HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICMediumContained
Alera Group, Inc.
bd_43a2a7cbde02dff7 · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to its network occurring between July 19 and August 4, 2024. The incident resulted in the exfiltration of personal information, including names, from approximately 8,343 New Hampshire residents. Alera Group detected the activity in August 2024, engaged third-party cybersecurity specialists, and is offering 24 months of credit monitoring services to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_69b4192ea6eb9f94California State AGfiled 2025-07-29Candidate
- bd_ca0bc76a00a8880aDelaware State AGfiled 2025-07-29Verified
- bd_e7ea8ca0d160b7f9South Carolina State AGfiled 2025-07-30(1d gap)Verified
- bd_1ed3f272d914f341New Hampshire State AGfiled 2025-08-28(30d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 46d gap
- bd_d9430cde35cab839New Hampshire State AGfiled 2025-09-05(38d gap)Verified
- bd_145c82e3ce4b31b0California State AGfiled 2025-06-13(46d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/alera-group-20250729.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2025
- Raw hash
- bba296cc7a0105e7b72f463b050b6b24181f84fc9cb6f5a4243e71fdcd82228d
Reporting entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- Apr 28, 2025
- Notification sent
- Jul 29, 2025
- Affected individuals
- 8,343
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 52 weeks(362 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.