Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationmass-credential-exposure

Kelly Benefits Reports Data Theft After Unauthorized Network Access

Updated 1mo agoFirst seen Apr 29, 20265 sources

Kelly & Associates Insurance Group, Inc. (Kelly Benefits) disclosed that an unauthorized party accessed its environment between December 12 and December 17, 2024 and copied certain files from its systems. The company said it engaged third-party forensic specialists to investigate, completed its review of the affected files on March 3, 2025, and determined that the compromised data included individuals’ names along with additional, unspecified data elements. Kelly Benefits also reported the incident to the FBI and said it notified affected data owners and impacted individuals.

The breach notices say Kelly Benefits is offering complimentary IDX credit monitoring and identity protection services to affected people, with enrollment available until September 30, 2025. The company’s notices also direct recipients to consider fraud alerts, credit freezes, and ongoing credit report monitoring, and one state filing indicated that about 14 Rhode Island residents were affected.

Share:
Kelly Benefits Reports Data Theft After Unauthorized Network Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 3, 20251y ago

Kelly Benefits reports incident to FBI and notifies affected parties

After determining the scope of the breach, Kelly Benefits reported the incident to the Federal Bureau of Investigation, notified affected data owners, and began offering impacted individuals complimentary IDX credit monitoring and identity protection services.

Kelly Benefits completes review of affected files

On March 3, 2025, Kelly Benefits completed its review of the impacted files and determined that they contained affected individuals' names and additional unspecified data elements.

Dec 12, 20242y ago

Unauthorized access at Kelly Benefits leads to file theft

Kelly & Associates Insurance Group, Inc. (Kelly Benefits) identified unauthorized access to its environment between December 12 and December 17, 2024, during which certain files were copied and taken.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Organizations
5 linked
TransUnionExperianEquifaxIDXKelly & Associates Insurance Group, Inc.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.