Mark Thomas Data Breach: What the Network Intrusion Notice Means for You

Mark Thomas notified an individual recipient that its network was accessed without authorization sometime around October 19, 2024, after which the company brought in outside cybersecurity specialists to figure out what happened. That investigation determined the intruder was actually inside the network earlier than first thought — from around October 11 through October 19, 2024 — and may have viewed or copied files during that window. It wasn’t until February 19, 2025, following a lengthy forensic review and manual document check, that Mark Thomas confirmed this particular recipient’s personal information was among the files that could have been taken.

Because this letter was sent to one named person rather than describing a broader population in aggregate terms, the copy of the notice available here doesn’t state how many people in total were told about the incident. If you’re reading this because you received your own version of this letter, treat it as confirmation that your specific file was identified in the review — not as a guess or a mass mailing sent to everyone regardless of impact.

What exactly was in the files that may have been accessed?
  • The source letter leaves the description of the specific data elements blank in the version reviewed here, so the exact categories of information tied to this notice aren’t spelled out in the text we have.
  • The letter does include a dedicated section on protecting against medical identity theft, which suggests health-related information may be relevant to at least some recipients, though this isn’t stated as a certainty for every notice sent.
  • Mark Thomas is offering credit monitoring as a precaution, which typically points to financial or identity-related data being part of what’s at stake, even where the letter doesn’t itemize every field.

Mark Thomas is offering a complimentary 12-month membership in credit monitoring services delivered through Cyberscout, a TransUnion company, covering single-bureau credit monitoring, a credit report, and a credit score, along with fraud assistance if you need it. The letter references an enrollment website and a unique activation code, but both were left blank in the copy of the notice available to us, along with the enrollment deadline — so if you received a physical copy of this letter, check it directly for those specific details, since they weren’t captured in this filing.

Steps worth taking even without a full data inventory
  • Enroll in the free credit monitoring Mark Thomas is offering through Cyberscout as soon as you locate the activation code and web address in your physical letter.
  • Place a fraud alert with one of the three major credit bureaus (Equifax, Experian, or TransUnion) — notifying one automatically alerts the other two, and it’s free for a year.
  • Consider a full security freeze on your credit files if you want stronger protection than a fraud alert alone provides; just remember you’ll need to lift it temporarily to enroll in credit monitoring.
  • Pull your free annual credit reports at annualcreditreport.com and scan them for accounts or inquiries you don’t recognize.
  • If any health insurance or medical information is involved, review your insurance explanation of benefits statements for services you didn’t receive and follow up with your provider on anything unfamiliar.
  • For ongoing peace of mind, you may want to sign up for a service like Aura or LifeLock, which can alert you if your personal details turn up somewhere they shouldn’t.
  • Watch your financial statements over the coming months, and file a police report if you spot signs your information has actually been misused.

Leave a Comment