Data breach
TESSCO
- Records
- 3,225,129
- Breach date
- 7 May 2026Estimated
- Added
- 15 May 2026
What was exposed
6 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses3,225,129
- Names1,482,478
- Phone numbers775,928
- Street addresses773,965
- Dates of birth12,324
- Social security numbers7,640
- Bank account numbersReported, not counted
- Card numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Tessco, LLC, a Maryland-based distributor of wireless infrastructure products, has been added to the index after a dataset tied to the company surfaced with more than 3.2 million rows. Our investigation team estimates the breach occurred on or around May 7, 2026, and the listing was added on May 15, 2026. The incident appears connected to a ransomware attack claimed earlier by a group calling itself PayoutsKing, though the company's own regulatory filings came months later and describe a narrower set of compromised data. Tessco did not claim the event on its own channels in the sources reviewed.
April 30, 2026: The ransomware group PayoutsKing listed Tessco on its leak site, according to Ransomware.live, which recorded the claim and an estimated 615 GB of exfiltrated data. Those figures are attacker claims and have not been confirmed by Tessco.
September 16, 2026: Tessco filed breach notifications with the Vermont Attorney General and notified Massachusetts residents, per the Almeida Law Group and Class Action U.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (about 3.2 million), names (about 1.48 million), phone numbers (about 776,000), street addresses (about 774,000), dates of birth (about 12,300), and Social Security numbers (about 7,600).
Tessco's own notifications, filed on September 16, 2026, identified Social Security numbers, financial account codes, and credit and debit account information in the Vermont filing, while the Massachusetts notice confirmed names and information belonging to minor dependents. The company's filings and our indexed data do not fully match, which may reflect differing disclosure requirements by state.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of Social Security numbers with names, addresses, and dates of birth carries the highest risk, because that information can be used to open fraudulent accounts, file fraudulent tax returns, or commit other forms of identity theft. Financial account details from the company's filings add a risk of direct payment fraud. For families, the exposure of minor dependents' information is a particular concern: children's stolen identities can go undetected for years because parents rarely check for credit files in a child's name. Email addresses and phone numbers, even without financial data, fuel phishing and smishing attacks that impersonate banks, employers, or Tessco itself.
What Is Tessco Doing in Response?
Tessco filed breach notifications with state regulators on September 16, 2026 and began mailing notice letters to affected individuals. For minors whose information was involved, the company is offering 24 months of complimentary identity monitoring and restoration services through Experian IdentityWorks. Enrollment requires an activation code from the notification letter and must be completed by December 31, 2026. Questions can be directed to Experian at 1-833-918-9283, Monday through Friday, 9 a.m. to 9 p.m. Eastern. As of September 25, 2026, Tessco had not published a detailed public statement confirming the full scope reported by outside researchers, and no class action lawsuit had been confirmed as filed, though multiple law firms are investigating.
What Should You Do If You Were Affected?
Enroll in the offered Experian IdentityWorks monitoring if you received a letter, and do so before the December 31, 2026 deadline.
Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion, especially if a child's information was involved. Check whether a credit file already exists in your minor's name using each bureau's minor-specific request process.
Review your free credit reports at AnnualCreditReport.com and monitor bank and card statements for unfamiliar activity.
Watch for phishing emails or texts referencing Tessco, and avoid clicking links in unsolicited messages.
If you suspect misuse of your information, file a report at IdentityTheft.gov for a personalized recovery plan.
In the news
- Ransomware.live – TESSCO victim listingransomware.live (opens in a new tab)
- Almeida Law Group – Tessco, LLC Data Breach Investigationalmeidalawgroup.com (opens in a new tab)
- Class Action U – Tessco Data Breachclassactionu.org (opens in a new tab)
- ClaimDepot – Tessco Data Breachclaimdepot.com (opens in a new tab)
