
Century Support Services Breach: 160,000 Identities Compromised in Silent Cyberattack
Failed to add items
Add to basket failed.
Add to Wish List failed.
Remove from Wish List failed.
Follow podcast failed
Unfollow podcast failed
-
Narrated by:
-
By:
About this listen
In this episode, we examine the major data breach at Century Support Services—also operating under the name Next Level Finance Partners—that exposed the personal information of over 160,000 individuals. While the company discovered indicators of a cyberattack as early as November 2023, it wasn’t until May 2024 that investigators confirmed sensitive data had likely been accessed or exfiltrated. The exposed data is deeply sensitive: names, Social Security numbers, dates of birth, driver’s license and passport details, health and financial information, and even digital signatures.
This breach is notable not just for its scale, but for its opacity—no ransomware group has claimed responsibility, and the breach remained largely under the radar compared to other high-profile cyber incidents. Yet the implications are just as serious.
We dig into what this breach reveals about the current state of cybersecurity and breach response across industries. From the rise of data leakage as a legally defined event to the complexities of breach detection timelines, this incident reflects many of the systemic issues plaguing organizations today.
Topics explored include:
- The anatomy of the Century Support breach: timeline, scope, and the delayed confirmation of data compromise.
- Legal definitions and disclosure obligations surrounding personal data exposure.
- The evolution of data breaches since the early 2000s—and why most are still detected by third parties, not the breached company.
- Common vulnerabilities that enable such breaches: lack of encryption, social engineering, and third-party risk.
- The dark web economy: how exposed data circulates and why victims face elevated identity theft risk for years.
- The role of breach response playbooks, including incident containment, legal reporting, and the offer of identity theft protection (and why consumer uptake remains low).
- Why attackers might remain silent—exploring motivations and the growing role of stealth attacks not associated with ransomware branding.
As attacks become more intricate and visibility more difficult, the Century Support Services case underscores a larger truth: data breaches are no longer exceptional events—they are persistent, costly, and often avoidable failures of digital trust.