Pan American Group Data Breach Investigation

Pan American Group, LLC reported a hacking/IT incident that may have involved sensitive personal information stored on its network. State regulatory materials identify several data categories, but the number of affected people has not been publicly confirmed in the information reviewed. Strauss Borrelli PLLC is investigating the incident and the rights of people who received notice. If you believe you were affected, fill out the secure contact form on this page to ask whether you may qualify to participate in a potential claim.

Key Facts at a Glance

  • Entity Involved: Pan American Group, LLC (Franchisee)
  • Incident Type: Reported Hacking/IT Incident
  • Date of Incident: April 8, 2026 to April 9, 2026
  • Discovery Date: Not publicly disclosed in the information reviewed
  • Official Notice Date: August 24, 2026
  • Exposed Information: Names, Social Security numbers, driver’s license numbers, financial account numbers, and medical record numbers may have been involved
  • Affected Population: Under investigation; no confirmed total was provided in the information reviewed

What Happened?

According to the California Attorney General’s breach-list entry and related regulatory information, Pan American Group reported an incident spanning April 8 to April 9, 2026. The matter was classified as a hacking/IT incident involving information maintained on a network. A notice was listed publicly by the California Attorney General on August 24, 2026, and the available incident information also identifies a Massachusetts regulatory filing.

The materials reviewed do not provide a discovery date or explain precisely how an unauthorized party may have gained access to the network. They also do not establish that every listed data element was accessed or misused for every notice recipient. Individuals should read their personal notice carefully because the information involved may differ from person to person. The scope and circumstances may become clearer if additional notices or regulatory materials are released.

What Information Was Exposed?

The incident records provided for this matter identify several categories of information that may have been involved:

  • Names
  • Social Security numbers
  • Driver’s license numbers
  • Financial account numbers
  • Medical record numbers

These categories do not necessarily apply to every affected person. Social Security and driver’s license information can increase the risk of identity or account fraud, while financial account information may be used in convincing payment or verification scams. Medical record numbers may create medical identity-theft risks. Because the entity operates as a franchisee, recipients should also watch for payroll, benefits, vendor-invoice, password-reset, or employment-related phishing messages.

What Should You Do Next?

  1. Review the notice: Determine which data categories may apply to you, preserve the notice and envelope, and retain any related emails or account records.
  2. Secure financial and online accounts: Change reused passwords, enable multifactor authentication, and contact your bank directly if you notice an unfamiliar transaction or account-change request.
  3. Check your credit reports: Review reports from Equifax, Experian, and TransUnion for unfamiliar accounts, addresses, or credit inquiries. Consider a free credit freeze or fraud alert.
  4. Watch for targeted scams: Be cautious of payroll updates, vendor-payment requests, benefits messages, medical billing inquiries, and texts asking you to verify an account. Use a known phone number or website rather than links in unsolicited messages.
  5. Document suspicious activity: Save screenshots, letters, transaction records, and notes about time spent responding. Report identity theft through IdentityTheft.gov and promptly dispute unauthorized activity with the relevant institution.

Your Legal Rights

People affected by a reported data incident may have rights under federal or state privacy, consumer-protection, and data-breach notification laws. The rights available depend on factors such as where the person lives, what information was involved, whether the information was accessed or misused, and whether the person experienced losses or spent time addressing the incident.

Potential relief may include compensation for documented losses or other remedies where permitted by law, but eligibility cannot be determined from a public filing alone. Preserve your notice and records, follow any response deadlines, and consider speaking with a qualified attorney about your circumstances. This general information is not individualized legal advice.

Why Hire Strauss Borrelli PLLC?

The firm represents consumers in privacy and data security matters and can evaluate regulatory filings, notice language, the information reportedly involved, and potential legal options. An attorney can also help determine whether an individual may qualify for a claim and explain the next steps without promising a particular result. Contacting counsel for an evaluation does not replace taking immediate steps to protect financial, medical, and online accounts.

If you received a breach notification letter from Pan American Group:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY