CSIDB logo
Incident

North Star Fertility Partners LLC

Incident posture

Attack window
Aug 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 19:04

Linked entities

Victim
North Star Fertility Partners LLC
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

North Star Fertility Partners LLC experienced a cybersecurity incident involving its third‑party vendor Salesloft, which resulted in unauthorized access to a database hosted on the Salesforce platform. The compromised database may have contained personal information such as names and driver’s license numbers. After learning of the breach, the company launched an investigation with the assistance of a cybersecurity firm and subsequently began sending notification letters to potentially affected individuals. Edelson Lechtzin LLP is now pursuing a class‑action inquiry on behalf of those whose data may have been exposed.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

North Star Fertility Partners LLC is a Boston-based network of fertility clinics, hospital groups, individual doctors, and attorneys that has facilitated the birth of over 11,500 babies through surrogacy and egg donation programs. In mid-August 2025, the organization learned of a cybersecurity incident that occurred between August 12 and August 17, 2025. The breach involved unauthorized access to a database hosted on the Salesforce platform and was traced to a third‑party vendor, Salesloft. Upon discovering the incident, Northstar initiated an investigation with the assistance of a cybersecurity firm.

The investigation determined that the compromised database may have contained certain personal information, specifically names and driver’s license numbers. Following the completion of the forensic review, Northstar began mailing notification letters to potentially affected individuals in February 2026. The notifications informed recipients that their data might have been exposed in the breach.

In response to the incident, the class‑action law firm Edelson Lechtzin LLP announced that it is investigating claims on behalf of Northstar’s clients whose data may have been compromised. The firm is based in suburban Philadelphia and is preparing to pursue legal remedies for those affected. The law firm’s outreach includes providing contact information for individuals who wish to discuss the case with an attorney.

Sources

Sources available to members: 1 source.

CSIDB