Uni-Select data breach: you may be owed a payment
If a Uni-Select letter arrived in your mailbox, here is what it means, why you received it, and the free steps you can take right now.
Why you received this letter
Uni-Select operates as a prominent distributor of automotive replacement parts, paint, and refinish products, serving a vast network of commercial customers, repair shops, and independent jobbers across North America. Because of the nature of its enterprise-level operations, supply chain management, and extensive workforce, Uni-Select maintains a massive repository of sensitive information. The company routinely collects and stores deeply personal records concerning its employees, independent contractors, vendors, and commercial clients, including comprehensive human resources files, payroll administration data, tax documentation, and proprietary corporate records necessary to sustain its extensive distribution infrastructure. In 2025, Uni-Select reported a significant data security incident to the Maryland Attorney General, signaling that unauthorized actors may have breached its digital perimeter. While the exact vector and forensic mechanisms of the intrusion are often subject to ongoing investigation during such corporate disclosures, incidents within the automotive distribution and commercial supply chain sectors typically involve sophisticated cyberattacks such as ransomware deployments, unauthorized database access, or vulnerabilities exploited within third-party vendor networks. In many cases, threat actors target these enterprise networks precisely because they house centralized administrative and human resources databases containing high-value personally identifiable information. Preliminary indications and standard industry disclosures suggest that the breach compromised a wide array of sensitive data categories, each carrying severe risks for the affected individuals. Exposed records frequently include full legal names, Social Security numbers, dates of birth, home addresses, direct deposit and banking information, and compensation details. The compromise of Social Security numbers and tax-related documents exposes victims to the immediate and enduring threat of identity theft, fraudulent tax filings, and unauthorized credit applications. Furthermore, leaked banking and direct deposit details create an acute vulnerability for financial account takeover, leaving victims susceptible to unauthorized withdrawals and severe financial disruption. Under applicable state data protection laws, including the Maryland Personal Information Protection Act, as well as overarching federal standards governing corporate data security, Uni-Select had a legal and fiduciary obligation to implement and maintain reasonable security procedures to safeguard sensitive personal information. Organizations that collect and store employee and customer data are legally required to employ robust encryption, multi-factor authentication, network segmentation, and proactive vulnerability management. The occurrence of a successful breach capable of extracting sensitive records strongly indicates a potential failure in these mandated security controls, raising critical questions regarding whether the company fulfilled its legal duty of care. Receiving a data breach notification letter from Uni-Select is a formal acknowledgment by the company that your confidential information was compromised due to their security failures. Legally, the receipt of this notice establishes the concrete injury and legal standing required to participate in a class action lawsuit aimed at holding the company accountable. Affected individuals do not need to wait until they experience actual financial fraud or identity theft to seek legal recourse. Our firm handles these complex data privacy cases on a contingency fee basis, meaning there are never any out-of-pocket costs or fees unless we successfully recover compensation on your behalf.
Information the filing reports as involved
- Full Name
- Social Security Number
- Date of Birth
- Mailing Address
- Wage and Compensation Information
- Tax Return Information
- Direct Deposit Account Details
- Employee ID Number
What to do after the letter
Confirm the notice is genuine
A legitimate Uni-Select notice references the specific incident reported to the Maryland Attorney General and describes which categories of your information were involved. Compare the letter against the public filing before acting on any links or phone numbers it contains.
Keep the letter — it is your proof of connection
The notification letter is the document that ties your personal information to this incident. Keep the original and photograph it. If you later request a case review, this letter is the strongest evidence that you were among the affected individuals.
Protect your accounts and credit
Depending on what was exposed, consider a free credit freeze with all three bureaus, new passwords for reused credentials, and monitoring of financial statements. These steps are free and do not require you to wait for anyone's permission.
Find out whether you have a claim
Whether the Uni-Select breach gives you a legal claim depends on the facts. A free, no-obligation case review will tell you where you stand — there is no cost and no commitment to find out.
This page summarizes a data breach reported to the Maryland Attorney General for informational purposes and is attorney advertising. It does not create an attorney-client relationship. DataBreachPayment.com does not provide legal advice through this page.