HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
MARSH & MCLENNAN COMPANIES, INC.
bd_fa303094cee7b57b · schema v1 · pii pii-v1
Full breach record for MARSH & MCLENNAN COMPANIES, INC. →Marsh McLennan reported a data breach affecting Rhode Island residents (532 individuals) where an unauthorized actor exploited a third-party software vulnerability between April 22 and April 30, 2021, to access personal information including names. Marsh McLennan notified law enforcement, restricted access, and offered two years of credit monitoring via Experian.
California clockDiscovered Apr 26, 2021 → Notified Jun 30, 202165d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_5f0d93b73a89ebf1Washington State AGfiled 2021-06-30Candidate
- bd_7ce38a76e1439674New Hampshire State AGfiled 2021-06-30Verified
- bd_983239faa8378189Montana State AGfiled 2021-06-30Verified
- bd_f54cc90d7abb4835South Carolina State AGfiled 2021-06-30Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_e9678b0aaa98aeb8Oregon State AGfiled 2021-07-01(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542377
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2021
- Raw hash
- e66cc918457aec918f54fe702cd283b2fe0e922fa9ac1cc6e61de5de08d6be3b
Reporting entity
- Name
- MARSH & MCLENNAN COMPANIES, INC.norm: marsh mclennan companies
Victim entity
- Name
- MARSH & MCLENNAN COMPANIES, INC.norm: marsh mclennan companies
Incident
- Discovered
- Apr 26, 2021
- Materiality determined
- —
- Notification sent
- Jun 30, 2021
- Affected individuals
- 532
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- CA 60-day late · 65d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 26, 2021→ Notified: Jun 30, 202165d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.