US employee screening firm DISA hit with data breach affecting over 3.3 million people

US-based employee screening services provider DISA Global Solutions said it was breached by hackers, putting the personally identifiable information of 3.3 million people at risk.

While DISA informed Maine’s attorney general of the data breach yesterday (thanks, TechCrunch) and reported the hack to Massachusetts’s Office of Consumer Affairs and Business Regulation earlier on February 22, the attack began over a year ago, on February 9, 2024. The unidentified hacker accessed DISA’s network for two months before the company noticed on April 22, 2024. However, there’s allegedly “no evidence of actual or attempted misuse” of personal information.

In a sample notification letter sent to those affected by the hack, DISA claimed it “could not definitively conclude the specific data procured” even after an investigation with third-party assistance. However, the Massachusetts filing listed what the attackers accessed: Social Security numbers, financial accounts, driver’s licenses and credit and debit numbers. DISA didn’t share other details on the attack.

DISA serves over 55,000 customers, including 30 percent of Fortune 500 companies. The company offers drug, alcohol and background checks. This allows it to collect sensitive information, making it a prime target for cybercriminals.

It’s unknown why DISA took almost a year to notify anyone, especially when employee screening is a highly sensitive industry. Those affected can enroll for 12 months of credit monitoring and identity restoration services, a common act of apology companies often take after a cybersecurity incident.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/us-employee-screening-firm-disa-hit-with-data-breach-affecting-over-33-million-people-145658681.html?src=rss https://www.engadget.com/cybersecurity/us-employee-screening-firm-disa-hit-with-data-breach-affecting-over-33-million-people-145658681.html?src=rss
Created 2mo | Feb 25, 2025, 3:20:21 PM


Login to add comment

Other posts in this group

Wholesome Direct 2025 will premiere on June 7

Wholesome Direct, an annual showcase of cute and cozy games, is returning on Saturday, June 7 at 12PM ET / 9AM PT. This year's event will show off "a vibrant lineup of artistic, uplifting, and emot

Apr 28, 2025, 10:40:18 PM | Engadget
There’s a massive power outage cross Spain, Portugal and parts of France

Spain, Portugal and parts of France have experienced a

Apr 28, 2025, 8:30:19 PM | Engadget
How to delete your Twitter (or X) account

There are plenty of good reasons to delete your X account, whether it's because of a general desire to

Apr 28, 2025, 8:30:18 PM | Engadget
Mycopunk is an upbeat love letter to extraction shooters

The extraction-shooter genre is getting a little more crowded and a lot more stylish with the announcement of Mycopunk, a four-player, first-person romp from indie studio Pigeons at Play a

Apr 28, 2025, 8:30:16 PM | Engadget
Researchers secretly experimented on Reddit users with AI-generated comments

A group of researchers covertly ran a months-long "unauthorized" experiment in one of Reddit’s most popular communities using AI-generated comments to test the persuasiveness of large language mode

Apr 28, 2025, 8:30:15 PM | Engadget
Russian regulators are trying to seize assets from the developers of World of Tanks

Top executives from Wargaming and Lesta Games, the joint developers of World of Tanks, could have their stakes in their respective companies seized by the Russian government, according to

Apr 28, 2025, 8:30:14 PM | Engadget