Menu
Browse

Cyber Incident Victim: PRGX Global

Date:

Apr 2022

Location:

United States of America

Summary

PRGX Global experienced a cybersecurity incident involving unauthorized access to its computer network, compromising sensitive consumer information including names, Social Security numbers, and financial account details. The breach impacted over 13,000 individuals and prompted the company to secure its systems, conduct an investigation with external specialists, and subsequently notify affected parties through formal data breach letters. The incident stemmed from an intrusion that allowed the unauthorized party to view and potentially download files containing confidential data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 9, 2022, PRGX Global, Inc. detected unauthorized access to portions of its computer systems, rendering them inaccessible. The Atlanta-based business services company immediately secured its network and initiated an internal investigation with assistance from data security specialists. Forensic analysis confirmed that an unauthorized actor had viewed and potentially downloaded certain files during a two-day window between April 8 and April 9, 2022. The compromised files contained sensitive consumer information, though the company did not disclose specific technical details about the attack vector or systems targeted. PRGX completed its review of affected data nearly thirteen months later, determining that exposed information included individuals' names, Social Security numbers, and financial account details. The breach impacted 13,231 consumers according to the company's filing with the Maine Attorney General's office.

Cyber Incident Image

PRGX formally notified state authorities about the data breach on May 5, 2023, and began distributing individual notification letters to affected parties the same day. The delayed disclosure timeline between the April 2022 intrusion and May 2023 notifications reflected the duration required for forensic investigation and data review. While the company did not specify containment measures beyond securing its network, the breach exposed victims to heightened risks of identity theft and financial fraud due to the sensitivity of compromised Social Security numbers and banking information. No information was provided regarding whether data appeared on dark web forums or whether attackers made specific demands. The incident affected a global client base across multiple industries served by PRGX's recovery audit and spend analytics services, though the notification did not identify specific corporate clients or business impacts beyond individual consumer data exposure.

Sources
Sources available to members
1 source