- Disa confirms that hackers were present for over two months
- The siphoned sensitive data about hundreds of thousands of users
- The company did not say how it was compromised
US employee screening company Disa has confirmed to suffer a cyberattack where it lost sensitive customer data.
In a letter of violation sent to affected persons as well as in reports filed with Maine and Massachusetts Attorney General Contor, the company said it discovered a violation affecting a “limited part” of its network, on April 22, 2024.
The subsequent study determined that the threat actors who were not named gained access to the company’s infrastructure on February 9 and stayed for almost three months, during which period Crooks managed to get “some information” about DISA’s customers.
3.3 million affected
“Although our forensic examination could not definitively complete the specific data that was acquired, DISA conducted a detailed and time -intensive review of the files concerned to identify the personal information contained therein,” the letter reads.
The company added that there is currently no evidence suggesting that the data was abused in other attacks.
In the filing at Maine Attorney General, DISA said the total number of people affected is 3,332,750. In the filing at Massachusetts AG, it said the stolen data included people’s social security number, financial account information (credit card numbers included) and government -issued identification documents – more than enough data to run phishing fraud, identity theft and even wire fraud.
We do not know who the striker was or what their final goals are. We also do not know how they managed to infiltrate DISA and whether they were trying to extort the company for the stolen information.
Disa Global Solutions is a prominent American company that specializes in employee background screening, drug and alcohol tests and compliance solutions. According to its site, DISA serves over 55,000 customers across different industries, including transport, energy, manufacturing and healthcare. Allegedly user approx. 30% of the Fortune 500 companies DISA’s services.
Via Techcrunch