Forum Communications Company data breach: you may be owed a payment
If a Forum Communications Company letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.
Why you received this letter
Forum Communications Company operates as a prominent media, publishing, and communications enterprise, overseeing a vast network of regional newspapers, digital news platforms, commercial printing operations, and broadcasting outlets. Because of the multi-faceted nature of its business operations, the company functions as a significant repository of sensitive data. It maintains comprehensive human resources, payroll, and benefits administration systems for hundreds of journalists, editors, press operators, and administrative staff across multiple states. Furthermore, its commercial and subscriber networks regularly handle extensive customer databases containing billing details, subscription histories, advertising client profiles, and marketing analytics, making the organization an attractive target for malicious cyber actors seeking high-value personal information. In 2025, Forum Communications Company formally reported a significant data security incident to the Maryland Attorney General, alerting affected individuals and regulatory authorities to an unauthorized compromise of its network infrastructure. While specific technical forensics continue to be analyzed, cyberattacks targeting media and publishing organizations typically involve sophisticated malware deployment, ransomware operations, or unauthorized third-party access to centralized corporate databases. Organizations in this sector often manage sprawling digital architectures that bridge legacy publishing systems with modern cloud-based customer management platforms, creating potential vulnerabilities that cybercriminals exploit to infiltrate internal networks and exfiltrate confidential files. The data compromised during the Forum Communications Company security incident encompasses a broad spectrum of personally identifiable information (PII) belonging to employees, contractors, and consumers. Based on the operational scope of media enterprises, exposed data sets frequently include full legal names, Social Security numbers, dates of birth, banking and direct deposit details, home addresses, and confidential employment or subscription records. The exposure of this information creates severe, long-term risks for victims. Social Security numbers and dates of birth serve as the primary keys for identity theft, enabling bad actors to open fraudulent credit accounts, secure unauthorized loans, or intercept government benefits. Meanwhile, compromised banking and payroll records expose victims to immediate financial fraud, direct deposit diversion, and targeted phishing scams that can take years to fully resolve. Under state data protection statutes, the Maryland Personal Information Protection Act (MPIPA), and general common-law negligence principles, Forum Communications Company had a strict legal duty to implement and maintain reasonable security procedures to safeguard sensitive consumer and employee data from unauthorized access. This statutory framework requires businesses that collect and store PII to utilize robust encryption, advanced threat detection systems, secure access controls, and regular vulnerability assessments. The occurrence of a data breach strongly suggests a failure of these foundational security obligations. When a company experiences an intrusion that successfully siphons sensitive personal records, it frequently indicates that the organization failed to maintain adequate technical safeguards or neglected to remediate known system vulnerabilities in a timely manner. Receiving an official data breach notification letter from Forum Communications Company carries significant legal weight, serving as an admission by the company that your confidential information was compromised due to inadequate security. For affected individuals, this notification establishes the legal standing necessary to participate in a class action lawsuit aimed at holding the company accountable for its security failures. Importantly, under modern consumer protection jurisprudence, victims do not need to prove that they have already suffered actual financial theft or monetary loss to seek compensation; the imminent risk of future identity theft and the time and expense required to monitor one's credit are recognized legal harms. Our firm investigates these cases on a contingency fee basis, meaning affected individuals pay absolutely nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Information the filing reports as involved
- Full Name
- Social Security Number
- Date of Birth
- Mailing Address
- Wage and Compensation Information
- Direct Deposit Account Details
- Email Address
- Subscription and Account History
What to do after the letter
Confirm the notice is genuine
A legitimate Forum Communications Company notice references the specific incident reported to the Maryland Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.
Keep the letter — it is your proof of connection
The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.
Protect your accounts and credit
Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.
Find out whether you have a claim
Whether the Forum Communications Company breach gives you a legal claim depends on the facts. A free, no-obligation case review will tell you where you stand — there is no cost and no commitment to find out.
This page summarizes a data breach reported to the Maryland Attorney General for informational purposes and is attorney advertising. It does not create an attorney-client relationship. DataBreachPayment.com does not provide legal advice through this page.