Questo, Inc. data breach — notices going out; personal info including SSNs and medical data may be exposed

If you’ve used Questo (the travel/city-adventure app) and received a data breach notification, here’s what’s been disclosed publicly:

  • Questo, Inc. discovered suspicious activity on its network on or about October 9, 2025.
  • After investigating, on June 22, 2026 the company determined that files may have been accessed or acquired by an unauthorized third party between October 1–9, 2025.
  • The exposed data may include full names, dates of birth, driver’s license/government ID numbers, passport numbers, tax information, Social Security numbers, financial account and payment card information, and medical information.

If you were notified, a few practical steps worth taking:

  • Review your account statements and credit reports and watch for suspicious activity.
  • Preserve any breach notification letters or emails you received.
  • Consider placing a fraud alert and enrolling in credit monitoring.

For context: Edelson Lechtzin LLP, a national class action firm, is investigating a potential class action related to the breach and is offering free case evaluations. Not legal advice, and I’ll note this is attorney advertising — but if you got a notice, it may be worth understanding your options.

reddit.com
u/False-Battle1893 — 11 hours ago

Centers Laboratory (NJ) data breach — 542,377 patients affected by the WorldLeaks group. Here’s what was taken and what you can do.

Posting for anyone in NY, NJ, or PA who used Centers Laboratory (legal name Centers Lab NJ LLC) for diagnostic/lab testing.

What happened: The company detected suspicious network activity around Aug 25, 2025. An investigation found that between Aug 9–14, 2025, an unauthorized actor accessed its systems and exfiltrated data. The WorldLeaks extortion group — an outfit that emerged in 2025 from the operators of Hunters International — claimed responsibility for stealing more than 1.6 million files (~720 GB) and listed the company on its dark web leak site in October 2025. HHS lists the breach as affecting 542,377 individuals.

What was reportedly exposed: names, dates of birth, Social Security numbers, driver’s license/state ID numbers, passport numbers, health insurance information, and medical information (PHI). That combination is a serious long-term risk for identity theft, medical identity theft, and insurance fraud.

What you can do right now (regardless of any lawsuit): - Check whether you got a breach notification letter, and keep it.

  • Review bank/credit statements and pull your credit reports.
  • Consider a fraud alert or credit freeze with the three bureaus.
  • Watch for medical bills or insurance claims you don’t recognize.

On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected patients. Case evaluations are free. Not legal advice, and I’m sharing this because a lot of people affected by these breaches never realize it — happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said about what was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP. Attorney Advertising in some jurisdictions.

reddit.com
u/False-Battle1893 — 4 days ago
▲ 15 r/CyberSecurityAdvice+4 crossposts

Bath Fitter (Distributing, Inc.) data breach — SSNs and financial account info exposed. Here’s what was taken and what you can do.

Posting for anyone who’s used Bath Fitter (the one-day bathroom remodeling company, HQ in Springfield, TN) — its corporate affiliate Bath Fitter Distributing, Inc. disclosed a data breach.

> > What happened: On July 16, 2026, Bath Fitter began notifying individuals that their personal info was accessed in a data security incident. It reported the breach to the Vermont AG the same day, listing at least 44 Vermont residents affected. The nationwide total hasn’t been made public, so the real number could be much higher.

> > What was reportedly exposed (per the company’s regulatory filing): Social Security numbers, government ID numbers, financial account codes, and credit/debit account information. That’s a serious long-term identity theft and financial fraud risk.

> > What you can do right now (regardless of any lawsuit): > - Check whether you got a breach notice, and keep it. > - Review bank/credit-card statements and pull your credit reports. > - Consider a fraud alert or credit freeze with the three bureaus. > - Change passwords and security questions on your online accounts.

> > On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected individuals. Case evaluations are free. Not legal advice — I’m sharing because a lot of people affected by these breaches never realize it. Happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP.

reddit.com
u/False-Battle1893 — 5 days ago
▲ 10 r/CyberSecurityAdvice+4 crossposts

Ernst & Young disclosed a data breach affecting client tax records — here’s what affected people should know

Posting this because a lot of people may have gotten a notice and weren’t sure what it meant.

What happened: Ernst & Young (EY), one of the Big Four accounting firms, disclosed that an unauthorized third party accessed a third-party support/IT ticketing platform used for client tax services. The access window was March 28–April 12, 2026, and EY says the intruder downloaded client documents. EY detected it on April 23 and started notifying affected clients in July 2026.

Why it matters: The exposed documents may include personal and financial info used to prepare tax filings. That combination is a magnet for identity theft, fraudulent tax refund claims, and targeted phishing.

What EY has (and hasn’t) said: It says it secured the systems and notified law enforcement, and it’s offering affected people 24 months of Experian identity monitoring (enrollment deadline Oct 31, 2026). It has not said how many people were affected or which vendor was breached.

Practical steps if you were notified:

  • Enroll in the offered monitoring before the deadline
  • Freeze/monitor your credit
  • Get an IRS Identity Protection PIN to block fraudulent returns
  • Keep your notification letter

On the legal side: our firm (Edelson Lechtzin LLP) is investigating potential class action claims. Free/confidential case evaluations if you want to check your options — happy to answer general questions in the comments too.

reddit.com
u/False-Battle1893 — 5 days ago

Centers Laboratory (NJ) data breach — 542,377 patients affected by the WorldLeaks group. Here’s what was taken and what you can do.

Posting for anyone in NY, NJ, or PA who used Centers Laboratory (legal name Centers Lab NJ LLC) for diagnostic/lab testing.

What happened: The company detected suspicious network activity around Aug 25, 2025. An investigation found that between Aug 9–14, 2025, an unauthorized actor accessed its systems and exfiltrated data. The WorldLeaks extortion group — an outfit that emerged in 2025 from the operators of Hunters International — claimed responsibility for stealing more than 1.6 million files (~720 GB) and listed the company on its dark web leak site in October 2025. HHS lists the breach as affecting 542,377 individuals.

What was reportedly exposed: names, dates of birth, Social Security numbers, driver’s license/state ID numbers, passport numbers, health insurance information, and medical information (PHI). That combination is a serious long-term risk for identity theft, medical identity theft, and insurance fraud.

What you can do right now (regardless of any lawsuit): - Check whether you got a breach notification letter, and keep it.

  • Review bank/credit statements and pull your credit reports.
  • Consider a fraud alert or credit freeze with the three bureaus.
  • Watch for medical bills or insurance claims you don’t recognize.

On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected patients. Case evaluations are free. Not legal advice, and I’m sharing this because a lot of people affected by these breaches never realize it — happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said about what was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP. Attorney Advertising in some jurisdictions.

reddit.com
u/False-Battle1893 — 7 days ago

Centers Laboratory (NJ) data breach — 542,377 patients affected by the WorldLeaks group. Here’s what was taken and what you can do.

Posting for anyone in NY, NJ, or PA who used Centers Laboratory (legal name Centers Lab NJ LLC) for diagnostic/lab testing.

What happened: The company detected suspicious network activity around Aug 25, 2025. An investigation found that between Aug 9–14, 2025, an unauthorized actor accessed its systems and exfiltrated data. The WorldLeaks extortion group — an outfit that emerged in 2025 from the operators of Hunters International — claimed responsibility for stealing more than 1.6 million files (~720 GB) and listed the company on its dark web leak site in October 2025. HHS lists the breach as affecting 542,377 individuals.

What was reportedly exposed: names, dates of birth, Social Security numbers, driver’s license/state ID numbers, passport numbers, health insurance information, and medical information (PHI). That combination is a serious long-term risk for identity theft, medical identity theft, and insurance fraud.

What you can do right now (regardless of any lawsuit): - Check whether you got a breach notification letter, and keep it.

  • Review bank/credit statements and pull your credit reports.
  • Consider a fraud alert or credit freeze with the three bureaus.
  • Watch for medical bills or insurance claims you don’t recognize.

On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected patients. Case evaluations are free. Not legal advice, and I’m sharing this because a lot of people affected by these breaches never realize it — happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said about what was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP. Attorney Advertising in some jurisdictions.

reddit.com
u/False-Battle1893 — 7 days ago
▲ 7 r/lawsuitmoney+1 crossposts

Bought Omega, Cartier, Gucci, Hermès or another European luxury brand in the past year? You may have overpaid for tariffs that were struck down — and a firm is investigating refunds.

Quick background for anyone who bought European luxury goods recently:

Starting in early 2025, the federal government imposed sweeping tariffs on imported goods. A lot of brands raised retail prices to cover them. In February 2026, the Supreme Court ruled those tariffs unlawful.

Here’s the part worth knowing: the companies that paid those import duties can now seek that money back from the government — while, in many cases, keeping the higher prices they already charged customers. So the tariff cost potentially gets recovered twice, and the shoppers who actually paid it get nothing.

Edelson Lechtzin LLP (a national class action firm) is investigating potential refund claims involving several European luxury groups, including:

  • Hermès − luxury goods
  • Canada Goose − luxury outerwear
  • Kering — Gucci, Saint Laurent, Balenciaga, Bottega Veneta, Alexander McQueen
  • Richemont — Cartier, Van Cleef & Arpels, IWC, Jaeger-LeCoultre, Montblanc, Vacheron Constantin, Piaget
  • Swatch Group — Omega, Blancpain, Harry Winston, Longines, Tissot

If you bought from any of these in the U.S. while the tariffs were in effect, you may be entitled to a refund of the overcharge or a share of what the company recovers. Worth digging up your receipts/order history if so.

There’s no cost to speak with the firm: 844-696-7492.

Attorney advertising. This is an ongoing investigation, not a filed case against every brand named, and no court has found wrongdoing. Contacting the firm doesn’t create an attorney-client relationship, and no recovery is guaranteed.

reddit.com
u/False-Battle1893 — 8 days ago

Centers Laboratory (NJ) data breach — 542,377 patients affected by the WorldLeaks group. Here’s what was taken and what you can do.

Posting for anyone in NY, NJ, or PA who used Centers Laboratory (legal name Centers Lab NJ LLC) for diagnostic/lab testing.

What happened: The company detected suspicious network activity around Aug 25, 2025. An investigation found that between Aug 9–14, 2025, an unauthorized actor accessed its systems and exfiltrated data. The WorldLeaks extortion group — an outfit that emerged in 2025 from the operators of Hunters International — claimed responsibility for stealing more than 1.6 million files (~720 GB) and listed the company on its dark web leak site in October 2025. HHS lists the breach as affecting 542,377 individuals.

What was reportedly exposed: names, dates of birth, Social Security numbers, driver’s license/state ID numbers, passport numbers, health insurance information, and medical information (PHI). That combination is a serious long-term risk for identity theft, medical identity theft, and insurance fraud.

What you can do right now (regardless of any lawsuit): - Check whether you got a breach notification letter, and keep it.

  • Review bank/credit statements and pull your credit reports.
  • Consider a fraud alert or credit freeze with the three bureaus.
  • Watch for medical bills or insurance claims you don’t recognize.

On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected patients. Case evaluations are free. Not legal advice, and I’m sharing this because a lot of people affected by these breaches never realize it — happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said about what was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP. Attorney Advertising in some jurisdictions.

reddit.com
u/False-Battle1893 — 8 days ago
▲ 8 r/FraudPrevention+2 crossposts

Centers Laboratory (NJ) data breach — 542,377 patients affected by the WorldLeaks group. Here’s what was taken and what you can do.

Posting for anyone in NY, NJ, or PA who used Centers Laboratory (legal name Centers Lab NJ LLC) for diagnostic/lab testing.

What happened: The company detected suspicious network activity around Aug 25, 2025. An investigation found that between Aug 9–14, 2025, an unauthorized actor accessed its systems and exfiltrated data. The WorldLeaks extortion group — an outfit that emerged in 2025 from the operators of Hunters International — claimed responsibility for stealing more than 1.6 million files (~720 GB) and listed the company on its dark web leak site in October 2025. HHS lists the breach as affecting 542,377 individuals.

What was reportedly exposed: names, dates of birth, Social Security numbers, driver’s license/state ID numbers, passport numbers, health insurance information, and medical information (PHI). That combination is a serious long-term risk for identity theft, medical identity theft, and insurance fraud.

What you can do right now (regardless of any lawsuit): - Check whether you got a breach notification letter, and keep it.

  • Review bank/credit statements and pull your credit reports.
  • Consider a fraud alert or credit freeze with the three bureaus.
  • Watch for medical bills or insurance claims you don’t recognize.

On the legal side: Edelson Lechtzin LLP (a national class action firm) is investigating a potential class action for affected patients. Case evaluations are free. Not legal advice, and I’m sharing this because a lot of people affected by these breaches never realize it — happy to point folks to resources. > > Did anyone here get a notification letter? Curious what it said about what was exposed and whether they offered credit monitoring.

Disclosure: This references an investigation by Edelson Lechtzin LLP. Attorney Advertising in some jurisdictions.

reddit.com
u/False-Battle1893 — 9 days ago
▲ 20 r/CyberSecurityAdvice+3 crossposts

Fiesta Insurance data breach — 160,000+ people being notified that SSNs and financial data may have been exposed (notices went out ~13 months after discovery)

If you have insurance or tax services through Fiesta Insurance Franchise Corporation, heads up: the company has started mailing breach notification letters (on or about July 13, 2026) to more than 160,000 people across multiple states, including Texas and Massachusetts.

What reportedly happened: - The incident was discovered on June 9, 2025. - A forensic investigation reportedly took about a year. - In late June 2026, Fiesta determined that files potentially accessed contained personal information. - Notices went out ~13 months after the incident was first discovered.

Data that may have been involved (varies per person): full names, addresses, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, financial account and credit/debit card info, health-related financial information, and other government IDs.

Fiesta has said it has no indication of identity theft or fraud so far, but SSNs and financial data are exactly the categories that are most often misused.

If you got a letter, a few practical steps: - Confirm whether your info was actually involved and keep the letter. - Monitor your bank statements and credit reports. - Consider a fraud alert and credit monitoring. - Fiesta set up a response line: 844-959-7141 (Mon–Fri, 8:00 a.m.–5:30 p.m.).

For anyone tracking the legal side: Edelson Lechtzin LLP, a national class action firm, is investigating a potential class action and offering free case evaluations (844-696-7492). Not legal advice, and I’m not your lawyer — just flagging it.

reddit.com
u/False-Battle1893 — 9 days ago

Bought Omega, Cartier, Gucci, Hermès or another European luxury brand in the past year? You may have overpaid for tariffs that were struck down — and a firm is investigating refunds.

Quick background for anyone who bought European luxury goods recently:

Starting in early 2025, the federal government imposed sweeping tariffs on imported goods. A lot of brands raised retail prices to cover them. In February 2026, the Supreme Court ruled those tariffs unlawful.

Here’s the part worth knowing: the companies that paid those import duties can now seek that money back from the government — while, in many cases, keeping the higher prices they already charged customers. So the tariff cost potentially gets recovered twice, and the shoppers who actually paid it get nothing.

Edelson Lechtzin LLP (a national class action firm) is investigating potential refund claims involving several European luxury groups, including:

  • Hermès − luxury goods
  • Canada Goose − luxury outerwear
  • Kering — Gucci, Saint Laurent, Balenciaga, Bottega Veneta, Alexander McQueen
  • Richemont — Cartier, Van Cleef & Arpels, IWC, Jaeger-LeCoultre, Montblanc, Vacheron Constantin, Piaget
  • Swatch Group — Omega, Blancpain, Harry Winston, Longines, Tissot

If you bought from any of these in the U.S. while the tariffs were in effect, you may be entitled to a refund of the overcharge or a share of what the company recovers. Worth digging up your receipts/order history if so.

There’s no cost to speak with the firm: 844-696-7492.

Attorney advertising. This is an ongoing investigation, not a filed case against every brand named, and no court has found wrongdoing. Contacting the firm doesn’t create an attorney-client relationship, and no recovery is guaranteed.

reddit.com
u/False-Battle1893 — 10 days ago
▲ 9 r/therealreal+3 crossposts

Edelson Lechtzin LLP Is Investigating Richemont (Compagnie Financière Richemont S.A.) Over Tariff-Driven Price Increases That Were Not Refunded to Consumers After the Supreme Court Struck Down the Tariffs

Heads up for anyone who bought from IWC (Richemont) in the past year or so.

Quick background: in early 2025, the government imposed sweeping tariffs on imported goods, and a lot of companies raised retail prices to pass those costs to customers. On February 20, 2026, the Supreme Court ruled those tariffs (issued under the IEEPA) were unlawful and struck them down.

Here’s where it gets interesting. Importers who paid the tariffs can now claw those payments back from the government. So the open question is: if Richemont raised your price to cover the tariff, never refunded or credited you, and now recovers that same tariff from the government — it could effectively pocket the cost twice while the customers who actually paid it get nothing.

Edelson Lechtzin LLP, a national class action firm, is investigating exactly that. It covers Richemont’s whole roster, including IWC Schaffhausen.

To be clear: this is an investigation, not a filed lawsuit, and nothing has been proven. But if you bought a Richemont product while the tariffs were in effect, you can contact the firm to learn more or pass along info: 844-696-7492

Attorney advertising. Ongoing investigation only; no suit filed and no finding of wrongdoing. Contacting the firm doesn’t create an attorney-client relationship.

edelson-law.com
u/False-Battle1893 — 8 days ago
▲ 0 r/Luxury

Edelson Lechtzin LLP Is Investigating Richemont (Compagnie Financière Richemont S.A.) Over Tariff-Driven Price Increases That Were Not Refunded to Consumers After the Supreme Court Struck Down the Tariffs

Heads up for anyone who bought from Richemont brands in the past year or so.

Quick background: in early 2025 the government imposed sweeping tariffs on imported goods, and a lot of companies raised retail prices to pass those costs to customers. On February 20, 2026, the Supreme Court ruled those tariffs (issued under the IEEPA) were unlawful and struck them down.

Here’s where it gets interesting. Importers who paid the tariffs can now claw those payments back from the government. So the open question is: if Richemont raised your price to cover the tariff, never refunded or credited you, and now recovers that same tariff from the government — it could effectively pocket the cost twice while the customers who actually paid it get nothing.

Edelson Lechtzin LLP, a national class action firm, is investigating exactly that. It covers Richemont’s whole roster — Cartier, Van Cleef & Arpels, IWC Schaffhausen, Montblanc, Jaeger-LeCoultre, Vacheron Constantin, Panerai, Piaget, A. Lange & Söhne, Chloé, Net-a-Porter, Mr Porter, and more.

To be clear: this is an investigation, not a filed lawsuit, and nothing has been proven. But if you bought a Richemont product while the tariffs were in effect, you can contact the firm to learn more or pass along info: 844-696-7492

Attorney advertising. Ongoing investigation only; no suit filed and no finding of wrongdoing. Contacting the firm doesn’t create an attorney-client relationship.

globenewswire.com
u/False-Battle1893 — 11 days ago
▲ 1 r/therealreal+1 crossposts

Bought an Omega, Tissot, Longines, or other Swatch Group watch during the tariff period? A law firm is investigating possible refunds

Heads up for watch and jewelry buyers. Edelson Lechtzin LLP, a national class action firm, has opened an investigation into The Swatch Group — the parent company behind Blancpain, Harry Winston, Omega, Longines, Tissot, Hamilton, and 10 other brands.

Here’s the issue:

  • Starting in early 2025, sweeping import tariffs pushed up the cost of bringing goods into the U.S., and many companies raised retail prices to pass those costs to customers.
  • On February 20, 2026, the U.S. Supreme Court ruled those tariffs (imposed under the IEEPA) unlawful and invalidated them.
  • Importers that paid the tariffs can now seek refunds from the government.

The investigation is looking at whether Swatch Group raised prices to cover the tariffs, has not refunded or credited customers for those overcharges, and now stands to collect the same tariff money back from the government — potentially keeping both.

If you bought a Swatch Group watch or piece of jewelry at an inflated price during the tariff period, or have relevant information, you can contact the firm to learn more about your rights.

Contact: Edelson Lechtzin LLP — 844-696-7492 ext. 1 — elechtzin@edelson-law.com

Attorney advertising. This is an ongoing investigation only — no lawsuit has been filed, and no court has found any wrongdoing. Contacting the firm does not create an attorney-client relationship.

edelson-law.com
u/False-Battle1893 — 11 days ago
▲ 2 r/therealreal+2 crossposts

Bought Gucci, Saint Laurent, Balenciaga (or other Kering brands)? A law firm is investigating whether you’re owed a tariff refund.

Posting because this may be relevant to anyone who bought luxury goods over the past year.

Edelson Lechtzin LLP, a national consumer class action firm, is looking into Kering S.A. — the parent of Gucci, Yves Saint Laurent, Balenciaga, Bottega Veneta, Alexander McQueen, Creed, and Maui Jim.

The background:

  • Starting in early 2025, the government imposed sweeping import tariffs. Many companies raised retail prices to pass those costs on to customers.
  • On February 20, 2026, the Supreme Court ruled those tariffs unlawful.
  • Importers who paid the tariffs can now seek refunds from the government.

The concern the firm is investigating is that a company could keep the higher prices it already collected from customers and recover the same tariff money from the government — a potential double recovery, while the shoppers who paid more get nothing back.

If you bought any of these brands at a marked-up price during the tariff period, the firm wants to hear from you—no cost to talk to them.

Contact: 844-696-7492 | elechtzin@edelson-law.com

Attorney advertising. This is an ongoing investigation only — no lawsuit has been filed against Kering S.A. and no court has found wrongdoing. Contacting the firm does not create an attorney-client relationship.

edelson-law.com
u/False-Battle1893 — 11 days ago
▲ 5 r/therealreal+1 crossposts

Did you buy Hermès in the last year? You may be owed a refund. 💰

If you purchased a Hermès handbag, scarf, watch, jewelry, ready-to-wear, footwear, fragrance, or other luxury goods in the U.S. over the past year, you may have paid more than you should have.

Here’s why: When sweeping import tariffs took effect, many companies quietly raised their retail prices to pass those tariff costs on to customers. But on February 20, 2026, the U.S. Supreme Court ruled those tariffs unlawful.

Now importers can seek refunds of the tariffs they paid — and Edelson Lechtzin LLP is investigating whether Hermès kept the higher prices you paid while standing to recover the same tariffs from the government. If so, that could mean a double windfall at your expense.

You may be entitled to a refund of the tariff-inflated amount you paid.

👉 Find out if you qualify. Contact Edelson Lechtzin LLP for a free, no-obligation review of your rights.

📞 844-696-7492 ext. 1 ✉️ elechtzin@edelson-law.com

Attorney advertising. This describes an ongoing investigation only — no class action has been filed against Hermès, and no court has found that Hermès did anything wrong. Contacting the firm does not create an attorney-client relationship, and no recovery is guaranteed. Prior results do not guarantee a similar outcome. Hermès and other brand names are the property of their respective owners.

edelson-law.com
u/False-Battle1893 — 11 days ago