DataBreachCaseFile.com
MonitoringMontana AG filing · December 17, 2025

Eckerd Connects Data Breach Exposes Sensitive Records in Montana

Eckerd Youth Alternatives Inc., known as Eckerd Connects, reported a data breach to Montana regulators on December 17, 2025, after an incident on November 2, 2024. The breach exposed highly sensitive personal information, including Full Name, Social Security Number, and Medical and Behavioral Health History, putting vulnerable individuals at risk of identity theft and fraud.

State
Montana
Breach date
November 2, 2024
Reported
December 17, 2025

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Home Address
  • Contact Information
  • Medical and Behavioral Health History
  • Government-Issued ID Details
  • Employment and Compensation Records

Eckerd Youth Alternatives Inc., operating as Eckerd Connects, is a multi-state social services and non-profit organization supporting at-risk children, youth, and families. The organization provides critical child welfare services, behavioral health counseling, and juvenile justice programs, necessitating the collection and maintenance of extensive sensitive records for vulnerable populations, including program participants and employees.

The organization reported a data security incident to the Montana Attorney General on December 17, 2025, which occurred on November 2, 2024. The breach type was unspecified, and the investigation status is currently listed as monitoring. While the number of affected individuals remains unspecified in public filings, the compromised data included Full Name, Social Security Number, Date of Birth, Home Address, Contact Information, Medical and Behavioral Health History, Government-Issued ID Details, and Employment and Compensation Records.

Exposure of such deeply personal information carries significant risks, particularly for the sensitive demographics served by Eckerd Connects. Compromised data like Social Security Numbers and Government-Issued ID Details can lead to identity theft and various forms of financial fraud. The exposure of Medical and Behavioral Health History also poses unique harms, potentially subjecting individuals to medical fraud and targeted social engineering schemes.

Individuals who receive a data breach notification related to this incident should remain vigilant. It is advisable to review financial statements and explanation of benefits forms for any unauthorized activity. Consider placing a fraud alert or security freeze on credit files to prevent new accounts from being opened in your name. Additionally, update passwords for online accounts and be cautious of unsolicited communications that may attempt to phish for more personal details.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Check for medical identity theft

    Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Montana Attorney General filing

Related data breach cases