DataBreachSearch.com

Did 11 have a data breach?

Answer

Yes. 11 reported a data breach to the Indiana Attorney General on January 8, 2026.

View the official filing

What the filing says

Reported to
Indiana Attorney General
Filing date
January 8, 2026
Breach date
October 7, 2025
People affected
Not stated in the filing

Information involved

  • Full Name
  • Email Address
  • Password or Credential Hash
  • Mailing Address
  • Phone Number
  • Purchase and Order History
  • Payment Card Information
  • Account Settings and Preferences

In plain terms

Operating within the digital services and technology sector, 11 functions as a modern software and data solutions provider, handling vast quantities of proprietary consumer data, operational intelligence, and user accounts. Because their business model relies on cloud-hosted infrastructure, application programming interfaces, and large-scale data processing, 11 routinely accumulates and stores highly sensitive personal information, making them an attractive target for cybercriminals seeking to monetize stolen digital assets.

In 2026, 11 formally reported a significant security incident to the Indiana Attorney General, initiating mandatory notification procedures for impacted individuals. While investigations into sophisticated tech sector breaches often reveal complex attack vectors—ranging from credential stuffing and zero-day vulnerabilities to third-party vendor compromises and sophisticated ransomware deployments—the incident underscores systemic vulnerabilities in how digital service providers secure their internal perimeters and client-facing databases against unauthorized intrusion.

The breach exposed a wide array of sensitive consumer and employee data, which typically includes full names, email addresses, password hashes, physical mailing addresses, and transaction or communication histories. Exposure of these credentials creates an immediate and severe risk of credential-stuffing attacks across other platforms where victims maintain accounts, while compromised contact and purchase histories facilitate highly targeted phishing campaigns, financial fraud, and secondary identity theft that can plague victims for years.

As a technology company handling consumer data, 11 was bound by stringent legal obligations under state data protection statutes, the Federal Trade Commission Act, and industry-standard security frameworks to implement robust administrative, physical, and technical safeguards. The occurrence of a widespread data breach strongly indicates a failure to maintain reasonable security procedures, such as failing to enforce multi-factor authentication, neglecting timely software patching, or failing to properly monitor network traffic for anomalous exfiltration activities.

Receiving a data breach notification letter from 11 is a formal admission that your private information was compromised due to corporate negligence, and it establishes the legal standing necessary to participate in a class action lawsuit. Under modern consumer privacy jurisprudence, victims do not need to prove that financial loss has already occurred to seek legal redress; the increased risk of future identity theft is legally cognizable harm. Our firm is currently investigating potential claims against 11 on a contingency fee basis, meaning there are never any out-of-pocket costs or fees unless we successfully recover compensation on your behalf.

Commonly recommended next steps

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Secure your online accounts

    Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Indiana

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with 11.