HackingData ExfiltratedEmployee Data InvolvedDelayed DiscoveryIDENTITY_BASICPIILowContained
Alera Group, Inc.
bd_145c82e3ce4b31b0 · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc. reported unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and other data elements, may have been removed from its network. The incident affected current and former employees and their dependents. Alera engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring and identity theft protection services to affected individuals.
California clockDiscovered Aug 1, 2024 → Notified Jun 13, 2025316d ✗ CA 60-day late45 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_43a2a7cbde02dff7New Hampshire State AGfiled 2025-07-29(46d gap)Verified
- bd_69b4192ea6eb9f94California State AGfiled 2025-07-29(46d gap)Candidate
- bd_ca0bc76a00a8880aDelaware State AGfiled 2025-07-29(46d gap)Verified
- bd_e7ea8ca0d160b7f9South Carolina State AGfiled 2025-07-30(47d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 84d gap
- bd_1ed3f272d914f341New Hampshire State AGfiled 2025-08-28(76d gap)Verified
- bd_d9430cde35cab839New Hampshire State AGfiled 2025-09-05(84d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-604061
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- a002a93a22c5d28cd4164dca67dc49f5b0cfde65d73d741a9f35dfcc3808ad0a
Reporting entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Jun 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 45 weeks(316 days from discovery to filing)
- Compliance flags
- CA 60-day late · 316d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2024→ Notified: Jun 13, 2025316d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.