HackingVulnerability ExploitTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CBIZ Benefits & Insurance Services, Inc.
bd_cd16c942d4634e0a · schema v1 · pii pii-v1
Full breach record for CBIZ Benefits & Insurance Services, Inc. →CBIZ Benefits & Insurance Services, Inc. notified consumers of a data breach where an unauthorized party exploited a web page vulnerability to access databases between June 2 and June 21, 2024. The incident involved PII and government IDs. CBIZ engaged forensic investigators, fixed the vulnerability, and provided two years of free identity monitoring via Kroll.
Vermont clock✗ VT AG >45 bday9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_283e90cfc9d786e8Maine State AGfiled 2024-08-28Verified
- bd_4390450bb6cd260dHHS OCRfiled 2024-08-28Verified
- bd_5a40f16ebc5d4f59Indiana State AGfiled 2024-08-28Verified
- bd_61274703901e5b08New Hampshire State AGfiled 2024-08-28Verified
Show 1 more filing ↓Show fewer ↑
- bd_ce0aa1b8f498185eMontana State AGfiled 2024-08-28Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-08-28-cbiz-benefits-insurance-services-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2024
- Raw hash
- fbdda5e85deb1b558853c8b25bd41e445633ce96aa90bf6f391466c8fd503060
Reporting entity
- Name
- CBIZ Benefits & Insurance Services, Inc.norm: cbiz benefits insurance
Victim entity
- Name
- CBIZ Benefits & Insurance Services, Inc.norm: cbiz benefits insurance
Incident
- Discovered
- Jun 24, 2024
- Materiality determined
- —
- Notification sent
- Aug 28, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Working closely with the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.