HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Aon
bd_a3a4b3bd3ddac8fc · schema v1 · pii pii-v1
Full breach record for Aon →Aon Plc reported a cybersecurity incident to the California Attorney General's Office. An unauthorized third party accessed Aon systems between December 29, 2020, and February 26, 2022. The incident involved the exfiltration of personal information, including names, Social Security numbers, and driver's license numbers. Aon retained cybersecurity firms and notified law enforcement (FBI). Remediation included enhanced security measures and 24 months of complimentary credit monitoring via Experian IdentityWorks. The notification was sent on May 27, 2022.
California clockDiscovered Feb 25, 2022 → Notified May 27, 202291d ✗ CA 60-day late13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_d4e9fb69d737f7a6Leak Sitedispossessorfiled 2022-07-03(38d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_a34b45e6fa897e08Oregon State AGfiled 2022-05-26Verified
- bd_bdef13158191852dMaine State AGfiled 2022-05-26Candidate
- bd_bf4952e393f83732Washington State AGfiled 2022-05-26Verified
- bd_ee7cfc9886fcd713Maine State AGfiled 2022-06-24(29d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 36d gap
- bd_83344b1fed7fdb7aMaine State AGfiled 2022-07-01(36d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553817
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 26, 2022
- Raw hash
- 9702d98125fca9a8396d8489d5e07852ef92431670f4f0022eca84839f97d613
Reporting entity
- Name
- Aonnorm: aon
- Domain
- aon.com
Victim entity
- Name
- Aonnorm: aon
- Domain
- aon.com
Incident
- Discovered
- Feb 25, 2022
- Materiality determined
- —
- Notification sent
- May 27, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the incident to California Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- CA 60-day late · 91d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 25, 2022→ Notified: May 27, 202291d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.