TADTS comfirms ransomware attack with data breach notices to 748,763 people

Published
July 21, 2025
Updated
July 24, 2025
TADTS comfirms ransomware attack with data breach notices to 748,763 people
The Alcohol & Drug Testing Service
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

The Alcohol & Drug Testing Service

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

On July 9, 2024, The Alcohol & Drug Testing Service (TADTS) discovered a significant cybersecurity incident that resulted in the unauthorized download of sensitive data from its systems. The breach was extensive, affecting a reported total of 748,763 individuals across the United States. Among those impacted, 3,525 were Texas residents, while two individuals each were affected in Maine and Massachusetts.

The ransomware group, BianLian, claim credit for the attack. BianLian claimed to have 218 gigabytes of their data consisting of financial and HR records, drug test results, and email communications. The group made the announcement on the dark web.

screenshot of The Alcohol & Drug Testing Service on the dark web
The Alcohol & Drug Testing Service on the Dark Web

The disclosed types of compromised information included a wide range of personally identifiable information (PII) and protected health information (PHI): names, addresses, Social Security numbers, driver’s license numbers, government-issued ID numbers (such as passport or state ID card numbers), dates of birth, credit or debit card numbers, health insurance information, and financial account numbers.

When TADTS detected suspicious activity on July 9, 2024, they immediately began an investigation. The company confirmed that an unauthorized actor had downloaded data from its systems. The investigation, which involved a professional data mining team, took several months due to the volume of information involved. The review concluded recently, leading to the identification of affected individuals.

The breach was reported to federal law enforcement and disclosed to regulatory authorities in several states. Notices were filed with the Maine Attorney General and the Massachusetts Attorney General on July 17, 2025, followed by the Texas Attorney General and the Vermont Attorney General on July 18, 2025. The New Hampshire AG was notified on the 21st of July.

The company notified affected consumers by U.S. Mail, publication in print media, and postings on its website.

The Alcohol & Drug Testing Service's response

In response to the breach, TADTS acted quickly to contain and remediate the situation. The company reset all passwords, enhanced endpoint detection protocols, and implemented additional monitoring tools to strengthen system security. TADTS also engaged experienced privacy and cybersecurity professionals to assist with the investigation and response.

The company has provided resources to help affected individuals protect their information. These include a toll-free assistance line at 855-361-0328, available Monday through Friday from 8 a.m. to 8 p.m. Central Time, excluding U.S. holidays. The notice to consumers recommends that individuals remain vigilant, monitor their credit reports, review account statements, and report any suspicious activity to financial institutions. Additional resources and guidance, such as information on placing fraud alerts and security freezes with major credit bureaus, are included in the consumer notice.

Given the breadth of the data exposed—including Social Security numbers, financial account information, and health insurance details—affected individuals should take steps to protect themselves from potential identity theft or fraud. Reviewing credit reports regularly, placing fraud alerts, and considering a security freeze are prudent measures in light of the sensitive nature of the information involved.

More information about the company can be found on the TADTS website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
July 17, 2025
Date of Breach
Breach Discovered Date
July 09, 2024
Total People Affected
748763
Information Types Exposed
  • names
  • dates of birth
  • Social Security numbers
  • driver’s license/government-issued identification
  • passport numbers
  • bank/financial information
  • credit/debit card information
  • username and passwords
  • email and passwords

-

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image