Menu
Browse

Cyber Incident Victim: Creative Services, Inc.

Date:

Nov 2021

Location:

United States of America

Summary

A Massachusetts-based background check services provider experienced unauthorized network access, leading to potential exfiltration of files containing sensitive client information over a three-year period. The breach compromised personal data including names, birth dates, financial account details, Social Security numbers, and driver's license information affecting approximately 164,673 individuals. Following investigation, notification letters were distributed with offers of complimentary credit monitoring and identity theft services. The incident prompted four class-action lawsuits alleging insufficient data protection measures, with plaintiffs claiming failures to implement adequate security protocols and proper encryption standards. This marked the second security event disclosed within months for the organization, which acknowledged the breach while emphasizing ongoing enhancements to existing safeguards.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 26, 2021, Creative Services, Inc. (CSI), a Massachusetts-based background check and security consulting firm operating for 45 years, detected suspicious activity on its computer systems. Subsequent investigation revealed an unauthorized individual had accessed the company's network and potentially copied files spanning November 2018 through November 2021. By late January 2022, forensic analysis confirmed the compromise of personal identifying information belonging to CSI's clients, including names, dates of birth, financial account numbers, Social Security numbers, and driver's license numbers. The breach impacted approximately 164,673 individuals whose data resided in the accessed files. This incident occurred just two months after CSI notified over 1,000 individuals about a separate unauthorized access event involving their PII, though no direct connection between the two breaches was specified in available documentation.

Cyber Incident Image

In February 2022, CSI initiated mailed notifications to affected individuals and offered 24 months of complimentary credit monitoring, fraud consultation, and identity theft restoration services. The company acknowledged the breach in a privacy incident notice, stating it took the event seriously and was implementing enhanced security measures despite having existing safeguards. By March 2022, four parallel class-action lawsuits were filed against CSI in federal courts, including one by New York plaintiff Santos Acosta. The suits collectively alleged CSI failed to implement adequate security measures to protect sensitive PII, specifically citing insufficient data encryption practices and negligent cybersecurity policies. Plaintiffs contended these deficiencies enabled the breach and exposed individuals to identity theft risks, with Acosta's filing asserting CSI acted recklessly by not maintaining reasonable safeguards for the background check data it collected.

Sources
Sources available to members
1 source