[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3hw5mlkcvlno":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":25,"affectedCount":25,"affectedCountStatus":26,"affectedCountLowerBound":13,"affectedCountUnit":27,"hasEnglishDescription":4,"contentLocale":28,"availableLocales":29,"translations":31,"severity":34,"dataClasses":35,"description":44,"seoTitle":45,"seoDescription":46,"logoUrl":47,"isVerified":4,"isSensitive":4,"isSpamList":48,"isMalware":48,"company":49},"6a4f95193384083f42ce5f47","Decisely 2024","Decisely 2024 Data Breach","decisely-2024","decisely.com","2024-12-16T00:00:00.000Z","2026-07-09T12:33:29.371Z",null,"2026-07-19T00:11:12.040Z","Official notice; state regulator notice; healthcare security reporting; official organization website and logo","https:\u002F\u002Fdecisely.com\u002Fwp-content\u002Fuploads\u002F2025\u002F06\u002Fdecisely_website_notice_12560425-6.pdf",[16,18,19,20,21,22,23,24],"https:\u002F\u002Fago.vermont.gov\u002Fdocument\u002F2025-06-13-decisely-insurance-services-data-breach-notice-consumers","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002Fassigned-data-breach-number-2025-1077-decisely-insurance-services-llc\u002Fdownload","https:\u002F\u002Fwww.classaction.org\u002Fdata-breach-lawsuits\u002Fdecisely-june-2025","https:\u002F\u002Fwww.hipaajournal.com\u002Fdata-breaches-decisely-insurance-services-apex-global-solutions\u002F","https:\u002F\u002Fdecisely.com\u002F","https:\u002F\u002Fdecisely.com\u002Fabout-us","https:\u002F\u002Fdecisely-marketing-site-assets.s3.us-west-2.amazonaws.com\u002Fbranding\u002Fdecisely_logo.svg",537603,"known","unknown","en",[28,30],"tr",{"en":32,"tr":33},{"slug":9},{"slug":9},"High",[36,37,38,39,40,41,42,43],"Names","Dates of birth","Phone numbers","Passport numbers","Digital signatures","Social security numbers","Financial account information","Protected health information","\u003Cp>The Decisely 2024 data breach is an incident of unauthorized data acquisition that occurred in the cloud storage environment related to benefits administration, human resources, payroll, compliance, and retirement services conducted by Georgia-based Decisely Insurance Services, LLC. The organization noticed suspicious activity in the cloud storage environment on December 17, 2024, and initiated an investigation. The investigation determined that some personal information may have been acquired by an unauthorized party on December 16, 2024.\u003C\u002Fp>\n\u003Cp>This record addresses the Decisely 2024 data breach in terms of individuals who may have been affected through employers, benefit plan providers, MetLife-related records, and Decisely customers. The number of affected individuals appeared lower in the initial notifications and later increased to 537,603 in the federal health breach record. This number is not the verified unique online account count that was leaked, but the impact count used for individuals who were notified or may have been affected in connection with the incident.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Within the scope of the Decisely 2024 incident, the types of data that may be at risk are name and surname, date of birth, phone number, passport number, digital signature, Social Security number, and financial account information. Since the organization's announcements mention personal information and protected health information, the incident also carries the risk of sensitive benefit and health-related records. However, additional fields not directly listed in this record, such as health insurance, have not been used as a data class.\u003C\u002Fp>\n\u003Cp>Since social security numbers and passport numbers are permanent identity fields, they can be misused in credit applications, fake account openings, official transaction fraud, and identity verification processes. Digital signatures are sensitive areas that can be used to give the impression of fake documents or authorization. For individuals with financial account information, bank transactions, automatic payment instructions, and account change requests should be monitored carefully. Phone numbers and dates of birth create additional risks in targeted fraud and identity verification stages when combined with other information.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In this record, the violation date has been used as December 16, 2024, and the date the incident was noticed as December 17, 2024. Notifications began around June 13, 2025, and the number of people increased later. The initial publicly disclosed health notifications mentioned 65,405 people, and the most recently updated impact count has been reported as 537,603. Therefore, the record uses the current expanded count rather than the early number; it is clearly stated in the text that this is not a tally of records but the number of individuals affected in the scope of the incident.\u003C\u002Fp>\n\u003Cp>Data types may vary on an individual basis. While some individuals may only have limited fields such as name and phone number, others may have Social Security numbers, passport numbers, digital signatures, or financial account information. The record focuses on the notification process carried out through Decisely's own services and related data owners. Since there is an allegation of unauthorized acquisition from the cloud storage environment, the risk is not limited to the possibility of viewing alone, but also includes scenarios in which some information may have been obtained.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk consists of small businesses served by Decisely, employers, benefit plan providers, and individuals whose records are processed through human resources and payroll processes. A person may not recognize the name Decisely directly, because the record may have originated through their employer, benefit provider, retirement service, payroll process, or health\u002Fbenefit program. Therefore, the notified individuals should consider not only whether they have a Decisely account, but also their employment institution and benefit plan history.\u003C\u002Fp>\n\u003Cp>Individuals with a Social Security number or passport number carry a higher risk in terms of identity theft. People with financial account information should regularly review banking and payment transactions. Those affected by digital signatures should be cautious about forms, authorization documents, or account change requests issued in their name. Individuals with a phone number and date of birth should be cautious about calls and messages claiming to be from employers, insurance, payroll, retirement, or benefits update purposes.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Individuals who may have been affected by the Decisely 2024 data breach should first check which types of data are included in the notification they received. If it contains a Social Security number or passport number, a credit report should be obtained, and options such as credit freeze or fraud alert should be considered. If financial account information is included, bank transactions, automatic payment instructions, and new account openings should be monitored regularly. If a digital signature is affected, account changes and authorization requests should also be checked.\u003C\u002Fp>\n\u003Cp>Individuals whose phone numbers and birth dates are known should not click on unexpected links that arrive under the pretext of benefit renewal, employer forms, payroll corrections, retirement plans, or identity protection. For genuine communication, official channels listed in the notification or independently known should be used. Employees or former employees should clarify with their employer's human resources department which data subject made the notification and which plan is affected. If financial and identity risks occur simultaneously, the steps should be carried out together.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In this incident, protection should be long-term because identity, passport, digital signature, and financial account information can be included in the same notification set. Password changes may be useful for benefits or payroll accounts; however, areas like Social Security numbers, passport numbers, and digital signatures are permanent or hard-to-change information. Users should review their credit reports at regular intervals, be aware of the risk of fraudulent applications during tax periods, and use alerts to detect new account openings early.\u003C\u002Fp>\n\u003Cp>On the employer and benefit plan side, the open enrollment period, payroll changes, retirement contributions, bank account changes, and dependent information updates should be carefully checked. Users should access the employer portal directly from a known address and should not consider links in emails or messages as reliable on their own. In events involving backend service providers like Decisely, users may not recognize the company name; therefore, the employer, data owner, date, and data types mentioned in the notification should be evaluated together.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The record check on this page allows the user to see identity, benefit, financial, and protected health information records that may be associated with the Decisely 2024 data breach. A match does not mean that all types of data listed were exposed for the same person. Users should rely on the fields in their own notification text and which employer or benefit relationship they were affected through.\u003C\u002Fp>\n\u003Cp>Users who are matched should prioritize permanent and hard-to-stop areas of misuse. Credit and official transaction checks for Social Security numbers and passports, bank checks for financial account information, authorization and form checks for digital signatures, and benefit and health program records for protected health information are important. The Decisely 2024 data breach is a significant third-party data security incident showing that data held by benefit and human resources providers serving small businesses could pose large-scale individual risk.\u003C\u002Fp>","Decisely 2024 Data Breach (537.6 Thousand Reported Records)","Decisely 2024 Data Breach. 537.6 Thousand reported records are reported. Reported data: Names, Dates of birth, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdecisely-2024.svg",false,{"name":50,"sector":51,"country":52,"website":10,"websiteArchiveUrl":53,"websiteStatus":53,"websiteCheckedAt":13},"Decisely Insurance Services, LLC","Benefits brokerage and human resources services","United States",""]