DataBreachCaseFile.com
Investigation OpenIndiana AG filing · December 22, 2025

The John Buck Company Confirms 2025 Data Incident in Indiana

The John Buck Company, a real estate firm, reported a data security incident to Indiana regulators in December 2025, affecting personal information within its systems. Individuals who received notification letters should review them for specifics on the exposed data and recommended protective measures.

State
Indiana
Breach date
January 10, 2025
Reported
December 22, 2025

The John Buck Company, a real estate development and investment firm based in Indiana, officially reported a data security incident to regulators on December 22, 2025. This incident, which reportedly occurred on January 10, 2025, involved unauthorized access to the company's systems.

While the specific categories of information involved were not detailed in public filings, the company confirmed that personal information was compromised during the security event. As part of its extensive business operations, The John Buck Company routinely handles sensitive personal data for its employees, tenants, and business partners.

Following the discovery of the incident, The John Buck Company initiated an investigation, which remains ongoing. The company has also issued formal data breach notification letters to all individuals determined to have been affected by this security incident.

If you have received a notification letter from The John Buck Company, it is crucial to review it carefully for any specific details provided regarding the incident and your personal information. It is also advisable to monitor your financial accounts and credit reports for any unusual activity. Consider placing a fraud alert or credit freeze with credit bureaus as a proactive step to protect against potential misuse of your data.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases