HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
GOOSEHEAD INSURANCE, INC.
bd_bccf3fe3ea138107 · schema v1 · pii pii-v1
Full breach record for GOOSEHEAD INSURANCE, INC. →Goosehead Insurance Agency, LLC notified California residents of an unauthorized access incident occurring between March 6 and March 13, 2025. An external actor accessed systems and copied files containing personal information, including names and other breached elements. The company implemented technical security measures and is offering credit monitoring.
Leak gap clock✗ Leak >180d30 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_c036d85d395a610aIndiana State AGfiled 2025-10-10Verified
- bd_e81990469abb0e6eNew Hampshire State AGfiled 2025-10-10Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-612688
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 10, 2025
- Raw hash
- a1aa5daa7f54e80779f6b2fb7d0bbbeba1be078d6f213f79cd83989960c1f879
Reporting entity
- Name
- GOOSEHEAD INSURANCE, INC.norm: goosehead insurance
- Domain
- goosehead.com
Victim entity
- Name
- GOOSEHEAD INSURANCE, INC.norm: goosehead insurance
- Domain
- goosehead.com
Incident
- Discovered
- Mar 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notify applicable regulatory authorities, as required by law
Compliance
- Time to disclose
- 30 weeks(211 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.