HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICLowContained
Alera Group, Inc.
bd_69b4192ea6eb9f94 · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc., an insurance brokerage, reported unauthorized access to its network between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names, may have been removed. First awareness of the activity occurred in August 2024. The firm engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring to affected individuals. This is a supplemental notice.
California clockDiscovered Aug 1, 2024 → Notified Jul 29, 2025362d ✗ CA 60-day late52 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_43a2a7cbde02dff7New Hampshire State AGfiled 2025-07-29Verified
- bd_ca0bc76a00a8880aDelaware State AGfiled 2025-07-29Verified
- bd_e7ea8ca0d160b7f9South Carolina State AGfiled 2025-07-30(1d gap)Verified
- bd_1ed3f272d914f341New Hampshire State AGfiled 2025-08-28(30d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 46d gap
- bd_d9430cde35cab839New Hampshire State AGfiled 2025-09-05(38d gap)Verified
- bd_145c82e3ce4b31b0California State AGfiled 2025-06-13(46d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606284
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2025
- Raw hash
- 9e1604a19bac46de4ab7a123005fc43e67c480d28f8e5e6848f84ef1d101f8ea
Reporting entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Jul 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 52 weeks(362 days from discovery to filing)
- Compliance flags
- CA 60-day late · 362d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2024→ Notified: Jul 29, 2025362d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.