HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICEMPLOYMENTLowContained
DISA Global Solutions, Inc.
bd_e9d244f30e93f9af · schema v1 · pii pii-v1
Full breach record for DISA Global Solutions, Inc. →DISA Global Solutions, Inc., a third-party administrator of employment screening services, disclosed a cyber incident where an unauthorized third party accessed its network between February 9, 2024, and April 22, 2024. The breach was discovered on April 22, 2024. The incident involved personal information including names and employment screening data. DISA contained the incident, engaged forensic experts, notified law enforcement, and is offering 12 months of credit monitoring and identity restoration services to affected individuals.
California clockDiscovered Apr 22, 2024 → Notified Feb 21, 2025305d ✗ CA 60-day late46 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0cf41ac0d43a088fCalifornia State AGfiled 2025-02-24(14d gap)Candidate
- bd_5d6c5c4a512d44c4Washington State AGfiled 2025-02-24(14d gap)Verified
- bd_638fe8643027dbceIndiana State AGfiled 2025-02-21(17d gap)Verified
- bd_a919be093e5b4fe0Iowa State AGfiled 2025-02-21(17d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 17d gap
- bd_c99560602c0629b1Oregon State AGfiled 2025-02-21(17d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-599684
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2025
- Raw hash
- b008c89623427ed0f600786ee06f2194af5cb919edb236cf53734a7e9d429c32
Reporting entity
- Name
- DISA Global Solutions, Inc.norm: disa global
- Domain
- disa.com
Victim entity
- Name
- DISA Global Solutions, Inc.norm: disa global
- Domain
- disa.com
Incident
- Discovered
- Apr 22, 2024
- Materiality determined
- —
- Notification sent
- Feb 21, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement authorities
Compliance
- Time to disclose
- 46 weeks(322 days from discovery to filing)
- Compliance flags
- CA 60-day late · 305d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 22, 2024→ Notified: Feb 21, 2025305d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.