DisclosureLens
HackingProfessional ServicesProfessional ServicesVulnerability ExploitCustomer Data InvolvedIdentity (basic)Government IDHighResolved

CRB GROUP, INC.

bd_5e29086617cf07f2 · schema v1 · pii pii-v1

Severity

High

Discovered

May 29, 2024

Filed

Aug 21, 2024

To disclose

12 weeks

Affected · nationwide

1,1984 in this filing

Linked

6 filings

Confidence

65%
Full breach record for CRB GROUP, INC.2 incidents on file

CRB Group, Inc. reported an external system breach (hacking) occurring on December 25, 2023, discovered on May 29, 2024. The incident affected 1,198 individuals nationwide, including 4 Maine residents. Personal information, including names and government identifiers, was compromised. CRB Group notified affected individuals in writing on August 21, 2024, and offered 12 months of credit monitoring via TransUnion.

Leak gap clock Leak >180d12 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 156 days
discovery → filing · 12 weeks / 84 days

Dec 25, 2023

Begins

May 29, 2024

Discovered

Aug 21, 2024

Filed

vs. sector median

7 wks faster

This filing is one of 6 about the same incident.View merged incident
A leak claim by lockbit_3 about this victim predates this filing by 241 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGAug 21 · first
New Hampshire State AGAug 21 · first
Indiana State AGAug 21 · first
Massachusetts State AGAug 21 · first
Maine State AGAug 21 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.