Data breach
Xerox
- Records
- 42,735
- Breach date
- 31 May 2023Estimated
- Added
- 2 December 2024
What was exposed
6 types of data
- Names42,686
- Employee badge numbers42,220
- Email addresses40,565
- Employment26,226
- Job titles26,226
- Phone numbers12,484
About this breach
Xerox appears among the latest companies whose employee data has surfaced online following the sprawling MOVEit file transfer breaches. According to our investigation team, the listing covers 42,735 rows of data tied to an estimated attack date of May 31, 2023, though the records only became publicly visible in December 2024 when a hacker began dumping them on a cybercrime forum. The incident traces back to the Cl0p ransomware group's exploitation of a vulnerability in Progress Software's MOVEit product, which affected hundreds of organizations and millions of individuals starting in May 2023. The data surfaced more than a year later, posted by an actor using the alias "Nam3L3ss" on the BreachForums platform alongside stolen records from Nokia, Koch Industries, Bank of America, Morgan Stanley, Bridgewater Associates, and JLL.
Breach Timeline
May 2023: The Russia-linked Cl0p ransomware group began exploiting a critical vulnerability in Progress Software's MOVEit file transfer tool, according to The Register, accessing data from thousands of organizations.
December 2, 2024: An actor using the handle "Nam3L3ss" began publishing employee data, including records for 42,735 Xerox employees, on BreachForums, as reported by The Register and TechNadu.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (42,686 records), employee badge numbers (42,220), email addresses (40,565), job titles (26,226), and phone numbers (12,484).
Security researchers who analyzed the wider dump confirmed it also contained job locations and usernames, according to The Register. Atlas Privacy, a data removal firm, verified the authenticity of the leaked records, per TechNadu.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposed data is personal rather than financial. No Social Security numbers, payment details, or passwords appear in the indexed fields for this listing. That limits the risk of direct financial fraud, but it does not eliminate it.
Names paired with job titles, email addresses, phone numbers, and badge numbers are valuable to scammers. Criminals can use this combination to craft convincing phishing emails that appear to come from a person's employer or a known colleague. Because the data identifies where someone works and what role they hold, attackers can impersonate IT staff, human resources, or senior managers with credible detail.
Employee badge numbers and workplace locations could also support physical social engineering, such as tailgating into office buildings or impersonating staff on site. Anyone affected should treat unexpected messages referencing their job, employer, or workplace as suspicious.
What Should You Do If You Were Affected?
If you worked for Xerox and your data may be included, take these practical steps:
Be alert to phishing. Watch for emails or texts that reference your job, badge number, or employer. Do not click links or open attachments from unexpected senders, and verify requests through a known channel before responding.
Never share credentials in reply to a message. Legitimate IT departments and HR teams will not ask for your password by email or phone.
Use strong, unique passwords and enable multi-factor authentication on your work and personal accounts.
Screen calls and texts carefully. Caller ID can be faked, so hang up and call back on a number you know is genuine.
Monitor your accounts for unusual activity, and report any suspected fraud to your employer's security team and local authorities.
Because this data was leaked on a public forum rather than held for ransom, it may circulate indefinitely. Staying cautious about unsolicited contact is the most effective long-term defense.
