2024 DISA Global Solutions — confirmed hack; 3.3M people (Maine AG); SSNs, DLs, financial IDs
Data compromised
Per DISA/Maine filing: names, SSNs, driver’s license or other government ID numbers, financial account information, and other data elements (varies by individual). Current, former, and prospective employees of DISA customers may be affected.
Technical writeup
Verified company and regulator notice — disclosed August 2026 in national press citing a Maine Attorney General filing. DISA Global Solutions (Houston employee screening and drug-testing vendor serving ~55,000 enterprises including Fortune 500 clients) said it discovered a breach on 22 April 2024 with activity dating to 9 February 2024, labeled as external hacking. Maine regulators list 3,300,000 affected individuals — current, former, and prospective employees of customer organizations. Data may include name, SSN, driver’s license or other government IDs, financial account information, and other elements varying by person. DISA said it was unaware of attempted or actual misuse as of its notice and is offering Experian credit monitoring. Supersedes the earlier California AG stub row disa-global-solutions-inc-2025-ca-20250310 on census and field detail. recordsAffected 3300000 from Maine filing via The Record.
Root cause
External hacking (company notice); illicit activity traced to 9 February 2024, discovered 22 April 2024