Security Industry Specialists, a California security guard company, is warning people that their Social Security numbers, driver’s license numbers, medical information and financial account details may have been exposed. The company has not said what happened, when it happened or how many people are affected.
What Security Industry Specialists Has Reported
Security Industry Specialists, Inc. (SIS) is a security services company headquartered in Culver City, California. It supplies security officers and security staff to corporate clients.
SIS is mailing letters titled “Notice of Data Security Incident” through Kroll, a company that handles breach notices and identity monitoring. The letter says a data security incident “may have involved some of your personal information held by” SIS. The company filed the letter with Massachusetts regulators on September 26, 2026.
What the SIS Letter Leaves Out
The letter is short on facts. It does not say:
- When the incident happened or when SIS discovered it
- How the incident happened, or who was behind it
- How many people were affected
- Whether SIS has seen any misuse of the information
Massachusetts law bars a notice sent to its residents from describing the nature of a breach, so letters sent to people in other states may say more. The letter also fills in the exposed information person by person, so each recipient should read their own letter closely to see what applies to them.
Four Kinds of Sensitive Data in One Incident
The Massachusetts filing lists four types of information: Social Security numbers, driver’s license numbers, medical information and financial account information. Each one is valuable to criminals on its own. Together, they can give a criminal most of what is needed to pass as someone else: a Social Security number and driver’s license to open accounts, account details to reach money, and medical information to get care or file insurance claims in another person’s name.
What Information Was Exposed?
According to the Massachusetts data breach report, the information involved may include:
- Name
- Social Security number
- Driver’s license number
- Medical information
- Financial account information
The letter itself does not list the data types; it fills them in for each person. Not every recipient may have had every type of information exposed.
How Many People Were Affected?
SIS has not disclosed a total. Massachusetts lists 40 of its residents as affected, according to the state’s data breach report. Because SIS is based in California and operates in many states, that count reflects only one state and is not a measure of the total.
What Is Security Industry Specialists Offering?
SIS is offering 24 months of identity monitoring through Kroll at no cost. The services include:
- Triple-bureau credit monitoring
- Fraud consultation with a Kroll specialist
- Identity theft restoration
People enroll at enroll.krollmonitoring.com using the membership number printed on their letter, by the deadline stated in the letter. Credit monitoring requires being over 18 with established U.S. credit, a Social Security number and a U.S. address on file. Questions go to the SIS call center at (844) 958-8975, Monday through Friday, 8 a.m. to 8 p.m. Central Time. The letter says SIS will not ask people to give up any legal right to receive these services.
Your Information Is at Risk
A Social Security number and driver’s license number together are enough for a criminal to apply for credit, open bank accounts, file a false tax return or create a fake ID. Financial account information can be used for unauthorized withdrawals or targeted scams. Medical information can be used for medical identity theft, which can leave false entries in a person’s health records. A Social Security number usually cannot be changed, so the risk can last for years after a breach.
Do You Have Legal Options?
Companies that collect Social Security numbers, driver’s license numbers, medical and financial information, including employers that keep this data in personnel, payroll and screening records, have a duty to protect it and to notify people promptly when it is exposed. When that obligation is not met, affected individuals may have legal rights and remedies worth discussing with an attorney. Emery | Reddy is investigating this incident on behalf of people who received a notice letter.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review. No Fee Unless We Recover. Call 916.995.5968.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Frequently Asked Questions
Did Security Industry Specialists have a data breach?
SIS is sending letters saying a data security incident may have involved people’s personal information. It filed the letter with Massachusetts regulators on September 26, 2026. The letter does not say when the incident happened.
How many people were affected?
SIS has not said. Massachusetts lists 40 of its residents. The national total has not been disclosed.
What information was exposed?
According to the Massachusetts filing, the information may include:
- Name
- Social Security number
- Driver’s license number
- Medical information
- Financial account information
Check your own letter, since the information listed varies by person.
When did the breach happen?
SIS has not said. The letter gives no date for the incident or for when the company discovered it.
What are the risks when medical information is exposed?
Medical information can be used for medical identity theft, where someone gets care, prescriptions or insurance payments in your name. That can leave false entries in your medical records and bills you did not run up. Check your Explanation of Benefits statements for care you did not receive.
How do I protect myself from scams that mention the breach?
Criminals often send emails, texts or calls that mention a recent breach by name to seem real. Do not click links or give information to anyone who contacts you about the SIS breach. Use only the website and phone number printed on your letter, and never share your Kroll membership number with someone who calls you.
What should I do if I received a letter?
Take these steps:
- Enroll in the Kroll monitoring by the deadline on your letter
- Place a free credit freeze with Equifax, Experian and TransUnion
- Review your credit reports and bank statements for activity you do not recognize
- Check your Explanation of Benefits statements for care you did not receive
- Keep your letter
Do I have a legal claim?
You may. Companies that collect Social Security numbers, driver’s license numbers, medical and financial information have a duty to protect it and to notify people promptly when it is exposed. If you received a Notice of Data Breach letter from Security Industry Specialists, contact Emery | Reddy at 916.995.5968 or visit emeryreddy.com for a Free Case Review to see what you may qualify for. No Fee Unless We Recover.