Nasdaq-listed Cognizant has notified affected individuals of a data security breach that occurred around April 21 this year.In a notification letter, Cognizant’s US entity informed individuals about a breach involving their personal information and expressed regret over the incident. The company did not specify the number of people affected or the nature or volume of personal information involved. It said it has no reason to believe that compromised information was misused.Cognizant offered affected individuals identity theft protection services through IDX for 24 months. The package includes credit and CyberScan monitoring, a $1 million insurance reimbursement policy and fully managed identity theft recovery services.The company advised recipients to monitor their account statements and credit reports and remain alert for suspicious activity. It also outlined steps including placing fraud alerts or security freezes on their credit files with major credit reporting agencies.A security freeze restricts credit reporting agencies from releasing information in a consumer’s credit report without authorisation, although it could delay or interfere with applications for loans, mortgages, employment, housing and other services, the notice said. Under US federal law, consumers cannot be charged to place, lift or remove a security freeze.Affected individuals were also advised of their right to obtain a police report relating to the incident under Massachusetts law and to file a police report if they become victims of identity theft.Separately, ClaimDepot said a threat actor group known as CoinbaseCartel claimed responsibility for the incident. According to ClaimDepot, the group posted on a dark web site hosted on the Tor network on April 15 claiming to have obtained data belonging to the organisation.Cognizant’s notice does not provide details on how the breach occurred, whether it involved an external cyberattack or unauthorised access, or the categories of personal information that may have been exposed. An email sent to Cognizant did not elicit a response by press time.Earlier this year, Cognizant subsidiary TriZetto Provider Solutions (TPS) suffered a data breach that exposed sensitive information of about 3.4 million individuals, according to a filing with the Office of the Maine Attorney General. TPS said the incident may have exposed certain protected health information.
