CBIZ, INC.
ent_019de1cdc81b18aeeafc2a8a5ff57ecf
Disclosures
11
Leak Site · State AG · HHS OCR · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
436,198
nationwide · HHS OCR NJ
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- CBIZ, INC.
- Normalized
- cbiz— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900D5X8CFM8O1N813
- SEC EDGAR CIK
- 0000944148
- Domain
- cbiz.com
Disclosure history (11)newest first
- GLOBALLeak Siteas victim2024-07-16
6999$
- GLOBALLeak Siteas victim2024-06-22
SALE
- ⛰️New Hampshire State AGas victim2023-12-29
CBIZ, Inc. filed a supplemental notification with the New Hampshire Attorney General regarding the MOVEit security incident. The company mailed notification letters to 3,238 New Hampshire residents whose personal information was involved. CBIZ is offering complimentary credit monitoring and identity theft restoration services through Kroll.
- 🦞Maine State AGas victim2023-12-29
CBIZ, Inc. experienced an external system breach between May 29, 2023, and June 5, 2023, discovered on August 10, 2023. The breach affected 482 Maine residents, compromising names and financial account or credit/debit card numbers with associated security codes or PINs. CBIZ offered credit monitoring and identity theft protection services to those affected.
- NJHHS OCRas victim2023-11-10
CBIZ KA Consulting Services, LLC reported to HHS on 2023-11-10 a Hacking/IT Incident affecting 436,198 individuals. Breached information located on Network Server. A software application used by its vendor exposed PHI including names, DOB, addresses, SSN, driver's license, diagnoses, and financial/insurance data. The BA implemented additional administrative, technical, and security safeguards.
- 🦬Montana State AGas victim2023-09-01
CBIZ, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-01. The breach occurred from 5/29/2023 to 6/5/2023. 149 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2023-09-01
CBIZ, Inc. notified the New Hampshire Attorney General on September 1, 2023, regarding a MOVEit Transfer vulnerability exploited between May 29 and June 5, 2023. The incident affected 77 New Hampshire residents. CBIZ applied patches, investigated, and mailed notifications offering credit monitoring. Data exfiltrated included personal information.
- 🦞Maine State AGas victim2023-09-01
CBIZ, Inc. experienced an external system breach between May 29, 2023, and June 5, 2023, which was discovered on August 10, 2023. The breach affected 35,843 individuals, compromising their names and Social Security numbers. CBIZ notified affected consumers in writing on September 1, 2023, and offered complimentary credit monitoring and identity theft protection services through Kroll.
- 🐻California State AGas victim2023-09-01
CBIZ, Inc. notified California residents of a data breach involving its IT environment for client Mayer Hoffman McCann P.C. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer software, accessing a server between May 29 and June 5, 2023, and downloading data. Affected information includes names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and is offering two years of identity monitoring.
- 🍁Vermont State AGas victim2023-09-01
CBIZ, Inc. disclosed a data breach involving its MOVEit Transfer server, exploited via a vulnerability in Progress Software's software. Unauthorized access occurred between May 29 and June 5, 2023, resulting in the exfiltration of names, dates of birth, and Social Security numbers. CBIZ patched the vulnerability and offered two years of identity monitoring services.
- 🦬Montana State AGas victim2018-07-18
CBIZ MHM, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2018-07-18. The breach occurred from 5/2/2018 to 5/23/2018. 1 Montana residents were affected.
Subsidiary disclosures (9)filed by group companies
◈ These filings were made by or about subsidiaries of CBIZ, INC. — not by CBIZ, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia CBIZ Benefits & Insurance Services, Inc.2026-01-21
Diversified Benefit Services Insurance Marketing, Inc. reported that an unauthorized actor gained access to its email system on August 7, 2025, potentially downloading emails and files containing names, Social Security Numbers, and health insurance information. The company secured the environment, engaged forensic experts, and is offering credit monitoring and fraud assistance to affected individuals.
- 🦞Maine State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. reported a data breach affecting 7 Maine residents. The incident occurred between June 2, 2024, and June 21, 2024, and was discovered on June 24, 2024. The nature of the breach was not specified. The company is offering two years of credit monitoring and identity theft protection services through Kroll to those affected.
- OHHHS OCRvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. (OH), a business associate, reported to HHS on 2024-08-28 a Hacking/IT Incident affecting 9,602 individuals. PHI involved included names, Social Security numbers, and dates of birth, located on a Network Server. The BA notified HHS and affected individuals, provided substitute notice, offered complimentary credit monitoring, and implemented additional administrative, technical, and security safeguards.
- 🏎️Indiana State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-02 and was reported on 2024-08-28. 40 Indiana residents were affected. 7,006 individuals affected in total.
- ⛰️New Hampshire State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. notified the NH Attorney General of a security incident where an unauthorized party exploited a web page vulnerability to access databases containing retiree health and welfare plan information (including PII and PHI) for NH residents between June 2-21, 2024. CBIZ detected the incident on June 24, 2024, engaged cybersecurity professionals, fixed the vulnerability, and is offering credit monitoring via Kroll.
- 🍁Vermont State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc. notified consumers of a data breach where an unauthorized party exploited a web page vulnerability to access databases between June 2 and June 21, 2024. The incident involved PII and government IDs. CBIZ engaged forensic investigators, fixed the vulnerability, and provided two years of free identity monitoring via Kroll.
- 🦬Montana State AGvia CBIZ Benefits & Insurance Services, Inc.2024-08-28
CBIZ Benefits & Insurance Services, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2024-08-28. The breach occurred from 6/2/2024 to 6/21/2024. 1 Montana residents were affected.
- 🦬Montana State AGvia CBIZ Accounting, Tax & Advisory of Utah2021-03-30
CBIZ Accounting, Tax & Advisory of Utah reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-30. The breach occurred on 12/30/2020. 12 Montana residents were affected.
- ⛰️New Hampshire State AGvia CBIZ Accounting, Tax & Advisory of Utah2021-03-30
CBIZ Accounting, Tax & Advisory of Utah, LLC reported unauthorized access to a single employee's email account on December 30, 2020. The breach affected two New Hampshire residents, exposing names, Social Security numbers, and financial account numbers. CBIZ engaged a forensic firm, secured the account, and notified the NH Attorney General on March 30, 2021. Affected individuals received one year of credit monitoring via Kroll.