HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Alera Group, Inc.
bd_1ed3f272d914f341 · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The incident was discovered in August 2024. Approximately 101 New Hampshire residents were notified. Personal information was potentially exfiltrated. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and provided 24 months of complimentary credit monitoring through IDX.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_d9430cde35cab839New Hampshire State AGfiled 2025-09-05(8d gap)Verified
- bd_e7ea8ca0d160b7f9South Carolina State AGfiled 2025-07-30(29d gap)Verified
- bd_43a2a7cbde02dff7New Hampshire State AGfiled 2025-07-29(30d gap)Verified
- bd_69b4192ea6eb9f94California State AGfiled 2025-07-29(30d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 76d gap
- bd_ca0bc76a00a8880aDelaware State AGfiled 2025-07-29(30d gap)Verified
- bd_145c82e3ce4b31b0California State AGfiled 2025-06-13(76d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/alera-group-20250828.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2025
- Raw hash
- e987e78783069f861911498a9a682b43ce5bf9136da66b7de8f3c1cf7a795fc3
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Aug 28, 2025
- Affected individuals
- 101
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(392 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.