CBIZ, INC.
ent_019de1cdc81b18aeeafc2a8a5ff57ecf
Disclosures
17
Leak Site · State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
436,198
nationwide · HHS OCR NJ
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- CBIZ, INC.
- Normalized
- cbiz— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900D5X8CFM8O1N813
- SEC EDGAR CIK
- 0000944148
- Domain
- cbiz.com
Disclosure history (17)newest first
- GLOBALLeak Siteas victim2024-07-16
- GLOBALLeak Siteas victim2024-06-22
SALE
- New Hampshire State AGas victim2023-12-29
CBIZ, Inc. filed a supplemental notification with the New Hampshire Attorney General regarding the MOVEit security incident. The company mailed notification letters to 3,238 New Hampshire residents whose personal information was involved. CBIZ is offering complimentary credit monitoring and identity theft restoration services through Kroll.
- Maine State AGas victim2023-12-29
CBIZ, Inc. experienced an external system breach between May 29, 2023, and June 5, 2023, discovered on August 10, 2023. The breach affected 482 Maine residents, compromising names and financial account or credit/debit card numbers with associated security codes or PINs. CBIZ offered credit monitoring and identity theft protection services to those affected.
- NEW JERSEYHHS OCRas victim2023-11-10
CBIZ KA Consulting Services, LLC reported to HHS on 2023-11-10 a Hacking/IT Incident affecting 436,198 individuals. Breached information located on Network Server. A software application used by its vendor exposed PHI including names, DOB, addresses, SSN, driver's license, diagnoses, and financial/insurance data. The BA implemented additional administrative, technical, and security safeguards.
- South Carolina State AGas victim2023-09-05
CBIZ, Inc. notified South Carolina residents of a data incident involving the MOVEit Transfer software provider, Progress Software. An unauthorized party exploited a vulnerability in MOVEit to access a CBIZ server and download data containing names, dates of birth, and Social Security numbers between May 29 and June 5, 2023. CBIZ patched the vulnerability and offered two years of identity monitoring.
- Massachusetts State AGas victim2023-09-01
CBIZ, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-01. 31,370 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-09-01
CBIZ, Inc. notified individuals of a data incident involving MOVEit Transfer software. An unauthorized party exploited a vulnerability in MOVEit to access a server and download data between May 29 and June 5, 2023. Affected data included names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and offered two years of identity monitoring.
- New Hampshire State AGas victim2023-09-01
CBIZ, Inc. notified the New Hampshire Attorney General on September 1, 2023, regarding a MOVEit Transfer vulnerability exploited between May 29 and June 5, 2023. The incident affected 77 New Hampshire residents. CBIZ applied patches, investigated, and mailed notifications offering credit monitoring. Data exfiltrated included personal information.
- Maine State AGas victim2023-09-01
CBIZ, Inc. experienced an external system breach between May 29, 2023, and June 5, 2023, which was discovered on August 10, 2023. The breach affected 35,843 individuals, compromising their names and Social Security numbers. CBIZ notified affected consumers in writing on September 1, 2023, and offered complimentary credit monitoring and identity theft protection services through Kroll.
- Indiana State AGas victim2023-09-01
CBIZ, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-29 and was reported on 2023-09-01. 1,211 Indiana residents were affected. 35,843 individuals affected in total.
- California State AGas victim2023-09-01
CBIZ, Inc. notified California residents of a data breach involving its IT environment for client Mayer Hoffman McCann P.C. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing a server between May 29 and June 5, 2023, and downloading data. Affected information includes names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and is offering two years of identity monitoring.
- Vermont State AGas victim2023-09-01
CBIZ, Inc. disclosed a data breach involving its MOVEit Transfer server, exploited via a vulnerability in Progress Software's software. Unauthorized access occurred between May 29 and June 5, 2023, resulting in the exfiltration of names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and offered two years of identity monitoring services.
- Illinois State AGas victim2023-01-01
CBIZ, INC. filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-874). The register records the breach as discovered on May 29, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2018-07-18
CBIZ MHM, LLC notified the NH Attorney General of a security incident affecting one NH resident. Unauthorized access to an employee's email occurred May 21-22, 2018, discovered June 13, 2018. Data included names, SSNs, driver's licenses, and financial account numbers. Notifications sent July 19, 2018, with credit monitoring offered.
- Montana State AGas victim2018-07-18
CBIZ MHM, LLC notified Montana residents of a phishing incident where an employee's email account was compromised between May 2 and May 23, 2018. Unauthorized parties may have accessed names and variable data. CBIZ secured the account, engaged forensic investigators, and offered one year of Experian IdentityWorks.
- Massachusetts State AGas victim2018-07-18
CBIZ MHM LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-07-18. 6 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- CBIZ, INC.’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of CBIZ, INC. — not by CBIZ, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- California State AGvia CBIZ Benefits & Insurance Services, Inc.2026-01-21
Diversified Benefit Services Insurance Marketing, Inc. reported that an unauthorized actor gained access to its email system on August 7, 2025, potentially downloading emails and files containing names, Social Security Numbers, and health insurance information. The company secured the environment, engaged forensic experts, and is offering credit monitoring and fraud assistance to affected individuals.
- Illinois State AGvia CBIZ Benefits & Insurance Services, Inc.2024-09-01
CBIZ BENEFITS & INSURANCE SERVICES, INC. filed a data-breach notice with the Illinois Attorney General in September 2024 (case 24-09-070). The register records the breach as discovered on June 2, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-28. 382 Massachusetts residents were affected.
- Maine State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. reported a data breach affecting 7 Maine residents. Unauthorized access occurred between June 2 and June 21, 2024, via exploitation of a web page vulnerability. The incident exposed names and Social Security numbers of individuals associated with CBIZ clients. CBIZ engaged cybersecurity professionals, fixed the vulnerability, and provided two years of credit monitoring.
- OHIOHHS OCRvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. (OH), a business associate, reported to HHS on 2024-08-28 a Hacking/IT Incident affecting 9,602 individuals. PHI involved included names, Social Security numbers, and dates of birth, located on a Network Server. The BA notified HHS and affected individuals, provided substitute notice, offered complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- Indiana State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-02 and was reported on 2024-08-28. 40 Indiana residents were affected. 7,006 individuals affected in total.
- New Hampshire State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. notified the NH Attorney General of a security incident where an unauthorized party exploited a web page vulnerability to access databases containing retiree health and welfare plan information (including PII and PHI) for NH residents between June 2-21, 2024. CBIZ detected the incident on June 24, 2024, engaged cybersecurity professionals, fixed the vulnerability, and is offering credit monitoring via Kroll.
- Vermont State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. notified consumers of a data breach where an unauthorized party exploited a web page vulnerability to access databases between June 2 and June 21, 2024. The incident involved PII and government IDs. CBIZ engaged forensic investigators, fixed the vulnerability, and provided two years of free identity monitoring via Kroll.
- Montana State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. notified Montana residents of a data incident where an unauthorized party exploited a web page vulnerability to access databases between June 2 and June 21, 2024. CBIZ discovered the incident on June 24, 2024, engaged forensic professionals, fixed the vulnerability, and is cooperating with the FBI. Affected individuals are offered two years of Kroll identity monitoring.
- Illinois State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-01
CBIZ BENEFITS & INSURANCE SERVICES, INC. filed a data-breach notice with the Illinois Attorney General in August 2024 (case 24-08-056). The register records the breach as discovered on June 2, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.