Were you recently affected by a data breach?

Express Employment Professionals Data Breach

Express Employment Professionals was named on a dark web leak site in September 2026 by a cybercriminal group claiming to have stolen and released company files, following an earlier 2024 data security incident at the staffing firm.

Express Employment Professionals
Date of Breach: Not disclosed; publicly reported via dark web leak site posting in September 2026
CAU logo

Who was affected:

Clients of Express Employment Professionals

Impacted Data:

Not publicly disclosed by the company as of this writing

Express Employment Professionals, a national staffing and recruiting firm, was named on a dark web leak site in September 2026 by a cybercriminal group that claimed to have obtained and begun releasing company files.

Companies that manage sensitive employment and personal data for job seekers and employees take on a responsibility to protect that information, and when an incident like this occurs, affected individuals deserve clear answers about what happened and what steps they can take next.

Express Employment Professionals’s Data Breach Investigation

According to a posting identified on a dark web leak site, a cybercriminal group known as Chaos claimed responsibility for a cybersecurity incident involving Express Employment Professionals. The claim was reportedly posted in September 2026, and the group stated it had begun releasing files it says it obtained from the company’s systems. Express Employment Professionals has not publicly confirmed the cybersecurity incident, and the specific categories of information potentially involved have not been confirmed as of this writing. Express Employment Professionals, formally known as Express Services, Inc., is a staffing and recruiting company that operates franchise offices across the United States, Canada, South Africa, Australia, and New Zealand, connecting job seekers with temporary, contract, and permanent positions.

Ransomware and data-extortion groups like Chaos typically gain access to a victim’s network, copy files containing sensitive information, and then threaten to publish the stolen data publicly unless a ransom is paid. When a company does not pay, or negotiations break down, these groups often follow through by posting samples or full archives of the stolen files to dark web leak sites, as reportedly occurred here. This double-extortion model has become increasingly common among ransomware operators targeting companies that store large volumes of personal data, including staffing and human-resources firms that maintain files on both employees and job applicants. Because staffing companies like Express Employment Professionals routinely collect Social Security numbers, dates of birth, banking details, and other sensitive identifiers as part of onboarding and payroll processing, a breach at this type of company can expose information belonging to a very large number of people.

This is not the first data security issue reported involving Express Employment Professionals. In 2024, the company, then operating as Express Services, Inc., disclosed a separate data breach after an unauthorized party accessed two company email accounts between May and June of that year; a filing with the Texas Attorney General’s Office reported that names, Social Security numbers, driver’s license numbers, financial information, medical information, and health insurance information were involved for thousands of affected individuals. That earlier incident is a distinct event from the 2026 dark web posting described here, and it is mentioned only to note that this is not the company’s first reported data security issue, not to suggest the two incidents involved the same information.

When personal information tied to employment records is exposed, affected individuals can face an elevated risk of identity theft, tax fraud, and unauthorized use of financial accounts. Fraudsters can use stolen Social Security numbers and dates of birth to file fraudulent tax returns, open new lines of credit, or apply for loans in a victim’s name. Employment records can also contain banking and direct deposit information that, if exposed, could be used to redirect wages or initiate unauthorized transactions. Because staffing agencies act as intermediaries holding data for many different employers and job seekers at once, a single breach at a company like Express Employment Professionals has the potential to affect an unusually broad and varied group of people, from current employees to prior applicants who may not expect their information to still be on file.

State data breach notification laws generally require companies to investigate a suspected security incident and notify affected individuals within a set window once the scope of the exposure is understood, though timelines and requirements vary by state. Because Express Employment Professionals has not yet publicly confirmed the incident described in the Chaos leak site posting, it is not yet clear whether or when formal notification letters will be sent to individuals whose information may have been involved, or which states’ laws will apply given the company’s nationwide footprint of franchise locations.

When Did This Breach Occur?

The cybercriminal group Chaos posted its claim regarding Express Employment Professionals on a dark web leak site in September 2026. The group did not disclose a specific date on which it says it first gained access to the company’s systems, and Express Employment Professionals has not publicly confirmed the incident or provided its own timeline. Because the claim originated from a dark web leak site rather than a formal breach notification letter, key dates such as when the alleged intrusion began, when it was discovered, and when it may have ended are not currently available. This is a common pattern with dark web leak-site disclosures, where a threat actor’s own announcement can predate any official acknowledgment or investigation timeline from the affected company by weeks or months. If Express Employment Professionals confirms the incident and issues notification letters, those letters would typically include more specific dates regarding when unauthorized access occurred and when it was discovered.

What Information Was Breached?

The cybercriminal group claiming responsibility for this incident has not published a confirmed list of the specific data types it says it obtained from Express Employment Professionals, and the company has not issued its own public statement identifying which categories of information may have been affected. Given the nature of Express Employment Professionals’ business as a staffing and recruiting firm, the types of information it typically collects and stores can include full names, Social Security numbers, dates of birth, addresses, driver’s license or other government-issued identification numbers, banking and direct deposit information, and employment history. It is not yet confirmed whether any or all of these categories were involved in the incident reported here. This page will reflect updated information if Express Employment Professionals or a state Attorney General’s office publishes a formal notification identifying the specific information involved.

What You Can Do

If you have worked with or applied for a position through Express Employment Professionals, there are steps you can take to help protect yourself while more information about this incident becomes available:

  • Monitor your financial accounts and credit reports closely for any unauthorized activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
  • Be cautious of phishing emails, calls, or texts that reference Express Employment Professionals or claim to offer help related to this incident.
  • Enable two-factor authentication and update passwords on any accounts associated with your employment or job search activity.
  • Keep any communication you receive from Express Employment Professionals regarding this incident, in case formal notification letters are issued later.

File a Data Breach Lawsuit Against Express Employment Professionals

If Express Employment Professionals confirms that your personal information was exposed in this incident, or if you receive a notification letter regarding it, you may have legal options available to you. Companies that collect and store sensitive personal information have a legal responsibility to implement reasonable safeguards to protect it, and a failure to do so can form the basis of a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not disclosed; publicly reported via dark web leak site posting in September 2026
Date of Breach: Reported to the Texas Attorney General on September 17, 2026
Date of Breach: Reported to the Texas Attorney General on September 17, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.