MARSH & MCLENNAN COMPANIES, INC.
bd_5f0d93b73a89ebf1 · schema v1 · pii pii-v1
Full breach record for MARSH & MCLENNAN COMPANIES, INC. →7 incidents on fileMarsh McLennan notified Washington AG of a cyberattack where an unauthorized actor exploited a third-party software vulnerability between April 22-30, 2021. Discovered April 26, 2021. Affected 2,550 WA residents, exposing names, SSNs, IDs, passports, and health insurance data. Marsh McLennan engaged FBI, reset admin rights, and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 22, 2021
Begins
Apr 26, 2021
Discovered
Jun 30, 2021
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_7ce38a76e14396742021-06-30Verified
- Montana State AGbd_983239faa83781892021-06-30Verified
- South Carolina State AGbd_f54cc90d7abb48352021-06-30Verified
- California State AGbd_fa303094cee7b57b2021-06-30Verified
Show 2 more filings ↓Show fewer ↑up to 183d gap
- Oregon State AGbd_e9678b0aaa98aeb82021-07-01 · +1dVerified
- Maine State AGbd_8767e869d58fdbbb2021-12-30 · +183dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Pattern: first filing Jun 30 (NH), last Dec 30 (ME) — a 183-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.