HackingIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Alera Group, Inc.
bd_ca0bc76a00a8880a · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc. notified individuals of a data breach involving unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The incident resulted in the potential removal of personal information, including names and government identifiers. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and offered 24 months of credit monitoring and identity theft protection services through IDX to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_43a2a7cbde02dff7New Hampshire State AGfiled 2025-07-29Verified
- bd_69b4192ea6eb9f94California State AGfiled 2025-07-29Candidate
- bd_e7ea8ca0d160b7f9South Carolina State AGfiled 2025-07-30(1d gap)Verified
- bd_1ed3f272d914f341New Hampshire State AGfiled 2025-08-28(30d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 46d gap
- bd_d9430cde35cab839New Hampshire State AGfiled 2025-09-05(38d gap)Verified
- bd_145c82e3ce4b31b0California State AGfiled 2025-06-13(46d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/01/Alera-Group-Inc.-Notice-of-Data-Event-DE.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 29, 2025
- Raw hash
- abbe8d2ad6009d5c298d005a71b40fc51e9f1a3300a343e714c08c858c139c4b
Reporting entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Jul 29, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 52 weeks(362 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.