Skip to main content

Company intelligence

Verisource cybersecurity incidents and threat signals

verisource.com

Verisource logo

This company page brings together public reporting currently associated with Verisource. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Verisource. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Verisource

Verisource logoRansomware
Medium

VeriSource Services Data Breach

Employee benefit administrative services provider VeriSource Services is notifying four million individuals that their personal information was stolen in a year-old hack. The incident, the company says, was discovered on February 28, 2024, one day after a threat actor exfiltrated data from its systems. A review of the compromised data was concluded on August 12, 2024, and the company started notifying the potentially impacted individuals a week later. The stolen information, VeriSource says, belonged to employees and dependents of companies using its services, and it has been working with these companies to “collect the necessary information to notify additional individuals affected by this incident”. “That process was completed on April 17, 2025. We then took steps to notify impacted individuals of the incident as quickly as possible,” VeriSource notes in a data breach notice . The potentially compromised information, the company says, differs by individual, but generally includes names, addresses, dates of birth, gender information, and Social Security numbers. Advertisement. Scroll to continue reading. VeriSource says it is not aware of any of the stolen information being misused, but it is providing the potentially affected individuals with 12 months of free credit monitoring and identity protection services. “We suggest that you review your debit and credit card statements carefully in order to identify any unusual activity.  If you see anything that you do not understand or that looks suspicious, you should contact the issuer of the debit or credit card immediately,” the company’s notice reads. Last week, the benefits administrator notified the Maine Attorney General’s Office that four million individuals were impacted by the incident. Founded in 1997 and based in Houston, Texas, VeriSource provides employee benefits administration and HR outsourcing solutions and services, including data management, employee enrollment, billing, ACA reporting, dependent verification, FMLA administration, and more. Related: African Telecom Giant MTN Group Discloses Data Breach Related: Blue Shield of California Data Breach Impacts 4.7 Million People Related: 5.5 Million Patients Affected by Data Breach at Yale New Haven Health Related: Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Verisource

FAQ

Questions about Verisource cybersecurity reporting

What does the Verisource page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Verisource.

Does every mention of Verisource appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.