Reported to the NH Attorney General on April 11, 2025.
NH residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.
Check My Rights →Sirva, Inc. was the subject of a data breach notification filed with the NH Attorney General. The AG filing was recorded on April 11, 2025.
Sirva, Inc. is a globally recognized leader in relocation services, moving solutions, and corporate global mobility management. Operating at the intersection of corporate enterprise and personal transition, the company orchestrates complex relocations for multinational corporations, government agencies, and individual employees. Because of its core business operations, Sirva routinely collects, processes, and stores an immense volume of deeply sensitive personal, financial, and logistical data. This includes exhaustive dossiers on transferring employees and their families, encompassing relocation expense receipts, banking and payroll details for reimbursement, passport and visa documentation, Social Security numbers, home addresses, and detailed employment histories required to coordinate international and domestic moves. The 2025 security incident reported to the New Hampshire Attorney General highlights the severe cyber vulnerabilities inherent in managing centralized enterprise mobility platforms. While exact forensic findings continue to emerge, data breaches affecting relocation and logistics firms typically involve sophisticated network intrusions, unauthorized access to legacy databases, or compromised third-party vendor systems. Because relocation service providers integrate tightly with corporate human resources systems, global supply chains, and financial institutions, an unauthorized actor who breaches their perimeter can potentially gain persistent access to sprawling repositories of unencrypted or inadequately secured employee records. The exposure of this magnitude places affected individuals at immediate and severe risk of identity theft, financial fraud, and targeted cyberattacks. Relocation dossiers often contain a comprehensive suite of Personally Identifiable Information (PII) that enables malicious actors to bypass standard authentication protocols. When core identifiers such as Social Security numbers, dates of birth, banking details, and government-issued identification numbers are compromised together, cybercriminals can easily open fraudulent credit accounts, execute unauthorized wire transfers, intercept tax filings, and engage in sophisticated social engineering schemes directed at both employees and their corporate employers. Under state and federal data protection mandates, including the New Hampshire Regulation of Certain Information Brokers and the broader statutory frameworks governing commercial data security, companies like Sirva, Inc. have a strict legal duty to implement and maintain reasonable administrative, physical, and technical safeguards to protect sensitive PII. The occurrence of a data breach of this scale strongly indicates a failure to adhere to these foundational standards, potentially reflecting vulnerabilities such as insufficient network segmentation, lax multi-factor authentication controls, or delayed patching of known system weaknesses. These shortcomings form the legal foundation for holding the company accountable for negligence and breach of implied contract. For individuals who have received an official data breach notification letter from Sirva, Inc., the communication serves as a formal legal acknowledgment that your private information was compromised due to corporate security failures. Legally, this notification establishes the necessary standing to participate in a class action lawsuit aimed at securing compensation and compelling systemic security reforms. Crucially, affected individuals do not need to demonstrate actual financial loss to pursue claims, as the increased risk of future identity theft and the costs associated with proactive credit monitoring constitute compensable harms. Our firm evaluates these cases on a strict contingency fee basis, ensuring that you pay zero out-of-pocket costs and that we only recover fees if we successfully secure a recovery on your behalf.
Based on the data types reported in this filing, affected individuals face the following specific risks:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Under the New Hampshire data breach notification law, you may have a legal claim against Sirva, Inc. if any of the following apply:
Applicable law: This breach was reported under the New Hampshire data breach notification law, which establishes your right to seek damages from Sirva, Inc..
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under New Hampshire data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Sirva, Inc. does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Sirva, Inc. during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Sirva, Inc.?
Read our dedicated guide — what the letter means and exactly what to do.
If you were affected by the Sirva, Inc. data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.
Source: State Attorney General filing, NH
View Official AG Filing →Sirva, Inc. breach?
Free case review · No fee unless you win