MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTPHIHEALTH_BASICAUTHENTICATIONBIOMETRICMediumContained
ARTHUR J. GALLAGHER & CO.
bd_cbd9465155c75b1c · schema v1 · pii pii-v1
Full breach record for ARTHUR J. GALLAGHER & CO. →Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems. The breach window spanned from June 3, 2020, to September 26, 2020. An unknown actor accessed or acquired data, including SSNs, driver's licenses, financial account info, PHI, and credentials. Gallagher took systems offline, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring via Kroll. The notice was filed with the California AG on June 30, 2021.
California clockDiscovered Sep 26, 2020 → Notified Jun 30, 2021277d ✗ CA 60-day late40 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 21 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_367230a44c0b4f07South Carolina State AGfiled 2021-08-04(35d gap)Verified
- bd_98f9af366bf05501Delaware State AGfiled 2021-08-12(43d gap)Verified
- bd_46c22c0e135074c1South Carolina State AGfiled 2021-08-17(48d gap)Verified
- bd_4802bf691a0b05cfDelaware State AGfiled 2021-08-17(48d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 92d gap
- bd_5a60d99cfc68d2f6South Carolina State AGfiled 2021-08-17(48d gap)Verified
- bd_d8eb454e54010120South Carolina State AGfiled 2021-08-17(48d gap)Verified
- bd_d559ecce5b338533Delaware State AGfiled 2021-08-19(50d gap)Verified
- bd_e05a56a536c799ddNew Hampshire State AGfiled 2021-09-07(69d gap)Verified
- bd_e1bf416a552091dfSouth Carolina State AGfiled 2021-09-08(70d gap)Verified
- bd_97dcb7179082a9e8South Carolina State AGfiled 2021-09-30(92d gap)Verified
Showing first 10 of 20 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542441
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2021
- Raw hash
- 2ffb797f4055f4a2ce72c5ae3f1a8070ddbcd7db135583784d298a0d0766de05
Reporting entity
- Name
- ARTHUR J. GALLAGHER & CO.norm: arthur j gallagher
Victim entity
- Name
- ARTHUR J. GALLAGHER & CO.norm: arthur j gallagher
Incident
- Discovered
- Sep 26, 2020
- Materiality determined
- Jun 30, 2021
- Notification sent
- Jun 30, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTPHIHEALTH_BASICAUTHENTICATIONBIOMETRIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to law enforcement and regulatory authorities
Compliance
- Time to disclose
- 40 weeks(277 days from discovery to filing)
- Compliance flags
- CA 60-day late · 277d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 26, 2020→ Notified: Jun 30, 2021277d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.