HackingVulnerability ExploitStolen CredentialsZero-DayData ExfiltratedRansom DemandedMulti-Stage ChainTargetedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCVE-2021-27852MediumContained
Aon
bd_bed97e68b6fb0b6c · schema v1 · pii pii-v1
Full breach record for Aon →Aon Corporation PLC notified the New Hampshire Attorney General of a cyber event affecting approximately 233 NH residents. Unauthorized access occurred between Dec 29, 2020, and Feb 26, 2022, exploiting a zero-day vulnerability (CVE-2021-27852). The attacker staged and exfiltrated unstructured data from SharePoint and Outlook, including names, SSNs, and driver's license numbers. Aon settled with the attacker, who deleted the data. Aon provided 24 months of credit monitoring and enhanced security controls.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d90bc38aa5d1753cMontana State AGfiled 2022-05-26(5d gap)Candidate
- bd_f3bea3092e6d8eccMontana State AGfiled 2022-06-13(13d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/aon-20220531.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2022
- Raw hash
- 284874850856aab0239583e769ab5f58d11b707b3f893b10d0e6388aa9fa50ba
Reporting entity
- Name
- Aonnorm: aon
- Domain
- aon.com
Victim entity
- Name
- Aonnorm: aon
- Domain
- aon.com
Incident
- Discovered
- Feb 25, 2022
- Materiality determined
- —
- Notification sent
- May 27, 2022
- Affected individuals
- 233
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1074 Data StagedT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the event to federal law enforcement
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 14 weeks(95 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.