Volvo Group North America, LLC
bd_fb690e3b860971d3 · schema v1 · pii pii-v1
Full breach record for Volvo Group North America, LLC →Volvo Group North America reported a data incident involving its health plan administrator's third-party vendor, Conduent Business Services, LLC. Conduent experienced a ransomware attack where an unauthorized third party accessed its environment from October 21, 2024, to January 13, 2025. The incident impacted a limited portion of Conduent's network, resulting in the exposure of personal information for 4 New Hampshire residents. Conduent secured its networks, engaged forensic experts, notified law enforcement, and provided credit monitoring services to affected individuals. Notifications to consumers began on January 28, 2026.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_c510bba3d334fe22Indiana State AGfiled 2026-01-28(12d gap)Candidate
- bd_cc587fc65012bd8cIndiana State AGfiled 2026-01-28(12d gap)Candidate
- bd_470b84b69163e518New Hampshire State AGfiled 2026-03-26(45d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/volvo-group-north-america-20260209.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 9, 2026
- Raw hash
- 8d4d189cc7e5a97124033352a8c101fdd8993e6e6441d52bd810bdad84a98120
Reporting entity
- Name
- Alston & Bird LLPnorm: alston bird
Victim entity
- Name
- Volvo Group North America, LLCnorm: volvo group north america
Incident
- Discovered
- Jan 13, 2025
- Materiality determined
- —
- Notification sent
- Jan 28, 2026
- Affected individuals
- 4
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General's Consumer Protection Bureau
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 months(392 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.