Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

3.3 Million People Impacted by DISA Data Breach

Background and drug screening giant DISA has revealed that a 2024 data breach impacts more than 3.3 million people.

Data breach

Texas-based employee screening giant DISA Global Solutions has revealed that a data breach suffered by the company in 2024 impacts more than 3.3 million people.

DISA provides background screening, drug and alcohol testing, and compliance solutions. The company boasts serving more than 55,000 customers, and says it performs millions of drug tests and background screens every year.

The firm told the public and authorities this week that 3.33 million individuals whose current or former employers used DISA screening services had their personal information stolen last year as a result of a cyber incident. 

According to DISA, an intrusion into a limited portion of its network was discovered on April 22, 2024. An investigation revealed that hackers had access to its systems up until that date starting with February 9, 2024. 

The company conducted what it described as a “detailed and time-intensive” review of the files stolen by the hackers in an effort to identify individuals whose personal information was compromised as a result of the incident.

A data breach notice posted on the DISA website reveals that the stolen information includes names, Social Security numbers, driver’s license and other government ID numbers, financial account information, and other types of data. 

Advertisement. Scroll to continue reading.

Impacted individuals are being notified and offered free credit monitoring and identity restoration services for one year. DISA says it’s unaware of actual misuse of the information compromised in the incident. 

It’s unclear if DISA was targeted in a ransomware attack. No known ransomware group appears to have taken credit for the breach.

Related: Cisco Says Ransomware Group’s Leak Related to Old Hack

Related: VC Firm Insight Partners Hacked

Related: Finastra Starts Notifying People Impacted by Recent Data Breach

Related: OpenAI Finds No Evidence of Breach After Hacker Offers to Sell 20 Million Credentials

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Jacki Monson has joined CVS Health as SVP, Deputy CISO.

Gigi Schumm has been promoted to Chief Revenue Officer at Securonix.

Chris Sistrunk has been promoted to Practice Leader for Mandiant's OT Security Consulting.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.