Data breach
Sun Source
- Records
- 905,144
- Breach date
- 13 May 2026Estimated
- Added
- 19 May 2026
What was exposed
10 types of data · 4 more reported · 3 put you at serious risk
- Names905,144
- Street addresses802,985
- Phone numbers505,821
- Email addresses474,219
- Dates of birth17,939
- Licence plates14,165
- Social security numbers11,743
- Vehicle VINs1,304
- Driving licence numbers729
- Bank account numbers8
- Card numbersReported, not counted
- Government IDsReported, not counted
- Medical recordsReported, not counted
- Insurance detailsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
SunSource Borrower LLC, an Illinois-based industrial distributor, is notifying customers and employees after an intrusion into its network exposed personal information for more than 900,000 people. The leaked dataset contains roughly 905,144 records, with names on nearly every entry and phone numbers, email addresses, and street addresses attached to hundreds of thousands of them.
March 31 to April 5, 2026: Per a sample notification letter reviewed by ClassAction.org, a third-party forensic investigation found an unauthorized party accessed SunSource's network and part of its file server during this window.
April 30, 2026: A ransomware group calling itself Payouts King claimed responsibility for the attack on a leak site, saying it obtained about 700 GB of data, according to a report tracked by BreachSense.
May 4, 2026: The company's investigation determined whose information and what types of data were compromised, per the notification letter.
June 16, 2026: SunSource began mailing notices to affected individuals, according to ClaimDepot.
What Information Was Compromised?
Our analysis found the following data types in this breach: 905,144 names, 802,985 street addresses, 505,821 phone numbers, 474,219 email addresses, 17,939 dates of birth, 14,165 vehicle plates, 13,044... wait, 1,304 vehicle VINs, 11,743 Social Security numbers, 729 driver's licenses, and 8 bank account numbers.
The company's notification letter, as reported by ClassAction.org, describes additional categories not tallied in our indexed data, including credit and debit card numbers, medical records, health insurance information, and other government-issued ID numbers.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of full names, addresses, phone numbers, and emails creates a ready-made toolkit for phishing and impersonation scams. Criminals can pose as banks, employers, or government agencies and use accurate personal details to appear credible.
The Social Security numbers in the dataset carry the most serious long-term risk. With a name, date of birth, and SSN, a thief can open credit accounts, file fraudulent tax returns, or commit medical identity theft using stolen insurance details. The exposure of medical and health insurance information makes that last scenario a real concern for the affected subset. Driver's license numbers and vehicle plates could support forged IDs or targeted fraud, though those groups are far smaller. Only eight bank account numbers appear in the indexed data, so direct account fraud is a narrow risk here, but financial account information was flagged in the company's own disclosures.
What Is Sun Source Doing in Response?
SunSource engaged an outside forensic firm to investigate, contained the affected portion of its network, and began mailing notification letters in mid-June 2026. According to ClaimDepot, the company is offering affected individuals a complimentary two-year identity monitoring membership through Kroll, with enrollment instructions and a membership number included in each letter. It has also set up a dedicated call center, available weekdays from 8 a.m. to 5:30 p.m. Central Time.
Attorneys with ClassAction.org opened an investigation into potential class action claims in June 2026 and later reported that their investigation into the matter was complete.
What Should You Do If You Were Affected?
If you received a letter from SunSource, enroll in the Kroll identity monitoring service using the membership number in your notice, and do so before the deadline printed on the letter.
Whether or not you received a notice, take these steps:
Check your credit reports at annualcreditreport.com and watch for accounts you did not open.
Consider placing a free credit freeze with Equifax, Experian, and TransUnion, which blocks most new credit applications.
File your tax return early, or request an IRS Identity Protection PIN, to block fraudulent returns.
Be skeptical of unsolicited calls, texts, or emails referencing SunSource, since scammers often follow breaches with convincing phishing attempts.
Review medical and insurance statements for services you did not receive.
In the news
- ClassAction.org: SunSource Data Breach Exposes SSNsclassaction.org (opens in a new tab)
- ClaimDepot: SunSource Data Breach Exposes SSNs and Medical Recordsclaimdepot.com (opens in a new tab)
- BreachSense: SunSource Data Breach in 2026breachsense.com (opens in a new tab)
- Cole & Van Note: SunSource Data Breach Investigationcolevannote.com (opens in a new tab)
