LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Washington State Food Worker Card Data Breach (2022)

CRITICAL severityConfirmedHow we verify

Washington State Food Worker Card Data Breach (2022): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·November 17, 2022

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Washington State Food Worker Card Data Breach (2022)

Reported November 17, 2022. Approximately 1.6M people affected.

CRITICAL
Severity
1.6M
People affected
5
Data types exposed
November 17, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Washington State Food Worker Card Data Breach (2022) (reported November 17, 2022) exposed Dates of birth, Driver's licenses, Email addresses and Geographic locations belonging to roughly 1.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Washington State Food Worker Card Data Breach (2022) breach?
1.6M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Public-sector and training platforms that hold large volumes of personal identity data remain a steady target in today’s threat landscape. Attackers continue to seek out older backups and secondary systems, then list the results on criminal forums months or years later. The Washington State Food Worker Card incident fits that pattern: a large set of records tied to a required food-safety credential later appeared in a public dump, prompting an official notice long after the underlying data had been taken.

In June 2023 the Tacoma-Pierce County Health Department announced a data breach affecting its Washington State Food Worker Card online training system. The material had already been published to a popular hacking forum the year before and was described as originating from a 2018 database backup. Roughly 1.6 million people are reported to have been affected. The episode matters because the card is a routine occupational requirement across Washington, so the exposed records touch a broad cross-section of food-service workers and the agencies that certify them.

Breaking down the breach

According to the public account, the Tacoma-Pierce County Health Department disclosed the incident in June 2023. The data set had been posted on a popular hacking forum in 2022 and was linked to a database backup dating to 2018. Reporting associated with the disclosure places the number of affected individuals at 1.6 million. The published material is described as containing approximately 1.6 million unique email addresses together with names, post codes, dates of birth, and roughly 9,500 driver’s-licence numbers. Geographic-location data and additional identity fields are also named among the exposed types. No further technical detail on the initial intrusion method, the precise date of compromise, or any ransom demand has been supplied in the available summary. The listing on the forum is therefore treated as a claim about the origin and contents of the file rather than an independently verified forensic timeline.

How a breach like this happens

Incidents of this type commonly begin with unauthorized access to a web application, an administrative interface, or a poorly protected backup store. Once inside, an attacker may copy database dumps that were created for routine maintenance or disaster recovery and then left accessible longer than intended. Those files are later advertised or simply uploaded to criminal forums, sometimes years after the original theft. In many cases the operators of the system learn of the exposure only when the dump surfaces publicly or when a third party notifies them. No specific threat group has been attributed in the facts of this case, and none is asserted here. The general sequence—compromise, exfiltration of a historical backup, delayed public listing, and eventual organizational notice—is a recurring pattern across government and training platforms that hold large volumes of personal data.

About Washington State Food Worker Card

The Washington State Food Worker Card is the credential required for most people who handle unpackaged food in the state. Local health departments, including Tacoma-Pierce County, administer online training and testing systems that issue the card. Those systems necessarily collect identifying information so that a worker’s completion of the course can be verified and the card can be linked to the correct individual. Because the credential is mandatory across restaurants, cafeterias, grocery operations and similar workplaces, the underlying databases accumulate records for a large share of the state’s food-service workforce. A breach of such a system therefore reaches beyond a single employer and into a regulated public-health function that many residents must use to keep or obtain work.

The information in question

The facts name the following data types as exposed: dates of birth, driver’s licences, email addresses, geographic locations, and names. The departmental summary further specifies approximately 1.6 million unique email addresses, names, post codes, dates of birth, and about 9,500 driver’s-licence numbers. Organisations that run food-worker certification platforms typically also hold mailing addresses, test results, and card-issue dates; whether any of those additional fields were present in the 2018 backup remains unconfirmed in the public record. Exact contents beyond the types and counts already stated should therefore be treated as limited.

The real-world impact

For affected individuals the combination of name, date of birth, email address, post code and, in a smaller subset of cases, driver’s-licence number creates concrete risks of identity fraud, targeted phishing, and account takeover. An email address paired with personal details can make social-engineering messages more convincing; a driver’s-licence number can be misused in attempts to open new accounts or to pass identity checks. Because the card is occupational, some workers may also face secondary inconvenience if employers or regulators later question the integrity of credential records. For the health department and the wider food-worker programme, the incident carries operational and reputational costs: notification obligations, potential credit-monitoring offers, system hardening, and the need to reassure both workers and the public that future training data will be better protected. No dollar figure for remediation or confirmed fraud losses has been supplied in the available facts.

Were you affected?

If you obtained or renewed a Washington State Food Worker Card in the years surrounding the 2018 backup, treat the possibility of exposure seriously. Monitor financial and email accounts for unexpected activity, enable multi-factor authentication wherever it is offered, and be alert to phishing that references food-handler training or personal details. Consider placing a fraud alert or credit freeze if you believe your driver’s-licence number may have been included. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets and to decide what further steps are warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyWashington State Food Worker Card security record
74/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Washington State Food Worker Card’s full breach history →

More recent breaches

RailYatri Data Breach (2022)December 26, 2022Gemini Data Breach (2022)December 13, 2022SevenRooms Data Breach (2022)December 11, 2022Activision Data Breach (2022)December 4, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the Washington State Food Worker Card Data Breach (2022) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram