AutoAPS and Knights of Columbus: Knights of Columbus Data Breach Exposes Medical Records and SSNs

AutoAPS and Knights of Columbus: Knights of Columbus Data Breach Exposes Medical Records and SSNs

Knights of Columbus Data Breach Exposes Sensitive Member Information

Knights of Columbus, a global Catholic fraternal benefit society offering life insurance and financial services, recently disclosed a data breach stemming from a third-party vendor, AutoAPS, a medical record retrieval services company. The breach was reported to the Massachusetts Office of Consumer Affairs and Business Regulation on August 3, 2026, though the total number of affected individuals across the U.S. remains undisclosed.

AutoAPS detected suspicious network activity on December 25, 2025, and later confirmed the breach to Knights of Columbus on May 4, 2026. The compromised data included personally identifiable information (PII) such as names, addresses, dates of birth, email addresses, phone numbers, Social Security numbers, driver’s license numbers, and financial details as well as protected health information (PHI), including medical records.

In response, Knights of Columbus is providing identity protection services to impacted individuals and has issued guidance on placing security freezes with major credit bureaus (Experian, TransUnion, and Equifax). The breach highlights the risks of third-party vendor vulnerabilities in handling sensitive data.

Source: https://www.claimdepot.com/data-breach/knights-of-columbus-2026

Knights of Columbus cybersecurity rating report: https://www.rankiteo.com/company/knights-of-columbus

AutoAp, Inc. cybersecurity rating report: https://www.rankiteo.com/company/autoap-inc-

"id": "KNIAUT1785947780",
"linkid": "knights-of-columbus, autoap-inc-",
"type": "Breach",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Insurance and Financial Services',
                        'location': 'Global',
                        'name': 'Knights of Columbus',
                        'type': 'Organization'},
                       {'industry': 'Medical record retrieval services',
                        'name': 'AutoAPS',
                        'type': 'Third-party vendor'}],
 'attack_vector': 'Third-party vendor compromise',
 'customer_advisories': 'Guidance on placing security freezes with major '
                        'credit bureaus (Experian, TransUnion, and Equifax)',
 'data_breach': {'personally_identifiable_information': ['Names',
                                                         'Addresses',
                                                         'Dates of birth',
                                                         'Email addresses',
                                                         'Phone numbers',
                                                         'Social Security '
                                                         'numbers',
                                                         'Driver’s license '
                                                         'numbers',
                                                         'Financial details',
                                                         'Medical records'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally identifiable '
                                              'information (PII)',
                                              'Protected health information '
                                              '(PHI)']},
 'date_detected': '2025-12-25',
 'date_publicly_disclosed': '2026-08-03',
 'description': 'Knights of Columbus, a global Catholic fraternal benefit '
                'society offering life insurance and financial services, '
                'recently disclosed a data breach stemming from a third-party '
                'vendor, AutoAPS, a medical record retrieval services company. '
                'The breach exposed personally identifiable information (PII) '
                'and protected health information (PHI) of members.',
 'impact': {'data_compromised': 'Personally identifiable information (PII) and '
                                'protected health information (PHI)',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High'},
 'lessons_learned': 'Highlights the risks of third-party vendor '
                    'vulnerabilities in handling sensitive data',
 'post_incident_analysis': {'root_causes': 'Third-party vendor compromise '
                                           '(AutoAPS)'},
 'references': [{'source': 'Massachusetts Office of Consumer Affairs and '
                           'Business Regulation'}],
 'regulatory_compliance': {'regulatory_notifications': ['Reported to '
                                                        'Massachusetts Office '
                                                        'of Consumer Affairs '
                                                        'and Business '
                                                        'Regulation']},
 'response': {'communication_strategy': 'Public disclosure and advisories to '
                                        'affected individuals',
              'remediation_measures': 'Identity protection services, guidance '
                                      'on security freezes with credit '
                                      'bureaus'},
 'title': 'Knights of Columbus Data Breach Exposes Sensitive Member '
          'Information',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.