
Service Management Group LLC (SMG), a privately held experience management software company headquartered in Kansas City, Missouri, disclosed a data breach involving unauthorized access to its internal corporate systems.
SMG provides software and professional services to help brands in industries such as restaurants, retail, grocery, convenience stores, entertainment and healthcare measure and improve customer and employee experiences.
The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation.
SMG first detected suspicious activity on its systems on March 31, 2026. An investigation into the incident revealed that an unauthorized party accessed certain SMG internal corporate systems and obtained files between March 18 and April 7, 2026.
SMG, with the support of third-party cybersecurity experts, conducted a detailed review of the compromised files to identify individuals whose personal information may have been contained in them. On July 15, 2026, the review identified personal information in the affected files that had been collected in connection with employment at SMG.
The types of personally identifiable information (PII) exposed included names, Social Security numbers, driver's license numbers and other government-issued identification numbers.
Protected health information (PHI) was also involved, including health and dental insurance information and medical records.
SMG is offering affected individuals a complimentary 24-month membership to Experian IdentityWorks as a precaution. Affected individuals can enroll by visiting the Experian IdentityWorks enrollment page by Nov. 30, 2026.
SMG has set up a dedicated incident hotline for affected individuals. The hotline is available Monday through Friday between 8 a.m. and 8 p.m. CT, excluding major U.S. holidays. The phone number and a unique engagement number needed to access the service are included in each individual's notification letter.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)