HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHighContained
KELLY & ASSOCIATES INSURANCE GROUP, INC.
bd_ffbecc7a42efe32c · schema v1 · pii pii-v1
Full breach record for KELLY & ASSOCIATES INSURANCE GROUP, INC. →Kelly and Associates Insurance Group, Inc. disclosed a cybersecurity incident affecting approximately 1,280 Delaware residents. Unauthorized access occurred between December 12 and 17, 2024, resulting in the copying of files containing names and government identifiers. The company engaged forensic specialists, notified the FBI, and provided credit monitoring services to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_0f7d076c53a7287fIndiana State AGfiled 2025-04-09Verified
- bd_e980ad4c2b5fa9f9New Hampshire State AGfiled 2025-04-09Verified
- bd_081d4f7ea0b31364California State AGfiled 2025-05-02(23d gap)Candidate
- bd_2c6bb1bf725cb263Delaware State AGfiled 2025-05-30(51d gap)Candidate
Show 4 more filings ↓Show fewer ↑up to 82d gap
- bd_4f44a4adf124ba68Delaware State AGfiled 2025-05-30(51d gap)Candidate
- bd_41072bfcc8a1e6bbCalifornia State AGfiled 2025-06-30(82d gap)Verified
- bd_48914041e37aa218Delaware State AGfiled 2025-06-30(82d gap)Candidate
- bd_c7f910f60a9343cfDelaware State AGfiled 2025-06-30(82d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/04/Kelly-Benefits-Supplemental.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2025
- Raw hash
- b035733cc46ac3593e746516a74ec0ee489419772e55db9d573d63d2ddfff40c
Reporting entity
- Name
- KELLY & ASSOCIATES INSURANCE GROUP, INC.norm: kelly associates insurance
- Domain
- kellybenefits.com
Victim entity
- Name
- KELLY & ASSOCIATES INSURANCE GROUP, INC.norm: kelly associates insurance
- Domain
- kellybenefits.com
Incident
- Discovered
- Dec 12, 2024
- Materiality determined
- —
- Notification sent
- Apr 21, 2025
- Affected individuals
- 1,280
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported matter to the Federal Bureau of Investigation
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 17 weeks(118 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.