LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Perrigo Data Breach Notice (Vermont Attorney General)

CRITICAL severityConfirmedHow we verify

Perrigo Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 18, 2026
Perrigo Data Breach Notice (Vermont Attorney General)

Reported May 18, 2026. Approximately 54 people affected.

CRITICAL
Severity
54
People affected
1
Data types exposed
May 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Perrigo Data Breach Notice (Vermont Attorney General) (reported May 18, 2026) exposed Social Security Numbers belonging to roughly 54 people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
54 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where identity-related data remains a persistent target for criminals, even relatively small disclosures can create lasting risk for the people named in them. On May 18, 2026, Perrigo notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General. The notice lists Social Security numbers among the information exposed and indicates that 54 people were affected.

Public detail beyond that filing is limited. What is known is enough to matter: Social Security numbers are durable identifiers, and their exposure can support fraud long after an incident is first reported. This article sets out the disclosed facts, explains how breaches of this general type typically unfold, and outlines practical steps for anyone who may be concerned.

Inside the incident

According to the Vermont Attorney General filing dated May 18, 2026, Perrigo provided notice of a data breach affecting Vermont residents. The filing states that 54 people were affected and that Social Security numbers were among the information exposed. The notice is framed as a data breach notification to those residents through the state attorney general’s reporting channel.

The public record provided here does not describe when the incident began or was detected, how long unauthorized access may have lasted, what systems were involved, or what technical method was used. It does not name a threat actor, describe ransomware or extortion activity, or state whether data were stolen, viewed, or otherwise mishandled beyond the fact of exposure of the named data type. Scale outside the figure of 54 affected people is not detailed in the facts given. Readers should treat timing, root cause, and full scope as undisclosed unless Perrigo or regulators publish further confirmed information.

How a breach like this happens

Incidents that result in notices naming Social Security numbers often follow familiar patterns, though none of these patterns is confirmed for this specific event. Attackers may obtain credentials through phishing, reuse of passwords from other breaches, or malware on an employee or contractor device. They may exploit unpatched remote access services, misconfigured cloud storage, or vulnerabilities in third-party software that handles HR, benefits, pharmacy, or customer records. In other cases, a business partner or service provider is compromised, and the primary organization’s data are reached indirectly.

Once inside a network or application, unauthorized parties commonly search for repositories that hold identity documents, tax forms, payroll files, insurance enrollments, or customer account databases—places where government identifiers are stored for legitimate business reasons. Exfiltration can be quiet and incremental. Organizations may learn of a problem through internal monitoring, law-enforcement notice, or unusual account activity reported by individuals. Notification laws in many U.S. states, including processes that route notices through attorneys general, then require outreach when certain personal data—especially Social Security numbers—are reasonably believed to have been compromised.

No specific group is attributed in the Perrigo filing facts summarized here. General background should not be read as a reconstruction of this incident’s cause.

Perrigo and its sector

Perrigo is a well-known name in the consumer self-care and pharmaceutical sector, associated with over-the-counter products and related health and wellness offerings. Companies in this sector typically maintain workforce records, contractor and vendor information, and, depending on their business lines, customer, patient-support, or pharmacy-related data needed to manufacture, distribute, and support products. They may also hold data tied to clinical, regulatory, or commercial partners.

A breach affecting such an organization is consequential because health-adjacent and consumer-product firms sit at the intersection of personal identity data and sensitive commercial operations. Even when a notice is limited to a modest number of individuals—as the Vermont filing indicates with 54 people affected—the data types involved can be highly sensitive. Sector peers routinely face phishing, supply-chain, and credential-based threats; that industry context explains why regulators and individuals pay attention when Social Security numbers appear in a notice, without implying fault or a particular failure mode in this case.

The information in question

The Vermont Attorney General notice, as reported, lists Social Security numbers among the information exposed. That is the data type explicitly named in the facts provided. The filing does not, in the summary available here, enumerate a fuller inventory such as addresses, financial account numbers, health details, or driver’s license data. Whether additional categories were involved is unconfirmed in the material given.

Organizations of Perrigo’s type commonly hold, for lawful business purposes, employee and sometimes customer identifiers, contact information, and records needed for payroll, benefits, compliance, or product support. That general pattern does not establish what was exposed in this incident beyond Social Security numbers. Exact contents outside the named category remain unconfirmed.

The real-world impact

For affected individuals, exposure of a Social Security number raises concrete risks: new-account identity fraud, tax-refund fraud, attempts to open credit in someone else’s name, and social-engineering attacks that cite the number to sound legitimate. These harms may appear months later. The reported count of 54 people means the known affected population is limited in size, but impact is personal rather than statistical for anyone included.

For the organization, consequences typically include regulatory notification duties, costs of investigation and consumer support, potential civil exposure, and reputational scrutiny—especially in a sector tied to health and consumer trust. The facts here do not state financial losses, litigation outcomes, or operational disruption, so those remain outside what can be asserted.

Because Social Security numbers are difficult to “change” in daily life, vigilance often matters more than a single password reset. Monitoring and careful handling of unexpected financial or government correspondence are practical responses rather than signs of panic.

Were you affected?

If you have a connection to Perrigo as an employee, former employee, or in another capacity that might place your data in their systems, watch for an official breach notice and treat unsolicited messages that demand urgent action or payments with skepticism. Consider placing a fraud alert or credit freeze with the major credit bureaus, reviewing credit reports and IRS online account activity if you use those tools, and documenting any suspicious account openings. Use only contact channels you verify independently if you need to reach the company about the notice.

You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data, which may help you prioritize password changes and monitoring on unrelated accounts. Public detail on this incident remains centered on the May 18, 2026 Vermont Attorney General filing, the figure of 54 people affected, and the naming of Social Security numbers; anything beyond that should be confirmed through official updates rather than assumption.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyPerrigo security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See Perrigo’s full breach history →

More recent breaches

ASOS US Sales LLC Data Breach Notice (Vermont Attorney General)August 21, 2026Carolina Internal Medicine Data Breach Notice (Vermont Attorney General)August 21, 2026Apollo Management Holdings, L.P. Data Breach Notice (Vermont Attorney General)August 21, 2026Valley Perinatal Services LLC d/b/a Advanced Women's Care Data Breach Notice (Vermont Attorney General)August 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Perrigo Data Breach Notice (Vermont Attorney General) →

Source: Vermont Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram