DataBreachCaseFile.com
MonitoringIndiana AG filing · September 28, 2026

Smith Dollar Confirms 2026 Data Breach Affecting Customer Data

Smith Dollar, an Indiana-based retailer, reported a data security incident to state authorities on September 28, 2026. The breach, which occurred on March 31, 2026, involved multiple categories of customer data, including names, contact information, and payment card details. Affected individuals should take protective measures against potential misuse of their exposed information.

State
Indiana
Breach date
March 31, 2026
Reported
September 28, 2026

What may have been exposed

  • Full Name
  • Email Address
  • Mailing Address
  • Phone Number
  • Password or Credential Hash
  • Payment Card Information
  • Purchase and Order History
  • Loyalty Account Details

Smith Dollar, a prominent discount retailer with extensive operations in Indiana and the broader Midwest, filed a data breach notification with Indiana authorities on September 28, 2026. This filing disclosed a data security incident that the company indicated occurred on March 31, 2026. The investigation into the incident is ongoing, with Smith Dollar stating it is actively monitoring the situation.

The publicly reported details from this filing indicate that the breach exposed a range of customer personal information. The categories of data reported as compromised include Full Name, Email Address, Mailing Address, Phone Number, Password or Credential Hash, Payment Card Information, Purchase and Order History, and Loyalty Account Details.

Such incidents typically involve unauthorized access to a company's systems, often through methods like exploiting software vulnerabilities or credential-based attacks. Retailers and e-commerce platforms like Smith Dollar manage vast repositories of customer data, which can make them high-value targets for cybercriminals seeking to exfiltrate sensitive records.

Individuals who may be affected by this data exposure should take steps to safeguard their personal and financial information. It is advisable to closely monitor all financial accounts for any unusual or unauthorized activity and to consider changing the password for your Smith Dollar account. If that password is used on other online services, it should be updated there as well, using a strong, unique password for each account.

Maintaining vigilance against phishing attempts, which may leverage exposed information to trick individuals into revealing further sensitive data, is also important. Regularly reviewing credit reports for any unfamiliar accounts or inquiries can help in detecting potential identity theft or fraud stemming from compromised data.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Indiana Attorney General filing

Related data breach cases