HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumContained
Southeast Series of Lockton Companies, LLC (Lockton)
bd_2920eb8e7cca2748 · schema v1 · pii pii-v1
Full breach record for Southeast Series of Lockton Companies, LLC (Lockton) →Lockton experienced unauthorized access to a single employee account on Nov 20, 2024. Data included names, SSNs, DOBs, and PHI for 3 Maryland residents. Lockton engaged forensic experts, notified law enforcement, and is offering 24 months of credit monitoring.
Maryland clock✗ MD AG >90d14 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_38cfececfca4b041HHS OCRfiled 2025-02-28Verified
- bd_7ee2b0704c0f6823Indiana State AGfiled 2025-02-28Verified
- bd_ea9f16c658323c72Maine State AGfiled 2025-03-07(7d gap)Verified
- bd_43bd7d1ade59b3d0South Carolina State AGfiled 2025-03-20(20d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 20d gap
- bd_5df5b90dd55b9668Washington State AGfiled 2025-03-20(20d gap)Verified
- bd_9085e77425a5f07dMontana State AGfiled 2025-03-20(20d gap)Candidate
- bd_b2f928ad9456819eOregon State AGfiled 2025-03-20(20d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376437.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2025
- Raw hash
- d08817d673fabc0ca5d33a76db3458f7d9096e10da9cb2130ea61fd58206dfad
Reporting entity
- Name
- Norton Rose Fulbright US LLPnorm: norton rose fulbright us
Victim entity
- Name
- Southeast Series of Lockton Companies, LLC (Lockton)norm: southeast series of lockton companies llc lockton
Incident
- Discovered
- Nov 20, 2024
- Materiality determined
- —
- Notification sent
- Feb 5, 2025
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.