ARTHUR J. GALLAGHER & CO.
bd_5a60d99cfc68d2f6 · schema v1 · pii pii-v1
Full breach record for ARTHUR J. GALLAGHER & CO. →Arthur J. Gallagher & Co. notified South Carolina and other state attorneys general of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of systems and unauthorized access to certain network segments. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification letters were issued starting May 24, 2021.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_46c22c0e135074c1South Carolina State AGfiled 2021-08-17Verified
- bd_4802bf691a0b05cfDelaware State AGfiled 2021-08-17Verified
- bd_d8eb454e54010120South Carolina State AGfiled 2021-08-17Verified
- bd_d559ecce5b338533Delaware State AGfiled 2021-08-19(2d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 44d gap
- bd_98f9af366bf05501Delaware State AGfiled 2021-08-12(5d gap)Verified
- bd_367230a44c0b4f07South Carolina State AGfiled 2021-08-04(13d gap)Verified
- bd_cace63e34906c9e1Delaware State AGfiled 2021-08-04(13d gap)Verified
- bd_e05a56a536c799ddNew Hampshire State AGfiled 2021-09-07(21d gap)Verified
- bd_e1bf416a552091dfSouth Carolina State AGfiled 2021-09-08(22d gap)Verified
- bd_97dcb7179082a9e8South Carolina State AGfiled 2021-09-30(44d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/ContinentalCasualtyCompany.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2021
- Raw hash
- 394b4d4e160f01d5329ee8ebff5cda7ae58bf3f578aab4f4e50ff03449a4eaeb
Reporting entity
- Name
- ARTHUR J. GALLAGHER & CO.norm: arthur j gallagher
Victim entity
- Name
- ARTHUR J. GALLAGHER & CO.norm: arthur j gallagher
Incident
- Discovered
- Sep 26, 2020
- Materiality determined
- —
- Notification sent
- May 24, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to law enforcement and regulatory authorities
Compliance
- Time to disclose
- 46 weeks(325 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.