MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Graebel Companies, Inc.
bd_2c087f5658292a9b · schema v1 · pii pii-v1
Full breach record for Graebel Companies, Inc. →Graebel Companies, Inc. notified the New Hampshire Attorney General of a cybersecurity incident occurring between December 19 and 22, 2024. The incident involved unauthorized access to and exfiltration of files containing Social Security numbers and financial account numbers. Approximately 18 New Hampshire residents were identified as affected. Graebel reported the incident to federal law enforcement, implemented additional security measures, and provided 24 months of complimentary credit monitoring through TransUnion to impacted individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_22d338674a0c0fa3Maine State AGfiled 2025-11-10Candidate
- bd_3338885415a19f86Indiana State AGfiled 2025-11-10Verified
- bd_362736f9c58a9c4aVermont State AGfiled 2025-11-10Verified
- bd_8a7899be71a5b644Montana State AGfiled 2025-11-10Candidate
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_8f785a8bea830a5eTexas State AGfiled 2025-11-12(2d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/graebel-20251110.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 10, 2025
- Raw hash
- 64879b1e7916571fe97109fb1d7c4f455d538e35790ac64ce56d0402278f342f
Reporting entity
- Name
- Graebel Companies, Inc.norm: graebel companies
Victim entity
- Name
- Graebel Companies, Inc.norm: graebel companies
Incident
- Discovered
- Dec 19, 2024
- Materiality determined
- —
- Notification sent
- Nov 10, 2025
- Affected individuals
- 18
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this event to U.S. federal law enforcementproviding written notice of this event to relevant privacy regulators and to the major U.S. credit reporting agencies
Compliance
- Time to disclose
- 47 weeks(326 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.