Eisen, Inc., a financial technology company based in New York, experienced a data breach that occurred on December 12, 2025. The breach was a result of a social engineering attack where a threat actor impersonated the California State Controller’s Office to obtain a file of unclaimed property compliance records. The company mailed notification letters to affected consumers on June 24, 2026, and reported the incident to the California Attorney General and the Massachusetts Attorney General on the same date.
The exposed data included names, mailing addresses, email addresses, Social Security numbers (SSNs), dates of birth (DOBs), government IDs, medical information, financial information, and unclaimed property balance details. The exact number of affected individuals has not been publicly stated. Eisen, Inc. is a third-party service provider, meaning the breach affected clients of its financial institution partners. Eisen offered 24 months of complimentary Experian IdentityWorks credit monitoring and identity theft restoration services to affected individuals.
Details about the extent of the breach and the total number of affected individuals may emerge over time. Notices to consumers are sometimes delayed.