Confirmed breach. Intrusion Mar 30, 2025–Mar 31, 2025, discovered Apr 2, 2025 — the first regulatory filing landed 196 days later (flagged late). 506 individuals reported across the linked filings.
Coalesce, LLC dba Benefitelect notified California residents of unauthorized access and exfiltration of files containing names, addresses, dates of birth, and Social Security numbers between March 30-31, 2025. Suspicious activity was detected on April 2, 2025. The company secured systems, engaged third-party specialists, and is offering credit monitoring.
CA 60-day late · 146d
🇺🇸AZHHS OCRlinked via same-victim cross-source · 100%
Coalesce, LLC dba Benefitelect, an Arizona-based Business Associate, reported to HHS OCR on 2025-10-15 a Hacking/IT Incident affecting 501 individuals. Breached information was located on a Network Server. A business associate was present. No further detail is available in the public filing.
Affected (this filing): 501
HHS notified
🦬Montana State AGlinked via multistate filing link · 100%
Coalesce, LLC dba BenefitElect reported a data breach to the Montana Attorney General. The breach was reported on 2025-10-15. The breach occurred from 03/30/2025 to 03/31/2025. 5 Montana residents were affected.
Affected (this filing): 5
⛰️New Hampshire State AGMost recentlinked via same-victim cross-source · 100%
Coalesce, LLC dba Benefitelect notified the NH AG of a data event where an unauthorized actor exploited a Crush FTP vulnerability to access and exfiltrate files containing names, addresses, DOBs, and SSNs between March 30-31, 2025. The company detected suspicious activity on April 2, 2025, and began notifying NH residents in October 2025.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.