Devereux Foundation Data Breach Exposes Social Security Numbers

Published
January 12, 2026
Updated
August 5, 2026
Devereux Foundation Data Breach Exposes Social Security Numbers
The Devereux Foundation
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

One of the nation's largest nonprofit behavioral healthcare organizations, The Devereux Foundation, disclosed a data breach that occurred in November 2025.

The Devereux Foundation identified suspicious activity within certain systems on its computer network. The organization took prompt and extensive action to isolate its systems, assess the security of its network and launch an investigation to determine the nature and scope of the event.

The investigation determined that an unauthorized actor gained access to certain systems from Nov. 6, 2025, to Nov. 9, 2025, and copied files without permission.

A ransomware group known as The Gentlemen claimed responsibility for the attack. On Nov. 28, 2025, the group posted on the dark web through the Tor network, claiming to have obtained the organization's data and threatening to publish it within nine to 10 days.

The Devereux Foundation then conducted a thorough review of the affected files to identify what sensitive information they contained and who was affected. According to the company's notification, this review was completed on June 23, 2026. Affected individuals may include current or former employees, employees' beneficiaries, clients or loved ones of clients, donors, payors and business partners.

The breach exposed a wide range of personally identifiable information (PII), including names, Social Security numbers, driver's license numbers, government-issued ID numbers (such as passports and state ID cards), dates of birth, digital or electronic signatures, financial account information, payment card information, taxpayer identification numbers and U.S. Alien registration numbers.

The breach also compromised protected health information (PHI), including medical information and health insurance information.

The breach affected 5,341 Texas residents, 3,316 Massachusetts residents, approximately 577 Rhode Island residents, 50 New Hampshire residents and 43 Vermont residents

The organization reported the breach to the U.S. Department of Health and Human Services, as well as the attorneys general of California, Texas, Massachusetts and Vermont on July 23, 2026. The organization also posted a notice on its website.

The Devereux Foundation's response

The organization is offering affected individuals 24 months of complimentary credit monitoring and identity restoration services through Experian IdentityWorks.

To enroll, affected individuals should visit the Experian IdentityWorks website and enter the unique activation code included in their notification letter. The enrollment deadline is Oct. 31, 2026.

Individuals with questions can call 833-745-1528 (toll-free), Monday through Friday from 9 a.m. to 9 p.m. Eastern Time, excluding U.S. holidays. They may also write to The Devereux Foundation, Attn: Compliance, 444 Devereux Drive, Villanova, PA 19085.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
November 6, 2025 - November 9, 2025
Breach Discovered Date
November 9, 2025
Total People Affected
501
Information Types Exposed
  • Drivers Licenses
  • Financial Account
  • Government ID Numbers
  • Health Records
  • Name of individual
  • Social Security Number Information
  • Driver’s License number
  • Government-issued ID number (e.g. passport)
  • Social Security Numbers
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image