Families United Network Data Breach Investigation

Families United Network (FUN), a Pennsylvania nonprofit, has posted a data event notice concerning a reported hacking/IT incident that may have involved sensitive personal information. The available incident data identifies email as the location involved, but it does not provide a confirmed affected-person count or a public notice date. Strauss Borrelli PLLC is investigating the incident and its potential impact. If you received a notice, you may fill out the secure contact form on this page to ask whether you may qualify to pursue a claim.

Key Facts at a Glance

  • Entity Involved: Families United Network (FUN) (Nonprofit)
  • Incident Type: Reported Hacking/IT Incident
  • Date of Incident: Reported as December 19, 2025 to December 22, 2025
  • Discovery Date: Not publicly specified in the available materials
  • Official Notice Date: Not provided in the records reviewed
  • Exposed Information: Names, Social Security numbers, dates of birth, driver’s license numbers, financial account numbers, health records, and health insurance information may have been involved
  • Affected Population: Not publicly specified in the available materials

What Happened?

According to the incident information provided for this matter and FUN’s online data event notice, Families United Network reported a hacking/IT incident involving information maintained in email. The incident records identify a period from December 19, 2025 to December 22, 2025. The available materials do not identify when FUN discovered the activity, when individual notices were mailed, or when any attorney general listing became public. They also do not state how access occurred, whether ransomware was used, whether a third party was involved, or how many people were affected.

A state attorney general filing is referenced in the incident data, but the regulator and filing date are not specified. Accordingly, the known facts should be read narrowly: the event was reported as an information-security incident, and certain categories of personal, financial, and health-related information may have been involved. Individuals should rely on their own notice letter for details specific to them because the affected data can vary by person.

What Information Was Exposed?

Based on the reported incident data, potentially involved records may include names, Social Security numbers, dates of birth, driver’s license numbers, financial account numbers, health records, and health insurance information. The available materials do not establish that every listed category applied to every affected person.

This combination of data may create risks of identity theft, fraudulent financial transactions, medical identity theft, false patient billing, and health insurance verification scams. Because FUN is a nonprofit, recipients should also be cautious about fraudulent donation requests, event-related messages, and emails impersonating staff or organizational leaders. Unexpected prescription, insurance, or account inquiries should be independently verified.

What Should You Do Next?

  1. Review your notice carefully: Keep the letter and envelope, note which information the notice says was involved, and follow any enrollment instructions or response deadlines. Do not assume every publicly reported data category applies to you.
  2. Monitor financial and credit activity: Review bank and credit card statements for unfamiliar transactions. Check your credit reports for accounts, loans, addresses, or inquiries you do not recognize, and promptly dispute inaccurate information.
  3. Consider fraud alerts or credit freezes: A fraud alert asks lenders to take additional identity-verification steps. A credit freeze generally restricts access to your credit file and can make it more difficult for someone to open new credit in your name.
  4. Watch for nonprofit and healthcare scams: Independently verify donation requests, payment instructions, insurance calls, prescription inquiries, and messages claiming to come from FUN. Avoid clicking unexpected links or providing personal information in response to unsolicited communications.
  5. Preserve evidence and report misuse: Save notices, suspicious emails, text messages, bills, credit reports, and records of time or money spent responding. Report suspected identity theft through IdentityTheft.gov and contact the relevant financial institution, insurer, or healthcare provider.

Your Legal Rights

People affected by a reported data incident may have rights under federal and state laws, depending on where they live, what information was involved, how the incident occurred, and whether they experienced losses or other harm. Potential issues may include whether reasonable safeguards were used, whether required notices were timely and complete, and whether available protective services adequately address the reported risks.

Consumers also have rights concerning their credit files, including the ability to review reports, dispute inaccurate information, and request fraud alerts or security freezes. Some circumstances may support claims for documented financial losses, identity-theft response expenses, lost time, or other legally recognized harm. Available rights and deadlines vary, so this general information should not be treated as individualized legal advice.

Why Hire Strauss Borrelli PLLC?

Strauss Borrelli PLLC represents consumers in privacy and data incident matters and investigates whether affected individuals may have viable claims. The firm can evaluate the available notice, the information reportedly involved, and any resulting harm while explaining possible next steps in clear terms. Contacting counsel does not guarantee a recovery, and the availability of any claim depends on the facts and applicable law.

If you received a breach notification letter from Families United Network:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY