Catalyst Brands LLC Discloses Customer Data Breach in Washington Filing
Catalyst Brands LLC officially reported a data breach to the Washington Attorney General on September 4, 2026. This incident involved the compromise of various customer data types, including names, email addresses, and payment information. Individuals affected should be aware of potential risks to their personal and financial security.
- State
- Washington
- Reported
- September 4, 2026
What may have been exposed
- Full Name
- Email Address
- Mailing Address
- Password or Credential Hash
- Purchase and Order History
- Payment Card Information
- Date of Birth
- Phone Number
On September 4, 2026, Catalyst Brands LLC submitted a public filing to the Washington Attorney General confirming a data security incident. This filing indicates that the company experienced a breach that exposed customer information.
Catalyst Brands LLC manages a diverse portfolio of direct-to-consumer brands, requiring it to aggregate and store significant amounts of consumer data. Its operations encompass e-commerce infrastructure and digital marketing, positioning it as a central repository for various customer profiles and transactional histories.
The data categories reportedly compromised in this incident include Full Name, Email Address, Mailing Address, Password or Credential Hash, Purchase and Order History, Payment Card Information, Date of Birth, and Phone Number. These specific data types were identified in the company's report.
Exposure of such personal and financial details can lead to several risks for affected individuals. These may include the potential for identity theft, unauthorized purchases, or fraudulent access to online accounts. It is important for individuals to understand what data was involved to take appropriate protective measures.
To help mitigate potential risks, affected individuals should consider monitoring their financial statements and credit reports for any unusual or unauthorized activity. It is also advisable to update passwords for online accounts, particularly those that might share credentials or be linked to the exposed information.
Source: Attorney General filing