Data Breach & Privacy
Blog > Data Breach & Privacy
Families United Network Data Breach: An Employee Inbox Was Downloaded
Families United Network, a Pennsylvania child welfare nonprofit, says an intruder downloaded the contents of an employee’s email account in December 2025, and the affected files contained Social Security, driver’s license, financial and medical details. Here’s what the notice confirms and what to do now.

What Happened at Families United Network
One employee email account, accessed December 19 to 22, 2025
Families United Network, known as FUN, says it recently learned of suspicious activity in its email environment. According to its website notice, the organization quickly took steps to confirm that its systems were secure and opened an investigation into the nature and scope of the event.
That investigation confirmed that an unauthorized actor got into a single employee email account between December 19 and December 22, 2025, and downloaded everything in it. FUN then reviewed the downloaded items to work out what information they held and whom it belonged to. The notice does not say when the activity was first noticed or how the intruder got in.
Information Found in the Downloaded Email
Identity numbers, account data and health information
According to the notice, the review found names along with these types of information in the affected files: dates of birth, driver’s license numbers, state identification numbers, Social Security numbers, financial account information, health insurance information and medical information. FUN says the details involved differ from person to person.
That mix creates several kinds of risk at once. Identity numbers can be used to open new accounts, financial account information can be used against existing accounts, and insurance or medical details can be used to obtain care or file claims in someone else’s name. FUN says it has no indication of actual or attempted misuse of anyone’s information.
Who May Be Affected by the FUN Breach
People connected to a Pennsylvania child welfare agency
FUN describes itself as a Pennsylvania-based nonprofit licensed by the state Department of Human Services as a voluntary child welfare agency. It began its work in 1996, gives Muncy, Pennsylvania, as its location in the notice, and offers foster care, adoption, peer support, pregnancy support, and drug and alcohol recovery services.
The notice does not say how many people are involved or whether they are children in care, foster or adoptive families, employees or others. As of October 5, 2026, we found no listing for this incident on the federal HHS breach portal, in the breach records of the California, Vermont and Texas attorneys general, or in Massachusetts’ 2026 breach report. The notice says Rhode Island residents may be among those involved.
How Families United Network Responded
Policy review and staff reminders, but no monitoring offer
FUN says its response included making sure its systems were secure, completing its investigation and reviewing the affected files. It also says it is reviewing its existing security policies and has reinforced with staff the importance of safeguarding the information the organization holds.
The website notice does not offer complimentary credit monitoring or identity protection. It instead explains free credit reports, fraud alerts and credit freezes, and it states that the notice was not delayed by law enforcement. It gives no date for when individual letters were or will be mailed.
Protecting Yourself After the FUN Breach
Covering identity, account and medical risks
Because the downloaded account held identity, financial and health details, these steps address each area:
- Freeze your credit with Equifax, Experian and TransUnion. A freeze is free and makes it far harder for someone to open credit with a stolen Social Security or license number.
- Watch your financial accounts. Withdrawals, transfers or new payees you don’t recognize can be early signs that account information is being misused.
- Read your health plan’s Explanation of Benefits statements. Claims for visits or treatment you never received can point to medical identity theft.
- Check whether a child has a credit file if a child’s information may be involved. Most children have no credit history, so a report in a child’s name can be a red flag.
- Be wary of anyone who contacts you about the incident. Before sharing details, confirm who you’re dealing with by using contact information you look up yourself.
This is general information, not legal advice; a legal professional can help you prioritize based on what your letter says.
Talk to Wilshire Law Firm
Was your information in the Families United Network breach?
Did Families United Network tell you that your Social Security number, financial account information or medical details were in the downloaded email account? Wilshire Law Firm’s award-winning, nationally recognized team reviews data breach and privacy matters, and breaches involving this range of sensitive information are sometimes brought as class actions. You can speak with a legal professional in a free consultation or free case review, our team is available 24/7, and there are no fees unless you get paid.
Reach out to Wilshire Law Firm, and we’ll help you understand what the notice means for you.
FAQs
FUN says an unauthorized actor had access to one employee email account from December 19 to December 22, 2025, and downloaded its contents. The notice does not give the date FUN discovered the activity.
The notice lists names together with dates of birth, driver’s license numbers, state ID numbers, Social Security numbers, financial account information, health insurance information and medical information. The elements vary by person.
FUN has not published a number. As of October 5, 2026, none of the government breach listings we checked showed a count for this incident.
Its website notice does not mention free credit monitoring or identity protection services. It explains how to get free credit reports and place fraud alerts or credit freezes, which cost nothing at the three national bureaus.
FUN says it has no indication of actual or attempted misuse. That reflects what the organization knew when it posted its notice, so continuing to watch your accounts and benefit statements is still worthwhile.
FUN is a nonprofit child welfare agency in Pennsylvania that has worked with foster and adoptive families since 1996, according to its website.
You may have options. FUN’s notice says Social Security numbers, driver’s license and state ID numbers, financial account information and medical information were in an email account that an unauthorized actor downloaded. Incidents like this are frequently examined as potential class action cases, and a free case review is a no-cost way to learn whether your situation fits.

