Churchill Claims Services, Inc., an independent insurance claims adjusting and investigation firm, experienced a data security incident that was discovered on March 31, 2026. The breach occurred on September 14, 2025, and external notification of the breach, including a dark web posting by the Securotrop ransomware group, occurred on October 10, 2025. The company issued written notifications to affected individuals starting on April 27, 2026.
Approximately 2,610 individuals in the United States were affected by this data breach. The compromised data included client names, contact details, insured vehicle lists, appraisal logs, profit margin analyses, employee phone numbers, compensation records, and executive and general division records. While not explicitly confirmed as exposed, the breach notification letter referenced Social Security Numbers and dates of birth in security freeze instructions, suggesting these data types may have been involved. Maine, Massachusetts, Indiana, Vermont, and New Hampshire residents are among those affected.
It is important to note that details regarding data breaches can emerge over time as investigations continue and notifications are processed. Consumers who receive notification letters should review the information provided carefully.