DISA Data Breach Affects Over Three Million Americans

Published
February 24, 2025
Updated
August 28, 2026
DISA Data Breach Affects Over Three Million Americans
DISA

On April 22, 2024, DISA Global Solutions, Inc., a leading provider of employee screening and compliance services, discovered one of the biggest data breaches of the year, as it has affected approximately 3,332,750 individuals across the United States.

The breach, which occurred on two separate dates, February 9, 2024, and April 22, 2024, resulted in the exposure of a wide range of sensitive personal and health information.

The scale of the breach is notable, with 687,033 individuals affected in Texas, 360,473 in Massachusetts, 29,481 in Washington, 15,198 in Maine, 14,241 in Rhode Island and 11,088 in Iowa. The breach was additionally disclosed to state authorities in California, Oregon, Vermont between February 21 and February 27, 2025.

The breach exposed both personally identifiable information (PII) such as names, addresses, Social Security numbers, dates of birth, and government-issued ID numbers were exposed. Additionally, protected health information (PHI), including medical and health insurance details were involved.

DISA Global Solutions' response

Following the discovery of the breach, DISA Global Solutions, Inc. promptly notified affected individuals and relevant state authorities. The company used multiple notification methods to reach as many impacted people as possible, including U.S. mail, email, print media, and updates on its website. While details about specific support resources have not been provided, individuals whose information was compromised should take immediate steps to protect themselves.

If you believe you may have been affected by this breach, it is important to:

  1. Monitor your financial accounts and credit reports for any suspicious activity.
  2. Consider placing a fraud alert or credit freeze with the major credit bureaus.
  3. Watch for any signs of medical identity theft, such as unfamiliar medical bills or insurance claims.
  4. Be cautious of phishing attempts or scams that may use your exposed personal information.
  5. Contact your health insurance provider to review recent claims and ensure your coverage has not been misused.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
DISA
Consumers Notification date
February 21, 2024,
Date of Breach
02/09/2024, 04/22/2024
Breach Discovered Date
April 22, 2024
Total People Affected
3332750
Information Types Exposed
  • Name of individual
  • Address
  • Social Security Number Information
  • Driver’s License number
  • Government-issued ID number (e.g. passport, Social Security numbers, account numbers, addresses, credit card information, credit or debit card number)
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image