Promises2Kids Data Breach

Promises2Kids, an organization that provides services and support to foster youth, filed a data breach notification with the California Attorney General’s office on May 16, 2025. Unfortunately, the official filing submitted for public record appears to be a scanned image rather than searchable text, so specific details about what happened, how the incident occurred, and which systems were involved could not be extracted from the document. Because of this, we cannot say with certainty whether the incident involved unauthorized access, a phishing attack, a third-party vendor, or another cause. We’re reporting what is publicly confirmed and will update this article if a clearer version of the filing becomes available.

The filing does not state, in any readable portion, how many people were affected or who they are — for example, whether they are children in care, families, donors, employees, or another group connected to the organization. If you received a letter directly from Promises2Kids, that letter is the most reliable source of details specific to your situation, and we encourage you to keep it for reference.

What information was exposed?
  • The specific categories of personal information involved were not disclosed in the readable portion of the filing.
  • Because the source document could not be read in full, we cannot confirm whether sensitive data such as Social Security numbers, financial account details, or health information were involved.

The filing does not mention any offer of free credit monitoring or identity protection services. If Promises2Kids is providing such a service to affected individuals, it should be described in the direct notification letter sent to you.

What should you do now?
  • Read any letter you received from Promises2Kids carefully, since it may contain specifics not available in the public filing.
  • Watch your mail, email, and phone for any unusual contact claiming to be from Promises2Kids or related organizations, and verify independently before sharing information.
  • Check your bank and credit card statements regularly for any charges you don’t recognize.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus (Equifax, Experian, TransUnion) if you’re concerned about identity theft, especially if the letter you received suggests sensitive data may have been involved.
  • Since the exact data exposed isn’t confirmed, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, as a precaution.
  • Keep a copy of any notification letter and note the date you received it, in case you need it for future reference or to dispute fraudulent activity.

Leave a Comment