QuestionPro Inc. Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do
QuestionPro Inc. notified Massachusetts Attorney General of a data breach that came to light on August 18, 2026, exposing Social Security numbers and financial account numbers of two individuals. Anyone who received notice or suspects involvement should review their account statements and consider placing a fraud alert or credit freeze.
A small number of people may have had highly sensitive personal information exposed in a data security incident involving QuestionPro Inc. According to a notice reported to Massachusetts authorities, the company informed affected Massachusetts residents that Social Security numbers and financial account numbers were among the data involved. Even when the count of people named is low, the kinds of information at issue can create lasting practical risk for those individuals.
The disclosure was reported on August 18, 2026, through a filing with the Massachusetts Office of Consumer Affairs in connection with notice to the Massachusetts Attorney General’s office. Public detail beyond that notice is limited. What is known is enough to matter: identifiers that can be used for identity theft and account misuse were listed as exposed.
Inside the incident
QuestionPro Inc. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 18, 2026. The notice lists Social Security numbers and financial account numbers among the information exposed. The filing indicates that two people were affected.
The public record provided in that notice does not describe how the incident was discovered, how long unauthorized access may have lasted, what systems were involved, or whether the data was encrypted, copied, or otherwise removed. Method, root cause, and technical timeline are undisclosed in the available summary. No threat group is attributed in the disclosure.
What can be stated with confidence is only what the notice itself reports: a formal breach notification to Massachusetts residents, the August 18, 2026 reporting date, a stated count of two people affected, and the inclusion of Social Security numbers and financial account numbers among the exposed information categories.
How a breach like this happens
Incidents that lead to notices naming Social Security numbers and financial account data often follow familiar patterns, though none of these patterns is confirmed for this specific case. In general terms, attackers may obtain access through stolen or phished employee credentials, vulnerable remote-access services, unpatched software, misconfigured cloud storage, or compromised third-party tools that connect to customer or survey platforms. Once inside, they may search for databases, exports, backups, or administrative panels that contain identity and payment-related fields.
Organizations that run online survey, feedback, or research platforms commonly process contact details, demographic answers, and sometimes payment or incentive information. A breach of that environment does not always mean every record was taken; it can mean a limited subset was accessible during a window of unauthorized access. Ransomware groups and data thieves sometimes exfiltrate files before encryption or simply copy what they can find. In other cases, a vendor or contractor with legitimate access becomes the entry point.
Because no technical cause is stated in the QuestionPro notice summary, these remain general background explanations of how similar incidents typically unfold—not a description of what happened here. Without a published forensic account, the precise path of compromise stays unconfirmed.
Who is QuestionPro Inc.?
QuestionPro Inc. is a company known publicly for online survey, research, and experience-management software used by businesses, researchers, and organizations to collect feedback and analyze responses. Firms in this sector typically hold account credentials for administrators, respondent contact information, survey content, and—depending on product features—billing details, incentive or payout data, and other personal information supplied by clients or participants.
A breach at a survey and research platform can be consequential because the business model concentrates personal data from many sources in systems designed for collection, storage, and analysis. Even when a formal notice names only a small number of affected individuals in one state filing, the sensitivity of the data types listed—government identifiers and financial account numbers—raises the stakes for those people. The company’s role as a processor of information on behalf of clients also means incidents can affect both end users and the organizations that rely on the platform, though the Massachusetts notice summarized here focuses on the residents who were notified.
What was likely exposed
The notice explicitly lists Social Security numbers and financial account numbers among the information exposed. Those categories are confirmed by the disclosure. The filing does not publish a full inventory of every field that may have been accessible, nor does it describe the format of the records or whether additional data elements were involved.
Organizations of this kind often also hold names, email addresses, phone numbers, survey responses, IP logs, and billing contacts in the ordinary course of business. Whether any of those were part of this incident is unconfirmed. Readers should treat only the named categories—Social Security numbers and financial account numbers—as established by the notice, and treat any broader assumption as speculative.
The real-world impact
For the people affected, exposure of a Social Security number combined with financial account numbers creates concrete risks: fraudulent opening of credit accounts, tax-refund fraud, unauthorized attempts to access or drain bank or payment accounts, and long-term identity misuse that can take months to fully unwind. Even a notice that names only two individuals does not reduce the severity of harm if those two people’s core identifiers were involved.
For the organization, a reported breach can bring regulatory scrutiny, notification costs, potential claims, and pressure to harden access controls, logging, and vendor oversight. Clients who use the platform may ask for assurances about how respondent and account data are segregated and monitored. None of that establishes negligence as a legal finding; it simply describes the ordinary consequences that follow public breach notices involving high-value personal data.
Because the public summary does not describe whether the data was posted for sale, used in fraud, or recovered, the actual criminal misuse—if any—remains unconfirmed. The prudent assumption for anyone notified is that the named data types could be misused and should be monitored.
Were you affected?
If you received a notice from QuestionPro Inc. or from Massachusetts authorities about this incident, treat it as confirmation that your information may be involved. Place a fraud alert with the major credit bureaus, review bank and credit-card statements for unfamiliar activity, and consider a credit freeze if you want to block new accounts in your name. If a Social Security number was involved, watch for unexpected tax notices or benefits activity and follow the steps in any official letter you received. Keep the notice for your records; it may be needed for dispute or identity-recovery processes.
If you are unsure whether your email or accounts have appeared in known breach datasets more broadly, you can run a free exposure scan of your email to check whether your information has surfaced in known breach data. That check does not replace official notice from the company, but it can help you decide where to focus monitoring. When public detail is limited, steady verification and careful account hygiene remain the most practical response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Infinity Globus Business Services LLC Data Breach Notice (Massachusetts Attorney General)Merced Union High School District Data Breach Notice (Massachusetts Attorney General)Rockland Trust Data Breach Notice (Massachusetts Attorney General)Aerospace Alloys Inc Data Breach Notice (Massachusetts Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.