UFCW Local 135 reported that an unauthorized party acquired data from its network in August 2024. The public record supports a breach notice, not an open class settlement.
No UFCW Local 135 class settlement, settlement administrator, or claim deadline is publicly announced. The union sent notices beginning January 28, 2025 after identifying affected individuals. One outside lawsuit investigation later reported that its investigation was complete, but that is not evidence that a case settled or that compensation is available. The original notice offered 12 months of identity-protection services to affected people.
StatusBreach Notice; No Settlement Announced
Incident DateAugust 23, 2024
Notices BeganJanuary 28, 2025
Reported People Affected62,692
What Happened at UFCW Local 135?
UFCW Local 135 detected suspicious activity in its computer network on August 23, 2024 and engaged outside cybersecurity specialists. The investigation determined that an unauthorized party acquired data from the network. A review to identify affected records was completed January 15, 2025, and written notices began January 28. The Maine Attorney General record classifies the event as an external system breach caused by hacking.
How Many People Were Reported Affected?
The regulatory filing reports 62,692 affected people. That figure is larger than the union’s current membership because stored records can include former members, employees, dependents, applicants, or other people whose information remained in the system. Receiving an individual notice is the strongest indication that the review connected a person’s data to the incident; general membership alone does not prove that every listed data element was affected.
What Information May Have Been Involved?
Public filings indicate that names and other identifying information could have been involved, with Social Security numbers reported for some affected records. The individual letter was designed to identify the data types relevant to that recipient, so not every person should assume the same fields were exposed. The incident notice did not say that payment-card or bank-account data was affected in every case.
What Protection Was Offered?
The regulatory record says affected people were offered 12 months of complimentary credit monitoring and identity-protection services. Enrollment was governed by the unique instructions and deadline in the breach letter. That protective service was an incident response benefit, not a cash settlement. An expired enrollment code does not establish a claim against a settlement fund.
Was a Class Action Settlement Reached?
No public settlement is identified. Several law firms advertised investigations after the notices, but an investigation is only an effort to determine whether litigation may be viable. One prominent investigation later marked its work complete. No cited court case, settlement agreement, preliminary approval order, administrator portal, or payment fund supports the old page’s settlement label or its statement that a claim deadline passed.
What Can an Affected Person Do?
Keep the original notice and enrollment confirmation, review credit reports, consider a security freeze or fraud alert, and document any concrete misuse or expense. Use the breach notice and official government record to confirm the event rather than sending identity information to a generic lead form. People seeking legal advice about individual losses may consult counsel, but this page does not promise compensation or collect potential claims.