Score Services LLC d/b/a Score Capital Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do
Score Services LLC d/b/a Score Capital disclosed a data breach to the Vermont Attorney General on September 11, 2026, affecting three individuals whose Social Security numbers, financial account codes, and credit and debit account information were exposed. Anyone who may have been involved with Score Capital should review the notice and take steps to protect their personal information.
Score Services LLC, doing business as Score Capital, notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on September 11, 2026. According to that notice, the incident involved three people and exposed Social Security numbers, financial account codes, and credit and debit account information. Public detail beyond the filing remains limited, but the combination of identity and financial data makes the event consequential for anyone whose records were involved.
Because the disclosure came through a state attorney general channel, the core facts can be stated directly from the notice itself. What is not described—how the intrusion occurred, when systems were first accessed, or the full technical scope—stays undisclosed rather than assumed.
What happened
On September 11, 2026, Score Services LLC d/b/a Score Capital submitted a data-breach notice to the Vermont Attorney General. The filing states that three individuals were affected and that the exposed information included Social Security numbers, financial account codes, and credit and debit account information. No further operational timeline, attack vector, or forensic findings appear in the reported summary. The notice does not attribute the incident to any named threat group, nor does it describe whether the data left the company’s control through unauthorized access, misconfiguration, or another pathway. Those particulars remain unconfirmed in the public record.
The small number of people listed does not reduce the sensitivity of the data types involved. When Social Security numbers and payment-related identifiers appear together in a single notice, the practical risk for those three individuals is the same as in larger incidents that expose the same categories of information.
How a breach like this happens
Incidents that surface Social Security numbers and financial account details typically begin with unauthorized access to systems that store customer or client records. Common pathways, in general terms, include compromised employee credentials, phishing that yields remote access, unpatched software vulnerabilities, or exposed databases that were never intended to be reachable from the public internet. Once inside, an attacker or unauthorized party may copy files containing identity and payment data. In other cases the exposure is accidental—an unsecured cloud bucket, a misdirected file transfer, or a vendor system that retained more data than necessary.
None of these mechanisms is confirmed for the Score Services LLC event; they are the ordinary background patterns seen across the financial-services sector. Organizations that handle capital, lending, or account-servicing work routinely keep precisely the kinds of identifiers named in the Vermont notice. When those systems are breached or misconfigured, the result is often a regulatory filing that lists Social Security numbers alongside account codes and card-related information. Detection may occur days or weeks later through internal monitoring, a third-party alert, or notification from a business partner. The public notice then follows once the organization has determined who was affected and what categories of data were involved.
About Score Services LLC
Score Services LLC operates under the trade name Score Capital and functions in the financial-services space. Firms of this type typically assist with capital access, account servicing, or related financial products and therefore maintain records that include personal identifiers, account numbers, and payment credentials. Even a company whose client base is modest still holds data that can be reused for identity theft or account takeover if it leaves authorized control.
A breach at such an organization matters because the data it holds is inherently high-value. Social Security numbers do not expire and can be paired with financial account codes to open new credit, drain existing accounts, or file fraudulent claims. Credit and debit account information adds a direct path to unauthorized transactions. For the three people named in the Vermont filing, the exposure is personal and immediate; for the company, the event triggers notification duties, potential regulatory scrutiny, and the operational cost of remediation and monitoring.
The information in question
The Vermont Attorney General filing explicitly lists Social Security numbers, financial account codes, and credit and debit account information among the data exposed. Those are the only categories confirmed in the public notice. No additional fields—such as dates of birth, full addresses, driver’s license numbers, or email addresses—are named in the reported summary, so their presence or absence cannot be stated as fact.
Organizations that provide capital or account-related services ordinarily retain precisely these elements in order to verify identity, process transactions, and meet regulatory record-keeping requirements. When a notice confirms that Social Security numbers and payment-related codes were involved, the practical implication is that the affected individuals face elevated risk of identity fraud and financial misuse until protective steps are taken. Exact file names, volumes, or encryption status are not described in the available disclosure.
The real-world impact
For the three people whose information appears in the notice, the concrete risks are identity theft, new-account fraud, and unauthorized use of existing credit or debit accounts. A Social Security number combined with financial account codes can allow someone to apply for credit, file false tax returns, or attempt account takeovers. Credit and debit details can be used for card-not-present purchases or to probe linked accounts. Because Social Security numbers are long-lived, the exposure window can last years unless credit freezes and monitoring are put in place.
For Score Services LLC the impact includes the cost of investigation, notification, and any required credit-monitoring offers, plus potential follow-up from regulators and affected individuals. Reputational harm is harder to quantify but is a routine consequence when financial data is confirmed exposed. The small headcount of affected people does not eliminate these obligations; state breach-notification laws generally require notice once a defined threshold of personal information is involved, regardless of whether the total is three or three thousand.
No dollar losses, ransom demands, or secondary fraud cases are reported in the Vermont filing, so those outcomes remain unconfirmed. The known harm is the confirmed exposure of the listed data types for the three individuals.
Were you affected?
If you have ever done business with Score Services LLC or Score Capital, treat the Vermont notice as a signal to act. Request a free credit report from each of the major bureaus, place a credit freeze or fraud alert, and monitor bank and card statements for unfamiliar activity. Change passwords on any related financial accounts and enable multi-factor authentication where available. Keep the breach notice or any letter you receive from the company; it may contain reference numbers useful for disputes.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets. That check does not replace credit monitoring, but it can show whether the same address has surfaced elsewhere and help you prioritize further steps. If you receive confirmation that you are one of the three individuals named, follow any specific instructions in the company’s notice and consider consulting the Federal Trade Commission’s identity-theft resources for additional guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Ocean Edge Resort and Golf Club Data Breach Notice (Vermont Attorney General)Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)Valley Perinatal Services LLC d/b/a Advanced Women's Care Data Breach Notice (Vermont Attorney General)Boston Healthcare for the Homeless Program Data Breach Notice (Vermont Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.