PSEA notified more than 517,000 people after Rhysida claimed 2024 breach
- Organization
- Pennsylvania State Education Association
- Exploit
- Ransomware
- Industry
- Non-profit
The Pennsylvania State Education Association, the state's largest public-sector union, told 517,487 people in March 2025 that their personal information had been taken in a network intrusion the previous summer. The union said the incident occurred on or about July 6, 2024, and that its review of the affected files was not completed until February 18, 2025.
The exposed records varied by individual and included names, dates of birth, state-issued identification numbers, Social Security numbers, financial account and routing numbers, payment card details, passport numbers, taxpayer identification numbers, and health insurance and medical information. Those affected included current and former members and their dependents.
PSEA did not name an attacker in its notification. The Rhysida ransomware group had claimed the union on its leak site in September 2024. The union said it had taken steps, to the best of its ability and knowledge, to ensure the data taken by the unauthorized actor was deleted. The Register read that wording as an indication the union had been in contact with the attackers, though PSEA did not say publicly whether it paid.
The union said it had notified law enforcement, engaged outside cybersecurity specialists and had no evidence that the information had been used for identity theft or financial fraud. It offered complimentary credit monitoring and identity restoration to those whose Social Security numbers were involved.