API Financial Solutions, a Missouri-based financial service company, suffered a major data breach that compromised the sensitive personal information of more than 71,000 individuals.
API Financial Solutions provides payroll, human relations, and hiring services to corporate customers in the US. It also provides employee benefit services to its clients.
In a filing with the Office of the Maine Attorney General, API Financial said that around June 28, it became aware of a cyber security incident that affected “limited number of API Financial Solutions documents.”
Immediately after identifying the cyber attack, the organisation launched an internal investigation to understand the nature and scope of the incident and took steps to mitigate the impact and contain the incident.
On August 30, API Financial
concluded that the compromised documents contained sensitive personal inflations of its clients.
The compromised data includes names, Social Security Numbers, drivers license numbers, passport numbers, financial account information including debit and credit card numbers along with its security code, access code, password or PIN for the account.
The filing with the Mine Attorney General’s Office also confirms that at least 71,886 individuals have been affected by the cyber security incident. On September 29, API Financial Solutions sent out data breach notification letters to all individuals affected by the data breach.
The company is also providing a year of complimentary credit monitoring and identity theft protection service via IDX to every individual whose data has been compromised during the incident.
“Please accept our apologies that this incident occurred. We are committed to maintaining the privacy of personal information in our possession and have taken many precautions to safeguard it,” API Financial said in its letter to affected customers.
“We continually evaluate and modify our practices and internal controls to enhance the security and privacy of your personal information,” it added.