Form I-9 Compliance
ent_115b992a32165738
Disclosures
16
State AG · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
193,612
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Form I-9 Compliance
- Normalized
- form i 9 compliance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (16)newest first
- Maine State AGas victim2024-11-07
Form I-9 Compliance reported an external system breach (hacking) occurring between Feb 5 and Apr 12, 2024, discovered on Apr 12, 2024. The incident affected 193,612 individuals nationwide, including 183 Maine residents. Personal information including names and addresses was compromised. The company engaged external experts, reset credentials, and offered 24 months of credit monitoring via Experian.
- South Carolina State AGas victim2024-10-17
Form I-9 Compliance reported a cybersecurity incident where an unauthorized third party accessed its network on or about February 5, 2024. The company became aware of the activity on April 12, 2024. Affected data included names and addresses. The company engaged external experts, reported to law enforcement, reset credentials, and offered credit monitoring.
- Oregon State AGas victim2024-10-16
Form I-9 Compliance reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-16. The breach occurred during 2/5/2024 - 4/12/2024. The breach was discovered on 4/12/2024. 169,200 individuals were affected. Notice was sent on 1/1/0001.
- Washington State AGas victim2024-10-16
Form I-9 Compliance notified the Washington AG of a cybersecurity incident occurring on Feb 5, 2024, discovered April 12, 2024. Unauthorized access affected PII including SSNs, driver's licenses, and biometrics. Notifications began May 31, 2024. 2,852 WA residents notified. Remediation included credential resets and credit monitoring.
- New Hampshire State AGas victim2024-10-15
Form I-9 Compliance reported a cybersecurity incident where an unauthorized third party accessed its network via a compromised third-party IT provider account on or about Feb 5, 2024. Discovered April 12, 2024, the incident affected approximately 72 New Hampshire residents, exposing personal information including SSNs and driver's licenses. Notifications began May 31, 2024.
- Vermont State AGas victim2024-10-12
Form I-9 Compliance reported a cybersecurity incident where an unauthorized third party accessed its network between Feb 5 and Apr 12, 2024. The breach affected customer personal information including name, address, and other data elements. Form I-9 engaged external experts, reset credentials, and offered 24 months of credit monitoring. No fraud was detected at the time of filing.
- Maine State AGas victim2024-10-11
Form I-9 Compliance reported an external system breach (hacking) occurring between Feb 5 and Apr 12, 2024. The incident affected 96,982 individuals, including 58 Maine residents. Personal information such as name and address was compromised. The company engaged external experts, reset credentials, and offered 24 months of credit monitoring.
- California State AGas victim2024-10-11
Form I-9 Compliance experienced unauthorized access to its network on February 5, 2024, discovered on April 12, 2024. An external actor accessed personal information including names and addresses. The company contained the incident, reset credentials, and engaged forensic experts. Two years of credit monitoring were offered to affected individuals.
- Illinois State AGas victim2024-10-01
FORM I-9 COMPLIANCE filed a data-breach notice with the Illinois Attorney General in October 2024 (case 24-10-030). The register records the breach as discovered on February 5, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2024-06-10
Form I-9 Compliance notified the NH AG of a cybersecurity incident affecting approximately 13 NH residents. Unauthorized access occurred on Feb 5, 2024, via compromised credentials from a third-party IT provider. Discovered April 12, 2024. Data included basic PII. Remediation included disabling legacy app, rebuilding on Azure, and implementing MFA.
- Maine State AGas victim2024-05-31
Form I-9 Compliance, a professional services firm based in Newport Beach, California, reported an external system breach (hacking) occurring between February 5, 2024, and April 12, 2024. The incident compromised the names and Social Security Numbers of 27,592 individuals, including 16 Maine residents. The company notified affected individuals in writing on May 31, 2024, and provided 24 months of identity theft protection and credit monitoring through Experian.
- Massachusetts State AGas victim2024-05-31
Form I-9 Compliance reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-05-31. 2,565 Massachusetts residents were affected.
- California State AGas victim2024-05-31
Form I-9 Compliance experienced unauthorized access to its network on February 5, 2024, discovered on April 12, 2024. An external actor accessed employee and customer data related to Form I-9 employment verification services. The company contained the incident, reset credentials, engaged forensic experts, and offered credit monitoring.
- Indiana State AGas victim2024-05-31
Form I-9 Compliance reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-05 and was reported on 2024-05-31. 2,206 Indiana residents were affected. 96,982 individuals affected in total.
- Montana State AGas victim2024-05-31
Form I-9 Compliance experienced unauthorized network access on or about February 5, 2024, discovered on April 12, 2024. The incident involved personal information of customers. The company engaged external experts, reset credentials, and reported to law enforcement. No fraud was identified at the time of notification.
- New Hampshire State AGas victim2014-06-09
Form I-9 Compliance reported an incident on May 29, 2014, where an internal individual accessed another employee's I-9 form without authorization due to a system error. The affected data included name, address, birth date, SSN, driver's license, phone, and email. The company corrected the system error, investigated for other occurrences, and notified the affected employee.