National Accident Health General Agency (NAHGA), a Maine-based third-party administrator specializing in healthcare claims for youth sports, day care centers, and NCAA athlete accidents, reported a significant data breach affecting over 181,000 individuals. The breach, discovered in April, involved unauthorized access to NAHGA's network, potentially compromising sensitive claims data, including medical information and personal identifiers related to sports-related accidents. NAHGA responded by securing its systems and engaging third-party cybersecurity experts to investigate the incident, confirming that files and data were accessed or acquired between April 8 and April 11.
The affected data includes information from a wide range of clients, such as K-12 youth sports programs, NCAA athletic programs, and other specialty organizations. NAHGA has notified impacted individuals and submitted a breach report to the Maine attorney general, outlining the scope and nature of the compromised information. The company continues to work on mitigating the impact and enhancing its security posture to prevent future incidents.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
At least one proposed federal class action lawsuit was filed against NAHGA alleging inadequate security practices in connection with the breach. The suit followed disclosure of the incident and the exposure of sensitive claimant data.
NAHGA began notifying affected individuals after concluding that over 181,000 people may have had sensitive personal and medical information exposed in the April breach. The notifications disclosed the scope of the compromised data and the potential impact on claimants.
After discovering the intrusion, NAHGA said it secured its systems and engaged third-party cybersecurity experts to investigate the incident. The company determined that data potentially affected included names, Social Security numbers, dates of birth, driver's license numbers, health insurance details, and medical or treatment information.
National Accident Health General Agency said an unauthorized party accessed its systems between April 8 and April 11, 2025. The incident potentially exposed personal, insurance, and medical information tied to youth sports and NCAA-related accident claims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.