DISA Global Solutions breach exposed data on 3.3 million screening subjects
- Organization
- DISA Global Solutions, Inc.
- Exploit
- Hacking
- Industry
- Business Services
DISA Global Solutions, a Houston based provider of employment background checks and drug and alcohol testing, disclosed in February 2025 that an intrusion into its network had exposed the personal information of more than 3.3 million people. The company said an unauthorized third party had access between 9 February and 22 April 2024, the date the activity was detected.
DISA said it contained the incident, notified law enforcement, engaged outside forensic specialists and restored operations with additional security measures in place. It told regulators it could not definitively conclude which specific information had been taken, but that the files at issue could have contained names, Social Security numbers, driver's license numbers, government identification and financial account information. The company said it was unaware of any attempted or actual misuse of the data.
Notification letters began going out on 21 February 2025, roughly ten months after discovery, accompanied by filings with state attorneys general including Maine's. Affected individuals were offered twelve months of credit monitoring and identity restoration through Experian.
The delay drew comment from several outlets. Cybersecurity Dive and Infosecurity Magazine both highlighted the gap of about ten months between detection and notification, and analysts quoted by Infosecurity questioned the company's monitoring and incident response arrangements. Because DISA screens applicants and employees on behalf of tens of thousands of employers, including a large share of the Fortune 500, the exposed records related to people at many companies with no direct relationship to DISA.