The American Association of Critical-Care Nurses (AACN) experienced a data breach where an unauthorized party accessed information through its website payment processor. This incident began on March 8, 2025, and was discovered on July 31, 2025. AACN worked with its payment processor and cybersecurity experts to investigate and secure its systems. Official notification letters were sent to state Attorney General offices, including Massachusetts.
The breach affected 57,526 individuals. The compromised data included payment card information, names, and contact details like email addresses and phone numbers associated with website transactions. No SSN or protected health information was reported as compromised. AACN stated that it was unable to determine the specific cards affected but notified individuals who made purchases on its website during the relevant timeframe.
More details about this incident may emerge as investigations continue, and affected individuals may experience delayed notifications.