Reported to the IN Attorney General on March 31, 2026.
IN residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.
Check My Rights →Clarity Telecom LLC dba Bluepeak was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on March 31, 2026. The breach or discovery date reported in the filing is December 11, 2025.
Clarity Telecom LLC, operating under the trade name Bluepeak, is a regional broadband and telecommunications provider delivering high-speed fiber-internet, television, and digital phone services to residential and commercial customers across multiple states, including Indiana. Because modern telecommunications companies function as critical digital infrastructure, Bluepeak collects and centralizes vast quantities of sensitive consumer data to facilitate account creation, service provisioning, automated billing, and ongoing customer support. This trove of information typically includes government-issued identification details, banking and credit card data for recurring auto-payments, extensive credit history checks for new subscribers, and detailed network usage logs. Consequently, the operational footprint of a telecommunications provider makes it a high-value target for malicious cyber actors seeking to exploit centralized data repositories. In 2026, Clarity Telecom LLC dba Bluepeak reported a significant data security incident to the Indiana Attorney General, highlighting vulnerabilities within its digital infrastructure. While the exact vector of the compromise—whether a sophisticated ransomware deployment, an unauthorized intrusion into backend database servers, or a vulnerable third-party vendor integration—continues to be scrutinized, incidents of this magnitude in the telecommunications sector invariably point toward systemic failures in network segmentation, access controls, and active threat monitoring. Telecommunications networks handle massive influxes of operational data daily, and a failure to maintain robust perimeter defenses or properly patch legacy systems can allow unauthorized parties to infiltrate internal servers and harvest sensitive consumer files undetected for extended periods. The breach compromised a wide array of Personally Identifiable Information (PII) and financial records, exposing victims to severe, long-term risks. Exposed data fields commonly include full legal names, dates of birth, Social Security numbers, home mailing addresses, encrypted or plaintext account credentials, and banking or credit card details utilized for monthly billing. The exposure of Social Security numbers and financial account information creates an immediate and acute danger of identity theft, fraudulent credit card applications, unauthorized loan openings, and full financial account takeover. Unlike transient password compromises that can be resolved with a simple reset, permanent identifiers like Social Security numbers cannot be changed, leaving affected individuals vulnerable to ongoing fraudulent exploitation for years to come. As a commercial entity collecting and storing sensitive consumer data, Clarity Telecom LLC dba Bluepeak had clear legal obligations under state and federal consumer protection frameworks, including the Federal Trade Commission Act, which mandates reasonable and appropriate data security practices. Companies that collect high-risk identifiers are legally obligated to implement robust administrative, technical, and physical safeguards—such as multi-factor authentication, rigorous encryption standards, regular vulnerability assessments, and comprehensive employee cybersecurity training. The occurrence of a widespread data breach strongly indicates a failure to uphold these standard industry practices, potentially breaching implied contracts of safe data custody and violating state consumer protection statutes that prohibit deceptive and unfair business practices. Receiving an official data breach notification letter from Clarity Telecom LLC dba Bluepeak serves as formal legal confirmation that your confidential personal information was compromised due to inadequate security measures. Under established legal precedents, the receipt of such a notification establishes the concrete legal standing necessary to participate in a class action lawsuit and seek financial compensation for the distress, risk, and remedial expenses incurred. Significantly, affected individuals do not need to prove that actual financial theft or identity fraud has already occurred to file a claim; the increased risk of future harm and the time and money spent on credit monitoring are recognized injuries under the law. Our firm is prepared to investigate these matters on a strict contingency fee basis, meaning you pay absolutely nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Based on the data types reported in this filing, affected individuals face the following specific risks:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Under the Indiana data breach notification law, you may have a legal claim against Clarity Telecom LLC dba Bluepeak if any of the following apply:
Applicable law: This breach was reported under the Indiana data breach notification law, which establishes your right to seek damages from Clarity Telecom LLC dba Bluepeak.
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Clarity Telecom LLC dba Bluepeak does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Clarity Telecom LLC dba Bluepeak during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Clarity Telecom LLC dba Bluepeak?
Read our dedicated guide — what the letter means and exactly what to do.
If you were affected by the Clarity Telecom LLC dba Bluepeak data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.
Source: State Attorney General filing, IN
View Official AG Filing →Clarity Telecom LLC dba Bluepeak breach?
Free case review · No fee unless you win