2025 Tungsten Automation (fka Kofax) — corporate IT intrusion; ~5.5k employees/former staff
Data compromised
Workforce PII held in HR/payroll systems per notification templates
Technical writeup
Tungsten Automation Corporation—successor brand to Kofax, Inc.—notified regulators of a cybersecurity incident discovered May 27, 2025, after unauthorized access beginning May 20, 2025, to internal IT systems. Consumer-facing breach summaries and Maine Attorney General filings cite 5,556 affected individuals (current and former employees) with exposure of identifiers spanning SSN, DOB, contact data, driver-license numbers, and financial account details in some notices; the firm stated customer/partner production datasets were not impacted. Complimentary credit monitoring was offered.
Root cause
External intrusion into corporate network segment (detailed TTP limited in public notifications)
References
- https://securityledger.com/2025/08/tungsten-automation-data-breach-what-you-need-to-know/
- https://sharedserviceslink.com/news/tungsten-automation-notifies-clients-of-cybersecurity-incident
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/37b04f5a-9289-4adc-ace3-edb87ebc32b2.html