IDX Data Breach Notice: Why You Got That Letter — and How to Verify It
An envelope or letter marked “Return to IDX, P.O. Box 989728, West Sacramento, CA 95798-9728” is real — IDX is a data-breach notification and identity-protection vendor that companies hire after a security incident. It is not a settlement, and it does not ask you for money. But because the same three words show up on letters from unrelated companies, it is worth knowing exactly what IDX is, why it has your information, and how to enroll in the free monitoring it offers without falling for a lookalike scam.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Is IDX?
IDX is the trading name of a data-breach notification and identity-protection company, formerly known as ID Experts. In the announcement of its sale, ZeroFox described the business as one that specializes in post-breach forensics, incident response, and regulatory compliance support. IDX does not sue anyone and does not administer class-action settlements — it is hired by a company after a data security incident to mail the notices state law requires and to run the free identity-protection benefit that company is offering. Ownership has changed: IDX became part of ZeroFox when the acquisition was announced December 20, 2021, and then, on November 22, 2024, ZeroFox divested IDX to Kingswood Capital Management, its owner today. We could not verify IDX’s exact legal entity name or incorporation record.
Case Details
IDX’s corporate address is 4145 SW Watson Ave, Suite 400, Beaverton, OR 97005, a Portland, Oregon suburb; a 2026 breach letter also lists a legal/regulatory contact at 5065 Westheimer Rd., Suite 700E, Houston, TX 77056. General customer support was 1-800-939-4170 as of an archived idx.us contact page dated March 7, 2026 (idx.us itself blocks most automated visits, so confirm the number is still current). There is no single consumer hotline — each breach letter prints its own, for example (833) 406-2408 on the 2021 Audi/Volkswagen letter and (844) 814-3163 on the 2026 SitusAMC letter. Enrollment portals live only on idx.us: a client-specific address such as response.idx.us/audivwdataprotect on older letters, or the general app.idx.us/account-creation/protect page since roughly 2025. On the envelope, five verified letters from 2021 through 2026 all return to the same box — P.O. Box 989728, West Sacramento, CA 95798-9728 — with minor wording differences (“C/O IDX,” “Return to IDX:,” or, on the 2026 SitusAMC letter, no “IDX” at all). That box is not Kroll’s — Kroll’s data-breach mail uses P.O. Box 980108 in the same West Sacramento ZIP; see our Kroll notice page if that is the box on your envelope.
Why Did I Get a Letter From IDX?
How to Tell a Real IDX Notice From a Scam
Five checks before you trust — or dismiss — a letter like this: (1) Read the letterhead, not the envelope — the breached company is named and signs the letter; the West Sacramento P.O. box is the return address on IDX mail, and we could not confirm whether that box belongs to IDX itself or to a mailing contractor. (2) Confirm that company’s own breach statement on its own website, typed in by hand, not clicked. (3) Search a public state attorney-general breach archive — California’s list at oag.ca.gov/privacy/databreach/list is where the sample letters cited here are actually filed. (4) Contact IDX only through 1-800-939-4170 or the idx.us domain; real enrollment portals live only at app.idx.us and response.idx.us — a similar-looking different domain is not IDX. (5) No genuine letter asks for a payment, a gift card, cryptocurrency, or your banking login — enrolling costs nothing.
What IDX Actually Offers (It Is Not a Payment)
Breach Notifications IDX Has Mailed
- 1
Audi of America / Volkswagen Vendor Breach (2021)
A vendor breach affecting Audi of America and Volkswagen Group of America customers; notice letter dated June 11, 2021 and filed with the California Attorney General. Offered 24 months of credit and CyberScan monitoring; enrollment deadline September 11, 2021; hotline (833) 406-2408; enrollment at response.idx.us/audivwdataprotect.
- 2
LCS Financial Services (2023)
A breach at this nationwide debt-collection agency produced a notice letter dated October 24, 2023, filed with the California Attorney General — and, in November 2023, the identical letter filed again with the Delaware Attorney General, evidence the same IDX return block is used across states. Enrollment via QR code or response.idx.us/lcs.
- 3
Donaghy Sales LLC (2025)
Notice letter dated December 12, 2025, filed with the California Attorney General, with an enrollment deadline of March 12, 2026 and hotline 1-833-788-9712. This letter uses IDX’s newer generic enrollment portal, app.idx.us/account-creation/protect, rather than a client-specific address.
- 4
SitusAMC Holdings Corporation (2026)
Notice letter dated April 3, 2026, filed with the California Attorney General, offering 24 months of monitoring with an enrollment deadline of July 3, 2026; hotline (844) 814-3163, email SitusAMC@idx.us. Unusually, this letter’s return block drops the word IDX entirely and prints only the P.O. box — the same address, the same purpose.
- 5
What IDX Cannot Do
IDX is a vendor the breached company hires — it cannot undo a breach and does not pay compensation for one. If a breach later becomes a class-action settlement, that money comes years afterward from the breached company or its insurer, distributed by a separate, court-appointed administrator, not IDX. IDX also cannot extend the enrollment deadline on your specific letter — call before that date if you want the free coverage. We could not verify what legal entity operates behind the “IDX” trading name, and found no FTC or state attorney-general warning naming IDX-impersonation scams specifically — which does not prove none exist, only that none is documented in what we checked.
Scam Alert: Spotting a Fake IDX-Style Letter
IDX’s own letters carry blunt warnings, and the U.S. Postal Inspection Service publishes general rules that apply to any unexpected mail like this. Three patterns to watch for:
Requests for sensitive information by phone or email
The 2021 Audi/Volkswagen letter states it plainly: “We will never request sensitive personal information (such as credit card numbers, Social Security numbers, or passwords) through email or telephone communications,” and warns recipients to “be cautious when opening links or attachments from unsolicited third parties.” If someone claiming to be IDX asks you to confirm that kind of detail, hang up or do not reply.
Any request for payment
The U.S. Postal Inspection Service’s general mail-fraud guidance applies directly here: “Don’t give your financial information — Social Security number, credit card, or bank account numbers — to anyone you don’t know and don’t trust,” and “Any offer that requires a payment first…is probably a scam.” Enrolling in IDX’s free monitoring never costs anything — a request for a fee, a gift card, or cryptocurrency is not a genuine IDX communication.
Links, calls, or letters that do not match idx.us
The real enrollment portals live only at app.idx.us and response.idx.us; the real general support number is 1-800-939-4170. Type addresses into your browser yourself rather than clicking a link in an email or text, and verify an unexpected letter’s claimed hotline against the number on the breached company’s own official breach page before you call it.
IDX Data Breach Notice FAQ
Is IDX legit?
Yes. IDX is the trading name of a data-breach notification and identity-protection vendor companies hire after a security incident — not a scam operation. It has been owned by Kingswood Capital Management since November 22, 2024, after roughly three years as part of ZeroFox (acquisition announced December 20, 2021). We could not verify IDX’s exact legal entity name or incorporation record; idx.us blocks most automated visits, so this page relies on IDX’s own breach letters, ZeroFox’s press releases, and an archived idx.us snapshot dated March 7, 2026.
Why is IDX contacting me if I never signed up for anything?
Because IDX is not working from a sign-up list — it is working from the records of a company you already had a relationship with. When that company reports a data security incident, state law requires it to notify everyone whose information was involved, and many companies outsource that mailing, along with a free monitoring offer, to a vendor like IDX.
Is this the same thing as a class-action settlement check?
No — common mix-up. A settlement notice names a court case, points to a case-specific settlement website, and usually carries a Claim ID or Class Member ID; it can lead to a payment. An IDX breach letter carries an Enrollment Code, not a claim ID, offers free monitoring, and involves no money and no court case. If the breach behind your letter ever turns into a settled lawsuit, that arrives later as a separate notice, typically from a different, court-appointed administrator.
How do I actually get the free monitoring IDX is offering?
Use the Enrollment Code on your letter at the address it names — a client-specific page such as response.idx.us/audivwdataprotect on older letters, or the general app.idx.us/account-creation/protect page since roughly 2025 — or call the toll-free number on that letter. Enroll before its deadline; after that date the free coverage described in the letter may no longer be available to activate.
Is there one phone number for IDX?
IDX’s general line was 1-800-939-4170 as of an archived contact-page snapshot dated March 7, 2026. For a specific breach, use the number on your own letter instead — each notice prints its own, such as (833) 406-2408 on the Audi/Volkswagen letter or (844) 814-3163 on the SitusAMC letter. Never use a number from an unsolicited text or email.
How do I check whether the breach described in my letter is real?
Look up the breached company’s own breach statement on its own website — type the address in yourself — and search a state attorney-general breach archive, such as California’s at oag.ca.gov/privacy/databreach/list, where the sample letters referenced here are actually filed. If neither the company nor the incident turns up independently, treat the letter with caution before enrolling or calling any number it lists.
I found an old IDX letter I never opened — is the code inside still worth using?
Maybe, but check rather than assume. IDX letters warn recipients not to discard them because the enrollment code cannot easily be replaced, and every letter reviewed here carries a specific deadline — some as short as three months after the letter date. If that date has passed, call the number on the letter, or IDX’s general line 1-800-939-4170, and ask whether enrollment is still possible.
What does “Return to IDX, P.O. Box 989728, West Sacramento, CA 95798-9728” on my envelope mean?
It means IDX mailed the letter on behalf of a company whose data was breached — the address is real, verified on letters from four companies between 2021 and 2026: Audi of America/Volkswagen, LCS Financial Services (filed in both California and Delaware), Donaghy Sales, and SitusAMC Holdings, whose letter drops the word “IDX” and prints only the box number. It is not a settlement check and there is nothing to claim. Inside is a notice on the breached company’s own letterhead, plus an offer of free identity-protection services you activate with the Enrollment Code before a specific deadline. One wrinkle: West Sacramento, CA 95798 is also home to a different breach-mail box used by Kroll — P.O. Box 980108, not IDX’s 989728. Same ZIP, two unrelated vendors; if your envelope reads 980108, see our Kroll settlement administration page instead.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
What Is a Settlement Administrator?
Who appoints them, what they can and cannot do, and the firms whose names show up on envelopes
Return to Kroll — Is That Letter Legit?
The most-searched administrator envelope, explained
Phoenix Settlement Administrators
Same question, California administrator
Data Breach Settlement Hub
200+ active and settled data breach cases tracked