← Blog

Tessco Breach: Minors’ SSNs in VT/MA AG Notices

Share on X

September 16, 2026: Tessco, LLC — the Hunt Valley, Maryland wireless infrastructure distributor formerly known as TESSCO Technologies — filed state security-breach notices in Vermont and Massachusetts confirming that attackers obtained Social Security numbers, financial-account codes, and credit or debit information for some people, including names and data on minor dependents. Vermont’s AG listing cites only two Vermont residents; Tessco has not published a nationwide headcount, incident timeline, or root-cause write-up. Canonical record: tessco-payoutsking2026. Sources: Vermont AG security-breach notices, TEISS coverage of the Tessco disclosure.

Parents searching “Tessco data breach minors” are not overreacting. When a B2B distributor puts children’s SSNs in the same notice packet as credit and debit fields, the fraud risk is identity theft and synthetic identity creation — not a forgotten Wi-Fi router password. Tessco is offering affected minors 24 months of Experian IdentityWorks, with enrollment through December 31, 2026. That offer is the clearest company signal that dependent data was in the mix.

What this is not: a company-confirmed nationwide census, a published forensic timeline, or an admission that every PayoutsKing figure from April is accurate. Nearly five months earlier, the ransomware group PayoutsKing claimed Tessco on April 30, 2026, advertising roughly 615 GB of stolen data, contacts for more than 100,000 people, and Salesforce customer records north of 500,000. Those are unverified actor claims. Treat them as campaign noise until Tessco or a regulator adopts them.

What happened: Tessco breach timeline

The public record starts with regulator filings, not a glossy Tessco status page.

On September 16, 2026, Tessco’s notices appeared in the Vermont Attorney General’s security-breach category and in Massachusetts’s consumer-affairs breach channel. Vermont lists two residents and flags Social Security numbers plus financial account codes and credit/debit information. Massachusetts reporting, as summarized by TEISS, confirms compromise of names and minor-dependent information for some individuals — the detail that pushed this past a routine vendor-CRM leak into a family-identity story.

Tessco has not published when the intrusion began, when it was discovered, which systems were hit, or how many people nationwide are in scope. Those gaps are intentional early-notice posture, not proof the event was tiny. State AG samples often land months after discovery while counsel finishes the census. A two-resident Vermont line item can sit next to a much larger unpublished mailing list in other states.

Separately, on April 30, 2026, PayoutsKing listed Tessco in ransomware trackers with the 615 GB / 100k contacts / 500k Salesforce marketing pitch. Tessco’s September AG notices do not name PayoutsKing, do not cite those volumes, and do not confirm ransomware encryption. BreachHistory indexes both threads on one canonical row because the victim name matches — with the actor half labeled unverified.

If you are trying to build a calendar for “when was Tessco hacked,” you will hit a wall. The only hard public dates are the actor’s April claim and the September 16 regulator filings. Everything between those poles — detection, containment, forensic imaging, counsel review — remains unpublished. That silence frustrates journalists and parents alike, but it is common when counsel is still counting households before more AG samples go out.

Who is Tessco — and why a distributor breach hits families

Tessco sells wireless infrastructure products and supply-chain services to carriers, integrators, and enterprise radio buyers. Most consumers never open a Tessco invoice. That is exactly why dependents show up in HR and benefits files: employees, contractors, and sometimes customer contacts keep family SSNs for insurance elections, W-4 withholding, and emergency contacts.

A wireless distributor’s CRM can also hold partner contacts, purchase history, and shipping addresses useful for business email compromise. Pair that with payroll-adjacent SSN fields and you get two fraud markets at once — vendor invoice fraud and child identity theft. The Tessco brand may be obscure at the grocery store; it is familiar on carrier and government radio projects, which is why channel partners should treat this as an accounts-payable event even if their kids were never enrolled in Tessco benefits.

Legacy TESSCO Technologies branding still appears on older contracts. Treat Tessco, LLC and that name as the same victim unless a later notice splits subsidiaries.

What was exposed in the Tessco data breach

From the verified Vermont and Massachusetts notices:

  • Social Security numbers — including where dependents were in scope.
  • Financial account codes and credit/debit information (Vermont listing).
  • Names, and for some people minor-dependent information (Massachusetts notice).

Tessco has not published a full field inventory. Do not invent passport numbers, driver’s licenses, medical charts, or password hashes. The notices are enough to justify credit freezes and careful tax-season monitoring for kids. “Financial account codes” in AG language often means bank routing/account identifiers or similar payment references; “credit/debit information” can range from truncated card data to fuller payment fields — Tessco has not clarified which shade applies.

What was not exposed is also unpublished. Tessco has not said whether network diagrams, radio-system designs, or customer RFQs were taken. Absence of those categories in AG notices does not prove they were safe; it only means the consumer-facing notices focused on personal identifiers that trigger state notification statutes.

What Tessco has not published

To be clear about the gaps:

  • Incident start date, discovery date, or containment date.
  • Root cause (phishing, ransomware, SaaS misconfiguration, insider — unpublished).
  • Nationwide count of affected individuals.
  • Whether ransomware operators encrypted production systems.
  • Confirmation or denial of PayoutsKing’s 615 GB / Salesforce figures.

Those omissions are why recordsAffected stays at 0 on the BreachHistory catalog until a company or regulator census appears. Two Vermont residents is a state sample, not a U.S. total. Readers should resist treating the Vermont number as “only two people nationwide.” AG portals routinely publish partial samples while other states are still processing.

PayoutsKing’s April claim — unverified

Unverified claim: On April 30, 2026, PayoutsKing marketed a Tessco intrusion of about 615 GB, contacts for more than 100,000 individuals, and Salesforce records for more than 500,000 customers.

Actor leak-site numbers routinely inflate. Salesforce object counts are not people. Contact exports mix employees, vendors, dead leads, and duplicates. Gigabyte totals mix databases, email archives, and junk. None of those figures appear in Tessco’s September AG notices. TEISS and BreachHistory report the claim for context; neither treats it as company-confirmed impact.

If you see Telegram sellers hawking “Tessco full dump 615GB,” assume recycling, malware, or padding until a primary forensic source lands. Do not download alleged archives. Paying a broker who promises to scrub your child’s SSN from a dump is how victims get hit twice — once by the breach, once by the cleanup scam.

Could the April listing and the September AG notices describe the same intrusion? Possibly. Timing fits a long notification clock. Could they be unrelated? Also possible. Without Tessco naming an actor or publishing a discovery date, journalists should keep both hypotheses open and refuse to launder actor marketing into “Tessco admitted 500,000 customers.”

Verified vs unverified — how to read this incident

  • Verified (company / AG): September 16, 2026 Vermont and Massachusetts notices; SSN and financial data categories; minor-dependent information for some people; Experian IdentityWorks offer for affected minors through Dec. 31, 2026.
  • Unverified (actor): PayoutsKing April 30 listing; 615 GB; more than 100k contacts; more than 500k Salesforce customers; ransomware branding as confirmed cause.

Searchers asking “was Tessco hacked” get a yes on unauthorized acquisition of personal information attested by state notices. They do not get a yes on half a million Salesforce customers until Tessco says so. That distinction matters for company risk teams drafting customer emails: lead with AG-attested fields, footnote actor claims, and avoid inventing a headcount your counsel has not signed.

Who is at risk after the Tessco breach

Employees, contractors, and their families

If you worked at Tessco (or a closely related entity) and listed dependents for benefits, watch for a mailed notice with an Experian enrollment code. Children’s clean credit files are attractive to fraudsters who open utility accounts or file false tax returns. A freeze on a minor’s credit file is often more useful than monitoring alone. Keep copies of birth certificates and Social Security cards offline; do not email scans of kids’ IDs to anyone who cold-calls about “Tessco verification.”

Vermont and Massachusetts residents already listed

Vermont’s two-resident sample proves at least some Northeast households are in scope. Massachusetts notices covering minor information mean parents in that state should treat any Tessco letter as high priority — enroll monitoring, freeze credit, and keep the letter for tax season. If you live elsewhere and get a letter, the same playbook applies; state portals simply published first where statutes forced a sample.

Business partners and wireless channel contacts

Even if your SSN was never on file, CRM contact fields power convincing “Tessco AP update” phishing. Accounts payable teams at carriers and integrators should verify bank-change requests by phone using a number from an old invoice — not from the email. Procurement staff should expect spear-phish that references real PO numbers or radio SKUs if CRM history walked out the door.

People who never heard of Tessco

You can still be affected if a spouse or parent shared your SSN for insurance. “I don’t buy radios” is not a defense against dependent identity theft. Ask household members who work in wireless supply chains whether Tessco (or legacy TESSCO) ever collected family data for benefits.

What Tessco and regulators said

Tessco’s remediation signal in the notices is concrete: 24 months of Experian IdentityWorks for affected minors, enroll by December 31, 2026. Adults should read their letter carefully for whether credit monitoring extends to them or only to dependents. Do not assume every household member gets the same product.

Vermont’s AG portal posts the filing in its security-breach notices category. Massachusetts’s consumer channel is the parallel confirmation for names and minor information. Neither filing, as covered in trade press, supplies the forensic narrative journalists usually want — and that absence is itself news for parents waiting on scope.

Tessco has not, at catalog time, posted a detailed public FAQ that maps systems, timelines, or a national count. Until that appears, the AG notices plus the Experian offer are the authoritative company-facing facts.

Industry context: AG notices, kids’ SSNs, and Salesforce claims

2026 keeps producing the same awkward pattern: ransomware or CRM actors shout huge Salesforce counts in the spring; state AG samples with Social Security numbers arrive in the fall. Adjacent BreachHistory coverage includes Vermont AG samples like Brome Bird Care and SSN-heavy notices such as Rockwood Retirement. Salesforce-adjacent contact theft shows up elsewhere too — see Canva’s Canny / Salesforce episode — but Tessco’s September notices do not confirm that path.

Minors in breach letters are not a niche problem. School and benefits systems keep putting children’s identifiers next to adult payroll data. When distributors and healthcare vendors get hit, dependents ride along. Wireless infrastructure firms may feel far from “consumer privacy,” yet benefits administration is the same shared service stack every mid-market employer buys.

Was I affected by the Tessco data breach?

As of catalog time there is no public Tessco lookup portal and no nationwide census. Practical checks:

  1. Watch U.S. mail for a Tessco or Experian enrollment letter.
  2. If you are a current or former Tessco worker, ask HR through a known channel whether your household is in the notice population — do not use a link from a cold email.
  3. Ignore random “Tessco breach check” websites asking for a child’s SSN.
  4. Assume elevated phishing risk even before your letter arrives if you are a Tessco vendor contact.

No mail yet does not mean you are safe forever — notice waves can stagger by state. Vendor contacts should keep the phishing posture regardless.

What you should do — action items

  1. Parents of affected minors: enroll the Experian IdentityWorks code from the Tessco letter before December 31, 2026.
  2. Freeze children’s credit at Equifax, Experian, and TransUnion. Kids rarely need open credit; freezes block most new-account fraud.
  3. Adults with SSNs in scope: consider freezes or fraud alerts; file taxes early; watch IRS “your return already filed” notices.
  4. Financial accounts: if credit/debit data was listed, review statements and enable bank alerts. Ask issuers about card replacement when the letter confirms payment-card fields.
  5. Vendors: out-of-band verify any Tessco payment-instruction change for at least 90 days.
  6. Phishing: hang up on callers who claim they need a child’s SSN to “activate Tessco monitoring.” Legitimate enrollment uses the mailed code.
  7. Do not pay anyone claiming they can delete Tessco data from ransomware sites.
  8. Do not download alleged PayoutsKing Tessco archives.

Phishing and fraud patterns to expect

With SSNs and financial codes in play, expect:

  • “Tessco Experian enrollment” emails that ask you to “confirm” a child’s full SSN before showing a dashboard.
  • Tax-season SMS claiming a dependent’s refund was redirected — with a link to a fake IRS page.
  • Vendor BEC using real Tessco contact names from CRM exports to push ACH changes.
  • Callback scripts after a text: “This is Tessco security — read us the code we just texted.”

Real monitoring offers arrive by letter (or from an address Tessco publishes in that letter), not from a Google ad. If a search ad promises “Tessco breach help,” close it. Bookmark the Vermont AG notices page and TEISS article for facts; use your mailed letter for enrollment.

Legal and regulatory outlook

State AG notices are the floor, not the ceiling. If Tessco’s nationwide census crosses other states’ thresholds, expect more samples. Class-action firms often file after dependent-SSN headlines; those complaints will argue notice delay and inadequate safeguards — separate from whether PayoutsKing’s spring numbers were real.

Tessco’s Experian offer for minors is a standard mitigation. It does not erase the need for credit freezes or careful handling of the mailed enrollment code. Regulators care that notices went out; parents should care that freezes stay on until children are old enough to manage credit deliberately.

How this compares to other 2026 notices

Thin AG filings with zero nationwide counts still deserve full write-ups when minors and SSNs are confirmed — that is BreachHistory policy for verified 2026 rows. Tessco sits with other September notices where the company speaks through regulators first. The PayoutsKing spring listing makes the story noisier than a quiet municipal sample, but noise is not confirmation.

Until Tessco publishes an FAQ or a larger AG sample cites a headcount, journalists should lead with Vermont/Massachusetts attestation and keep the 615 GB claim in the unverified column. That discipline is how you avoid turning every ransomware blog post into a fake census.

Canonical record and sources

BreachHistory catalog: https://breachhistory.com/tessco/tessco-payoutsking2026 — companyConfirmed true for AG-attested exposure; recordsAffected 0 pending nationwide census; PayoutsKing volumes labeled unverified.

Primary sources: Vermont Attorney General security-breach notices; TEISS — Tessco discloses data breach involving Social Security numbers of minors.

Readers arrive on queries like Tessco data breach, Tessco breach 2026, Tessco minors SSN, Tessco Vermont AG notice, Tessco Massachusetts breach, PayoutsKing Tessco claim, was I affected Tessco breach, Tessco Experian IdentityWorks, and what to do after Tessco data breach. This article sticks to attested notice facts and clearly separates actor marketing.

Updates worth watching

Watch for a Tessco customer or employee FAQ, additional state AG samples with larger populations, or a company statement that either adopts or rejects the April PayoutsKing volumes. BreachHistory will revise the canonical row when a census or root-cause narrative lands. Until then, treat mailed notices and Experian enrollment as the actionable truth — not leak-site screenshots.

If you already received a Tessco letter, keep it. Fraudsters love replaying old breach brands months later with “your monitoring expired — re-verify now” hooks. The enrollment deadline on the real offer is December 31, 2026 for the minors’ Experian product named in coverage; anything after that claiming urgency without a matching letter is almost certainly a scam.

Security teams at Tessco partners: AG-attested SSN and financial exposure is enough to raise vendor-risk tickets. You do not need a confirmed 500,000 Salesforce figure to freeze unsolicited banking updates claiming to be Tessco finance.