In July 2024, The Computer Merchant (TCM), an IT staffing and services firm based in Massachusetts, experienced a data breach that directly impacted its internal network. The incident was initially concluded in July 2024 to have not acquired data, but in January 2025, it was discovered that data was made publicly available. Further analysis in May 2025 confirmed that the exposed data included Social Security numbers and names. TCM issued an official breach notification letter and acknowledged the breach, sending notices to all affected individuals.
The breach affected 34,127 individuals nationwide, including job applicants, current employees, and former employees of TCM. The exposed data types included names, Social Security numbers (SSNs), dates of birth, financial information, health information, and addresses. The breach was reported to state attorneys general in California, Maine, Montana, and Texas. Specifically, 78 Montanans were affected.
Details surrounding data breaches can emerge over time, and notification processes may be delayed as investigations continue.