Data breach
Archway Marketing Services, Inc.
- Records
- 1,137,282
- Breach date
- 7 October 2025Estimated
- Added
- 5 November 2025
What was exposed
4 types of data · 1 puts you at serious risk
- Email addresses1
- Home addresses1
- Phone numbers1
- Social security numbers1
About this breach
Archway Marketing Services, Inc., a Westlake Village, California-based marketing logistics and fulfillment company, has been linked to a 2025 data breach involving more than 1.1 million records. According to a notification letter Archway filed with state regulators, an unknown actor accessed a limited number of the company's servers on September 19 and 20, 2025, and took or viewed files, including files that may have contained information about Archway employees. Separately, the Chaos ransomware group listed archway.com on its leak site on October 7, 2025, according to breach trackers. The investigation team estimates the attack date as October 7, 2025, and its index of the leaked data contains 1,137,282 rows.
September 19, 2025: In its notification letter, Archway said an unknown actor accessed a limited number of servers in its network between this date and the next day.
September 20, 2025: Archway discovered that certain servers and systems were inaccessible and launched an investigation with outside cyber incident response specialists.
October 7, 2025: The Chaos ransomware group published a leak page naming archway.com, according to RedPacket Security, which monitors ransomware leak sites.
December 10, 2025: Archway began mailing written notification letters to affected individuals, per filings with the Maine Attorney General and the Montana Department of Justice.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, email addresses, phone numbers, and home addresses. The number of each data type affected could not be confirmed from the available information.
The scope is large relative to the intrusion window Archway described. The company's letter says the actor reached "a limited number of servers" and that the files taken or viewed "may contain information related to Archway employees," yet the indexed dataset runs well over a million rows, suggesting contact and business records alongside a smaller subset of employee data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers carry the greatest risk. Combined with names and addresses, they can be used for identity theft, fraudulent loan or credit applications, and tax-related fraud. Email addresses and phone numbers are also valuable to scammers, who can use them for phishing messages that appear to come from a legitimate company or vendor.
Because this dataset includes a large volume of contact information, affected people may see an increase in targeted spam, fraudulent job offers, or impersonation attempts. Anyone who receives an unexpected email or call referencing Archway, a fulfillment order, or a data breach should treat it with suspicion and avoid clicking links or sharing personal details.
Archway stated in its letter that it is unaware of any identity theft or fraud associated with the event as of the notification date.
What Is Archway Marketing Services, Inc. Doing in Response?
According to its notification letter, Archway took steps to secure its systems upon learning of the event and hired cyber incident response specialists to investigate. The company says it has enhanced its safeguards and continues to monitor them.
Archway is offering affected individuals 12 months of free credit monitoring and identity restoration services through Cyberscout, a TransUnion company. Recipients must enroll themselves, within 90 days of the letter date, using the instructions enclosed with the notice. The company also reported the incident to multiple state attorneys general, including Maine, Montana, and Massachusetts.
What Should You Do If You Were Affected?
If you received a notification letter from Archway, enroll in the free Cyberscout credit monitoring it offers before the 90-day enrollment window closes. Even without a letter, consider these steps:
Place a free fraud alert with one of the three credit bureaus (Equifax, Experian, or TransUnion), which requires lenders to verify your identity before issuing credit.
Consider a credit freeze, which blocks new credit inquiries entirely and is free to place and lift.
Review your credit reports at annualcreditreport.com and watch bank and credit card statements for unfamiliar activity.
Change passwords on important accounts and avoid reusing passwords across sites.
If you believe your information has been misused, report it to the Federal Trade Commission at identitytheft.gov and to your state attorney general.
In the news
- Maine Attorney General, Data Breach Notifications: Archway Marketing Servicesmaine.gov (opens in a new tab)
- Montana Department of Justice, Archway consumer notification letter (PDF)dojmt.gov (opens in a new tab)
- Massachusetts Attorney General, December 2025 breach notification lettersmass.gov (opens in a new tab)
- RedPacket Security, Chaos ransomware victim: archway.comredpacketsecurity.com (opens in a new tab)
