RKA Consulting Group Data Breach

RKA Consulting Group filed a data breach notification with the California Attorney General’s office on October 27, 2025. The official notification letter submitted in that filing appears to be a scanned document, and no machine-readable text could be pulled from it. That means we cannot tell you, from this filing alone, exactly what happened, how the incident occurred, or which systems were involved. Because the specific method of attack was not available to us, we are labeling it unknown rather than guessing.

We also cannot confirm from the available filing how many people were affected or which individuals received a letter. If you received a notification directly from RKA Consulting Group, that letter is the most reliable source of details about your specific situation, including what happened and what information of yours may have been involved.

What information was exposed?
  • The specific types of personal information involved were not disclosed in the readable version of the filing available to us.
  • Companies are generally required to notify California residents when sensitive information such as Social Security numbers, driver’s license numbers, financial account details, or medical information may have been exposed, so it is reasonable to treat this notice seriously even without confirmed details.
  • Check any letter you personally received from RKA Consulting Group, as it should list the exact categories of your information that were involved.
What should you do now?
  • Read any letter you received from RKA Consulting Group carefully, since it should describe exactly what data was involved and what steps the company is offering.
  • Check your bank and credit card statements regularly for charges you do not recognize, and report anything suspicious to your financial institution right away.
  • Consider placing a fraud alert or a credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) as a precaution, especially if your letter mentions identity-related information.
  • Watch for phishing emails, texts, or phone calls that reference this incident or ask you to confirm personal details — legitimate follow-up notices will not ask you to provide sensitive information over email.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, particularly useful when the exact scope of a breach isn’t fully clear.
  • Keep a copy of the notification letter and any correspondence with the company in case you need it later to dispute fraudulent activity.

Leave a Comment