Almeida Law Group is investigating a data breach at American Future Technology Corporation d/b/a iBUYPOWER. The breach occurred on June 21st, 2025. If you were affected, contact Almeida Law Group.
About American Future Technology Corporation d/b/a iBUYPOWER
iBUYPOWER, legally American Future Technology Corporation, is a manufacturer of high-performance pre-built and custom gaming PCs founded in 1999. The company is based in City of Industry, California, at 529 Baldwin Park Blvd, and also operates a sister brand called HYTE, which produces PC cases. According to the breach notice, the incident involved employee data, including highly sensitive personal, financial, and health-related information.
What Happened?
American Future Technology Corporation d/b/a iBUYPOWER was listed in a California Attorney General sample breach notice. On June 21st, 2025, iBUYPOWER discovered unauthorized activity within its IT network. The company retained cybersecurity specialists to investigate and contain the incident. According to the notice letter, an unauthorized third party accessed certain individuals’ personal information, and on or about July 25th, 2025, data held in iBUYPOWER’s IT network — including personal information — may have been exposed. The breach notice describes this as an employee data incident. The compromised information may include mailing address, telephone number, Social Security number, date of birth, driver’s license number, passport number, U.S. Alien Registration Number, EAD card, identification card number, birth certificate, tax ID number, bank account number, medical information, and health insurance information. Notification letters were dated June 5th, 2026 — nearly one year after the incident was discovered. iBUYPOWER is offering 12 months of complimentary identity monitoring through Experian IdentityWorks to affected individuals.
The Lynx ransomware group, described as a spin-off of the INC ransomware group operating a ransomware-as-a-service scheme, claimed credit for the attack. Lynx listed iBUYPOWER on its data leak site around July 22nd, 2025. The attack reportedly disrupted iBUYPOWER’s phone lines, ERP, production, accounting, RMA, and customer service systems. iBUYPOWER publicly announced the incident on its Instagram page on June 24th, 2025 and stated that customer payment information is not stored within its network environment. As of the research date, no class action lawsuit has been filed, but at least two law firms — Cole & Van Note and Strauss Borrelli PLLC — are actively investigating the incident, with Cole & Van Note stating it will be pursuing legal action on behalf of those affected.
Key Facts at a Glance
- Company or Organization: American Future Technology Corporation d/b/a iBUYPOWER
- Industry: Consumer electronics / Gaming PC manufacturing
- Location: City of Industry, California
- Incident type: Ransomware attack (Lynx ransomware group); employee data breach
- Date of breach: June 21st, 2025
- Date breach discovered: June 21st, 2025
- Date of consumer notification: June 5th, 2026
- Identity theft protection offered: 12 months of Experian IdentityWorks
- Litigation status: No filed class action; Cole & Van Note and Strauss Borrelli PLLC are actively investigating
- Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-624771); New Hampshire AG filing (https://mm.nh.gov/files/uploads/doj/remote-docs/american-future-technology-ibuypower-20260605.pdf); Comparitech reporting (https://www.comparitech.com/news/ransomware-gang-says-it-hacked-pc-maker-ibuypower/)
What Should You Do?
If you received a notice from iBUYPOWER, enroll in the complimentary Experian IdentityWorks monitoring as soon as possible using the instructions provided in your letter. Given the range of sensitive information involved — including Social Security numbers, bank account numbers, and health information — you should also consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion). Review your credit reports at AnnualCreditReport.com and monitor your financial accounts closely for any suspicious activity. Because medical information and health insurance information were among the data types listed, review your Explanation of Benefits statements and check your medical records for any services you did not receive. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance on reporting and recovery.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.