Maryland-based insurance company Kelly & Associates Insurance Group (known as Kelly Benefits ) is notifying more than 553,000 people of a serious data breach that led to a leak of personal information .

The incident took place in 2024, between December 12 and 17, when unauthorized actors penetrated the company's information systems, extracting files with sensitive data. Although the company initially reported that 32,234 people had been affected, this number increased significantly in the following months, eventually reaching 553,660.
See also: Qantas: Cyberattack led to data breach
Kelly Benefits provides solutions to businesses and organizations in the area of employee benefits, payroll management, HRIS, etc. Many organizations use the services and, judging by the number of people affected by the data breach, things are serious.
In her latest update, Kelly listed 46 different entities that were directly affected by the attack. These include some of the largest healthcare organizations in the United States:
- United Healthcare
- Aetna Life Insurance Company (CVS Health)
- CareFirst BlueCross BlueShield
- Humana Insurance ACE
- The Guardian Life Insurance Company of America
- Mutual of Omaha Insurance Company
- OneAmerica Financial Partners, Inc.
Kelly Benefits: Sensitive personal and medical data exposed
Following the major data breach revealed by Kelly Benefits, thousands of people have already begun receiving alerts about the types of information that may have been leaked. According to the company, the nature of the data varies depending on the individual, but the general notice posted on the official website includes a worrying list of sensitive information.
See also: Johnson Controls: Notifies individuals about 2023 data breach
The information that was exposed may include:
- Full names
- Social security numbers
- Tax ID (tax identification numbers)
- Dates of birth
- Medical data
- Health insurance information
- Financial account details
Making such data public significantly increases the risk of phishing attacks , social engineering scams , and identity theft . Experts recommend that affected individuals be especially vigilant against suspicious communications and messages requesting personal information.

As a measure of immediate support, Kelly Benefits offers free credit monitoring for 12 months as well as protection services identity theft (through the IDX Identity Theft Protection platform).
Additionally, it is recommended to the recipients of the relevant notifications:
- Monitor bank and credit accounts closely for suspicious activity
- Consider the option of placing “freeze” (freeze) on their credit reports
- Promptly inform authorities in case of suspected fraud
See also: 263,000 people affected by Esse Health breach
The incident once again highlights the need for enhanced security measures in the healthcare and financial data sector, as the exposure of such information can have serious and long-lasting consequences for individuals. The Kelly Benefits is serious and concerning — not only because of the volume of individuals affected, but also because of the sensitivity of the information leaked.
What is also worrying is the length of time that has passed: the incident occurred in December 2024, but the final number of people affected was announced four months later. This makes it more difficult for citizens to react in a timely manner.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The situation is a loud warning not only for Kelly but for every company that handles critical citizen data.
Source: www.bleepingcomputer.com
