VeriSource Services, Inc.
bd_0b3973616ee57a56 · schema v1 · pii pii-v1
Full breach record for VeriSource Services, Inc. →VeriSource Services, Inc. (VSI), a provider of employee administrative and benefit data management services, experienced a data security incident. On February 28, 2024, VSI detected unusual activity disrupting system access. Investigation revealed an unknown actor acquired personal information (name, address, DOB, gender, SSN) without authorization on or about February 27, 2024. VSI secured its network, engaged forensic investigators, and notified the FBI. Affected individuals include current/former employees and their beneficiaries/dependents. VSI is offering complimentary credit monitoring and identity theft protection services.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_9ea22d2bed8194e1Washington State AGfiled 2025-04-25Candidate
- bd_f309ce1ca10615e7New Hampshire State AGfiled 2025-04-25Verified
- bd_16f2df32e1177c8eVermont State AGfiled 2025-04-23(2d gap)Verified
- bd_a88a6e1ac96df7c4Delaware State AGfiled 2025-04-23(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601930
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2025
- Raw hash
- 6f5e6c029a33cba10fd4655648db651fc468f0e257b7e1fedba0932990ad3237
Reporting entity
- Name
- VeriSource Services, Inc.norm: verisource services
Victim entity
- Name
- VeriSource Services, Inc.norm: verisource services
Incident
- Discovered
- Feb 28, 2024
- Materiality determined
- —
- Notification sent
- Apr 23, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to the FBI
Compliance
- Time to disclose
- 14 months(422 days from discovery to filing)
- Compliance flags
- CA 60-day late · 420d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 28, 2024→ Notified: Apr 23, 2025420d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.