DisclosureLens
HackingProfessional ServicesProfessional ServicesData ExfiltratedEmployee Data InvolvedDelayed DiscoveryIdentity (basic)PIILowContained

Alera Group, Inc.

bd_4ba58e33f9a13772 · schema v1 · pii pii-v1

Severity

Low

Discovered

Aug 1, 2024

Filed

May 21, 2025

To disclose

42 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

65%
Full breach record for Alera Group, Inc.5 incidents on file

Alera Group, Inc. notified California residents of unauthorized access to its network between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and potentially other data, may have been removed from its network. Affected individuals are current or former employees and dependents. Alera Group engaged third-party cybersecurity specialists, secured its environment, and is offering 24 months of credit monitoring and identity theft protection services through IDX.

California clockDiscovered Aug 1, 2024Notified May 21, 2025293d CA 60-day late42 weeks discovery → filing

Incident timeline

undetected · 13 days
discovery → filing · 42 weeks / 293 days

Jul 19, 2024

Begins

Aug 1, 2024

Discovered

May 21, 2025

Filed

vs. sector median

+24 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
New Hampshire State AGMay 21 · first
Indiana State AGMay 21 · first
California State AGMay 21 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.