Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
INSURANCE OFFICE OF AMERICA, INC.
bd_17bd8478f3f372c9 · schema v1 · pii pii-v1
Full breach record for INSURANCE OFFICE OF AMERICA, INC. →Insurance Office of America (IOA) notified the New Hampshire Attorney General on January 16, 2026, of a phishing incident affecting 54 NH residents. Unauthorized access occurred between June 25-30, 2025, resulting in the exposure of names and Social Security numbers. IOA engaged forensic experts, notified law enforcement, and provided 24 months of credit monitoring to affected individuals.
Leak gap clock⏱ Leak >90d29 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by daixin about this victim predates this filing by 126 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_75f2ffc917a84d45Indiana State AGfiled 2026-01-16Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/insurance-office-america-20260116.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2026
- Raw hash
- 9c01e77c6b51b5111de14698f37d4298b3263594818698212473aa4f1bb83f6e
Reporting entity
- Name
- FOLEY & LARDNER LLPnorm: foley lardner
- Domain
- foley.com
Victim entity
- Name
- INSURANCE OFFICE OF AMERICA, INC.norm: insurance office of america
- Domain
- ioausa.com
Incident
- Discovered
- Jun 30, 2025
- Materiality determined
- —
- Notification sent
- Jan 16, 2026
- Affected individuals
- 54
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 29 weeks(200 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.