2024-11-14-strauss-borrelli-logo-white-for-web-2
872.263.1100
  • Firm
  • Our Team
    • Samuel J. Strauss
    • Raina Borrelli
    • Camile Alvarez
    • Carolyn Chen
    • Andrew Gunem
    • Cassandra Miller
    • Stephen Pigozzi
    • Brittany Resch
    • Carly Roman
    • Sarah Soleiman
    • Marguerite Willis
  • Blog
    • Data Breach Blog
    • WARN Act Blog
  • Practices
    • Data Breach Litigation
    • Privacy Litigation
    • TCPA Litigation
    • WARN Act Litigation
  • Contact Us
  • Firm
  • Our Team
    • Samuel J. Strauss
    • Raina Borrelli
    • Camile Alvarez
    • Carolyn Chen
    • Andrew Gunem
    • Cassandra Miller
    • Stephen Pigozzi
    • Brittany Resch
    • Carly Roman
    • Sarah Soleiman
    • Marguerite Willis
  • Blog
    • Data Breach Blog
    • WARN Act Blog
  • Practices
    • Data Breach Litigation
    • Privacy Litigation
    • TCPA Litigation
    • WARN Act Litigation
  • Contact Us
872.263.1100
  • Firm
  • Our Team
    • Samuel J. Strauss
    • Raina Borrelli
    • Camile Alvarez
    • Carolyn Chen
    • Andrew Gunem
    • Cassandra Miller
    • Stephen Pigozzi
    • Brittany Resch
    • Carly Roman
    • Sarah Soleiman
    • Marguerite Willis
  • Blog
    • Data Breach Blog
    • WARN Act Blog
  • Practices
    • Data Breach Litigation
    • Privacy Litigation
    • TCPA Litigation
    • WARN Act Litigation
  • Contact Us
  • Firm
  • Our Team
    • Samuel J. Strauss
    • Raina Borrelli
    • Camile Alvarez
    • Carolyn Chen
    • Andrew Gunem
    • Cassandra Miller
    • Stephen Pigozzi
    • Brittany Resch
    • Carly Roman
    • Sarah Soleiman
    • Marguerite Willis
  • Blog
    • Data Breach Blog
    • WARN Act Blog
  • Practices
    • Data Breach Litigation
    • Privacy Litigation
    • TCPA Litigation
    • WARN Act Litigation
  • Contact Us
  • Strauss Borrelli PLLC
  • March 18, 2025

ESHYFT Cybersecurity Incident Investigation

Strauss Borrelli PLLC, a leading data breach law firm, is investigating Shiftster LLC, which does business as ESHYFT, regarding its recent cybersecurity incident. The ESHYFT cybersecurity incident may impact the privacy of sensitive personal information belonging to an undetermined number of individuals.

ABOUT SHIFTSTER, LLC D/B/A ESHYFT:

ESHYFT is a healthcare staffing company based in New Jersey. Today, ESHYFT provides a mobile application that connects Certified Nursing Assistants, Licensed Practical Nurses, and Registered Nurses to facilities.2 Additionally, the ESHYFT application allows healthcare providers to post shifts, review and accept applicants, and approve timecards.2 Headquartered in Howell, New Jersey, ESHYFT employs over 10 individuals.

WHAT HAPPENED?

Recently, it was reported by an online source that ESHYFT had experienced a cybersecurity incident impacting the privacy of its data. According to this source, a cybersecurity researcher discovered a non-password-protected database that contained thousands of records belonging to ESHYFT.1 The exposed database contained 86,341 records totaling 108.8 GB in size.1 The majority of the documents were contained inside of a folder labeled “App”.1 In a limited sampling of the exposed documents, the researcher noticed records that included profile or facial images of users, .csv files with monthly work schedule logs, professional certificates, work assignment agreements, CVs and resumes that contained additional personal identifiable information.1 One single spreadsheet document contained 800,000+ entries that detailed a nurse’s internal IDs, facility name, time and date of shifts, hours worked, and more.1 Additionally, the database contained what appeared to be medical documents uploaded to the app potentially proof for why individual nurses missed shifts or took sick leave.1 These medical documents included medical reports containing information of diagnosis, prescriptions, or treatments that could potentially fall under the ambit of HIPAA regulations.1 The name of the database as well as the documents inside it indicated that the records belonged to ESHYFT.1

 

According to the source, after discovering the database the researcher notified ESHYFT of the exposure. In response, ESHYFT thanked the researcher saying, “Thank you! we’re actively looking into this and working on a solution”.1 At this time, it is not known how long these documents were exposed to the public or if anyone else may have accessed the database.1 As of March 18, 2025, ESHYFT has not publicly acknowledged the data exposure or confirmed whether the incident resulted in a data breach.

If you received a breach notification letter from Shiftster, LLC d/b/a ESHYFT:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

LINKS:

[1] https://www.websiteplanet.com/news/eshyft-report-breach/

[2] https://eshyft.com/facilities/

[3] https://www.linkedin.com/company/eshyft/about/

Data Breach Website Blog Form
  • Contact Us

  • Learn about your legal rights

  • Format: (000) 000-0000.
  • By clicking Submit, you agree to our Terms & Conditions and Privacy Policy.

  • Should be Empty:

Contact Us

Learn about your legal rights

Please enable JavaScript in your browser to complete this form.
Name *
Terms & Conditions and Privacy Policy *
Privacy Policy  |  Terms & Conditions
Loading

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Recent Posts

  • All Posts
  • Data Breach
Human resource management and recruitment employment business concept

Quatrro Business Support Services Data Breach Investigation

March 26, 2026
Coastal Carolina Health Care Data Breach Investigation

Coastal Carolina Health Care Data Breach Investigation

March 26, 2026
Grayback Forestry Data Breach Investigation

Grayback Forestry Data Breach Investigation

March 26, 2026
Business Finance, accounting, contract, advisor investment consulting marketing plan for the company with using tablet and computer technology in analysis.

Cetera Financial Group Data Breach Investigation

March 25, 2026
Austin Plastic & Reconstructive Surgery Data Breach Investigation

Austin Plastic & Reconstructive Surgery Data Breach Investigation

March 25, 2026

Contact Us Now

Please enable JavaScript in your browser to complete this form.
Name *
Terms & Conditions and Privacy Policy *
Privacy Policy  |  Terms & Conditions
Loading

Featured Blog Posts

Cyber security data protection business technology privacy concept. 3D illustration.Data breach.

Keesal, Young & Logan Data Breach Investigation

December 1, 2024
Read More
Global cyber attack around the world with planet Earth viewed from space and internet network communication under cyberattack with red icons, worldwide propagation of virus online

Chimienti & Associates Data Breach Investigation

October 25, 2024
Read More
Yellow, green sponges and blue mitts for washing and microfiber fabric with cleaner cloth on white car

Autobell Car Wash Data Breach Investigation

October 23, 2024
Read More
Genetic research and Biotech science Concept. Human Biology and pharmaceutical technology on laboratory background.

Summit Pathology Data Breach Investigation

October 21, 2024
Read More
Medicine doctor write electronic medical record on tablet. DNA. Digital healthcare and network connection on hologram modern virtual screen interface, medical insurance, technology and network.

Boston Children’s Health Physicians Data Breach Investigation

October 11, 2024
Read More
a pile of books in front of university

Blackburn College Data Breach Investigation

March 11, 2024
Read More

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

Facebook Instagram Linkedin

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

Facebook Instagram Linkedin

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY