Aon
bd_bed97e68b6fb0b6c · schema v1 · pii pii-v1
Full breach record for Aon →11 incidents on fileAon Corporation PLC notified the New Hampshire Attorney General of a cyber event affecting approximately 233 NH residents. Unauthorized access occurred between Dec 29, 2020, and Feb 26, 2022, exploiting a zero-day vulnerability (CVE-2021-27852). The attacker staged and exfiltrated unstructured data from SharePoint and Outlook, including names, SSNs, and driver's license numbers. Aon settled with the attacker, who deleted the data. Aon provided 24 months of credit monitoring and enhanced security controls.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 29, 2020
Begins
Feb 25, 2022
Discovered
May 31, 2022
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitedispossessorbd_d4e9fb69d737f7a62022-07-03 · +33dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Indiana State AGbd_fde32f8598ecaa8b2022-05-27 · +4dVerified
- HHS OCRbd_1659c519cbbc91942022-05-26 · +5dVerified by operator
- Oregon State AGbd_a34b45e6fa897e082022-05-26 · +5dVerified
- California State AGbd_a3a4b3bd3ddac8fc2022-05-26 · +5dVerified
Show 5 more filings ↓Show fewer ↑up to 31d gap
- Maine State AGbd_bdef13158191852d2022-05-26 · +5dCandidate
- New Hampshire State AGbd_5ba6400246ccb57f2022-06-13 · +13dVerified by operator
- Montana State AGbd_f3bea3092e6d8ecc2022-06-13 · +13dVerified by operator
- Maine State AGbd_ee7cfc9886fcd7132022-06-24 · +24dCandidate
- Maine State AGbd_83344b1fed7fdb7a2022-07-01 · +31dCandidate
Showing first 10 of 13 linked disclosures.
Filing propagation · 10 filings · 7 states
View merged incident ↗Pattern: first filing May 26 (IL), last Jul 1 (ME) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.