TALX
ent_cd76b1f57ae34f2f5e2503ee
Disclosures
13
State AG · 5 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,467
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TALX
- Normalized
- talx— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- EQUIFAX INC.— as stated in the breach filing
Disclosure history (13)newest first
- New Hampshire State AGas reporting2019-09-03
TALX Corporation, a subsidiary of Equifax, provided a supplemental notification to the New Hampshire Attorney General regarding a security incident affecting CVS Health employees. On July 8, 2019, TALX discovered that an unauthorized individual accessed the account of one NH resident, potentially viewing their 2015 W-2 form. The access occurred on December 10, 2016, via Knowledge-Based Authentication (KBA) bypass. TALX has implemented MFA and fraud prevention tools.
- New Hampshire State AGas reporting2018-02-07
TALX Corporation, a subsidiary of Equifax, notified the New Hampshire Attorney General of a data security incident affecting one Entergy Services, Inc. employee. An unauthorized third party gained access to the employee's W-2 via the TALX online portal by answering personal security questions to reset a PIN. The incident occurred on June 21, 2017. TALX and Entergy terminated the portal service and offered 24 months of identity protection services.
- Massachusetts State AGas victim2017-08-28
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-08-28. 30 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2017-08-22
TALX Corporation, a subsidiary of Equifax, filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to Whole Foods Market employees' online payroll portal accounts. The incident involved unauthorized access between April 18, 2016, and July 17, 2017, affecting 4 New Hampshire residents. Data accessed included W-2 forms (SSN, earnings) and personal details. TALX notified law enforcement and the IRS, implemented enhanced fraud monitoring, and offered identity protection services.
- New Hampshire State AGas victim2017-07-21
TALX Corporation, a payroll services provider, notified the NH Attorney General of a data security incident affecting 12 NH residents (employees/family of Whole Foods Market). Unauthorized third parties accessed online portal accounts between April 2016 and April 2017 by answering personal security questions to reset PINs. Exposed data included W-2s, 1095-Cs, SSNs, names, addresses, and health insurance info. TALX notified law enforcement/IRS, enhanced security, disabled personal questions, and offered 2 years of identity protection.
- Massachusetts State AGas victim2017-07-17
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-17. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-07-03
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-03. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-06-02
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-06-02. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2017-05-23
TALX Corporation, a payroll services provider for Allegis Group, reported unauthorized access to employee online portal accounts between January 4, 2016, and March 29, 2017. Attackers reset PINs by answering personal security questions, accessing W-2 and 1095-C tax forms containing SSNs, names, addresses, and earnings/health insurance data. TALX notified law enforcement and implemented enhanced fraud monitoring and PIN resets.
- New Hampshire State AGas reporting2017-05-19
TALX Corporation, a subsidiary of Equifax, notified New Hampshire AG regarding unauthorized access to Erickson Living employee accounts. Attackers used social engineering to reset PINs and access W-2 forms. Incident occurred between April 2016 and March 2017. Two NH residents notified.
- New Hampshire State AGas reporting2017-05-15
TALX Corporation, a payroll service provider for Erickson Living, notified the NH AG of unauthorized access to employee accounts. Attackers used pretexting to reset PINs, accessing W-2 forms. Incident occurred between April 2016 and March 2017. Two NH residents were notified.
- Washington State AGas victim2017-05-15
TALX Corporation, a subsidiary of Equifax, disclosed a cyberattack affecting payroll data for Allegis Group employees. Unauthorized parties accessed accounts between Jan 2016 and Mar 2017 by answering personal security questions to reset PINs. Data exposed included names, SSNs, DOBs, and financial info. 1,467 Washington residents were notified in May 2017. TALX engaged forensic investigators, enhanced security controls, and offered 2 years of identity protection.
- Montana State AGas victim2017-05-11
TALX Corporation, a subsidiary of Equifax, notified individuals of unauthorized access to payroll portal accounts between Jan 2016 and Mar 2017. Attackers used personal info to reset PINs. Data exposed included W-2/1095-C forms, SSNs, names, addresses, and financial info. TALX notified law enforcement and IRS, reset credentials, and provided 24 months of identity protection.