TFG Benefits, Inc. was listed on the Nightspire ransomware leak site, indicating a data breach that occurred on July 27, 2026. This incident was identified through monitoring of ransomware group activities, as no official breach notice or company statement has been publicly released.
The breach reportedly involved the exfiltration of several types of sensitive data, including employee PII, payroll records, benefits information, financial documents, client HR files, and identity documents. The exact number of affected individuals remains undisclosed, and the specific states affected have not been identified. There is no confirmation of whether Social Security Numbers or medical records were exposed, though financial data was part of the exfiltrated files.
As of the available information, there is no evidence of an official breach notification letter, state Attorney General filings, or any class-action lawsuits or multidistrict litigation related to this incident. Details regarding the full scope and impact of the breach may emerge over time, and any official notifications to consumers have not been made public.