Harbor Regional Center Data Breach Notification

Harbor Developmental Disabilities Foundation, doing business as Harbor Regional Center, has notified individuals that it detected unusual activity in its network environment on or about March 7, 2026. The company says the activity itself occurred on March 6 and 7, 2026, and that its investigation — which involved outside legal counsel and third-party forensic specialists — found that an unauthorized individual may have viewed or copied certain information. This points to a hacking or system intrusion as the cause. Harbor states it completed its review of exactly what information was affected on July 7, 2026, roughly four months after the activity was first detected.

The letter is addressed to specific individuals whose information Harbor maintains, but the version of the notification reviewed here does not include an aggregate count of how many people were affected in total, so we can’t state a specific number. If you received a letter, it means Harbor identified your information as potentially involved.

What information was exposed?
  • The section of the letter meant to list the specific data types involved was blank in the copy reviewed, so we cannot confirm exactly which categories of your information (for example, Social Security number, financial account details, or health-related information) were affected.
  • Harbor states the potentially impacted information varied by individual, meaning not everyone’s letter would list the same data types.
  • The fact that Harbor is offering credit monitoring services is generally a sign that sensitive identifiers, such as a Social Security number or financial account information, may be involved for at least some individuals — but this notice does not confirm that directly, so treat your own letter as the authoritative source.

Harbor is offering Single Bureau Credit Monitoring, Single Bureau Credit Report, and Single Bureau Credit Score services at no charge for 12 months, delivered through Cyberscout, a TransUnion company. To enroll, log on to https://bfs.cyberscout.com/activate and enter the unique activation code printed in your individual letter (the code is case-sensitive). You must complete enrollment within 90 days from the date of the letter, July 13, 2026 — after that, the free offer expires.

What should you do now?
  • Enroll in the free credit monitoring offered by Harbor before the 90-day deadline, since this is your most direct protection tied to this specific incident.
  • Because the exact data types weren’t listed in the version of this letter available to us, treat your account and identity broadly as at risk — review your own letter carefully for any specifics it may include.
  • Request free copies of your credit reports from Equifax, Experian, and TransUnion at annualcreditreport.com and check them for accounts or inquiries you don’t recognize.
  • Consider placing a security freeze on your credit files with all three bureaus, which prevents new credit from being opened in your name without your explicit consent.
  • Place a fraud alert with one of the three bureaus (it will notify the others), which requires creditors to verify your identity before opening new accounts.
  • Watch for phishing attempts referencing this breach — scammers sometimes use real breach notifications to trick people into giving up more information.
  • Given the uncertainty about what data was involved and Harbor’s role serving individuals with developmental disabilities, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
  • Keep a copy of your notification letter and any confirmation of enrollment, in case you need to dispute fraudulent activity or file a police report later.

If you have questions, Harbor Regional Center can be reached at 1-800-405-6108, Monday through Friday from 8:00 a.m. to 8:00 p.m. Eastern Time.

Leave a Comment