HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
MARSH & MCLENNAN COMPANIES, INC.
bd_7ce38a76e1439674 · schema v1 · pii pii-v1
Full breach record for MARSH & MCLENNAN COMPANIES, INC. →Marsh McLennan notified the New Hampshire Attorney General on June 30, 2021, regarding a breach discovered on April 26, 2021. An unauthorized actor exploited a vulnerability in third-party software between April 22 and April 30, 2021, to access personal information of 485 New Hampshire residents. Affected data included names, SSNs, driver's license numbers, and passport information. Marsh McLennan notified the FBI, reset access rights, and is offering two years of credit monitoring via Experian.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5f0d93b73a89ebf1Washington State AGfiled 2021-06-30Candidate
- bd_983239faa8378189Montana State AGfiled 2021-06-30Verified
- bd_f54cc90d7abb4835South Carolina State AGfiled 2021-06-30Verified
- bd_fa303094cee7b57bCalifornia State AGfiled 2021-06-30Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_e9678b0aaa98aeb8Oregon State AGfiled 2021-07-01(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/marsh-mclennan-20210630.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2021
- Raw hash
- f0dba8e02bcbeffdd05957c40fc4c8f4b5e0bdd9a80404a53a0815e2cebf90fa
Reporting entity
- Name
- MARSH & MCLENNAN COMPANIES, INC.norm: marsh mclennan companies
Victim entity
- Name
- MARSH & MCLENNAN COMPANIES, INC.norm: marsh mclennan companies
Incident
- Discovered
- Apr 26, 2021
- Materiality determined
- —
- Notification sent
- Jun 30, 2021
- Affected individuals
- 485
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified the U.S. Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.