Skip to main content
Back to overview
Medium

VeriSource Services Data Breach

Employee benefit administrative services provider VeriSource Services is notifying four million individuals that their personal information was stolen in a year-old hack.

Key points

  • Affected approximately 4 million individuals.
  • Disclosed on April 14, 2025.
  • Cyberattack occurred in February 2024.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Apr 14, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking, Error activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

VerisourceData DisclosureVeriSource ServicesVeriSourceThatAdvertisement. ScrollLastMaine Attorney GeneralOfficeFounded

Quick context

Questions about this signal

What happened in this signal?

Employee benefit administrative services provider VeriSource Services is notifying four million individuals that their personal information was stolen in a year-old hack. The incident, the company says, was discovered on February 28, 2024, one day after a threat actor exfiltrated data from its systems. A review of the compromised data was concluded on August 12, 2024, and the company started notifying the potentially impacted individuals a week later. The stolen information, VeriSource says, belonged to employees and dependents of companies using its services, and it has been working with these companies to “collect the necessary information to notify additional individuals affected by this incident”. “That process was completed on April 17, 2025. We then took steps to notify impacted individuals of the incident as quickly as possible,” VeriSource notes in a data breach notice . The potentially compromised information, the company says, differs by individual, but generally includes names, addresses, dates of birth, gender information, and Social Security numbers. Advertisement. Scroll to continue reading. VeriSource says it is not aware of any of the stolen information being misused, but it is providing the potentially affected individuals with 12 months of free credit monitoring and identity protection services. “We suggest that you review your debit and credit card statements carefully in order to identify any unusual activity.  If you see anything that you do not understand or that looks suspicious, you should contact the issuer of the debit or credit card immediately,” the company’s notice reads. Last week, the benefits administrator notified the Maine Attorney General’s Office that four million individuals were impacted by the incident. Founded in 1997 and based in Houston, Texas, VeriSource provides employee benefits administration and HR outsourcing solutions and services, including data management, employee enrollment, billing, ACA reporting, dependent verification, FMLA administration, and more. Related: African Telecom Giant MTN Group Discloses Data Breach Related: Blue Shield of California Data Breach Impacts 4.7 Million People Related: 5.5 Million Patients Affected by Data Breach at Yale New Haven Health Related: Ransomware Group Claims Hacking of Oregon Regulator After Data Breach Denial Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

When was this signal reported?

Shadow Tier lists Apr 14, 2025 as the signal date.

Which organization is connected to this signal?

Verisource is the organization connected to this public signal.

Explore Verisource
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence