VeriSource Services , a company specializing in employee benefits management, announced that a security breach occurred that led to the leakage of personal data of approximately four million people.

The company began sending notifications to those affected by the incident, which occurred in February 2024.However, it took time (until April 2025) for them to gain a full picture of the incident.
See also: Telecom company MTN Group revealed data breach
As the internal investigation showed, unauthorized individuals gained access to sensitive information. According to an official announcement, on February 28, 2024, VeriSource detected unusual activity that caused access problems to some of its systems. Immediately after, measures were taken to protect the network, while VeriSource worked with a specialized cybersecurity company to investigate the incident and determine whether sensitive data was exposed.
VeriSource: Data Breach
The investigation concluded that unknown perpetrators may have gained access to personal information. The process of identifying the individuals whose personal data was exposed due to the breach was only completed on April 17, 2025. Official notifications of the breach were sent a few days later, on April 23.
According to the sample of the information provided to the Maine Attorney General's, the data that was potentially exposed includes basic personal information, such as the employee's full name, home address, date of birth, gender, and social security number.
See also: Yale New Haven Health: Data breach affects 5.5 million patients
In response to the incident, VeriSource is offering one year of free monitoring credit, identity theft protection , and identity restoration support.
It's worth noting that the company had sent notifications to around 55,000 people in May 2024 and another 112,000 in September of the same year. However, the investigation has now been completed, revealing that the VeriSource data breach affected a total of 4 million people.

This incident with VeriSource demonstrates a characteristic delay in fully understanding and communicating the extent of a serious data breach. The fact that it took over a year to identify all of the individuals affected – and that the total number increased so dramatically – raises legitimate questions about the company’s internal capacity to manage security incidents and transparency.
See also: Frederick Health: Data breach affects nearly 1 million patients
BleepingComputer reported that there are no records for VeriSource on data leak ransomware-related, which leaves the exact nature of the attack and the identity of the perpetrators unclear.
The absence of VeriSource from known ransomware leak sites may indicate either that the attack was not related to a traditional extortion campaign or that the perpetrators were not interested in making the data public. However, this does not reduce the risk, as the leaked data is extremely sensitive and could be used for financial fraud or identity theft.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
