Graebel Companies, Inc.
bd_6a95a3f3e16bf52f · schema v1 · pii pii-v2
Full breach record for Graebel Companies, Inc. →Graebel Companies, Inc. reported a cybersecurity incident to Nebraska regulators in November 2025. Unauthorized access occurred between December 19-22, 2024, resulting in the exfiltration of client data including Social Security numbers and financial account numbers. Approximately 25 Nebraska residents were notified starting September 22, 2025. Graebel reported the incident to federal law enforcement and provided 24 months of credit monitoring via TransUnion.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 19, 2024
Begins
Dec 19, 2024
Discovered
Nov 10, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Maine State AGbd_22d338674a0c0fa32025-11-10Candidate
- New Hampshire State AGbd_2c087f5658292a9b2025-11-10Verified
- Indiana State AGbd_3338885415a19f862025-11-10Verified
- Vermont State AGbd_362736f9c58a9c4a2025-11-10Verified
Show 6 more filings ↓Show fewer ↑up to 144d gap
- Massachusetts State AGbd_5821858b3ce91bb82025-11-10Verified
- Montana State AGbd_8a7899be71a5b6442025-11-10Candidate
- Texas State AGbd_8f785a8bea830a5e2025-11-12 · +2dVerified
- Vermont State AGbd_73c177814cb98cef2026-04-03 · +144dVerified
- New Hampshire State AGbd_8c8a4e0cfc33cf0e2026-04-03 · +144dVerified
- Maine State AGbd_c56149c9cc9becba2026-04-03 · +144dVerified
Filing propagation · 11 filings · 8 states
View merged incident ↗Pattern: first filing Nov 10 (ME), last Apr 3 (ME) — a 144-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.