DataBreachPayment.com
MonitoringIndiana AG filing · May 8, 2026

The 810New Congol LLC dba New Congoleum Data Breach: Incident Facts and Free Case Review

810New Congol LLC, doing business as New Congoleum, operates as a prominent enterprise in the manufacturing, flooring supply, and commercial distribution sectors. In the course of managing its extensive supply chain, manufacturing operations, human resources, and business-to-business commerce, the company routinely collects, processes, and stores vast quantities of sensitive non-public personal information. This repository includes extensive personnel records, payroll data, vendor banking details, employee tax documents, and proprietary corporate files. Because manufacturing and industrial enterprises must maintain deep administrative and operational records to coordinate nationwide distribution and workforce management, they represent high-value targets for malicious actors seeking access to confidential personally identifiable information.

Received a 810New Congol LLC dba New Congoleum notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
Indiana
Breach date
March 24, 2026
Reported
May 8, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Mailing Address
  • Wage and Compensation Information
  • Tax Return Information
  • Direct Deposit Account Details
  • Employee ID Number

In 2026, New Congoleum reported a significant cybersecurity incident to the Indiana Attorney General. While the full technical scope continues to be evaluated, security incidents affecting industrial manufacturing firms typically involve sophisticated cyberattacks such as ransomware deployments, unauthorized intrusions into internal corporate networks, or third-party vendor compromises. These attacks often exploit vulnerabilities in legacy IT infrastructure, remote desktop protocols, or corporate email systems, allowing unauthorized third parties to infiltrate administrative environments and exfiltrate sensitive files before detection.

The data compromised in incidents of this nature typically includes full legal names, Social Security numbers, dates of birth, home addresses, banking and direct deposit details, wage and compensation records, and tax identification information. The exposure of this specific blend of data creates severe, immediate risks for affected individuals. Social Security numbers and dates of birth form the core components required for identity theft, opening fraudulent financial accounts, and perpetrating tax refund fraud. Furthermore, compromised banking details expose victims to direct financial account takeover and unauthorized fund transfers, leaving workers and stakeholders vulnerable to prolonged financial disruption.

As an entity handling sensitive employee and business data within the state, New Congoleum is bound by foundational legal obligations to implement and maintain reasonable data security measures. Under the Indiana Disclosure of Security Breach Law, as well as common-law duties of care, companies operating within the state are required to safeguard stored personal information against unauthorized access, destruction, modification, or disclosure. A security breach of this magnitude strongly indicates potential failures in network segmentation, multi-factor authentication enforcement, timely patch management, or continuous intrusion detection, raising serious questions regarding whether the company fulfilled its legal mandates to protect sensitive data.

Receiving a data breach notification letter from New Congoleum serves as formal legal notice that an individual's private information was compromised due to corporate security failures. Under modern standing jurisprudence, the receipt of such a notice and the resulting imminent risk of identity theft confer the necessary legal standing to participate in class action litigation. Affected individuals are not required to demonstrate actual financial loss to seek legal recourse. Our firm evaluates these data breach matters on a contingency fee basis, meaning clients pay absolutely no upfront costs or out-of-pocket legal fees, and we only recover compensation if a successful resolution or recovery is achieved on behalf of the class.

Received the 810New Congol LLC dba New Congoleum notification letter? The 810New Congol LLC dba New Congoleum case file tracks this filing.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Guard against tax fraud

    File your tax return as early as possible and consider requesting an IRS Identity Protection PIN so no one can file a fraudulent return in your name.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Indiana Attorney General filing

Related data breach cases