Fedcap
ent_b1b70964b097aa31
Disclosures
5
State AG · Leak Site · HHS OCR · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
2,158
nationwide · HHS OCR NY
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Fedcap
- Normalized
- fedcap— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- fedcap.org
Disclosure history (5)newest first
- ⛰️New Hampshire State AGas victim2026-06-22
The Fedcap Group, Inc. notified the New Hampshire Attorney General of a data event affecting 2 NH residents. Unauthorized access occurred Dec 5-7, 2025; discovered Dec 7, 2025. Data potentially exposed: names, driver's license numbers, SSNs. Fedcap engaged third-party cybersecurity specialists, notified federal law enforcement, and provided 12 months of credit monitoring.
- 🍁Vermont State AGas victim2026-06-22
The Fedcap Group, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-22. The reporting organization type is Not-For-Profit. 1 Vermont residents were affected. Categories of data breached: Social Security Numbers.
- 🏛️Massachusetts State AGas victim2026-06-01
The Fedcap Group, Inc. notified Massachusetts residents of a cybersecurity incident involving unauthorized access to personal information. The breach exposed names, Social Security numbers, dates of birth, and driver's license numbers. The company engaged law enforcement, reviewed security policies, and offered 24 months of complimentary credit monitoring and identity restoration through Experian. The investigation is ongoing.
- GLOBALLeak Siteas victim2025-12-10
Founded in 1935, Fedcap is a nonprofit organization that creates opportunities for people with barriers to economic well-being. Fedcap's headquarters is in New York City, New York.
- NEW YORKHHS OCRas victim2019-08-29
Fedcap Rehabilitation Services, Inc. reported to HHS on 2019-08-29 a Hacking/IT Incident affecting 2158 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing ePHI including names, DOB, SSN, driver's license, passport, financial, and health insurance data. The CE offered credit monitoring, implemented safeguards, and retrained staff.