The Public Relations Society of America (PRSA) detected suspicious activity in its systems in September 2025. The organization contained the systems, notified federal law enforcement, and engaged experts to investigate. The unauthorized access to their server environment resulted in data being copied.
Confirmed data types include names, dates of birth, Social Security numbers, driver's license numbers, passport numbers, financial account information, health insurance information, medical condition or treatment information, usernames and access information for non-financial accounts, student identification card numbers, and in limited situations, credit card information. Addresses were also potentially involved. 873 individuals nationwide were affected, including 9 residents of Massachusetts and 1 resident of Maine. The number of individuals in other states has not been publicly confirmed.
Details about data breaches can emerge over time, and notification processes may be delayed.