ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

WebTPA data breach compromised the data of close to 2.5 million individuals

The personal information of close to 2.5 million individuals were compromised following a major cyber security incident at WebTPA Employer Services.

 

Texas-based WebTPA Employer Services, commonly known as WebTPA, provides administrative services to several benefit plans and insurance companies in the United States.

 

The company announced in a data security incident notice on its website that on December 28, it identified suspicious activity in its internal network and carried out an investigation, with assistance from external cyber security experts, to determine the nature and scope for the incident.

 

WebTPA said it also took steps to mitigate the threat, secured its affected network, and notified relevant law enforcement agencies about the incident.

 

“The investigation concluded that the unauthorised actor may have obtained personal information between April 18 and April 23, 2023. WebTPA promptly informed benefit plans and insurance companies about the incident and the potential exposure of personal information. WebTPA then diligently worked to confirm the extent of impacted data, which we provided to benefit plans and insurance companies on March 25, 2024,” it said.

 

According to the investigation, the compromised data included names, contact information, dates of birth, dates of death, Social Security numbers, and insurance information. A filing with the U.S. Department of Health and Human Services Office for Civil Rights states that at least 2,429,175 individuals were impacted by the data breach.

 

WebTPA added that financial data including account information or credit card numbers, and treatment or diagnostic information were not impacted by the incident.

 

While WebTPA found no evidence of the compromised information being misused, it has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.

 

It has also offered two years of complimentary identity protection and credit monitoring services through Kroll to all affected individuals.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543