Incident Response Portal

Notice of Data Security Incident

This notice is posted by Arielle Cadet-King pursuant to applicable state data breach notification laws, including N.C. Gen. Stat. § 75-65. Posted on July 19, 2026. Last updated July 28, 2026.

What Happened

Beginning in or around May 2019, an unauthorized party gained access to devices, systems, and accounts used in connection with this work and used that access, and the identity of the business owner, without authorization. The incident was discovered in March 2025. Unauthorized activity associated with the incident has continued to be identified through February 2026. The matter has been reported to law enforcement and remains under investigation.

The affected hardware included both business and personal devices used in connection with that work, along with a personal email account that was also compromised. An earlier description of this incident referred only to business hardware; the investigation has since shown that the unauthorized access was broader than that, and this notice reflects the corrected description. The full extent of the access across specific devices remains under investigation.

Unauthorized Cryptocurrency Activity

The investigation has determined that, during this period, an unauthorized party used the business owner’s identity to conduct cryptocurrency mining and related transactions without her knowledge or consent. Approximately $788 million in total activity is under investigation, of which approximately $700,000 has been confirmed to date. These figures are preliminary and may change as the investigation continues.

What Information Was Involved

Based on the nature of the incident, the personal information that was or may have been subject to unauthorized access or acquisition may have included prior clients’ names and contact information (such as mailing address, telephone number, and email address) and financial account information, or other information that would permit access to a financial account or resources. The full scope of the categories of information involved is still being determined through the ongoing investigation, and this notice will be updated as more is confirmed.

Who Is Affected

Based on current estimates, more than 1,000 individuals are potentially affected. Many affected individuals did not state their state of residence when they provided their information, so residency cannot be determined from available records for a substantial number of them. For that reason, this notice is addressed to all potentially affected individuals regardless of where they live, and it should not be read as limited to the residents of any one state.

What We Are Doing

Steps have been taken to protect personal information from further unauthorized access, including securing and replacing affected devices, securing affected accounts and systems, reporting the matter to law enforcement and cooperating with that process, notifying affected individuals, notifying the appropriate consumer protection authorities in 47 states, and establishing this website and a dedicated contact channel where affected individuals can obtain information and assistance.

The eight companies that own the affected loan records are being notified separately, as required by N.C. Gen. Stat. § 75-65(b).

What You Can Do

Please remain vigilant. Review your account statements regularly and monitor your free credit reports for signs of unauthorized activity. You are entitled to one free credit report every 12 months from each of the three nationwide consumer reporting agencies at annualcreditreport.com or by calling 1-877-322-8228. You may also place a fraud alert or security freeze on your credit file at no cost. See our Identity Theft & Consumer Resources page for step-by-step information.

For Further Information and Assistance

Telephone: 930-410-6815Email the incident team

You can also reach us through the contact page. Please do not include Social Security numbers, account numbers, or other sensitive personal information in email or form messages.

Nationwide Consumer Reporting Agencies

Equifax — P.O. Box 740241, Atlanta, GA 30374-0241 — 1-800-685-1111 — equifax.com

Experian — P.O. Box 9554, Allen, TX 75013 — 1-888-397-3742 — experian.com

TransUnion — P.O. Box 2000, Chester, PA 19016 — 1-800-916-8800 — transunion.com

Federal Trade Commission and State Attorneys General

You can obtain information from the Federal Trade Commission and from your state Attorney General’s office about steps you can take to prevent identity theft. Notice of this incident has been provided to the appropriate consumer protection authorities in 47 states. Those offices are not handling inquiries about this incident. For questions about this notice, please use the incident contact channel above rather than contacting a state Attorney General’s office.

Federal Trade Commission — Consumer Response Center, 600 Pennsylvania Avenue NW, Washington, DC 20580 — 1-877-438-4338 (1-877-IDTHEFT) — ftc.gov / identitytheft.gov

Your State Attorney General — Residents of any state may contact their own state Attorney General’s office. A directory of every state Attorney General is available from the National Association of Attorneys General at naag.org/find-my-ag.

Cryptocurrency Investment Solicitations

The investigation has identified that prior clients of the business were contacted and solicited to “invest” in cryptocurrency by a party purporting to represent the business or its owner. These solicitations were not authorized. If you were contacted about a cryptocurrency or other investment opportunity purporting to come from this business, do not respond or send funds. Please report it using the contact information above, and report suspected fraud to the FTC at reportfraud.ftc.gov and to the FBI’s Internet Crime Complaint Center at ic3.gov.