Aon
ent_019e20b29d23b000b492fcbc07664429
Disclosures
13
Leak Site · State AG · HHS OCR · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
153,784
as filed · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Aon
- Normalized
- aon— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 636700889M5LFOKPBC07
- SEC EDGAR CIK
- 0000315293
- Domain
- aon.com
Disclosure history (13)newest first
- GLOBALLeak Siteas victim2023-06-16
Better Decisions - Commercial Risk - Health - Reinsurance - Wealth - Aon
- GLOBALLeak Siteas victim2022-07-03
aon.com
- 🦞Maine State AGas victim2022-07-01
Aon Plc experienced a prolonged external system breach, lasting from December 29, 2020, to March 1, 2022. The incident was discovered on February 25, 2022. It affected 153,784 individuals, compromising names combined with driver's license or non-driver identification card numbers. In response, Aon offered 24 months of identity theft protection and credit monitoring services from Experian.
- 🦞Maine State AGas victim2022-06-24
Aon Plc, a professional services firm, reported an external system breach that occurred on December 29, 2020, but was not discovered until February 25, 2022. The incident, described as hacking, affected 145,889 individuals and compromised names along with driver's license or non-driver ID numbers. The company began notifying affected individuals on May 27, 2022, and offered 24 months of complimentary credit monitoring and identity theft protection services through Experian.
- 🦬Montana State AGas victim2022-06-13
Aon PLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-06-13. The breach occurred from 12/29/2020 to 2/25/2022. 250 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2022-05-31
Aon Corporation PLC notified the New Hampshire Attorney General of a cyber event affecting approximately 233 NH residents. Unauthorized access occurred between Dec 29, 2020, and Feb 26, 2022, exploiting a zero-day vulnerability (CVE-2021-27852). The attacker staged and exfiltrated unstructured data from SharePoint and Outlook, including names, SSNs, and driver's license numbers. Aon settled with the attacker, who deleted the data. Aon provided 24 months of credit monitoring and enhanced security controls.
- 🦫Oregon State AGas victim2022-05-26
Aon Plc reported a data breach to the Oregon Attorney General. The breach was reported on 2022-05-26. The breach occurred during 12/29/2020 - 3/1/2022. The breach was discovered on 2/25/2022. 31,799 individuals were affected. Notice was sent on 5/27/2022.
- 🐻California State AGas victim2022-05-26
Aon Plc reported a cybersecurity incident to the California Attorney General's Office. An unauthorized third party accessed Aon systems between December 29, 2020, and February 26, 2022. The incident involved the exfiltration of personal information, including names, Social Security numbers, and driver's license numbers. Aon retained cybersecurity firms and notified law enforcement (FBI). Remediation included enhanced security measures and 24 months of complimentary credit monitoring via Experian IdentityWorks. The notification was sent on May 27, 2022.
- 🦞Maine State AGas victim2022-05-26
Aon Plc, a financial services company, reported an external system breach that affected 31,799 individuals. The incident occurred between December 29, 2020, and March 1, 2022, and was discovered on February 25, 2022. The compromised data included names combined with driver's license or non-driver identification card numbers. Aon provided affected individuals with written notification and offered 24 months of complimentary identity theft protection and credit monitoring services.
- 🌲Washington State AGas victim2022-05-26
Aon Plc, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2022-02-25 and filed notice on 2022-05-26. 6,889 Washington residents were affected. 90 days elapsed between awareness and notification. 423 days to identify the breach. 4 days to contain the breach.
- 🦬Montana State AGas victim2022-05-26
Aon Corporation PLC reported a data breach to the Montana Attorney General. The breach was reported on 2022-05-26. The breach occurred from 12/29/2020 to 2/25/2022. 302 Montana residents were affected.
- 🦬Montana State AGas victim2021-05-21
Aon Corporation reported a data breach to the Montana Attorney General. The breach was reported on 2021-05-21. The breach occurred on 12/17/2020. 3 Montana residents were affected.
- PAHHS OCRas victim2010-09-07
Aon Consulting, a business associate, prepared a request-for-proposal document for a covered entity's vision benefit program that mistakenly included PHI of 22,642 individuals. The document was publicly posted online for five days. Breached information located on a Network Server. PHI exposed included Social Security numbers, dates of birth, gender, zip codes, and vision plan enrollment information. The covered entity implemented multi-layer review controls and enforced its BAA with Aon; Aon offered credit monitoring and identity theft insurance to affected individuals.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Aon — not by Aon itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🍁Vermont State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner, LLC (dba Salus Group) notified consumers of a data breach where an employee's email account was compromised on October 9, 2024, likely via phishing. Unauthorized access occurred, potentially exposing PII and credentials. The company engaged forensic investigators, reset credentials, and offered Kroll identity monitoring to affected individuals.
- ⛰️New Hampshire State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner, LLC dba Salus Group notified affected individuals of unauthorized access to an employee's email account on October 9, 2024. The incident involved phishing leading to credential compromise. Salus engaged forensic investigators, reset credentials, and provided 12 months of Kroll identity monitoring to affected individuals. Data types included PII and credentials.
- 🌲Washington State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner, LLC, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2024-10-09 and filed notice on 2025-04-07. 1,315 Washington residents were affected. 180 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
- NJHHS OCRvia Hafetz and Associates2024-09-27
Hafetz and Associates (NJ), a HIPAA-covered entity, reported a phishing-based hacking/IT incident affecting email accounts of multiple employees and the PHI of 26,474 individuals. Compromised data included names, dates of birth, SSNs, driver's license numbers, addresses, medications, claims and financial information, and health insurance information. The entity notified HHS, affected individuals, the media, and posted substitute notice; remediation included additional administrative, technical, and security safeguards.
- 🏎️Indiana State AGvia Hafetz and Associates2024-06-28
Hafetz & Associates reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-24 and was reported on 2024-06-28. 1 Indiana residents were affected. 2,391 individuals affected in total.
- ⛰️New Hampshire State AGvia Hafetz and Associates2024-06-28
Hafetz & Associates notified the NH Attorney General of a phishing incident resulting in unauthorized access to employee email accounts between July 24 and October 12, 2023. One NH resident's name was exposed. Hafetz blocked access, investigated, and mailed notifications on June 28, 2024, offering two years of credit monitoring via Kroll.
- 🦬Montana State AGvia CIC Group, Inc.2023-04-23
CIC Group Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-23. The breach occurred on 3/28/2023. 1 Montana residents were affected.
- 🦫Oregon State AGvia CIC Group, Inc.2023-04-23
CIC Group, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-04-23. The breach occurred during 3/28/2023. The breach was discovered on 4/13/2023. 4,500 individuals were affected. Notice was sent on 4/21/2023.
- 🐻California State AGvia CIC Group, Inc.2023-04-21
CIC Group, Inc. experienced a ransomware attack on March 28, 2023, which encrypted or destroyed data on affected systems. On April 13, 2023, the threat actor indicated that personal information, including names, addresses, SSNs, and passport info, was exfiltrated. The company disabled systems, engaged forensic investigators, notified law enforcement, and is offering 24 months of credit monitoring.
- 🍁Vermont State AGvia Benefits Partner, LLC2023-03-08
Benefit Link LLC notified consumers of a data security incident where an unauthorized party accessed a computer system on February 15, 2022. Files containing names and government identifiers (SSN, driver's license) were potentially exposed. Benefit Link secured the system, moved to the cloud, and offered one year of complimentary identity monitoring through Kroll.