MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Telcom Insurance Group
bd_80a3dc02e3a89868 · schema v1 · pii pii-v1
Full breach record for Telcom Insurance Group →Telcom Insurance Group notified the New Hampshire Attorney General of a ransomware incident occurring on May 26, 2025. The attack encrypted servers and files containing names and Social Security numbers. The company engaged Mindcrest for forensic analysis and TransUnion for address location. Two New Hampshire residents were identified and notified on November 19, 2025. Remediation included enhanced security measures and 12 months of identity theft monitoring via Kroll.
Leak gap clock✗ Leak >180d25 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by lynx about this victim predates this filing by 188 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_65b156e4aa9615c1Vermont State AGfiled 2025-11-19Verified
- bd_98fb7d6761f94c2bMontana State AGfiled 2025-11-19Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/telcom-insurance-group-20251119.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 19, 2025
- Raw hash
- 649b8b0ea529f448cbfca32f0fc17fd9b93b96ba04b60ccb888f16a5bfdd2050
Reporting entity
- Name
- Alston & Bird LLPnorm: alston bird
Victim entity
- Name
- Telcom Insurance Groupnorm: telcom insurance
- Domain
- telcominsgrp.com
Incident
- Discovered
- May 26, 2025
- Materiality determined
- —
- Notification sent
- Nov 19, 2025
- Affected individuals
- 2
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John M. Formella
Compliance
- Time to disclose
- 25 weeks(177 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.