VeriSource Services disclosed February 2024 breach of employee benefits data

Organization
VeriSource Services, Inc.
Exploit
Hacking
Industry
Employee Benefits Administration

VeriSource Services, Inc., a Houston based employee benefits administration and dependent verification firm, began notifying people in August 2024 of a data breach that had occurred six months earlier. The company also reported the incident to state regulators, including the Texas Attorney General, that month.

VeriSource said it detected unusual activity in its environment on February 28, 2024 and later determined that files had been exfiltrated on or about February 27, 2024. It secured its systems, brought in third party cybersecurity specialists and notified the FBI. The review of what the stolen files contained was completed on August 12, 2024.

The exposed information belonged to employees and dependents of companies that used VeriSource's benefits services. It included names, addresses, dates of birth, gender and Social Security numbers, with the specific fields varying by individual. The company said it had no indication the data had been misused and offered affected people 12 months of credit monitoring and identity protection.

The number of people involved rose sharply over time. An early filing put the figure at 1,382. A report to the US Department of Health and Human Services in August 2024 listed 112,726 individuals. In April 2025, after collecting information from client companies, VeriSource concluded that up to four million people were affected and notified the Maine Attorney General of the revised total, with notification letters continuing through 2025.

Sources