Almeida Law Group is investigating a data breach at Alcott HR. The breach occurred on February 12th, 2025. If you were affected, contact Almeida Law Group.
About Alcott HR
Alcott HR is a Professional Employer Organization (PEO) and Human Resources Outsourcing (HRO) provider founded in 1987 and headquartered in Farmingdale, New York, with additional offices in Buffalo/Rochester, NY and Philadelphia, PA. The company provides HR solutions to small and mid-sized businesses, including payroll administration, employee benefits management, regulatory compliance, workers’ compensation insurance, and risk management. Because Alcott HR administers HR functions on behalf of many client companies, a breach of its systems can affect employees across a wide range of client organizations, not only Alcott’s own staff. Alcott HR is part of The Cameron Group of companies.
What Happened?
Alcott HR was listed in a California Attorney General sample breach notice reported on June 17th, 2026. According to the breach notification letter, in February 2025 Alcott detected unusual activity on some of its systems. The company engaged forensic experts, reported the incident to law enforcement, and conducted an investigation. That investigation concluded in March 2026 that an unauthorized user had accessed systems where personal information was stored. Notification letters were dated June 15th, 2026 — roughly 16 months after the breach first occurred. The data involved includes names, Social Security numbers, and dates of birth. Alcott’s iSolved human capital management platform, which stores employee tax, benefits, and banking information, was not affected. Alcott is offering 24 months of identity theft protection services through Cyberscout, a TransUnion company, to affected individuals.
The Play ransomware group claimed responsibility for this attack. According to supplemental reporting, an initial access broker advertised access to Alcott HR on a hacking forum in February 2025, and approximately 18 days later Play listed Alcott HR on its extortion site. Cyberpress reported that the attackers exploited Fortinet SSL VPN vulnerabilities (CVE-2018-13379 and CVE-2020-12812) to gain initial access and used a double extortion model, threatening to publish stolen data on March 1st, 2025 unless ransom demands were met. Cyberpress also reported that approximately 214,000 employees across Alcott’s client organizations were potentially affected. No class action lawsuits specifically connected to this breach were identified at the time of research.
Key Facts at a Glance
- Company or Organization: Alcott HR
- Industry: Professional Employer Organization (PEO) / Human Resources Outsourcing (HRO)
- Location: Farmingdale, New York
- Incident type: Ransomware (Play ransomware group)
- Date of breach: February 12th, 2025
- Date breach discovered: February 27th, 2025
- Date of consumer notification: June 15th, 2026
- Total persons affected: Approximately 214,000 employees across client organizations (per Cyberpress reporting)
- Identity theft protection offered: 24 months of credit monitoring and fraud assistance through Cyberscout (a TransUnion company)
- Enrollment deadline: 90 days from June 15th, 2026
- Litigation status: No class action lawsuits connected to this breach found as of research date
- Source: California Attorney General Breach Report; Alcott HR Breach Notification Letter; Cyberpress – PLAY Ransomware Group Lists Two New Victims; Breachsense – February 2025 Breaches; Help Net Security – Ransomware Attack Trends
What Should You Do?
If you received a notice from Alcott HR, enroll in the 24-month Cyberscout credit monitoring service as soon as possible — you must enroll within 90 days of June 15th, 2026, and you will need the unique code provided in your notification letter. Beyond that, consider placing a fraud alert or a credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent new accounts from being opened in your name. Review your credit reports for unfamiliar accounts or inquiries at AnnualCreditReport.com, where you are entitled to free reports from each bureau. Because Social Security numbers and dates of birth were involved, be especially alert to signs of identity theft such as unexpected bills, tax filing issues, or unfamiliar account activity. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance on recovering from identity theft.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.