Alera Group, Inc.
ent_019dea42bdc63f9728c151457e1e7acc
Disclosures
25+
State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
174,378
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Alera Group, Inc.
- Normalized
- alera group— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2549003D76KZAKICNX26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- aleragroup.com
Disclosure history (newest 25)newest first
- Oregon State AGas victim2025-12-18
Alera Group reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-18. The breach occurred during 7/19/2025 - 8/4/2025. The breach was discovered on 4/28/2025. 18,159 individuals were affected. Notice was sent on 11/7/2025.
- California State AGas victim2025-11-07
Alera Group, Inc., an insurance brokerage firm, reported unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and other variable data elements, may have been removed from its network. The incident was first detected in August 2024. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring to affected individuals. This is a supplemental notice filed with the California Attorney General.
- Texas State AGas victim2025-10-24
Alera Group, Inc. based in Chicago, Illinois, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-28 and reported on 2025-10-24. 105,555 Texas residents were affected. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information. Consumers were notified via Posted at company website or special website;U.S. Mail.
- Maine State AGas victim2025-09-29
Alera Group, Inc. reported an external system breach (hacking) occurring on July 19, 2024, discovered on April 28, 2025. The incident affected 4 Maine residents. The company provided written notification on September 29, 2025, and offered 24 months of identity theft protection services through IDX.
- Maine State AGas victim2025-09-05
Alera Group, Inc. reported a supplemental data breach notice to the Maine Attorney General. Unauthorized access occurred between July 19 and August 4, 2024. The breach was discovered in August 2024. One Maine resident was affected. Personal information including names was involved. Alera Group engaged third-party cybersecurity specialists and is offering 24 months of credit monitoring through IDX.
- New Hampshire State AGas victim2025-09-05
Alera Group, Inc. filed a supplemental notice with the New Hampshire Attorney General on September 5, 2025, regarding a data breach occurring between July 19, 2024, and August 4, 2024. The incident involved unauthorized access resulting in the potential exfiltration of personal information, including names and government identifiers. Alera Group notified approximately one New Hampshire resident and provided 24 months of complimentary credit monitoring through IDX.
- Maine State AGas victim2025-08-28
Alera Group, an insurance brokerage, reported a supplemental breach affecting 169 Maine residents. Unauthorized access occurred between July 19 and August 4, 2024. The breach was discovered in August 2024. Personal information was potentially removed from the network. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and provided 24 months of credit monitoring through IDX to affected individuals.
- New Hampshire State AGas victim2025-08-28
Alera Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The incident was discovered in August 2024. Approximately 101 New Hampshire residents were notified. Personal information was potentially exfiltrated. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and provided 24 months of complimentary credit monitoring through IDX.
- California State AGas victim2025-08-28
Alera Group, Inc., an insurance brokerage, confirmed on April 28, 2025, that personal information may have been removed from its network due to unauthorized access occurring between July 19, 2024, and August 4, 2024. The company first learned of the activity in August 2024. Affected data includes names and other variable data elements. Alera Group engaged third-party cybersecurity specialists, secured its environment, and is offering 24 months of credit monitoring. This is a supplemental notice.
- Illinois State AGas victim2025-08-01
ALERA GROYP filed a data-breach notice with the Illinois Attorney General in August 2025 (case 25-08-362). The register records the breach as discovered on August 14, 2024. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- South Carolina State AGas victim2025-07-30
Alera Group, an insurance brokerage, notified South Carolina residents of unauthorized access to its network occurring July 19–August 4, 2024. Personal information, including names, was potentially removed. Alera engaged third-party cybersecurity specialists, implemented additional security measures, and offers 24 months of credit monitoring. No identity theft was confirmed.
- Montana State AGas victim2025-07-29
Alera Group, Inc. notified individuals of a data breach where unauthorized access to its network occurred between July 19 and August 4, 2024. Personal information, including names, was removed. The incident was discovered in August 2024. Alera engaged third-party specialists and is offering 24 months of credit monitoring.
- New Hampshire State AGas victim2025-07-29
Alera Group, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding unauthorized access to its network occurring between July 19 and August 4, 2024. The incident resulted in the exfiltration of personal information, including names, from approximately 8,343 New Hampshire residents. Alera Group detected the activity in August 2024, engaged third-party cybersecurity specialists, and is offering 24 months of credit monitoring services to affected individuals.
- ILLINOISHHS OCRas victim2025-07-29
Alera Group, Inc. reported to HHS on 2025-07-29 a Hacking/IT Incident affecting 174378 individuals. Breached information located on Network Server.
- Nebraska State AGas reporting2025-07-29
Alera Group, Inc. notified Utility Supply and Construction Co that unauthorized access to its network occurred between July 19, 2024, and August 4, 2024. The incident involved the removal of personal information, specifically names, from Alera Group's systems. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and offered 12 months of credit monitoring and identity theft protection to affected individuals. The notification was sent in July 2025.
- California State AGas victim2025-07-29
Alera Group, Inc., an insurance brokerage, reported unauthorized access to its network between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names, may have been removed. First awareness of the activity occurred in August 2024. The firm engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring to affected individuals. This is a supplemental notice.
- ILLINOISHHS OCRas victim2025-07-29
Alera Group, Inc. reported to HHS on 2025-07-29 a Hacking/IT Incident affecting 155567 individuals. Breached information located on Network Server. Business associate present.
- Iowa State AGas victim2025-07-29
Alera Group, Inc. notified Iowa AG of unauthorized access to its network occurring July 19–Aug 4, 2024. First detected in August 2024. Personal info including SSN, driver's license, financial accounts, and health/medical data was potentially exfiltrated. 8,014 Iowa residents notified on July 29, 2025. Response included forensic investigation, law enforcement notification, and 2 years of credit monitoring.
- Delaware State AGas victim2025-07-29
Alera Group, Inc. notified individuals of a data breach involving unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The incident resulted in the potential removal of personal information, including names and government identifiers. Alera Group engaged third-party cybersecurity specialists, implemented additional security measures, and offered 24 months of credit monitoring and identity theft protection services through IDX to affected individuals.
- Maine State AGas victim2025-07-29
Alera Group, Inc. reported a supplemental data breach affecting 1,845 Maine residents. Unauthorized access occurred between July 19 and August 4, 2024, with discovery in August 2024. Notices were sent on July 29, 2025. The incident involved external hacking resulting in the potential exposure of personal information. Alera Group engaged third-party cybersecurity specialists and provided 24 months of credit monitoring via IDX.
- California State AGas victim2025-06-13
Alera Group, Inc. reported unauthorized access to its technology environment between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and other data elements, may have been removed from its network. The incident affected current and former employees and their dependents. Alera engaged third-party cybersecurity specialists, implemented additional security measures, and is offering 24 months of credit monitoring and identity theft protection services to affected individuals.
- Maine State AGas victim2025-06-13
Alera Group, Inc. reported a supplemental data breach in Maine affecting 2 residents. Unauthorized access occurred between July 19 and August 4, 2024. The breach was discovered in August 2024. Notices were sent on June 13, 2025, offering 24 months of credit monitoring. Personal information was potentially removed from the network.
- Nebraska State AGas victim2025-05-21
Alera Group, Inc. notified Nebraska residents of a data breach involving unauthorized access to its network between July 19, 2024, and August 4, 2024. The incident affected approximately 7 Nebraska residents, exposing names, Social Security numbers, health insurance, financial account, and medical information. Alera Group notified federal law enforcement, implemented additional security measures, and provided two years of free credit monitoring through IDX.
- New Hampshire State AGas victim2025-05-21
Alera Group, Inc. notified New Hampshire residents that personal information was removed from its network due to unauthorized access occurring between July 19 and August 4, 2024. The company discovered the incident in August 2024. Approximately 150 NH residents were notified on May 21, 2025. Affected data includes PII such as names and government IDs. Alera Group engaged law enforcement, implemented security measures, and offered credit monitoring.
- California State AGas victim2025-05-21
Alera Group, Inc. notified California residents of unauthorized access to its network between July 19, 2024, and August 4, 2024. The company confirmed on April 28, 2025, that personal information, including names and potentially other data, may have been removed from its network. Affected individuals are current or former employees and dependents. Alera Group engaged third-party cybersecurity specialists, secured its environment, and is offering 24 months of credit monitoring and identity theft protection services through IDX.