Aon
ent_019e20b29d23b000b492fcbc07664429
Disclosures
25+
Leak Site · State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
153,784
nationwide · State AG ME
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- Aon
- Normalized
- aon— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 636700889M5LFOKPBC07
- SEC EDGAR CIK
- 0000315293
- Domain
- aon.com
Disclosure history (newest 25)newest first
- GLOBALLeak Siteas victim2023-06-16
Better Decisions - Commercial Risk - Health - Reinsurance - Wealth - Aon
- GLOBALLeak Siteas victim2022-07-03
aon.com
- Maine State AGas victim2022-07-01
Aon Plc experienced a prolonged external system breach, lasting from December 29, 2020, to March 1, 2022. The incident was discovered on February 25, 2022. It affected 153,784 individuals, compromising names combined with driver's license or non-driver identification card numbers. In response, Aon offered 24 months of identity theft protection and credit monitoring services from Experian.
- Maine State AGas victim2022-06-24
Aon Plc, a professional services firm, reported an external system breach that occurred on December 29, 2020, but was not discovered until February 25, 2022. The incident, described as hacking, affected 145,889 individuals and compromised names along with driver's license or non-driver ID numbers. The company began notifying affected individuals on May 27, 2022, and offered 24 months of complimentary credit monitoring and identity theft protection services through Experian.
- New Hampshire State AGas victim2022-06-21
Supplemental notice from Aon Corporation PLC to New Hampshire AG regarding a cyber event involving third-party vendor Ricoh USA Inc. Notifying 624 New Hampshire residents. Initial notice sent May 26, 2022.
- New Hampshire State AGas victim2022-06-13
Aon PLC, an insurance broker for Danaher, disclosed a breach where an unauthorized third party accessed systems between Dec 2020 and Feb 2022. Data included SSNs, DOBs, and health coverage info. 34 NH residents notified. Aon engaged FBI and forensic firms, enhanced security controls, and offered credit monitoring.
- Montana State AGas victim2022-06-13
Aon PLC disclosed a cyber incident where an unauthorized third party accessed systems between Dec 29, 2020, and Feb 26, 2022. Personal information including names and SSNs was obtained. Aon engaged forensic firms and notified the FBI. Affected individuals were offered 24 months of credit monitoring.
- New Hampshire State AGas victim2022-05-31
Aon Corporation PLC notified the New Hampshire Attorney General of a cyber event affecting approximately 233 NH residents. Unauthorized access occurred between Dec 29, 2020, and Feb 26, 2022, exploiting a zero-day vulnerability (CVE-2021-27852). The attacker staged and exfiltrated unstructured data from SharePoint and Outlook, including names, SSNs, and driver's license numbers. Aon settled with the attacker, who deleted the data. Aon provided 24 months of credit monitoring and enhanced security controls.
- Indiana State AGas victim2022-05-27
Aon Plc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-29 and was reported on 2022-05-27. 3,080 Indiana residents were affected. 31,799 individuals affected in total.
- ILLINOISHHS OCRas victim2022-05-26
Aon PLC reported to HHS on 2022-05-26 a Hacking/IT Incident affecting 129,682 individuals. Breached information located on Network Server. The incident involved ransomware encrypting PHI including names, DOBs, SSNs, and driver's license numbers.
- Oregon State AGas victim2022-05-26
Aon Plc reported a data breach to the Oregon Attorney General. The breach was reported on 2022-05-26. The breach occurred during 12/29/2020 - 3/1/2022. The breach was discovered on 2/25/2022. 31,799 individuals were affected. Notice was sent on 5/27/2022.
- California State AGas victim2022-05-26
Aon PLC disclosed a cyber incident where an unauthorized third party accessed systems between Dec 29, 2020, and Feb 26, 2022. The incident was discovered on Feb 25, 2022. Personal information including names, SSNs, driver's license numbers, and some benefit enrollment data was temporarily obtained. Aon engaged cybersecurity firms, notified the FBI, and offered 24 months of identity monitoring.
- Maine State AGas victim2022-05-26
Aon Plc, a financial services company, reported an external system breach that affected 31,799 individuals. The incident occurred between December 29, 2020, and March 1, 2022, and was discovered on February 25, 2022. The compromised data included names combined with driver's license or non-driver identification card numbers. Aon provided affected individuals with written notification and offered 24 months of complimentary identity theft protection and credit monitoring services.
- Washington State AGas victim2022-05-26
Aon Corporation PLC disclosed a cyber event where an unauthorized third party exploited a zero-day vulnerability (CVE-2021-27852) to gain access to systems between Dec 2020 and Feb 2022. The actor staged and exfiltrated unstructured data containing PII (names, SSNs, driver's licenses). Aon reported to law enforcement, engaged forensic experts, and notified 3,328 Washington residents, offering 24 months of credit monitoring.
- Montana State AGas victim2022-05-26
Aon PLC disclosed a cyber incident where an unauthorized third party accessed systems between Dec 29, 2020, and Feb 26, 2022. Personal information including names, SSNs, and driver's licenses was obtained. Aon detected the incident on Feb 25, 2022, engaged forensic firms, notified the FBI, and offered 24 months of credit monitoring. No evidence of misuse was found.
- Massachusetts State AGas victim2022-05-26
Aon Plc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-05-26. 648 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2020-08-14
Aon Insurance Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-08-14. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-03-10
Aon Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-03-10. 2 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2015-10-15
Aon Corp. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-15. 1 Massachusetts residents were affected. The report records the breach type as undefined.
- Massachusetts State AGas victim2015-07-10
Aon Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-07-10. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2013-09-17
AON Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-09-17. 45 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2013-09-11
Aon Hewitt, a vendor for The Bank of Tokyo-Mitsubishi UFJ Ltd., inadvertently emailed a file containing names and SSNs of 1,246 Bank of Tokyo employees to two individuals in another client's HR department on August 2, 2013. The error was detected on August 6, 2013. Notifications were mailed on September 3, 2013, offering one year of credit monitoring. 2 New Hampshire residents were affected.
- PENNSYLVANIAHHS OCRas victim2010-09-07
Aon Consulting, a business associate, prepared a request-for-proposal document for a covered entity's vision benefit program that mistakenly included PHI of 22,642 individuals. The document was publicly posted online for five days. Breached information located on a Network Server. PHI exposed included Social Security numbers, dates of birth, gender, zip codes, and vision plan enrollment information. The covered entity implemented multi-layer review controls and enforced its BAA with Aon; Aon offered credit monitoring and identity theft insurance to affected individuals.
- Massachusetts State AGas victim2008-06-20
Aon Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-06-20. 3,694 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2008-04-15
Aon Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-04-15. 1 Massachusetts residents were affected. The report records the breach type as paper.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Aon — not by Aon itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia Benefits Partner, LLC2025-04-08
Benefits Partner, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-08. 75 Massachusetts residents were affected.
- Vermont State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner, LLC (dba Salus Group) notified consumers of unauthorized access to an employee's email account on October 9, 2024. The company identified suspicious activity, disabled the account, and engaged forensic investigators. A review determined that emails containing personal information, including names, addresses, and potentially Social Security numbers, were accessed. The company implemented additional email security controls and offered identity monitoring services to affected individuals.
- Nebraska State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner LLC (dba Salus Group), an insurance agency, disclosed a security incident on October 9, 2024, involving unauthorized access to a single employee's email account. The actor accessed the account, but it was unclear which emails were viewed. Approximately 27 Nebraska residents were affected, with data including names, SSNs, driver's license numbers, financial account info, and health insurance info. Salus disabled the account, reset passwords, engaged forensic investigators, and notified affected individuals starting April 7, 2025, offering credit monitoring via Kroll.
- Washington State AGvia Benefits Partner, LLC2025-04-07
Benefits Partner, LLC dba Salus Group experienced unauthorized access to an employee's email account on October 9, 2024. The incident exposed personal information of approximately 1,315 Washington residents, including names, SSNs, driver's license numbers, financial account info, and health insurance data. Salus disabled the account, engaged forensic investigators, and began notifying affected individuals in March 2025, offering credit monitoring services.
- Illinois State AGvia Benefits Partner, LLC2025-04-01
BENEFIT PARTNERS, LLC D/B/A SALUS GROUP filed a data-breach notice with the Illinois Attorney General in April 2025 (case 25-04-072). The register records the breach as discovered on October 9, 2024. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- NEW JERSEYHHS OCRvia Hafetz and Associates2024-09-27
Hafetz and Associates (NJ), a HIPAA-covered entity, reported a phishing-based hacking/IT incident affecting email accounts of multiple employees and the PHI of 26,474 individuals. Compromised data included names, dates of birth, SSNs, driver's license numbers, addresses, medications, claims and financial information, and health insurance information. The entity notified HHS, affected individuals, the media, and posted substitute notice; remediation included additional administrative, technical, and security safeguards.
- New Hampshire State AGvia Hafetz and Associates2024-09-27
Supplemental notification from Hafetz & Associates to the New Hampshire Attorney General regarding an incident initially reported on June 28, 2024. The firm has completed notification, mailing letters to approximately 24 New Hampshire residents.
- Illinois State AGvia Hafetz and Associates2024-09-01
HAFETZ & ASSOCIATES filed a data-breach notice with the Illinois Attorney General in September 2024 (case 24-09-080). The register records the breach as discovered on July 24, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGvia Hafetz and Associates2024-06-28
Hafetz & Associates reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-28. 112 Massachusetts residents were affected.
- Indiana State AGvia Hafetz and Associates2024-06-28
Hafetz & Associates reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-24 and was reported on 2024-06-28. 1 Indiana residents were affected. 2,391 individuals affected in total.