HackingStolen CredentialsCustomer Data InvolvedPIIIDENTITY_BASICLowContained
CRB GROUP, INC.
bd_49ff40255db6cfb5 · schema v1 · pii pii-v1
Full breach record for CRB GROUP, INC. →CRB Group, Inc. notified the New Hampshire Attorney General of a data incident where an unauthorized actor acquired limited information of 9 NH residents between Dec 25, 2023, and Jan 3, 2024. CRB detected the incident on Jan 3, 2024, engaged third-party specialists, and confirmed the scope on May 29, 2024. Notices offering credit monitoring were sent on Aug 21, 2024.
Leak gap clock✗ Leak >180d33 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 241 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1b0368e8efedb4bbMontana State AGfiled 2024-08-21Candidate
- bd_5e29086617cf07f2Maine State AGfiled 2024-08-21Verified by operator
- bd_d7da9110f4502c63Indiana State AGfiled 2024-08-21Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/crb-group-20240821.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 21, 2024
- Raw hash
- eff2ca3caa34a22e1d2a1c59973e0847057c91fd33df45e6f23950521866f0d6
Reporting entity
- Name
- CRB GROUP, INC.norm: crb group
- Domain
- crbgroup.com
Victim entity
- Name
- CRB GROUP, INC.norm: crb group
- Domain
- crbgroup.com
Incident
- Discovered
- Jan 3, 2024
- Materiality determined
- May 29, 2024
- Notification sent
- Aug 21, 2024
- Affected individuals
- 9
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Office of the Attorney General Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 33 weeks(231 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.