Cornerstone Staffing Solutions holds sensitive employment-file data on the job seekers and workers it places, including Social Security numbers and, in many cases, medical and financial information. The company took roughly ten months to tell people their information had been exposed.
Cornerstone Staffing Solutions, Inc. has confirmed a data breach involving unauthorized access to its network. According to a notice filed with the California Attorney General, the breach occurred between November 6 and November 21, 2025. Cornerstone issued notice to affected individuals on or about September 11, 2026, roughly ten months after the breach ended.
A Massachusetts regulatory filing confirms 243 affected Massachusetts residents. Cornerstone has not disclosed a national total, though as a staffing company that places workers across multiple markets, the true population is likely larger than the Massachusetts figure alone.
What Information Was Exposed?
The Massachusetts filing confirms four separate categories of exposed information for this breach, the broadest confirmed set of any new data breach case this reporting cycle:
- Social Security numbers
- Medical records
- Financial account information
- Driver’s license numbers
Cornerstone’s own California notice was filed as a scanned document without a readable text layer, so the exact language used in the letter sent to California residents could not be independently reviewed. The four confirmed categories above come from Cornerstone’s Massachusetts regulatory filing.
A Ransomware Group’s Claims
A ransomware group calling itself Qilin has claimed responsibility for this breach, stating on the dark web that it obtained roughly 300 gigabytes of data, including the resumes of more than 120,000 job seekers as part of a larger cache of around one million files. Emery | Reddy has not independently verified the scope of this claim, and it is separate from the confirmed data categories in Cornerstone’s own regulatory filings. We are including it here because it is a matter of public record that a named ransomware group asserted responsibility for this incident.
Do You Have Legal Options?
Staffing companies collect and store some of the most sensitive information job seekers and workers provide, including Social Security numbers and, often, medical and financial details submitted as part of onboarding or background checks. Companies that hold this information have a legal duty to safeguard it and to notify affected individuals without unreasonable delay.
If you are a current or former job seeker or placed worker with Cornerstone Staffing Solutions and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Companies that collect this information are legally required to safeguard it. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Some of the information involved in this incident, including medical records, may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
Frequently Asked Questions
How many people were affected?
Massachusetts regulatory filings confirm 243 affected Massachusetts residents. Cornerstone has not disclosed a national total.
What information was exposed?
Massachusetts filings confirm Social Security numbers, medical records, financial account information, and driver’s license numbers. Cornerstone’s California notice could not be reviewed in full because it was filed as an unreadable scanned document.
Why did it take about ten months to notify affected people?
The breach occurred between November 6 and November 21, 2025, and Cornerstone issued notice around September 11, 2026. The company has not publicly explained the reason for this delay.
Has a ransomware group claimed responsibility?
A group calling itself Qilin has claimed responsibility and said it obtained roughly 300 gigabytes of data, including more than 120,000 resumes. This claim has not been independently verified and is separate from Cornerstone’s own confirmed disclosures.
I applied for a job through Cornerstone but was never placed. Am I still affected?
Possibly. Staffing companies typically retain applicant and candidate information regardless of whether a placement occurred. If you provided personal information to Cornerstone Staffing Solutions, including a resume or application, contact us so we can help evaluate your situation.
Do I have a legal claim?
You may. Companies that collect Social Security numbers, medical information, and financial data are required by law to protect it and to notify affected individuals without unreasonable delay. Contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.