I was surprised to see that no one has posted about this yet. If scammers are targeting Allstate employees on their personal devices via texts and phone calls, wouldn't that mean that our employee personal data was exposed? All these issues with ADP, the upcoming transition from Talent Connection to Workday...
23 replies (most recent on top)
Where does India fall on Allstate cyber threat country list? For other large corporations it is number eight in the world. Where does Allstate rank India
Smishing texts were a scattered spider attempt to gain access to internal systems. Employee phone numbers were breached elsewhere … LinkedIn, experian, or publicly available through legal data collection from third parties
——- goigle your name with Allstate and see what comes .
If Allstate got hacked they probably deserved it. With all the wrongs they have done to their customers and current/prior employees it was/is bound to happen.
We got hacked. This is why we are on a change freeze. They are trying to restore some of the systems.
Maybe they are using data from linkedin data breach.
Not shocking in the least that they handled something poorly once again.
any HR info system can affirmatively say breach, leak, replication, integration and/or hack
ADP WorkDay, and others….
You are a commodity to be”analyzed”
Post from TheLayoff.com
Knowing Allstate, they'd sell employees' internal organs of they thought they could get away with it.
Recently Allstate acquired NatGen. Each agent was required to complete a form including SS number, name home address and cell phone to be appointed. Each agent then received a confirmation from Pune India once approved.
Knowing Allstate if they could make a buck they probably sold all of our contact information. This company knows no morals or ethics
I heard China hacked our systems.
It is true a phishing campaign is targeting Allstate employees via text messaging on personal devices.
How did a scammer get employee numbers to target? Good question for sure.
Yep, every aspect of this company is a complete disaster. Except the one thing that is most important to senior management and the board of directors - the stock price.
Every aspect of this company is a complete disaster....there is no wonder something like this would happen.
This company is literally a piece of sh-t that has one thing or another every week. Are those scammers from India?
What a d-mb post
You must be that nieve to think scammers wouldn't reach out multiple ways. This company sends te-t ohishing emails all day cuse employees are as nieve as you.
P.s. a good portion of this company has company supplied cell phones
Wait, doesn't Allstate have InfoArmor (identity protection) to take care of this?
So if the All Alert said, and I quote "ALL-ALERT: Allstate Emergency Notification System message: Be on alert. Text and phone message scams are targeting employees, claiming to be from Allstate Human Resources and designed to trick users into clicking on a malicious link. If you receive such a message, DO NOT CLICK ON THE LINK OR PROVIDE ANY INFORMATION. Allstate will never send a link requesting your credentials. If you received or acted on a similar text message, notify cyber@allstate.com."
Were the scammers going to text me on teams with a link? Call my desk extension? No, scammers got our cell phone numbers somehow and know enough about us to know to pose as Allstate HR or Allstate ATSC.
Based on the panicked denial that this occurred, someone is shook.
Allstate texted you because that is the contact number in the system that YOU provided.
The company you work for texting you about a scam and scammets texting you are not the same thing
We literally got alerts on our cell phones about this last Friday and got an email from Allstate today that indicated what to do if we get calls or texts asking for our credentials, posing as Allstate HR or ATSC. Where else would I get a text if not on my cell phone after my personal information was involved in a security breach.
Seems slow on the layoff news so you are fishing to maintain your conspiracy and misery
Not one of those alerts said personal numbers. It never specified.
Dont make up stuff