HackingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Graebel Companies, Inc.
bd_8c8a4e0cfc33cf0e · schema v1 · pii pii-v1
Full breach record for Graebel Companies, Inc. →Graebel Companies, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a cybersecurity incident occurring between December 19 and 22, 2024. The incident involved unauthorized access to files containing client PII (names, addresses). Approximately 12 New Hampshire residents were notified. Graebel secured its network, engaged in an investigation, reported to federal law enforcement, and offered 24 months of credit monitoring via TransUnion.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_73c177814cb98cefVermont State AGfiled 2026-04-03Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/graebel-companies-20260403.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 3, 2026
- Raw hash
- f9ff39d52f4939e41c7c15a92f9061e7cf8ce2b20d47b95d8fd871d8fc5e838f
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- Graebel Companies, Inc.norm: graebel companies
Incident
- Discovered
- Dec 22, 2024
- Materiality determined
- —
- Notification sent
- Nov 13, 2025
- Affected individuals
- 12
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported this event to federal law enforcement
Compliance
- Time to disclose
- 16 months(467 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.