Data Leak

Kelly Associates Data Breach Exposes 410,000+ Users Personal Data

A data breach at Kelly & Associates Insurance Group (operating as Kelly Benefits) has exposed sensitive personal information of more than 410,000 individuals, significantly more than initially reported.

The Maryland-based benefits administration and payroll solutions provider confirmed that cybercriminals infiltrated its computer systems between December 12 and December 17, 2024.

According to recent notifications to the Maine Attorney General’s Office, the scope of the breach has grown dramatically since it was first reported. The company initially disclosed in early April that approximately 32,000 people were affected.

That number increased to nearly 264,000 just ten days later. The latest reports indicate the total has now exceeded 413,000 individuals.

The investigation, completed in early March 2025, revealed that unauthorized actors accessed and exfiltrated files containing highly sensitive personal information.

The compromised data includes names, Social Security numbers, dates of birth, tax identification numbers, financial account information, and health insurance and medical information.

Exposure of Personal Data

“Kelly Associates then began a time-intensive and detailed review of all files affected by this event to determine what information was present in the impacted files and to whom it related,” the company stated in its breach notification. The company has reported the incident to the Federal Bureau of Investigation.

Kelly Associates is notifying affected individuals on behalf of several major clients, including Amergis, Beam Benefits, Beltway Companies, CareFirst BlueCross BlueShield, Guardian Life Insurance Company of America, Intercon Truck of Baltimore, Publishers Circulation Fulfilment, Quantum Real Estate Management, and Transforming Lives.

Cybersecurity experts have not determined whether the breach was part of a ransomware attack, as no known ransomware group has claimed responsibility for the incident. The company has declined further comment, citing “the sensitive nature of the incident and subsequent investigation”.

Multiple law firms have launched investigations into the breach, with several pursuing potential class action lawsuits on behalf of affected individuals. One complaint alleges that Kelly Benefits “negligently failed to protect the personal information of thousands of people” and breached its duties under various laws, including HIPAA and the FTC Act.

The company is offering affected individuals 12 months of credit monitoring and identity protection services at no cost. Cybersecurity experts recommend that victims remain vigilant against potential identity theft and fraud by regularly monitoring credit reports and account statements for suspicious activity.

As data breaches continue to plague companies handling sensitive information, this incident highlights the growing scale and impact of such security failures on consumers.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago