HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHighContained
Decisely Insurance Services, LLC
bd_1d639799a42e9cf4 · schema v1 · pii pii-v1
Full breach record for Decisely Insurance Services, LLC →Decisely Insurance Services, LLC reported a supplemental data security incident affecting approximately 1,504 New Hampshire residents. Suspicious activity on Decisely's cloud storage platform was detected on December 17, 2024, with data acquisition occurring around December 16, 2024. Compromised data included names, DOBs, SSNs, passport numbers, and bank account details. Decisely engaged forensic experts, notified the FBI, and provided credit monitoring via Kroll.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3cd648a83eb0bdd4California State AGfiled 2025-07-21Verified
- bd_40a0cf061129ec59New Hampshire State AGfiled 2025-06-16(35d gap)Verified
- bd_0931d05286c611d0California State AGfiled 2025-06-14(37d gap)Verified
- bd_986d7ab39eab395bWashington State AGfiled 2025-06-14(37d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 38d gap
- bd_5233e95df693874aHHS OCRfiled 2025-06-13(38d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/decisely-20250721.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2025
- Raw hash
- 9f291337b21c235d417ae2a821aa2d9d90961800c9ddd834233967b27a652f98
Reporting entity
- Name
- Decisely Insurance Services, LLCnorm: decisely insurance
Victim entity
- Name
- Decisely Insurance Services, LLCnorm: decisely insurance
Incident
- Discovered
- Dec 17, 2024
- Materiality determined
- May 29, 2025
- Notification sent
- Jun 13, 2025
- Affected individuals
- 1,504
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 31 weeks(216 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.