Did 0WorldOne Inc dba Sermo have a data breach?
Answer
Yes. 0WorldOne Inc dba Sermo reported a data breach to the Indiana Attorney General on February 9, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- February 9, 2026
- Breach date
- March 19, 2024
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Professional License Number
- Financial Account Details
- Tax Identification Number
- Email Address
- Professional Credentials and Verification Records
In plain terms
Operating under the dba Sermo, 0WorldOne Inc functions as a specialized digital platform and online community tailored specifically for physicians and healthcare professionals. Because of its unique position at the intersection of medicine, clinical research, and pharmaceutical marketing, Sermo acts as a massive repository of sensitive professional and personal information. Healthcare providers utilize the network not only for peer-to-peer collaboration, clinical discussions, and medical polling, but also to complete professional credentialing, share career credentials, and engage in compensated medical research surveys. Consequently, the organization holds vast quantities of detailed profile data, including practitioner verification records, professional licensing details, academic histories, banking information for survey compensation, and extensive digital footprints of medical discourse.
In 2026, 0WorldOne Inc dba Sermo formally reported a significant security incident to the Indiana Attorney General, alerting members and industry stakeholders to a compromise of its network infrastructure. While investigations into such healthcare-adjacent technology breaches typically reveal unauthorized access to backend databases or vulnerabilities within third-party vendor integrations, the incident underscores the severe threats facing digital platforms that aggregate professional medical data. Cybercriminals increasingly target physician networks and healthcare tech platforms to harvest high-value credentials, corporate insights, and financial details associated with medical professionals and pharmaceutical interactions.
The exposure resulting from the 0WorldOne Inc dba Sermo breach encompasses a troubling array of sensitive categories, presenting acute risks to affected medical professionals. Compromised data sets typically involve full names, contact details, professional license numbers, dates of birth, Social Security numbers or tax identification numbers used for professional compensation, and financial account details. For physicians and healthcare workers, the exposure of professional credentials combined with financial data creates immediate vulnerabilities to targeted identity theft, fraudulent tax filings, unauthorized credit applications, and sophisticated spear-phishing campaigns designed to exploit their professional standing within the medical community.
As a digital platform handling sensitive professional and financial data, 0WorldOne Inc dba Sermo was bound by robust legal and regulatory obligations to secure its infrastructure against unauthorized intrusion. These duties stem from state consumer protection statutes, the Federal Trade Commission Act, and industry-standard cybersecurity frameworks requiring reasonable security measures to protect stored information. Under these legal standards, the failure to prevent unauthorized network access, properly encrypt sensitive databases, or maintain adequate access controls represents a potential breach of contract and negligence, signaling that the company failed to uphold its fundamental duty of care to its users.
Receiving a data breach notification letter from 0WorldOne Inc dba Sermo serves as formal legal acknowledgement that your sensitive information was compromised due to inadequate security practices. Under modern class action jurisprudence, the receipt of such a notification establishes legal standing to pursue claims against the company, and individuals are not required to demonstrate immediate financial loss or identity theft to participate in litigation. Our law firm is actively investigating this data breach on a contingency fee basis, meaning affected physicians and professionals incur no upfront costs or out-of-pocket expenses, and fees are collected only if a successful recovery is secured.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Guard against tax fraud
File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 0WorldOne Inc dba Sermo.