Roger Keith & Sons Data Breach Affects Client PII & PHI

Published
October 30, 2025
Updated
October 30, 2025
Roger Keith & Sons Data Breach Affects Client PII & PHI
Roger Keith Insurance
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Roger Keith Insurance

data breach?

Join the Lawsuit

It's free to join. 

Roger Keith & Sons Insurance Agency, an independent insurance agency, experienced a data breach that exposed sensitive data. On Jan. 27, 2025, the company learned that a threat actor gained access to an employee email account and the Roger Keith internal network using a remote desktop tool, following a phishing attack.

An investigation was launched and on Oct. 6, 2025 it was determined that the cyberattack compromised both personally identifiable information (PII) and protected health information (PHI). Exposed information included full names, Social Security numbers, dates of birth, driver’s license numbers, military or other U.S. government-issued identification numbers, mothers’ maiden names, passport numbers, usernames and passwords, credit or debit card numbers with access information, financial account numbers with access information and limited health-related information.

The total number of affected individuals has not been publicly disclosed, but may include thousands of Roger Keith clients. The insurance agency began notifying affected individuals by mail on Oct. 29, 2025 and published a Notice of Data Security Incident on its website.

The data breach was also disclosed to multiple state authorities, including the Massachusetts and Maine Attorney Generals offices.

Roger Keith & Sons' response

Upon discovering the cyberattack, Roger Keith & Sons secured the affected network and email account, and engaged third-party cybersecurity professionals to assist with the response. In addition to required state and federal disclosures, the agency is providing individuals whose Social Security numbers were compromised 12 free months of Experian IdentityWorks credit monitoring services.

If you receive a data breach notice from Roger Keith & Sons Insurance Agency, you may want to:

  • Sign up for the free credit monitoring services, if offered.
  • Monitor your credit reports and financial accounts for any unusual activity.
  • Be alert for phishing emails or phone calls that may use your exposed information.
  • Consider placing a fraud alert or credit freeze with major credit bureaus.

The agency also established a dedicated toll-free response line for clients with questions at 833-594-5303, Monday through Friday, 9:00 a.m. to 9:00 p.m. Eastern Time.

For more information about the insurance agency, visit the official Roger Keith & Sons Insurance Agency website.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Roger Keith Insurance
Consumers Notification date
10/29/2025
Date of Breach
October 6, 2025
Breach Discovered Date
2025-01-27
Total People Affected
Information Types Exposed
  • Drivers Licenses
  • Social Security numbers
  • Credit or debit card numbers with access information
  • Dates of birth
  • Driver’s license numbers
  • Financial account numbers with access information
  • First and last names
  • Full name

-

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image