A data breach at a U.S. employee screening company has leaked the personal information of more than 3.3 million people, Newsweek reports.
DISA Global Solutions, a background check and drug testing company for major U.S. companies, said it was the victim of a “cyber incident” in which hackers accessed the private information, including Social Security numbers, credit card and government ID numbers, of more than 3 million people.
DISA's customer list includes one-third of Fortune 500 companies.
The leak represents a major cybersecurity breach for a particularly sensitive industry, the media outlet said.
On Monday, DISA filed a statement with the attorney general of the U.S. state of Maine saying that the attack, which occurred on February 9, 2024, went unnoticed for two months and the company “was unable to conclusively determine what data was compromised.”
The statement confirms that 3,332,750 people were affected by the attack and that identity theft protection services were offered.
DISA's website says the company offers nine different screening and compliance solutions, ranging from drug and alcohol testing to medical tests such as physical exams and health screenings.

















