
Tower Administrative Services Inc., based in Lancaster, Pennsylvania, discovered suspicious activity in its network and launched an investigation that determined unauthorized access or acquisition of data occurred around February 3, 2026. The company completed its review of potentially affected information on or around May 20, 2026, more than three months after the initial intrusion.
The breach exposed names, Social Security numbers, addresses, and financial account information including debit and credit card numbers. Tower Administrative Services began notifying affected individuals on June 23. While the company did not disclose the total number of people impacted, at least 25,742 Texas residents and 78 Vermont residents were confirmed to be affected.
Tower Administrative Services notified the attorneys general of Nebraska, Texas, and Vermont and posted details of the incident on its website. The company is offering affected individuals complimentary credit monitoring and identity protection services through third-party providers Cyberscout and Identity Force. Those services require enrollment using an activation code provided in notification letters, and individuals must sign up within 90 days of receiving their letters.
The company established a dedicated assistance line for individuals with questions or concerns about the breach. The line operates between 8 a.m. and 8 p.m. Eastern Time, Monday through Friday, excluding major U.S. holidays. Affected individuals may also contact Tower Administrative Services by mail at 8 Marticville Road, Lancaster, Pennsylvania 17603.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543