CBIZ Benefits & Insurance Services, Inc. recently experienced a significant data breach that has raised concerns among its clients and affected individuals. On June 24, 2024, the company discovered that an unauthorized party had potentially accessed information from certain databases. This breach was the result of a vulnerability exploited on one of CBIZ's web pages, which allowed the unauthorized party to acquire sensitive data between June 2, 2024, and June 21, 2024.
The breach affected individuals associated with multiple CBIZ clients, exposing their personal information. The types of information exposed include:
While the total number of affected individuals in the United States remains undisclosed, it is confirmed that 7 residents in the state of Maine were impacted. The breach was publicly disclosed on August 28, 2024, and the company has notified the Maine Attorney General's office as well as the Massachusetts Attorney General's office.
In response to the breach, CBIZ took immediate action by launching an investigation with the help of cybersecurity professionals. The company has since fixed the identified vulnerability and implemented additional security measures to safeguard its systems. CBIZ has also collaborated with the FBI to address the incident.
To support affected individuals, CBIZ is offering two years of complimentary credit monitoring and identity theft protection services. A dedicated, toll-free call center has been established to provide further information and assistance to those impacted by the breach.
If you believe you have been affected by this data breach, it is crucial to take proactive steps to protect your personal information. Here are some recommended actions:
CBIZ Benefits & Insurance Services, Inc. provides actuarial, administration, and investment advisory solutions for organizations. The company also offers recordkeeping and administration services for retiree health and welfare plans. CBIZ is committed to protecting the confidentiality and security of the information in its care and is taking steps to prevent future incidents.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.