Birdi Inc. Data Breach Exposes Employee Personal Information
Birdi Inc., a Michigan-based digital pharmacy, recently disclosed a data breach that compromised sensitive employee information. On August 12, 2026, an unauthorized individual accessed a Birdi employee’s work email account after the employee opened a malicious file. During the intrusion, the attacker viewed an internal report containing personal data, including names, Social Security numbers, home addresses, telephone numbers, and pay rates.
The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on September 9, 2026, the same day affected individuals were notified. In response, Birdi is providing 18 months of free credit monitoring and identity theft protection through Norton/LifeLock Benefit Solutions. Impacted employees were expected to receive enrollment instructions via email starting September 1, 2026, with existing LifeLock members required to cancel their retail plans before transitioning to the employer-paid benefit.
The company has directed inquiries to [email protected], where compliance, HR, or information security teams will respond. The incident highlights the risks of phishing attacks and the potential exposure of sensitive employee data in corporate breaches.
Source: https://www.claimdepot.com/data-breach/birdi-2026
Birdi cybersecurity rating report: https://www.rankiteo.com/company/birdipharmacy
"id": "BIR1789511268",
"linkid": "birdipharmacy",
"type": "Breach",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Digital Pharmacy',
'location': 'Michigan, USA',
'name': 'Birdi Inc.',
'type': 'Company'}],
'attack_vector': 'Phishing (Malicious File)',
'customer_advisories': 'Affected employees notified via email with enrollment '
'instructions for credit monitoring.',
'data_breach': {'personally_identifiable_information': 'Names, Social '
'Security numbers, '
'home addresses, '
'telephone numbers, '
'pay rates',
'sensitivity_of_data': 'High (PII, SSN, pay rates)',
'type_of_data_compromised': 'Personal Information, Employment '
'Data'},
'date_detected': '2026-08-12',
'date_publicly_disclosed': '2026-09-09',
'description': 'Birdi Inc., a Michigan-based digital pharmacy, recently '
'disclosed a data breach that compromised sensitive employee '
'information. On August 12, 2026, an unauthorized individual '
'accessed a Birdi employee’s work email account after the '
'employee opened a malicious file. During the intrusion, the '
'attacker viewed an internal report containing personal data, '
'including names, Social Security numbers, home addresses, '
'telephone numbers, and pay rates.',
'impact': {'data_compromised': 'Names, Social Security numbers, home '
'addresses, telephone numbers, pay rates',
'identity_theft_risk': 'High',
'systems_affected': 'Employee work email account'},
'initial_access_broker': {'entry_point': 'Employee work email account'},
'lessons_learned': 'Highlights risks of phishing attacks and potential '
'exposure of sensitive employee data in corporate '
'breaches.',
'post_incident_analysis': {'corrective_actions': 'Provision of credit '
'monitoring and identity '
'theft protection; potential '
'employee training on '
'phishing awareness',
'root_causes': 'Phishing attack leading to '
'unauthorized access to employee '
'email account'},
'references': [{'source': 'Massachusetts Office of Consumer Affairs and '
'Business Regulation'}],
'regulatory_compliance': {'regulatory_notifications': 'Reported to '
'Massachusetts Office '
'of Consumer Affairs '
'and Business '
'Regulation'},
'response': {'communication_strategy': 'Notified affected individuals via '
'email; directed inquiries to '
'[email protected]',
'remediation_measures': 'Provided 18 months of free credit '
'monitoring and identity theft '
'protection',
'third_party_assistance': 'Norton/LifeLock Benefit Solutions '
'(credit monitoring and identity theft '
'protection)'},
'title': 'Birdi Inc. Data Breach Exposes Employee Personal Information',
'type': 'Data Breach',
'vulnerability_exploited': 'Employee error (opening malicious file)'}