Technology
HR firm confirms 4M records exposed in major hack
Data breaches have become alarmingly common and costly, putting sensitive information at risk. In fact, the number of data breaches in the United States jumped from 447 in 2012 to over 3,200 in 2023.
Even firms entrusted with managing personal information are not immune. The latest example is VeriSource Services, a Texas-based employee benefits and HR administration provider that experienced a major data breach.
The personal information of about 4 million people was exposed in this incident, and it took the company over a year to fully assess its impact, a critical failure for an organization specializing in data management, employee enrollment and HR support services that clients rely on to safeguard their most sensitive information.
Join The FREE CyberGuy Report: Get my expert tech tips, critical security alerts and exclusive deals — plus instant access to my free Ultimate Scam Survival Guide when you sign up!
An illustration of a hacker at work (Kurt “CyberGuy” Knutsson)
What happened at VeriSource?
VeriSource discovered the breach Feb. 28, 2024, when it noticed unusual activity disrupting some of its systems. The company later determined an unknown attacker had gained unauthorized access around Feb. 27, 2024, stealing data on or about that date.
Somehow, it took VeriSource over a year to determine the full scope of the breach, including the identification all individuals who had their information exposed.
According to the investigation, this was a criminal cyberattack carried out by external threat actors (hackers), as opposed to an insider mishandling data. The perpetrators accessed sensitive personal records stored by VeriSource. In a sample notice filed with state authorities, VeriSource reported that the compromised information included individuals’ full names, mailing addresses, dates of birth, gender and Social Security numbers (via BleepingComputer).
A person working on their laptop (Kurt “CyberGuy” Knutsson)
200 MILLION SOCIAL MEDIA RECORDS LEAKED IN MAJOR X DATA BREACH
Impact on affected individuals
For individuals whose data was exposed, this breach poses real risks. Information like your Social Security number, birth date and address can be misused for identity theft, such as opening fraudulent accounts or filing false tax returns in your name. Even beyond financial fraud, having such personal data in the wrong hands can lead to targeted phishing scams.
What worries me the most is the delay in fully notifying everyone affected. VeriSource had sent out preliminary breach notices to about 55,000 people in May 2024 and then to another 112,000 people in September 2024. However, those early notifications covered only a small fraction of the approximately 4 million victims eventually identified. This means the majority of affected individuals did not learn of the breach until the final notification wave in April 2025, more than a year after the data was actually compromised.
We reached out to VeriSource for a comment but did not hear back before our deadline.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
A person working on a laptop (Kurt “CyberGuy” Knutsson)
HERTZ DATA BREACH EXPOSES CUSTOMER INFORMATION
5 ways to protect yourself after the VeriSource data breach
If you think you were affected by the VeriSource data breach or just want to be cautious, here are some steps you can take right now to stay safe from the data breach:
1. Consider a personal data removal service: VeriSource hackers have access to your name, Social Security number, mailing address and more, which they can easily use against you. The more exposed your personal information is online, the easier it is for scammers to scam you. After the VeriSource breach, consider removing your information from public databases and people-search sites. Check out my top picks for data removal services here.
2. Safeguard against identity theft and use identity theft protection: Hackers now have access to high-value information from the VeriSource breach, including Social Security numbers. This makes you a prime target for identity theft. You can freeze your bank and credit card accounts to prevent further unauthorized use by criminals. Signing up for identity theft protection gives you 24/7 monitoring, alerts for unusual activity and support if your identity is stolen. See my tips and best picks on how to protect yourself from identity theft.
3. Set up fraud alerts: Requesting fraud alerts notifies creditors that they need extra verification before issuing credit in your name. You can request fraud alerts through any one of the three major credit bureaus. They’ll notify the others. This adds another layer of protection without completely freezing access to credit.
4. Monitor your credit reports: Check your credit reports regularly through AnnualCreditReport.com, where you can access free reports from each bureau once per yearor more frequently if you’re concerned about fraud. Spotting unauthorized accounts early can prevent larger financial damage.
5. Be wary of social engineering attacks and use strong antivirus software: Hackers may use stolen details like names or birthdates from breaches in phone scams or fake customer service calls designed to trick you into revealing more sensitive info. Never share personal details over unsolicited calls or emails. Also, never click on unexpected links or attachments in emails, texts or messages because they may contain malware or lead to phishing sites designed to steal your information.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
HACKERS USING MALWARE TO STEAL DATA FROM USB FLASH DRIVES
Kurt’s key takeaway
What stands out in the VeriSource breach isn’t just the scale, but the silence. When a company sits on breach data for over a year, regardless of intent, it erodes trust in systems designed to protect workers. These aren’t just compliance failures. They’re human ones. Four million people had their most sensitive information exposed, and for many of them, the warning came far too late. This should be a moment of reckoning for how organizations define responsibility after a breach. A timely response isn’t just good PR. It’s a baseline expectation. And if it takes over a year to realize the full scope of a cyberattack, maybe the incident isn’t the only vulnerability worth addressing.
Should companies face stricter penalties for delayed breach notifications? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
The latest iPad Air is $400 for the first time and arrives by Christmas
If you have $400 and want an iPad, your options are usually kind of limited to either just the base iPad, or better yet, the latest iPad Mini — if it happens to be on sale when you’re shopping (it is now, but that’s not always the case). But right now, you should consider getting the 128GB version of Apple’s 11-inch iPad Air with the capable M3 processor. At Target, multiple colors of this model are $399.99, beating the previous low of $449.99 we’ve seen during large-scale deal events. Currently, no other retailer is matching this price. This sale ends Saturday night.
$400 is a sweet price for this model, as it debuted in early 2025 for $600. In terms of how it stacks up to other iPad models, Verge editor-at-large David Pierce said in his impressions that the M3 Air is “exactly what you think it is. Which is fine.” I know, that sounds like a back-handed compliment, but it’s been a while since iPads peaked in terms of utility, design, and fast performance. This one carries the torch in Apple’s tablet dominance, and its M3 processor means it’ll be a fantastic tablet for longer than any other iPad at the $400 price point. Read our in-depth impressions.
Other Verge-approved deals
Technology
Facebook settlement scam emails to avoid now
NEWYou can now listen to Fox News articles!
Millions of Facebook users filed claims in a recent privacy settlement after the platform was accused of mishandling user data. The approved payouts have been rolling out, which means people are watching their inboxes for updates. Scammers know this and are sending look-alike emails that push you to click a “Redeem Virtual Card” button. Arlene B emailed us to share what landed in her inbox.
“I received an email stating that it was from (Facebook User Privacy Settlement Administrator) and that I needed to click on the button below to “Redeem Virtual Card.” Do you know if this is a scam or not?”
Her question shows how convincing these fake messages appear. A real settlement did happen, and people have been getting payments. Still, criminals are now piggybacking on the rollout with messages that look official but lead to dangerous sites that steal your information. Let’s walk through how to tell real emails from fake ones.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
NEW SCAM SENDS FAKE MICROSOFT 365 LOGIN PAGES
Scammers send fake settlement emails that mimic the real payout notices to trick you into clicking. (Kurt “CyberGuy” Knutsson)
How to check if your Facebook settlement email is legitimate
Scammers rely on confusion and urgency. These steps help you confirm the message before you click anything.
Confirm the sender’s address
Real settlement emails come from facebookuserprivacysettlement@notifications.kroll.com. Kroll is the official administrator.
Look for your claimant ID
Real notices include your unique claimant ID and reference the claim you filed last year. Fake emails skip this personalized detail.
Check where the link leads
Real payout links go to DigitalPay / Veritas or domains tied to krollsettlementadministration. If the link points to a strange or shortened URL, it is likely unsafe.
Watch for common red flags
Pressure to act right away. Clumsy wording or spelling mistakes. A button that goes to a suspicious URL. You never filed a claim in the first place. Any sender address that is not the official Kroll domain.
Remember that you are not required to click anything
If your claim was approved, you have already received a legitimate notice. Emails that say you must “redeem” again or “confirm” payment are signs of a scam.
GEEK SQUAD SCAM EMAIL: HOW TO SPOT AND STOP IT
A quick hover over the “Redeem Virtual Card” button often reveals a suspicious link that gives the scam away. (Kurt “CyberGuy” Knutsson)
Why scammers target large settlements
Whenever a major payout occurs, criminals blend in with legitimate messages because people expect money and may open emails quickly. When fake notices look similar to real ones, it only takes one careless click for scammers to grab your data.
DON’T FALL FOR FAKE SETTLEMENT SITES THAT STEAL YOUR DATA
A person logging onto Facebook (Kurt “CyberGuy” Knutsson)
Ways to stay safe from settlement scams
Use these simple habits to protect yourself from Facebook settlement scams and any future payout scam.
1) Verify the sender every time
Look at the full address. Scammers often change one character in hopes you will not notice.
2) Hover over links before tapping
Check the destination without clicking. A strange URL is your warning sign.
3) Never share sensitive information through email
Real administrators do not ask for banking info or logins.
4) Use a data removal service
Data brokers often collect your email address, phone number and other personal details that scammers use to target victims. A data removal service can pull you out of those databases, which reduces the amount of scam email that reaches you in the first place.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
5) Go directly to the official settlement site
Type in the address yourself instead of using a link from an email.
6) Use strong antivirus software
Good security software blocks dangerous links and pages. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
7) Delete emails that push urgency
Scammers want fast reactions. Slow down and confirm details.
Kurt’s key takeaways
The Facebook settlement payout created the perfect moment for scammers to slip fake messages into inboxes. Once you know the signs, it becomes much easier to separate real notices from dangerous ones. Stay alert, trust your instincts and verify before you click.
Would you open a payout email if you were not expecting money in the first place? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
The first Dolby FlexConnect soundbar is coming from LG
Dolby Atmos FlexConnect technology debuted this year with the TCL Z100 speakers, and now we’re getting our first FlexConnect soundbar thanks to LG. The new H7 soundbar — which runs on the same Alpha 11 Gen 3 chip as LG’s OLEDs and new Micro RGB LED — is a part of the LG Sound Suite, a modular home audio system the company will debut at CES 2026. In addition to the soundbar, the Sound Suite will include the M5 and M7 surround speakers and the W7 subwoofer. All of the speakers feature Peerless Audio components.
The two main drawbacks of TCL’s Dolby FlexConnect implementation were the limitation of only allowing four connected speakers, including a sub, and the need for a 2025 QM series TCL TV. So you needed to pick between better sound coverage with a fourth speaker or more bass performance with a sub. LG’s Sound Suite, on the other hand, will allow you to connect the soundbar with up to four surround speakers and a subwoofer for a potential 13.1.7-channel system.
And while the speakers can be used with a compatible LG TV (including the 2026 premium LG TV lineup and 2025’s C5 and G5 OLEDs), it isn’t required. It’s possible to use the H7 soundbar with any TV — or without — and have it act as what’s called the lead device to connect the surround speakers and sub. LG says there are 27 different speaker configurations possible, from using two speakers as a stereo pair up to the full system with soundbar, surrounds, and sub.
In my experience with the TCL Z100, calibrating FlexConnect speakers to your space is also fast. Once they’re in place and plugged in, a short musical clip is played for a few seconds and then setup is complete. The system is able to know where the speakers are placed and how to optimize the surround and Atmos sound for your room. With other room correction software, the process can take much longer, requiring taking sound readings from multiple locations in the room.
LG is using ultra-wideband technology to adjust the sweet spot based on your listening position that it’s calling Sound Follow. What will be interesting to see with the LG Sound Suite’s Dolby FlexConnect implementation is how customizable it is after setup (for instance, adjusting subwoofer levels).
I’ll be hearing the system at CES and plan on reviewing the system when it’s available to see how well the technology translates into a home.
-
Iowa3 days agoAddy Brown motivated to step up in Audi Crooks’ absence vs. UNI
-
Washington1 week agoLIVE UPDATES: Mudslide, road closures across Western Washington
-
Iowa5 days agoHow much snow did Iowa get? See Iowa’s latest snowfall totals
-
Maine2 days agoElementary-aged student killed in school bus crash in southern Maine
-
Maryland3 days agoFrigid temperatures to start the week in Maryland
-
Technology1 week agoThe Game Awards are losing their luster
-
South Dakota4 days agoNature: Snow in South Dakota
-
Nebraska1 week agoNebraska lands commitment from DL Jayden Travers adding to early Top 5 recruiting class