Data leak

DISA Global Solutions Employment Screening Data Breach

πŸ“… 2024-02-09
Primary Source β†—

Incident Details

DISA Global Solutions (background check, drug testing, and employment screening provider to 55,000+ companies including 135 Fortune 500 firms) was breached for 100+ days before discovery on 22 April 2024. The company did not begin notifying the 3.3 million affected individuals until 21 February 2025 β€” a 305-day delay from discovery. Exposed data potentially included SSNs, driver’s license numbers, financial account information, and other PII. Data appeared on the dark web. Multiple class action lawsuits filed.

Technical Details

Initial Attack Vector
Unauthorized third party gained access to DISA Global Solutions systems between 9 February and 22 April 2024; initial access vector not publicly disclosed

Timeline

  1. 2024-02-09 Breach occurred
  2. 2025-02-21 Publicly disclosed
  3. 2025-02-21 Customers notified