HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Progressive Auto Group
bd_e5b8471e2c3ca47f · schema v1 · pii pii-v1
Full breach record for Progressive Auto Group →Progressive Auto Group notified the New Hampshire Attorney General of a security incident involving unauthorized network access. The breach affected one New Hampshire resident, exposing name, driver's license/state ID, and potentially financial account numbers. The incident occurred on June 20, 2025, was discovered on that date, and notification was mailed on January 27, 2026. The company engaged a cybersecurity firm, secured the network, and provided one year of credit monitoring to the affected individual.
Leak gap clock✗ Leak >180d32 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
A leak claim by nitrogen about this victim predates this filing by 195 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6be3144308dc6396Leak Sitenitrogenfiled 2025-07-15(195d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_d377153f7de7aa5fIndiana State AGfiled 2025-12-29(29d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/progressive-auto-group-20260127.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 27, 2026
- Raw hash
- 25cd1ddaec1972665ca3bd9d3ad27e6a65f5a3262129a3db4cfcbc2b3ff3f7cb
Reporting entity
- Name
- Progressive Auto Groupnorm: progressive auto
- Domain
- progressiveautogroup.com
Victim entity
- Name
- Progressive Auto Groupnorm: progressive auto
- Domain
- progressiveautogroup.com
Incident
- Discovered
- Jun 20, 2025
- Materiality determined
- —
- Notification sent
- Jan 27, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 32 weeks(221 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.