Cambridge Mercantile Corp. (U.S.A.), which does business under the Corpay brand, has confirmed a data breach exposing Social Security numbers for individuals connected to the company through business and employment relationships.
Cambridge Mercantile Corp. (U.S.A.), a financial services company that does business as Corpay, reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation, confirming 34 affected Massachusetts residents. According to the company’s own notification, the incident involved personal information belonging to individuals connected to Cambridge Mercantile through a business relationship — either directly or through their employer. The company completed its review to identify affected individuals on August 28, 2026, and notification letters followed.
Source: Massachusetts Office of Consumer Affairs and Business Regulation filing 2026-1541, reported 09/14/2026.
Not a Typical Consumer Breach
This breach is a little different from a typical retail or healthcare data breach. Cambridge Mercantile / Corpay is a corporate payments and foreign exchange services company, and its own notice describes those affected as people connected to the company through a business relationship — potentially including employees of client companies who never dealt with Cambridge Mercantile directly themselves. If your employer uses Corpay for payment or foreign exchange services, your information may have been exposed even if you’ve never heard of the company.
What Information Was Exposed?
According to the Massachusetts filing, the confirmed exposed category is:
The filing does not itemize additional categories beyond Social Security numbers.
How Many People Are Affected?
Cambridge Mercantile has not disclosed a national total. The only confirmed figure is 34 Massachusetts residents — a single-state subset that likely understates the true scope for a company that provides payment services to businesses across the country.
Do You Have Legal Options?
Companies that collect and store Social Security numbers — including through business relationships with employers and corporate clients — have a legal duty to secure that information and to notify affected individuals without unreasonable delay.
If you received a notice letter from Cambridge Mercantile Corp. or Corpay, contact Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
FAQ
Who is affected by the Cambridge Mercantile / Corpay data breach?
Individuals connected to Cambridge Mercantile Corp. (U.S.A.), which does business as Corpay, through a business relationship — either directly or through an employer. Massachusetts’s filing confirms 34 affected residents; the total scope has not been disclosed.
What information was exposed?
According to the company’s filing with Massachusetts regulators, the confirmed exposed information is Social Security numbers.
I’ve never done business with Corpay directly. Could I still be affected?
Yes, potentially. The company’s own notice describes the affected group as including people connected through an employer’s business relationship with Corpay, not just direct customers.
Do I have a legal claim?
Companies that collect and store Social Security numbers have a legal duty to secure that information and to notify affected individuals without unreasonable delay, whether the relationship is direct or through an employer. If you received a notice letter from Cambridge Mercantile Corp. or Corpay, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.