Graebel Companies, Inc.
ent_69c49fb513613ab49cb4c496
Disclosures
9
State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
5,573
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Graebel Companies, Inc.
- Normalized
- graebel companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- 🍁Vermont State AGas victim2026-04-03
Graebel Companies, Inc. filed a supplemental notice with the Vermont AG regarding a December 2024 cybersecurity incident. The breach affected client data, including names and government IDs, impacting at least 4 Vermont residents. Graebel secured its network, engaged in investigation, notified federal law enforcement, and offered 24 months of credit monitoring via TransUnion.
- ⛰️New Hampshire State AGas victim2026-04-03
Graebel Companies, Inc. filed a supplemental notice with the New Hampshire Attorney General regarding a cybersecurity incident occurring between December 19 and 22, 2024. The incident involved unauthorized access to files containing client PII (names, addresses). Approximately 12 New Hampshire residents were notified. Graebel secured its network, engaged in an investigation, reported to federal law enforcement, and offered 24 months of credit monitoring via TransUnion.
- 🦞Maine State AGas victim2026-04-03
Graebel Companies, Inc. (a relocation services firm based in Aurora, CO) reported to the Maine AG a data security incident described as an 'External system breach (hacking).' The breach occurred on or about 12/19/2024 and was discovered on 10/24/2025 (a roughly 10-month delayed discovery). 17 Maine residents were affected; total persons affected was not disclosed in this filing. This is a supplemental notice; an initial notice related to the same event was issued on 11/10/2025, with additional consumer notifications on 11/13/2025, 12/19/2025, and 1/16/2026. The filing does not enumerate specific data elements compromised. 24 months of TransUnion credit monitoring and identity theft protection services were offered. Notice was filed via counsel Gregory Lederman of Mullen Coughlin LLC.
- ⭐Texas State AGas victim2025-11-12
Graebel Companies, Inc. based in Aurora, Colorado, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-10-13 and reported on 2025-11-12. 267 Texas residents were affected. 5,573 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via Posted at company website or special website;U.S. Mail.
- 🦞Maine State AGas victim2025-11-10
Graebel Companies, Inc. reported a data breach affecting 15 Maine residents. The incident was categorized as an external system breach (hacking) that occurred on December 19, 2024, and was discovered on October 24, 2025. Affected consumers were notified on November 10, 2025, and offered 24 months of credit monitoring and identity theft protection services through TransUnion.
- ⛰️New Hampshire State AGas victim2025-11-10
Graebel Companies, Inc. notified the New Hampshire Attorney General of a cybersecurity incident occurring between December 19 and 22, 2024. The incident involved unauthorized access to and exfiltration of files containing Social Security numbers and financial account numbers. Approximately 18 New Hampshire residents were identified as affected. Graebel reported the incident to federal law enforcement, implemented additional security measures, and provided 24 months of complimentary credit monitoring through TransUnion to impacted individuals.
- 🏎️Indiana State AGas victim2025-11-10
Graebel Companies Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-19 and was reported on 2025-11-10. 89 Indiana residents were affected. 5,573 individuals affected in total.
- 🍁Vermont State AGas victim2025-11-10
Graebel Companies, Inc. notified consumers of a cybersecurity incident occurring between December 19-22, 2024, where unauthorized actors accessed files containing personal information. Graebel secured its network, engaged in investigations, and reported the incident to federal law enforcement. Affected individuals are offered 24 months of credit monitoring through TransUnion. The specific data types were redacted in the template but typically include identity and government identifiers.
- 🦬Montana State AGas victim2025-11-10
Graebel Companies, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2025-11-10. The breach occurred from 12/19/2024 to 12/22/2024. 11 Montana residents were affected.