HackingCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICEMPLOYMENTLowContained
DISA Global Solutions, Inc.
bd_0cf41ac0d43a088f · schema v1 · pii pii-v1
Full breach record for DISA Global Solutions, Inc. →DISA Global Solutions, Inc., a third-party administrator of employment screening services, experienced a cyber incident where an unauthorized third party accessed its network between February 9, 2024, and April 22, 2024. The incident was discovered on April 22, 2024. Affected data included names and employment screening information. The company contained the incident, engaged forensic experts, notified law enforcement, and is offering 12 months of credit monitoring and identity restoration services.
California clockDiscovered Apr 22, 2024 → Notified Feb 21, 2025305d ✗ CA 60-day late44 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5d6c5c4a512d44c4Washington State AGfiled 2025-02-24Verified
- bd_638fe8643027dbceIndiana State AGfiled 2025-02-21(3d gap)Verified
- bd_a919be093e5b4fe0Iowa State AGfiled 2025-02-21(3d gap)Candidate
- bd_c99560602c0629b1Oregon State AGfiled 2025-02-21(3d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 14d gap
- bd_e9d244f30e93f9afCalifornia State AGfiled 2025-03-10(14d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-599040
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2025
- Raw hash
- 9d1d169ec2c1534c2089247f42c27ef1bdb6753caaa77c50d59ed953893dffd2
Reporting entity
- Name
- DISA Global Solutions, Inc.norm: disa global
- Domain
- disa.com
Victim entity
- Name
- DISA Global Solutions, Inc.norm: disa global
- Domain
- disa.com
Incident
- Discovered
- Apr 22, 2024
- Materiality determined
- —
- Notification sent
- Feb 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
Compliance
- Time to disclose
- 44 weeks(308 days from discovery to filing)
- Compliance flags
- CA 60-day late · 305d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 22, 2024→ Notified: Feb 21, 2025305d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.