Data breach
Mid-Cumberland Human Resource Agency
- Records
- 196,568
- Breach date
- 18 May 2026Estimated
- Added
- 26 August 2026
What was exposed
10 types of data · 3 put you at serious risk
- Names196,568
- Phone numbers185,375
- Street addresses114,020
- Dates of birth70,190
- Social security numbers40,100
- Email addresses19,633
- Driving licence numbers1,347
- Vehicle VINs308
- Licence plates285
- Passport numbers2
About this breach
The extortion group Insomnia has claimed responsibility for an attack on Mid-Cumberland Human Resource Agency, a Tennessee nonprofit that provides Meals-on-Wheels, public transit, in-home services, and community corrections programs. According to our investigation team, the incident involves roughly 196,568 rows of data, and our analysis found personal information including names, phone numbers, Social Security numbers, dates of birth, street addresses, email addresses, and driver's license numbers. Insomnia, a data-theft and extortion group that emerged in October 2025 and focuses mainly on US-based healthcare and social services organizations, threatened to publish the stolen files unless the agency negotiated, according to the group's public posting.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
May 18, 2026: Ransomware.live lists the estimated date of the attack on Mid-Cumberland Human Resource Agency as this date.
June 9, 2026: The Insomnia group is recorded as claiming the attack on ransomware.live, with a statement that "the full leak will be published soon, unless a company representative contacts us via the channels provided."
June 10, 2026: Breachsense records the breach as claimed by Insomnia.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Name: 196,568 records
Phone number: 185,375 records
Street address: 114,020 records
Date of birth: 70,190 records
Social Security number: 40,100 records
Email address: 19,633 records
Driver's license number: 1,347 records
Vehicle VIN: 308 records
Vehicle license plate: 285 records
Passport number: 2 records
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
A Social Security number combined with a full name, date of birth, and street address is enough for identity thieves to attempt fraudulent loans, credit cards, tax refunds, or government benefits in someone else's name. Because this dataset also includes phone numbers and email addresses, affected people may face targeted phishing calls, texts, or emails that use real personal details to appear convincing.
The presence of driver's license and vehicle information adds further risk, since license numbers can support identity fraud and plates and VINs can be used for targeted scams. Extortion groups like Insomnia typically publish stolen files if negotiations fail, meaning the data could circulate on criminal forums for years. Children, seniors, and people who receive in-home or transit services may be especially vulnerable to impostor scams that reference the agency by name.
What Should You Do If You Were Affected?
If you have used Mid-Cumberland Human Resource Agency's services and believe your information may be involved, take these steps:
Check whether you appear in the breach.
Place a free fraud alert or credit freeze with Equifax, Experian, and TransUnion. A freeze blocks most new credit accounts from being opened in your name.
Review your credit reports at annualcreditreport.com and dispute any accounts you do not recognize.
Watch for phishing. Do not click links or share personal details in unexpected calls, texts, or emails, even if the sender knows your name or claims to represent a familiar agency.
Check benefits accounts, including Social Security and IRS records, and file a report at IdentityTheft.gov if you see signs of misuse.
