Allied Services Division Welfare Fund (the Fund) has notified individuals about a data security incident involving unauthorized access to an employee email account. The Fund says it learned of the issue on or about November 25, 2024, and after working with outside cybersecurity investigators, determined on September 12, 2025 that personal data may have been improperly accessed sometime between October 9, 2024, and November 26, 2024. This matches the pattern of a hacking or system intrusion, where an outside party gets into an internal account rather than data being lost or mishandled by an employee.
The version of the letter available to us does not name a specific total number of people affected — it appears to have been sent as an individual notification rather than a mass mailing with an aggregate count. If you received this letter, it means the Fund believes your personal information was among the data in that employee mailbox.
What information was exposed?
- The section of the letter meant to list the specific data types involved was blank in the copy we reviewed, so we can’t confirm exactly which categories of your information were affected.
- The letter does include detailed guidance on credit freezes, fraud alerts, and protecting against medical identity theft, which suggests sensitive information such as Social Security numbers and/or health-related data may be part of what was involved — but this is not stated outright, so treat it as a strong possibility rather than a confirmed fact.
- If you want certainty about exactly what was exposed, contact the Fund directly and ask them to specify the data categories tied to your notice.
What should you do now?
- Request your free annual credit reports at annualcreditreport.com and review them closely for accounts or inquiries you don’t recognize.
- Place an initial one-year fraud alert with one of the three credit bureaus (Equifax, Experian, or TransUnion) — the one you contact is required to notify the other two.
- Consider placing a full security freeze on your credit files with all three bureaus, which prevents new accounts from being opened in your name without your explicit authorization.
- Watch your health insurance explanation of benefits statements closely for services you don’t recognize, since the letter specifically flags medical identity theft as a concern.
- Consider signing up for a service like Aura or LifeLock, which can alert you if your personal information appears somewhere it shouldn’t, such as on the dark web.
- If you spot suspicious activity on any account or credit report, file a police report and keep a copy — creditors often require it to resolve fraudulent charges.
- You can also file a complaint with the FTC at ftc.gov/idtheft or by calling 1-877-438-4338 if you believe your information is being misused.