In June 2026, the National Association of Credit Management (NACM) Intermountain, an Arizona-based organization supporting credit management professionals, experienced a data breach. This incident was disclosed after attorneys began investigating a potential class action lawsuit. NACM Intermountain reported the breach to the Massachusetts Office of Consumer Affairs and Business Regulation on June 18, 2026, and began notifying affected consumers on June 17, 2026.
The confirmed data types exposed in this breach include Social Security numbers, credit card numbers, debit card numbers, names, dates of birth, addresses, and government IDs. While medical information is listed as a potential category, it has not been explicitly confirmed as compromised. The exact total number of affected individuals is not yet officially finalized, though some reports mention it may have affected individuals nationwide, with one unconfirmed social media post mentioning 16,828 people in Maine. NACM Intermountain has stated there is no evidence to suggest that any information has been fraudulently misused, but as a precaution, they offered 24 months of credit monitoring through Cyberscout.
Details about data breaches can emerge over time, and official notices may be delayed. For the most current updates on the potential class action or final affected counts, individuals can refer to ClassAction.org or the Massachusetts Attorney General’s data breach notification public list.