2026 Kaplan North America — ~1.4M individuals (server intrusion; expanded disclosure)
Data compromised
Names, Social Security numbers, driver's license numbers, personal identifiers
Technical writeup
Kaplan North America LLC, an education and training company, disclosed a cybersecurity incident involving unauthorized access to internal servers between October 30 and November 18, 2025. Discovered February 21, 2026; consumer notifications began March 17, 2026. Early state regulatory filings listed hundreds of thousands of residents across states (e.g., Texas, South Carolina, Maine, Rhode Island); subsequent reporting and class-action summaries cited an expanded nationwide figure on the order of ~1.4 million individuals affected. Technical root-cause details were not fully disclosed publicly. Exposed data included names, Social Security numbers, and driver's license numbers. Kaplan offered one year Experian IdentityWorks credit monitoring with $1M identity theft insurance.
Root cause
Cybersecurity incident affecting internal systems; unauthorized server access (details limited)