Young, Black & Duncan's response to the breach

The firm is offering affected individuals complimentary identity protection services through IDX.

Affected individuals received a personalized enrollment code and deadline in their notification letters. They can enroll by scanning a QR code included in the letter or by visiting the IDX enrollment website. Those who need assistance with enrollment can contact IDX by phone.

The company has also established a dedicated and confidential call center for individuals with questions about the incident.

The notification letter also provided affected individuals with detailed instructions for placing fraud alerts and security freezes with the three major credit bureaus: Equifax, Experian and TransUnion.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
on or about September 10, 2019
Breach Discovered Date
October 12, 2019
Total People Affected
Information Types Exposed
  • Social Security numbers
  • Current PINs
  • Driver's license or state identification numbers
  • Financial account numbers
  • Routing numbers
  • First and last names
  • Health insurance information
  • Medical information
  • Passport numbers
  • Payment card
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image