The Children's Council of San Francisco experienced an external system breach (hacking) that began on or around August 1, 2025. This network disruption led to unauthorized access and acquisition of data. The company discovered the breach on February 23, 2026, and began notifying affected individuals on February 27, 2026. Regulators were notified starting March 3, 2026.
The breach affected 12,655 individuals. The exposed data included names, Social Security numbers (SSNs), driver's license numbers, state ID numbers, tax identification numbers, USCIS/alien registration numbers, passport numbers, personal medical information, health insurance ID numbers, and health insurance information. It remains unclear if any direct bank account details were compromised.
While details can emerge later and notices may be delayed, the Children's Council of San Francisco is offering 12 months of free credit monitoring and identity theft protection services through TransUnion.