Description

Cornwell Quality Tools, a prominent supplier of automotive and industrial tools, has confirmed a significant data breach that exposed the sensitive personal information of 103,782 individuals. The cybersecurity incident occurred on December 12, 2024, when unauthorized actors infiltrated the company’s computer network. The breach resulted in the compromise of a wide range of data, including names, Social Security numbers, medical records, and financial account details raising serious concerns about potential identity theft and fraud risks for those affected. Following the breach, Cornwell launched a comprehensive internal investigation to assess the extent of the intrusion and secure their systems. However, official notification letters were not sent to affected individuals until September 4, 2025 nearly nine months after the breach took place. These letters outlined the types of personal information that were compromised and provided recommendations for protective steps, such as credit monitoring and fraud alerts. While the delay in notification adheres to typical investigative procedures, it also underscores the complexities of responding to large-scale cybersecurity incidents involving protected health and financial data. In response to the breach, legal firm Goldenberg Schneider, LPA announced an investigation on behalf of affected individuals. The firm is offering support to those who received notification letters and may be entitled to legal recourse. This includes assistance through phone consultations and online contact forms. The Cornwell breach highlights the persistent cybersecurity threats businesses face and the serious consequences of failing to protect sensitive consumer data. With both personally identifiable information (PII) and protected health information (PHI) exposed, the incident serves as a stark reminder of the need for stronger data protection and faster response measures in the event of a breach.