Almeida Law Group is investigating a data breach at USA DeBusk LLC. The breach occurred on August 14th, 2025. If you were affected, contact Almeida Law Group.
About USA DeBusk LLC
USA DeBusk LLC is a privately held industrial services company that provides specialty and traditional industrial cleaning and infrastructure maintenance services to clients in chemicals, renewable fuels, refining, and power generation. Founded in 2012 by Andrew DeBusk, the company is headquartered in Deer Park, Texas, and operates from a network of 39 offices across the United States with more than 2,500 full-time employees. In May 2024, private equity firm H.I.G. Capital completed an acquisition of the company.
What Happened?
USA DeBusk LLC was listed in a California Attorney General sample breach notice filed on August 10th, 2026. According to the company’s notice letter, USA DeBusk experienced a cybersecurity incident on or around September 5th, 2025, involving unauthorized access to certain of its systems. The company determined on July 6th, 2026 — approximately ten months after the incident — that an unauthorized third party had obtained certain personal information belonging to affected individuals. The number of affected individuals was not disclosed in the available notice. The types of information involved varied by individual and included name, contact information (postal address, email address, and telephone number), date of birth, government-issued identification numbers (Social Security number, driver’s license number, and passport number), financial account information (bank account or payment card number), medical and health-related information, health insurance information, and username and password. USA DeBusk states it blocked the unauthorized party’s access, engaged external cybersecurity experts, and reported the incident to law enforcement. Kroll has been engaged to provide two years of identity monitoring services to affected individuals at no cost.
The Embargo ransomware group claimed responsibility for an attack on usadebusk.com, according to tracking by Ransomware.live. The leak-site listing was discovered on September 20th, 2025, with an estimated attack date of September 11th, 2025. The group alleged exfiltration of 2 TB of data, including contracts, client data, employee private data, and incident reports. These are attacker-side allegations from a ransomware leak site and have not been confirmed by USA DeBusk or any regulator. USA DeBusk’s own breach notice does not reference ransomware or identify any threat actor by name.
Key Facts at a Glance
- Company or Organization: USA DeBusk LLC
- Industry: Industrial cleaning and infrastructure maintenance services (energy, chemical processing, manufacturing sectors)
- Location: Deer Park, Texas, with offices across the United States
- Incident type: Unauthorized access to systems (ransomware attack alleged by Embargo group; unconfirmed by company)
- Date of breach: September 5th, 2025
- Date breach discovered: July 6th, 2026
- Date of consumer notification: August 10th, 2026
- Identity theft protection offered: Two years of Kroll identity monitoring (credit monitoring, fraud consultation, and identity theft restoration)
- Prior breach: None identified
- Litigation status: No class action lawsuits connected to this breach were found in available sources as of August 2026
- Source: California Attorney General sample breach notice; Ransomware.live victim listing; H.I.G. Capital acquisition announcement
What Should You Do?
If you received a notice from USA DeBusk, enroll in the two years of free Kroll identity monitoring services before the activation deadline listed in your notice letter — visit enroll.krollmonitoring.com and use the membership number provided. You should also place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to help prevent new accounts from being opened in your name. Request your free credit reports at AnnualCreditReport.com or by calling 1-877-322-8228, and review them carefully for accounts or inquiries you do not recognize. Because medical, health insurance, and financial account information was involved in this breach, review your Explanation of Benefits statements and medical records for services you did not receive, and monitor your bank and payment card accounts for unauthorized transactions. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance from the Federal Trade Commission.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.