Defense contractor RTX disclosed a breach that exposed Social Security numbers, fuel for the identity theft that can empty a retiree’s accounts

Elderly woman sitting in an armchair and holding her glasses while typing on a laptop.

The parent company of Raytheon and Pratt & Whitney has told an unknown number of people that criminals accessed their names, addresses and Social Security numbers. RTX Corp., one of the largest defense contractors in the country, disclosed the breach in written notices this month and reported it to state regulators. The exposed combination is the one identity thieves most want, because a Social Security number paired with a name and address is enough to try opening new accounts, filing fraudulent tax returns and chasing benefits in a victim’s name — the kind of slow, quiet fraud that can drain a retiree’s finances long after the headlines fade.

What RTX says was exposed

The compromised information includes first and last names, mailing addresses and Social Security numbers, and the underlying security incident traces to late June, according to reporting on the company’s disclosure. RTX began mailing written notices to affected individuals on July 23 and reported the breach to Massachusetts regulators the following day. The company is offering those affected 24 months of free credit monitoring and identity protection through Equifax Complete Premier, with an enrollment window that closes at the end of October.

The gap between the incident and the notifications has already drawn a legal challenge. A former employee filed a proposed class action arguing that the delay left people in the dark and cost them time they could have used to guard against fraud. Whatever the suit’s outcome, the practical takeaway for anyone who receives a letter is the same: the exposure is real, and the clock on protecting a credit file starts now.


Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Why a stolen Social Security number outlasts the breach

A leaked password can be changed and a stolen card canceled, but a Social Security number is permanent. It is the fixed identifier that lenders, the IRS and government programs use to confirm who a person is, which makes it the single most valuable item in a breach like this one. Once it circulates, criminals can try to open credit cards and loans, file a tax return to grab a refund, or apply for benefits — and they can attempt it repeatedly for years.

Retirees carry a specific version of that risk. A fraudulent tax return filed early in the season can intercept a legitimate refund, and new accounts opened in a retiree’s name often surface only when a debt collector calls or a credit application is unexpectedly denied. The two years of monitoring RTX is offering can flag some of that activity, but monitoring alerts a person after a thief has already acted; it does not block the attempt.

The step that actually blocks new-account fraud

Freezing a credit file does what monitoring cannot: it stops the fraud before it starts. With a freeze in place, a lender cannot pull the credit report a new application requires, so an account cannot be opened even by someone holding a valid Social Security number. The Federal Trade Commission explains that a credit freeze is free at all three national credit bureaus and does not lower a credit score, and it can be lifted temporarily whenever a genuine loan or card is planned. For a household not actively shopping for credit, a freeze can simply stay on indefinitely.

A freeze at each bureau covers the biggest exposure, but the same stolen data can also be used to file a tax return in a victim’s name. Requesting an Identity Protection PIN from the IRS closes that door, since the six-digit code must appear on a return for it to be accepted, and combining the PIN with a credit freeze addresses the two most common ways a breached Social Security number gets monetized.

Checking the credit file without waiting for an alert

The monitoring RTX is providing runs for two years and then stops, but the exposure from a stolen Social Security number does not. A durable habit fills that gap: the Federal Trade Commission notes that the three national credit bureaus provide free credit reports every week through the federally authorized site AnnualCreditReport.com. Pulling a report and scanning it for unfamiliar accounts, credit inquiries or addresses catches the footprints of new-account fraud without paying for a service or waiting for a company’s alert to arrive.

Reviewing the reports on a rotating schedule — one bureau at a time, spaced through the year — turns a one-time breach notice into an ongoing check. It costs nothing, and it keeps working after the enrollment window RTX set for October has passed and the contractor stops footing the bill for monitoring.

What to do with the RTX letter

Anyone who receives a notice can enroll in the offered monitoring before the October deadline, but the more durable protection comes from acting independently of what the company provides. The government’s identity theft recovery resource lays out how to report suspected misuse, dispute fraudulent accounts and document a recovery plan if a number is exploited. Because a Social Security number cannot be reissued at will, the defense is not to make the data disappear but to make it useless — freezing the credit file, guarding the tax return, and treating the exposure as a permanent condition to manage rather than a one-time event that passes.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

More Financial Reading