DisclosureLens
HackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumActive

NEVRO CORP.

bd_9385df3948cc112d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 1, 2024

Filed

Apr 2, 2025

To disclose

17 weeks

Affected

10state residents only

Linked

6 filings

Confidence

66%
Full breach record for NEVRO CORP.2 incidents on file

Nevro Corp. notified the New Hampshire Attorney General on April 2, 2025, of a data event affecting approximately 10 state residents. Unauthorized access occurred between November 21 and December 1, 2024, when an unknown individual accessed systems and potentially exfiltrated personal information. Nevro discovered the activity on December 1, 2024, and completed its review on March 14, 2025. Response measures included engaging third-party cybersecurity specialists, notifying federal law enforcement, and offering credit monitoring services through Cyberscout.

Incident timeline

undetected · 10 days
discovery → filing · 17 weeks / 122 days

Nov 21, 2024

Begins

Dec 1, 2024

Discovered

Apr 2, 2025

Filed

vs. sector median

+5 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 1d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Illinois State AGApr 1 · first
New Hampshire State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.