Cambridge Mercantile Corp. (U.S.A.), which operates as Corpay, disclosed a data security incident to the Massachusetts Attorney General on September 14, 2026. The company completed its review of potentially affected individuals on August 28, 2026, with the assistance of third-party cybersecurity experts.
The incident affected 34 individuals. Exposed data included name, contact details (email or physical address), and Social Security numbers. No passwords or authentication credentials were involved. The company stated that customer funds, payment processing, transaction execution, and service availability were not affected. Complimentary identity monitoring through Kroll was offered to affected individuals.
While a law firm investigation page mentions a potential class action, no confirmed filed complaint beyond the historical Drewry case was identified in the available sources regarding this specific incident. Details can emerge later, and formal notices may be delayed.