HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
KELLY & ASSOCIATES INSURANCE GROUP, INC.
bd_864ca5ef29cc3a4a · schema v1 · pii pii-v1
Full breach record for KELLY & ASSOCIATES INSURANCE GROUP, INC. →Kelly & Associates Insurance Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to its environment between December 12-17, 2024. The incident affected 941 New Hampshire residents, exposing names, SSNs, and financial account information. The company engaged forensic specialists, notified the FBI, and provided credit monitoring services to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_303c32a29abb8c81New Hampshire State AGfiled 2025-05-02(28d gap)Candidate
- bd_84dcd3063c063292New Hampshire State AGfiled 2025-06-30(31d gap)Verified
- bd_c69f40e6d4217f69Montana State AGfiled 2025-06-30(31d gap)Candidate
- bd_a12b2eead3f9e018New Hampshire State AGfiled 2025-04-21(39d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/kelly-associates-insurance-20250530.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 30, 2025
- Raw hash
- b990f64eae43fcb73f3e400df2f743c43fa9c93c36b55803588f806af941351a
Reporting entity
- Name
- KELLY & ASSOCIATES INSURANCE GROUP, INC.norm: kelly associates insurance
- Domain
- kellybenefits.com
Victim entity
- Name
- KELLY & ASSOCIATES INSURANCE GROUP, INC.norm: kelly associates insurance
- Domain
- kellybenefits.com
Incident
- Discovered
- Dec 12, 2024
- Materiality determined
- Mar 3, 2025
- Notification sent
- May 30, 2025
- Affected individuals
- 941
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this matter to the Federal Bureau of Investigationproviding written notice of this incident to relevant state and federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 weeks(169 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.