Alera Group, Inc.
bd_e4aec53334445310 · schema v1 · pii pii-v1
Full breach record for Alera Group, Inc. →Alera Group, Inc., an insurance brokerage firm, reported unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and other variable data elements, may have been removed from its network. The incident was first detected in August 2024. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring to affected individuals. This is a supplemental notice filed with the California Attorney General.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-613975
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 7, 2025
- Raw hash
- bb4866da2e7b8f090dd6973b933e90244ed24056d0c3332de6b353427ebc5cfa
Reporting entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Victim entity
- Name
- Alera Group, Inc.norm: alera group
- Domain
- aleragroup.com
Incident
- Discovered
- Aug 1, 2024
- Materiality determined
- —
- Notification sent
- Nov 7, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 15 months(463 days from discovery to filing)
- Compliance flags
- CA 60-day late · 463d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 1, 2024→ Notified: Nov 7, 2025463d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.