Cyberscout Data Breach Letter: What It Means and How to Verify It
If a letter or email mentioning Cyberscout, or an envelope marked “c/o Cyberscout,” showed up in your mail, the company itself is real: it's a data-breach and identity-protection brand owned by TransUnion, hired by an organization that had your information to notify you. It is not a lawsuit and not a check — it's a notice offering free credit monitoring, usually with about 90 days to enroll using a code printed in the letter. A separate class-action settlement notice can follow years later if the same breach ends up in court; this page explains both and how to tell them apart.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Is Cyberscout?
Cyberscout is a data-breach response and identity-protection brand — in TransUnion's own materials and in breach letters it's described as “Cyberscout, a TransUnion company,” not as a stand-alone corporation with public filings we were able to verify. TransUnion announced its agreement to acquire Sontiq for $638 million on October 26, 2021; that announcement lists Sontiq's brands as “IdentityForce, Cyberscout and EZShield.” In practice, when an organization discovers a data breach, it can hire Cyberscout to draft the notification letters, run the mailing and enrollment portal, staff a call center, and deliver the credit-monitoring and identity-theft-protection services offered to the people affected — that is the entire relationship. We could not verify Cyberscout's current legal entity name, its state of incorporation, or a present-day standalone office address; the brand now sits inside TransUnion, headquartered in Chicago, Illinois.
Case Details
Cyberscout doesn't have one public consumer address the way a settlement administrator does — it mails on behalf of whichever organization hired it, using a P.O. box tied to that mailing run. As archived on October 22, 2019 — before the Sontiq/TransUnion acquisition — cyberscout.com listed a Scottsdale, Arizona office (7580 N. Dobson Rd., Suite 201, Scottsdale, AZ 85256) and a main switchboard, 1-888-682-5911 (TTY 1-866-989-0389); we found no current, independently verified street address or general phone number. Two return addresses appear on breach letters we verified directly against samples filed with the California Attorney General: “Select Education Group, Inc., c/o Cyberscout, PO Box 1286, Dearborn, MI 48120-9998” (letter dated March 20, 2024), and “c/o Cyberscout, P.O. Box 3826, Suwanee, GA 30024” (from a letter for the Oakland Museum of California, dated November 12, 2025). Both P.O. boxes are mail-merge fields: the same “c/o Cyberscout” return-address structure, filled in with a different client name each time, turns up in other breach-notification filings we found referenced in state government archives — including Massachusetts, South Carolina, and Montana — though we weren't able to open every one of those PDFs directly to confirm their contents. The enrollment portal printed in the letters is bfs.cyberscout.com/activate; TransUnion's brand page is at transunion.com/cyberscout. There's no single consumer hotline for “Cyberscout” — each breach letter carries its own toll-free number.
Why Did I Get a Letter From Cyberscout?
How to Tell a Real Cyberscout Notice From a Scam
Five checks, based on what we found in the letters filed with regulators: (1) It names a specific organization you can independently confirm had a breach — search the organization's name plus “data breach,” or check a state attorney general's breach-notification list; a letter naming no organization at all is a red flag. (2) Enrolling is free — the portal is bfs.cyberscout.com/activate, and it only ever asks you to verify your own identity, never to pay anything or hand over a bank login. (3) It gives you a unique enrollment code tied to a real deadline (commonly 90 days from the letter's date, or a fixed date printed in the letter) — a code that “expires in 24 hours” or arrives only by text is not how these letters work. (4) The letter is signed by the breached organization, not by “Cyberscout” as if Cyberscout itself were suing or paying you. (5) When in doubt, don't click a link in an email or text — type bfs.cyberscout.com/activate into your browser yourself, or call the phone number printed on the paper letter, not one texted to you. We could not find any official FTC or state attorney-general warning that names Cyberscout impersonation specifically, but the general rule from the U.S. Postal Inspection Service applies here as it does to any mailed notice: any offer that asks for payment first, or for information a legitimate notice would not need, is probably a scam.
What Enrolling Actually Gets You
What Happens After a Cyberscout Letter Arrives
- 1
1. The Notification Letter Arrives
The letter arrives on the breached organization's own letterhead, not Cyberscout's — for example, a sample notice for <strong>Select Education Group, Inc.</strong> (covering the Institute of Technology, National Holistic Institute, Bauman College, Fremont University, and Arch USA) is dated <strong>March 20, 2024</strong>, and a sample for the <strong>Oakland Museum of California</strong> is dated <strong>November 12, 2025</strong>. Both were filed with the California Attorney General as required breach-notification samples. The envelope carries the “c/o Cyberscout” return address; the letter inside explains what happened and what data was involved.
- 2
2. You Enroll With Your Unique Code
Using the code printed only in your copy of the letter, you go to bfs.cyberscout.com/activate and verify your identity. The Select Education Group letter gave recipients 90 days from the date of the letter to do this; the Oakland Museum of California letter instead printed a fixed cutoff — “the deadline to enroll is February 12, 2026” — a window that, for that specific mailing, has since closed. Whichever format your own letter uses, the code stops working after its stated deadline.
- 3
3. Monitoring and Insurance Coverage Begin
Once enrolled, you get 12 or 24 months (the letter states which) of credit monitoring and identity-theft protection, plus the <strong>$1,000,000 identity-theft insurance policy</strong>, run by Cyberscout through Identity Force, a TransUnion company. This runs quietly in the background — there's nothing further to file or claim.
- 4
4. You're Alerted If Something Looks Wrong
If monitoring flags suspicious activity tied to your identity, Cyberscout's fraud-assistance and remediation service is the point of contact for help — the same team the letters describe as handling “fraud assistance and remediation services.” Credit freezes and fraud alerts, covered in the letter's accompanying reference guide, are additional steps you can take yourself regardless of whether you enroll.
- 5
5. A Lawsuit or Settlement, If One Happens, Comes Separately — Later
A Cyberscout breach letter is not a class-action notice and creates no court case by itself. If the breach later leads to litigation that settles, Federal Rule of Civil Procedure 23(c)(2)(B) requires that a <strong>separate</strong> settlement notice — sent by a court-appointed administrator, not Cyberscout — name the case, the class definition, and your rights, and that notice would typically arrive <strong>years</strong> after this one. See our <a href="/data-breach-settlement-calculator">data breach settlement calculator</a> if you're trying to figure out whether a specific breach has reached that stage.
Scam Alert: Fake Breach and Monitoring Letters
We could not find any official FTC or state attorney-general warning naming Cyberscout impersonation specifically as of September 2, 2026. That doesn't mean fraudsters ignore it — breach notifications and “free monitoring” offers are widely imitated in general — so the same structural checks that apply to any mailed notice apply here:
Any Request to Pay
The verified Cyberscout letters ask for no money and no bank information at any point — enrollment is free and only asks you to confirm your own identity. The U.S. Postal Inspection Service's rule of thumb applies directly: “any offer that requires a payment first … is probably a scam.” A page, call, or text claiming to be Cyberscout that asks for a credit card, gift cards, or a bank login is not the real thing.
Urgency Around a Breach You Can't Confirm
A real letter names the organization that was breached, and you can check independently — through the company's own site, news coverage, or a state attorney general's breach-notification archive — that an incident actually happened. A text or call demanding immediate action over a breach with no named organization, no incident you can verify, and no printed code is phishing, not a Cyberscout notice.
A Lookalike Enrollment Link
The verified enrollment address is bfs.cyberscout.com/activate. Type it yourself instead of clicking a link in an email or text, and check that the address matches exactly — a misspelled or extra-word domain is the standard tell for a fake enrollment page. If you're unsure, call the phone number printed on your paper letter rather than one texted or emailed to you.
Cyberscout Data Breach Letter FAQ
Is Cyberscout legit?
Yes, as a brand. Cyberscout provides breach-notification and identity-monitoring services and is described in TransUnion's own materials and in breach letters as “Cyberscout, a TransUnion company,” following TransUnion's October 26, 2021 agreement to acquire its parent, Sontiq. We verified its return addresses and letter format directly against sample notices filed with the California Attorney General. We could not verify Cyberscout's legal entity name or a current standalone address, since it now operates as a brand inside TransUnion.
Why is Cyberscout contacting me?
Because an organization that had your personal information — not Cyberscout itself — experienced a data breach or security incident and hired Cyberscout to send the required notification letters and run the monitoring enrollment on its behalf. You didn't need to sign up for anything to receive this letter.
Is this the same as a class-action settlement notice?
No — a common mix-up, and an important one. A Cyberscout letter is a data-breach notification: it arrives weeks to months after a breach, is signed by the breached organization itself, names no court and no case number, and offers free monitoring with an enrollment code. A class-action settlement notice is different: it arrives, if it happens at all, years later, comes from a court-appointed settlement administrator rather than the breached company, and under Federal Rule of Civil Procedure 23(c)(2)(B) must state the case, the class definition, your claims, your right to be excluded, and the binding effect of a judgment. Neither type of letter ever asks you for money. Getting a Cyberscout letter does not mean a lawsuit or settlement exists yet — see our data breach settlement calculator if you want to check on a specific breach.
Does Cyberscout pay me any money?
No. This letter offers free credit monitoring, identity-theft protection, and a $1,000,000 identity-theft insurance policy if identity theft actually happens to you — it isn't a cash payment for having been part of the breach. If you're looking for a settlement payout, that would be a separate, later notice from a court-appointed administrator, not this letter.
Is there one phone number for Cyberscout?
No. The archived 2019 cyberscout.com site listed a general switchboard, 1-888-682-5911 (TTY 1-866-989-0389), but we could not confirm this is still active today. Each individual breach letter prints its own dedicated toll-free number — for example, 1-833-961-6732 on the Select Education Group letter and 1-800-405-6108 on the Oakland Museum of California letter. Use the number printed on your own letter.
How do I check my enrollment status?
There's no claim number to look up, since this isn't a settlement. Go to bfs.cyberscout.com/activate and use the unique code from your letter to enroll or confirm you're already enrolled, or call the toll-free number printed on your specific letter.
I never did business with the company that sent this letter — why did I get it?
Breach notifications go out based on whose data was actually in the affected system, not who has a direct relationship with the sender. That can include former patients, students, employees, job applicants, or customers of a vendor the breached organization used — so receiving a letter from an organization you don't recognize by name doesn't make it fake.
What does “c/o Cyberscout” on my envelope mean?
It means the named organization — the one whose data was breached — used Cyberscout to print, mail, and manage enrollment for the notice, rather than handling it in-house. The address is real: we verified “Select Education Group, Inc., c/o Cyberscout, PO Box 1286, Dearborn, MI 48120-9998” on a letter dated March 20, 2024, and “c/o Cyberscout, P.O. Box 3826, Suwanee, GA 30024” on a letter for the Oakland Museum of California dated November 12, 2025, both filed with the California Attorney General. The same “c/o Cyberscout” format is a mail-merge field filled in with a different client name and P.O. box for each breach — it is not a bill and not a settlement check, and enrolling in the monitoring it offers costs nothing.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
What Is a Settlement Administrator?
Who appoints them, what they can and cannot do, and the firms whose names show up on envelopes
Return to Kroll — Is That Letter Legit?
The most-searched administrator envelope, explained
Phoenix Settlement Administrators
Same question, California administrator
Data Breach Settlement Hub
200+ active and settled data breach cases tracked