MisusePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Progressive County Mutual Insurance Company, Progressive Direct Ins. Co., Progressive Northern Ins. Co., Progressive Select Ins. Co., and Progressive Universal Ins. Co.
bd_5e77fdeafcb0ab7c · schema v1 · pii pii-v1
Full breach record for Progressive County Mutual Insurance Company, Progressive Direct Ins. Co., Progressive Northern Ins. Co., Progressive Select Ins. Co., and Progressive Universal Ins. Co. →Progressive insurance companies notified NH AG of an insider incident where an employee used a false identity to obtain employment. The employee accessed customer call data from Oct 2023 to Apr 2024. 56 NH residents were notified on June 7, 2024, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed56 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/progressive-county-mutual-direct-northern-select-universal-20240607.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 7, 2024
- Raw hash
- 8ea5615f6b0cd0e7fc90683ac655fc5f49a33f4098ede42bbd9eeac1564075fc
Reporting entity
- Name
- Progressive County Mutual Insurance Company, Progressive Direct Ins. Co., Progressive Northern Ins. Co., Progressive Select Ins. Co., and Progressive Universal Ins. Co.norm: progressive county mutual insurance company progressive direct ins co progressive northern ins co progressive select ins co and progressive universal ins
Victim entity
- Name
- Progressive County Mutual Insurance Company, Progressive Direct Ins. Co., Progressive Northern Ins. Co., Progressive Select Ins. Co., and Progressive Universal Ins. Co.norm: progressive county mutual insurance company progressive direct ins co progressive northern ins co progressive select ins co and progressive universal ins
Incident
- Discovered
- Apr 1, 2024
- Materiality determined
- —
- Notification sent
- Jun 7, 2024
- Affected individuals
- 56
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified Attorney General John Formella
- Initial access
- insider_action
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.