Investigation Open·Data Breach

C2M LLC dba Click2Mail Data Breach Case

State
IN
Filed
Sep 15, 2026
Data Types
8 types
Records
Not disclosed

If you were affected, free legal review is available — no obligation.

Free Review →
Filing Window Open

Received a Notice Letter?

Cases are filed first-come, first-served. Submit now for a free attorney review — no cost, no obligation.

Start typing to find a matching case, or enter a company not yet listed.

Attach a copy of your data breach notification letter. Accepted: PDF, JPG, PNG — max 10 MB.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

You Have a Legal Claim

Learn how to participate in the class action and what compensation you may be entitled to.

Join the Class Action →

Received a notice letter?

Use our verification tool to confirm your letter matches this official AG filing.

Verify My Notice Letter

This case file references a public filing made with the state filing in IN. This website is not affiliated with, endorsed by, or operated by any state government agency.

Quick Facts

State Filed
IN
Date Reported to AG
Sep 15, 2026
Date of Breach
Jul 6, 2026
Records Affected
Not disclosed
Status
Investigation Open
Last Updated
Oct 5, 2026
Data Types Exposed
Full NameMailing AddressEmail AddressPhone NumberFinancial Account InformationDocument Content and MetadataInternal Client ID NumbersTransaction History

The Breach — What We Know

C2M LLC dba Click2Mail was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on September 15, 2026. The breach or discovery date reported in the filing is July 6, 2026.

From the AG filing description

C2M LLC dba Click2Mail operates as a prominent digital printing and direct mail automation provider, serving businesses, legal practices, healthcare organizations, financial institutions, and government agencies nationwide. The company specializes in streamlining document production, mailing fulfillment, and direct marketing campaigns through robust cloud-based software and automated processing infrastructure. Because of the nature of its operations, Click2Mail routinely receives, ingests, and processes vast quantities of highly sensitive, unmasked client data—including customer lists, billing files, tax documents, legal notices, and personalized mailing lists containing confidential personal information uploaded by corporate clients for physical and digital distribution. In 2026, C2M LLC dba Click2Mail reported a significant security incident to the Indiana Attorney General, triggering mandatory notification protocols for impacted individuals. While the exact technical vectors of the intrusion continue to be evaluated, security events within the document processing and direct mail sector frequently involve unauthorized access to cloud storage environments, compromise of third-party vendor integrations, sophisticated phishing campaigns directed at administrative personnel, or exploitation of vulnerabilities within automated file-transfer and portal systems. These incidents can allow malicious actors to quietly infiltrate internal networks, dwell undetected, and exfiltrate substantial archives of client-provided data before discovery. Preliminary indications suggest that the compromised data files likely contained a dangerous amalgamation of personally identifiable information, including full names, mailing addresses, email addresses, phone numbers, and in many instances, sensitive financial identifiers, account numbers, or confidential document contents processed on behalf of corporate clients. The exposure of this information exposes victims to severe, long-term risks. Mailing addresses combined with names and transactional details provide cybercriminals with the foundational building blocks required to execute targeted phishing schemes, mail-fraud operations, and sophisticated identity theft. When confidential document text or financial records are intercepted, victims face heightened threats of unauthorized account access, fraudulent credit applications, and synthetic identity creation that can persist for years. As an entity handling sensitive consumer and corporate data, C2M LLC dba Click2Mail is bound by stringent legal obligations under state data protection statutes, common law duties of care, and applicable federal regulatory frameworks such as the Federal Trade Commission Act, which mandates reasonable and appropriate data security practices. Under these legal standards, companies that collect and process third-party data have an affirmative duty to implement robust administrative, technical, and physical safeguards—including multi-factor authentication, rigorous network monitoring, routine vulnerability assessments, and strict access controls. The occurrence of a data breach of this magnitude strongly suggests potential failures in these foundational security protocols, raising serious questions about whether Click2Mail fulfilled its legal and ethical duties to protect sensitive consumer information. Receiving a formal data breach notification letter from C2M LLC dba Click2Mail serves as official confirmation that your personal information was compromised due to corporate security failures. Legally, this notification establishes the necessary standing to participate in class action litigation aimed at holding the company accountable for its negligence. Plaintiffs in data breach lawsuits can seek remedies for out-of-pocket losses, compensation for time spent mitigating identity theft risks, and the establishment of court-mandated credit monitoring services, all without needing to demonstrate immediate financial loss. Our firm handles these complex class action cases on a strict contingency fee basis, meaning you pay absolutely nothing out of pocket and owe no legal fees unless we successfully recover compensation on your behalf.

Who Was Impacted?

Under the Indiana data breach notification law, you may have a legal claim against C2M LLC dba Click2Mail if any of the following apply:

  • You received a written data breach notification letter from C2M LLC dba Click2Mail
  • You are or were a customer, patient, or employee of C2M LLC dba Click2Mail
  • Your information was held by C2M LLC dba Click2Mail in IN
  • Your bank or payment card data was potentially exposed

Exposed Data — What's at Risk

Based on the data types reported in this filing:

SIM Swap & Vishingmedium risk

Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.

What the Law Gives You

Common categories of compensation in data breach class actions

Time & Inconvenience

Courts recognize that the time spent monitoring accounts, placing credit freezes, and dealing with the aftermath of a breach has real economic value. This category of damages is recoverable even without direct financial loss.

Financial Losses & Fraudulent Charges

Direct financial losses resulting from the breach — unauthorized charges, fraudulent transfers, or fees incurred through fraud — are recoverable as compensatory damages. Banks may reverse some charges; a class action recovers the remainder and associated costs.

Emotional Distress

Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.

Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against C2M LLC dba Click2Mail?

No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

My financial account data was exposed. Can the bank recover my losses?

Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.

Is there a deadline to file a claim?

State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.

What if C2M LLC dba Click2Mail offered me free credit monitoring after the breach?

Accepting free credit monitoring from C2M LLC dba Click2Mail does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

Do I need to have received a notice letter to be eligible?

Not necessarily. Many data breach victims are never notified directly. If your personal information was held by C2M LLC dba Click2Mail during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.

How long does a data breach class action lawsuit take?

Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.

Applicable State Law

This breach was reported under the Indiana data breach notification law, which mandates notification and establishes your right to seek damages.

Case review window ends November 10, 2026 — review your letter.

Review Your Letter →

C2M LLC dba Click2Mail breach?

Free case review · No fee unless you win

Call Now