ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Benefits plan provider Aviben says third party software breach impacted 40,000 customers

Linked InXFacebook
bookmark_borderSave to Library

Educators Benefit Consultants, a health and retirement benefit provider based in Cambridge, Massachusetts, said it experienced a data security incident that compromised the sensitive personal information of almost 40,000 individuals.

 

Educators Benefit Consultants, also known as Aviben, designs and manages health and retirement benefit plans for employees at public school and municipal sectors. Its offerings include employer-sponsored benefit plans to help workers get refunds on certain expenses, tax-free savings programs, retirement plans, and medical care support plans.

 

In a filing with the Office of Maine Attorney General, the company said that on February 22, it became aware of a data security incident that affected its internal network.

 

The company promptly launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to secure the affected network and notified law enforcement about the same.

 

“The investigation determined that the incident resulted from a zero-day vulnerability in a software program used by an external IT provider (meaning a security vulnerability that is exploited before it has been patched by the software company),” reads the notice.

 

The compromised data included names, Social Security numbers, and dates of birth. Aviben’s filing with the Maine state regulator also revealed that at least 39,640 individuals were impacted by the incident.

 

“The security and privacy of personal data remain among our highest priorities. Although the network vulnerability originated from an application used by an external IT provider, we have been conferring with cybersecurity experts to analyze and enhance our internal security architecture,” Aviben added.

 

The company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.

 

It has also offered one year of complimentary identity protection and credit monitoring services through TransUnion to all affected individuals.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543