Chemonics International discloses 2023 intrusion affecting 263,136 people
- Organization
- Chemonics International
- Exploit
- Hacking
- Industry
- Government Contractor
Chemonics International, a Washington-based international development firm whose largest client is the U.S. Agency for International Development, began notifying people in December 2024 about a network intrusion that had gone undetected for more than six months during 2023.
In its breach notice the company said it became aware of suspicious activity involving certain user accounts on December 15, 2023, and responded by resetting passwords and disabling the affected accounts. A forensic investigation later established that the unauthorized access had begun on May 30, 2023 and continued until January 9, 2024. Chemonics said the review of the affected data took until October 31, 2024 to complete, at which point it could identify whose records were involved.
Filings with state regulators put the total at 263,136 people. According to The Record, the exposed information included names, dates of birth, Social Security numbers, driver's licence and state ID details, passport information, U.S. military and tribal ID data, financial records, health information, usernames and passwords, biometric data and signatures.
The company said the incident had been contained and remediated and that it had strengthened multi-factor authentication, email security and endpoint monitoring, and blocked suspicious internet traffic. Notification letters went out from December 3, 2024 with 24 months of credit monitoring offered. Chemonics gave no detailed explanation for the year-long gap between discovery and notification, saying only that the investigation took time to complete.