RTX Corporation — the aerospace and defense conglomerate that owns Raytheon, Collins Aerospace and Pratt & Whitney — has begun notifying individuals that a security incident exposed their personal information, including Social Security numbers.

The timeline is the story:

  • June 25, 2026 — the security incident occurs
  • July 23, 2026 — RTX begins sending written notice to affected individuals
  • July 24, 2026 — the breach is reported to the Massachusetts Office of Consumer Affairs and Business Regulation

Roughly four weeks separate the incident from the first notification. A class action complaint filed shortly afterward makes that gap its central allegation: that RTX “kept class members in the dark and deprived them of an opportunity to timely mitigate the impacts of the breach.”

What Was Exposed

The notification identifies three data elements:

  • First and last names
  • Mailing addresses
  • Social Security numbers

That combination is the complete package for identity theft. Name plus address plus SSN is sufficient to open credit accounts, file fraudulent tax returns, and pass the knowledge-based authentication that financial institutions still use to verify identity over the phone.

RTX is offering 24 months of free Equifax Complete Premier credit monitoring — the standard remedy, and one whose duration is worth measuring against the shelf life of the exposed data. A payment card expires. A mailing address changes. A Social Security number is permanent, and the person holding it will still be exposed in 2046, long after the two-year monitoring subscription lapses.

What RTX Has Not Said

The disclosure is notable for what it omits:

  • How many people are affected — no figure has been published
  • How the breach occurred — attack vector undisclosed
  • Who was responsible — no threat actor identified, no group has claimed it
  • Whether employees, customers, or both — the notice refers to employee and/or customer personal information
  • Whether classified or export-controlled material was touched — not addressed

That last omission is the one that separates RTX from an ordinary corporate breach. RTX is a major US defense prime whose subsidiaries build missile systems, jet engines and avionics — a category of work that sits inside the ITAR, DFARS 252.204-7012 and CMMC regimes governing defense contractors and their handling of controlled unclassified information.

RTX has not said whether any of that was in scope, and nothing in the public record suggests classified networks were involved. The disclosure describes a personal-information incident and should be read as covering that and nothing more. But a defense prime declining to state the boundary leaves the obvious question unanswered, and it is the question that determines whether this is an HR-data breach or something else.

RTX is also not new to this. Collins Aerospace was the vendor at the centre of the September 2025 European airport disruption and the Dublin Airport breach that exposed 3.8 million passengers.

The Notification Gap Is Now Litigation Risk

Four weeks is not unusual. It is arguably fast by the standards of a large enterprise that has to complete forensics, determine which records were in scope, deduplicate an affected-person list across business units, and stand up a notification vendor before a single letter goes out. Investigators genuinely cannot name victims on day one.

It is also, increasingly, indefensible in court.

The plaintiffs’ bar has spent three years building the argument that the harm from a breach accrues during the delay, not at the moment of intrusion — that every week a victim doesn’t know is a week of unfrozen credit, unmonitored accounts and unfiled fraud alerts. The theory converts a defensible investigative timeline into a damages period, and it does so regardless of whether the defendant’s forensics were competent or slow.

RTX’s specific exposure is the mismatch between its two dates. Notices went out July 23. The Massachusetts regulator was told July 24. Notifying victims a day before the regulator is unusual sequencing and suggests the notification decision was made and executed before regulatory filing was complete — which is the right order from a victim’s perspective and an awkward set of facts to explain when a complaint asks why neither happened in June.

What Affected Individuals Should Actually Do

Credit monitoring detects fraud after it happens. It does not prevent it.

  • Freeze credit at all three bureaus — Equifax, Experian and TransUnion. Free, and it blocks new account opening outright, which monitoring does not.
  • Request an IRS Identity Protection PIN before the next filing season. SSN exposure is tax fraud exposure.
  • Enrol in the offered monitoring anyway — it costs nothing and provides an evidentiary record.
  • Treat the 24-month expiry as a calendar item, not an endpoint. Exposed SSNs surface in fraud years after the breach that produced them, precisely because attackers know when monitoring lapses.

Sources

  • RTX Corporation breach notification, July 23, 2026
  • Massachusetts Office of Consumer Affairs and Business Regulation filing, July 24, 2026
  • Bloomberg Law, RTX Corp Sued by Worker Over Social Security Number Data Hack
  • teiss, Aerospace and defense giant RTX Corp. discloses data breach exposing social security numbers