The Friesen Group confirmed unauthorized access to its network in July 2025. It didn’t finish figuring out whose data was affected until July 2026 — a full year later — and didn’t send notice until September 2026. All told, 490 days passed between discovery and notice.
The Friesen Group has begun notifying individuals of a data security incident involving their personal information, according to a filing with the California Attorney General. Per the company’s notice letter, Friesen received a suspicious email on May 19, 2025 suggesting data on its network may have been at risk. A forensic investigation determined on July 15, 2025 that an unauthorized user had gained access to the network. From there, the timeline stretches dramatically: Friesen did not determine that a given individual’s information was actually found within the compromised data until July 16, 2026 — a full year after confirming the intrusion — and notice was sent on September 21, 2026.
Source: The Friesen Group notice letter; California Attorney General data breach report sb24-630087, filed 09/21/2026 (breach reported as 05/15/2025).
A Timeline That’s Hard to Explain
This is one of the longest delays we’ve seen in a data breach notice: 490 days from when Friesen discovered the intrusion to when it told affected individuals, and 433 days from the date its own forensic investigation confirmed unauthorized access. The gap that stands out most is the twelve months between confirming the network was accessed (July 2025) and determining whose data was actually in it (July 2026). At that length, this isn’t a story about forensic investigations simply taking time — it’s a story that raises real questions about how seriously the review was prioritized.
What Information May Have Been Involved
The version of Friesen’s notice letter reviewed for this post does not specify what personal information was involved — the relevant section is an unpopulated template. No confirmed, itemized list of exposed data categories is currently available from any public source, and Friesen’s California filing does not supply one either. The company is offering twelve months of complimentary credit monitoring and identity restoration services through Cyberscout, a TransUnion company, to affected individuals — a standard precaution regardless of what specific data was involved.
What We Don’t Know
Beyond the missing data-type details, there’s uncertainty about who exactly The Friesen Group is and how many people are affected. No population figure has been released, and the company’s industry or sector isn’t clear from the public record. What is clear and confirmed is the delay itself — and that alone is worth taking seriously if you received a notice letter.
What You Can Do Now
- If you received a notice letter from The Friesen Group, enroll in the complimentary Cyberscout credit monitoring before the 90-day enrollment window closes
- Review your credit reports and account statements for unfamiliar activity
- Consider a fraud alert or credit freeze with the three major credit bureaus as a precaution, given how little is confirmed about what was exposed
- Contact us for a free case review if you received a notice letter from The Friesen Group
Do You Have Legal Options?
Companies have a legal duty to notify affected individuals without unreasonable delay once they know a data breach occurred and who it affects. A 490-day gap between discovery and notice — including a full year spent determining who was affected — is the kind of delay that itself may support a legal claim.
If you received a data breach notice from The Friesen Group, contact Emery | Reddy today for a free case review.
FAQ
How long did it take The Friesen Group to notify affected individuals?
490 days from discovery of the intrusion to notice, and 433 days from the date forensic investigators confirmed unauthorized network access. The company took a full additional year after that confirmation just to determine whose data was affected.
What information was exposed?
The notice letter reviewed for this post does not specify. No confirmed, itemized list of exposed data categories is currently available from any public source.
How many people are affected?
No population figure has been released by The Friesen Group or any regulator as of this writing.
Why does the delay matter if I don’t know what data was exposed?
Data breach notification laws generally require prompt notice once a company knows who was affected. A delay this long can itself be the basis for a legal claim, separate from the underlying data-type question — and it also means affected individuals went well over a year without knowing they needed to protect themselves.
Do I have a legal claim?
Companies have a legal duty to notify affected individuals without unreasonable delay after a data breach. If you received a notice letter from The Friesen Group, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.