DataBreachCaseFile.com
MonitoringIndiana AG filing · September 15, 2026

Click2Mail Data Breach Exposes Client Names, Addresses, Financial Info

C2M LLC dba Click2Mail, an Indiana-based digital printing and direct mail provider, reported a data breach on September 15, 2026. The incident exposed client names, mailing addresses, financial information, and confidential document content, potentially leading to identity-related risks for those affected.

State
Indiana
Breach date
July 6, 2026
Reported
September 15, 2026

What may have been exposed

  • Full Name
  • Mailing Address
  • Email Address
  • Phone Number
  • Financial Account Information
  • Document Content and Metadata
  • Internal Client ID Numbers
  • Transaction History

C2M LLC, operating as Click2Mail, a digital printing and direct mail automation provider, reported a data breach incident to regulators on September 15, 2026. Based in Indiana, the company specializes in processing and distributing client documents and marketing materials. The breach date was identified as July 6, 2026, and the investigation into the incident is currently ongoing.

The information reported as compromised in this breach includes Full Name, Mailing Address, Email Address, Phone Number, Financial Account Information, Document Content and Metadata, Internal Client ID Numbers, and Transaction History. Due to the nature of Click2Mail's services, it routinely handles sensitive data uploaded by its corporate clients for various distribution needs.

The exposure of these data types carries various risks for affected individuals. Full names and mailing addresses can be used for targeted phishing or mail fraud schemes. Combined with financial account information and transaction history, there is an elevated risk of unauthorized access to existing accounts or the creation of fraudulent new accounts. Document content and metadata, if exposed, could reveal further sensitive personal or business details.

Individuals who receive a notification regarding this incident should take steps to protect themselves. It is recommended to carefully review financial account statements and transaction history for any unfamiliar activity. Being vigilant about unsolicited emails, phone calls, or mail, particularly those requesting personal information, is also advisable. Consider placing a fraud alert or security freeze on your credit reports with the major credit bureaus to prevent unauthorized new accounts.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Indiana Attorney General filing

Related data breach cases