Massive Data Breach at Kelly Associates Exposes Over 410,000 Users’ Private Details

Massive Data Breach at Kelly Associates Exposes Over 410,000 Users’ Private Details

Kelly Benefits Cyberattack Exposes Private Data of Over 410,000: Scale of Breach Far Greater Than First Reported

A wide-reaching cyberattack has rocked Kelly & Associates Insurance Group—known publicly as Kelly Benefits—as it now confirms the personal data of over 413,000 individuals was compromised in a previously underreported breach.

Timeline of the Breach

The breach occurred silently over a five-day period from December 12 to 17, 2024, during which attackers gained unauthorized access to Kelly Benefits’ internal systems. Though initial disclosures in early April cited roughly 32,000 affected individuals, the number surged in a matter of days, ultimately ballooning to more than 410,000, according to filings with the Maine Attorney General’s Office.

What Was Stolen

An internal investigation concluded in March 2025 revealed that hackers accessed and extracted documents containing highly sensitive personal data. This includes:

  • Full names
  • Social Security numbers
  • Birthdates
  • Tax ID numbers
  • Bank account details
  • Health insurance and medical records

This type of information presents a high-value target for identity theft and fraud, and cybersecurity analysts caution that the long-term impact of such leaks can persist for years.

Response and Notification

In response, Kelly Benefits undertook a granular file review to determine exactly whose data had been compromised. The company has since begun issuing breach notifications on behalf of several prominent clients, such as CareFirst BlueCross BlueShield, Guardian Life, and Beltway Companies, among others.

The company has also alerted the FBI and is offering one year of free credit monitoring and identity protection services.

Ongoing Fallout

While the nature of the breach remains unclear—no ransomware group has claimed responsibility—legal consequences are already taking shape. Several law firms have begun investigating potential class-action lawsuits, accusing Kelly Benefits of failing to secure sensitive data in accordance with standards like HIPAA and the FTC Act.

A central claim is that the company exhibited “negligence in protecting consumer information”, raising broader questions about risk management and oversight in the healthcare and benefits industry.

A Broader Warning

This breach underscores a sobering trend: organizations handling vast amounts of personal data remain prime targets for sophisticated cyber threats. As regulators and consumers alike demand greater accountability, Kelly Benefits now finds itself at the center of a growing storm—one that may reshape how sensitive employee benefits data is secured in the future.

More Articles & Posts