[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3euoth137fz9v":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":4,"isSpamList":35,"isMalware":35,"company":36},"6a71b30ee5e0d1b176042bfd","Benefitelect2025","Benefitelect Data Breach","benefitelect-2025","benefitelect.com","2025-03-30T00:00:00.000Z","2026-08-04T09:38:22.139Z","Benefitelect consumer notice filed with the Massachusetts Attorney General","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-1767-coalesce-llc-dba-benefitelect\u002Fdownload",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fbenefitelect.com\u002F",29023,"known",null,"people","Medium",[24,25,26,27,28,29],"Names","Physical addresses","Dates of birth","Social security numbers","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The Benefitelect data breach\u003C\u002Fstrong> was a security incident in which certain files on the employee benefits administration platform were accessed and exfiltrated without authorisation. The company's official notice places the access on 30 and 31 March 2025.\u003C\u002Fp>\u003Cp>The Texas Attorney General reports that the incident affected 29,023 people across the United States. A company letter filed with the Massachusetts Attorney General independently confirms the same event timeline and the principal categories of affected information.\u003C\u002Fp>\u003Ch2>How was the incident discovered?\u003C\u002Fh2>\u003Cp>Benefitelect said it was alerted to suspicious activity on its systems on 2 April 2025. It secured the environment and began an investigation with third-party specialists.\u003C\u002Fp>\u003Cp>The investigation found that certain files were accessed or exfiltrated without authorisation between 30 and 31 March. The company then conducted a review to identify the people whose information was involved.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The company letter says the files contained benefits eligibility and onboarding census information. The disclosed fields were names, physical addresses, dates of birth and Social Security numbers.\u003C\u002Fp>\u003Cp>The Texas regulator entry also lists medical information and health insurance information. Passwords and financial account information were not added because the official sources do not confirm those categories.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports 29,023 affected people in total, including 4,054 Texas residents. The catalog count is the nationwide affected-person total.\u003C\u002Fp>\u003Cp>The Massachusetts record identifies 155 residents of that state. It is a state subset of the same nationwide event, not a separate incident, and state counts were not added together.\u003C\u002Fp>\u003Ch2>How could the information be misused?\u003C\u002Fh2>\u003Cp>A Social Security number combined with a date of birth and address can create persistent risk of fraudulent credit applications, impersonation and account-recovery abuse.\u003C\u002Fp>\u003Cp>The benefits and health-insurance context may make targeted messages about open enrollment, insurance claims or employer notices appear convincing. A message containing accurate personal details should still be verified independently.\u003C\u002Fp>\u003Ch2>What did Benefitelect do?\u003C\u002Fh2>\u003Cp>The company said it secured its systems, investigated with outside specialists, reviewed existing security policies and implemented additional cybersecurity measures.\u003C\u002Fp>\u003Cp>Eligible notice recipients were offered complimentary credit monitoring and identity-theft protection through IDX. At the time of the notice, the company said it was not aware of actual or attempted misuse of the information.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Recipients should verify an IDX enrollment code only against their own official letter and review credit reports, account statements and health-insurance explanation-of-benefits records for unfamiliar activity.\u003C\u002Fp>\u003Cp>Known contact channels for an employer or insurer should be used instead of links in unexpected benefits messages. Because Social Security numbers were involved, a fraud alert or credit freeze may also be appropriate.\u003C\u002Fp>","","Benefitelect Data Breach (29 Thousand People Affected)","Review the verified Benefitelect breach dates, the 29,023 people affected, the information involved and practical protective steps.","https:\u002F\u002Fbenefitelect.com\u002Fwp-content\u002Fuploads\u002F2023\u002F01\u002FBE_Logo-Tagline-Refresh_FINAL.jpg",false,{"name":37,"sector":38,"country":39,"website":10,"websiteArchiveUrl":31,"websiteStatus":40,"websiteCheckedAt":12},"Benefitelect","Business Services","United States","active"]