SM Energy data breach exposes Social Security numbers at Denver oil and gas producer (2026)
Denver-based oil and gas producer SM Energy began notifying individuals on 30 July 2026 that a spring 2026 network intrusion had exposed personal data including Social Security numbers.
- Victim
- SM Energy
On 30 July 2026, SM Energy โ a Denver-based, NYSE-listed independent oil and gas exploration and production company โ began mailing notification letters informing individuals that a cybersecurity incident had exposed their personal information, including Social Security numbers.
What happened
According to the company's filings, an unauthorized third party accessed SM Energy's systems on or around 15 May 2026. On 30 June 2026, the company determined that files containing personal information had been accessed and obtained. After completing its review, SM Energy mailed notification letters on 30 July.
The exposed records included names, postal and email addresses, phone numbers, and Social Security or taxpayer identification numbers โ a combination well suited to identity theft and financial fraud.
Scope and response
SM Energy filed breach notices in several U.S. states, reporting at least 3,931 affected individuals across those state filings โ including thousands of Texas residents โ while noting that a nationwide total had not been disclosed. As is standard for incidents involving Social Security numbers, the company offered affected individuals 24 months of complimentary credit monitoring through Experian, with an enrolment deadline later in the year, and several law firms opened investigations into potential class-action claims.
Why it matters
While smaller in headcount than the year's marquee breaches, the SM Energy incident is a reminder that energy-sector companies hold substantial employee and counterparty personal data alongside their operational systems. The roughly two-and-a-half-month gap between the May intrusion and the late-July notifications is typical of data-breach response timelines and leaves affected individuals exposed to fraud during the interval before they learn of the compromise.
Timeline
An unauthorized third party accesses SM Energy's systems on or around this date.
SM Energy determines that files containing personal information were accessed and obtained.
The company mails notification letters to affected individuals, disclosing that Social Security and taxpayer identification numbers were among the exposed data.
Sources
- classactionu.orghttps://classactionu.org/current-data-breaches/sm-energy/
- emeryreddy.comhttps://www.emeryreddy.com/blog/data-breach/sm-energy-data-breach-exposes-social-security-numbers-for-at-least-3931-people
- colevannote.comhttps://colevannote.com/2026/07/31/sm-energy-data-breach-investigation/
- sqmagazine.co.ukhttps://sqmagazine.co.uk/sm-energy-data-breach-ssn-exposed/