
Georgia-based data management company Drivestream Inc. said it suffered a major data breach incident in December 2024 that compromised sensitive information related to more than 91,000 customers.
The Suwanee, Georgia-based company, which helps business and enterprises migrate their employee data into Oracle cloud applications, recently announced that it suffered a major data breach incident between December 4 and December 9 in 2024 that impacted the information of 91,108 individuals.
The company sent notification letters to the offices of the Attorney Generals of Maine, Massachusetts and Oregon about the data breach incident, but did not specify how the breach occurred, whether it had suffered a ransomware incident, or why it took more than a year to notify affected individuals.
"Upon discovery, Drivestream promptly commenced an investigation to confirm the nature and scope of this incident. This investigation and response included confirming the security of our systems, reviewing the contents of relevant data for sensitive information, and notifying impacted individuals associated with that sensitive information," the company said.
"As part of our ongoing commitment to the privacy of personal information in our care, we are reviewing our policies, procedures, and processes related to the storage of and access to personal information to reduce the likelihood of a similar future event.
"We reported the incident to law enforcement and are cooperating with their investigation. We will also notify applicable regulatory authorities, as required by law," Drivestream added.
The company, however, provided more details about the data breach incident in a previous filing with the office of the Attorney General of Vermont in November 2025. In its filing, Drivestream said that it discovered unauthorised access to its systems on December 9, 2024, and subsequently determined that hackers had infiltrated its network on December 4 that year and exfiltrated certain files from its systems.
Drivestream said the data security incident occurred when it was in the process of migrating clients’ employee data to a new Human Capital Management system. The company began notifying affected individuals and clients on October 10, 2025 and is now offering complimentary credit monitoring and identity theft protection services for 24 months to all affected individuals.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543