Data breach
MassDevelopment
- Records
- 883,951
- Breach date
- 18 January 2025Estimated
- Added
- 16 September 2026
What was exposed
7 types of data · 2 put you at serious risk
- Street addresses883,951
- Names800,468
- Email addresses153,885
- Phone numbers141,021
- Dates of birth25,560
- Social security numbers21,522
- Bank account numbers18,765
About this breach
The investigation team has indexed a dataset tied to MassDevelopment, the Massachusetts Development Finance Agency, containing 883,951 rows of records. According to our investigation team, the estimated attack date is January 18, 2025, the same day the ransomware group BianLian listed the agency on its public leak site and claimed to have stolen 4 TB of data. That claim was reported by Comparitech but was never confirmed by the agency, and no group is formally credited with this listing in our records. The listing arrives against a backdrop of repeated trouble: MassDevelopment separately notified 1,039 people in January 2025 about a 2024 intrusion claimed by a different group, Cactus.
January 18, 2025: BianLian listed MassDevelopment on its leak site and claimed to have stolen 4 TB of data. Comparitech reported that the agency never confirmed the claim.
February 28, 2025: MassDevelopment notified state regulators, including Maryland's attorney general, about a separate incident in which its investigation found systems were accessed without authorization at various times between June 17 and November 28, 2024.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names: 800,468 records
Street addresses: 883,951 records
Email addresses: 153,885 records
Phone numbers: 141,021 records
Dates of birth: 25,560 records
Social Security numbers: 21,522 records
Bank account numbers: 18,765 records
Not every individual is affected by every type of data listed here.
The scale of this dataset is far larger than the 1,039 people MassDevelopment notified about the 2024 incident, which suggests the two events involve different pools of information. The exact origin of the 883,951-row dataset has not been publicly confirmed by the agency.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Are the Potential Risks for Affected Individuals?
Social Security numbers and bank account details carry the most direct danger. Combined with names, addresses, and dates of birth, they give identity thieves what they need to open loans or credit accounts, file fraudulent tax returns, or attempt unauthorized transfers from financial accounts. Even records containing only an email address or phone number are useful for phishing: a caller or email writer who knows your name and address can sound convincingly legitimate. The exposure of a state agency's financing and development records may also raise concerns for businesses and municipal partners whose details appear in agency files.
What Is MassDevelopment Doing in Response?
MassDevelopment has not publicly acknowledged the BianLian claim as of September 25, 2026, and Comparitech reported it could not independently verify it. In response to the separate 2024 incident, the agency said in its regulatory notice that it secured its systems, conducted a forensic investigation, notified federal law enforcement, and offered 24 months of free credit monitoring through Epiq to affected individuals. Whether any similar support applies to this listing is not known.
What Should You Do If You Were Affected?
If your information appears in this dataset, take these steps regardless of whether you receive a direct notice:
Place a free fraud alert and consider a security freeze with Equifax, Experian, and TransUnion. A freeze blocks most new credit from being opened in your name.
Review bank and credit card statements regularly, and report unfamiliar transactions to your financial institution immediately.
Watch for phishing emails, texts, and calls that reference your personal details. Do not click links or share codes from unexpected contacts.
File your taxes early if possible, so a fraudulent return cannot be submitted first, and consider getting an IRS Identity Protection PIN.
Check your credit reports for free at annualcreditreport.com and dispute anything you do not recognize.
If you were notified about the separate 2024 incident, you can enroll in the offered credit monitoring and contact the agency's assistance line for questions.
