ARTHUR J. GALLAGHER & CO.
ent_019e221b72cd00a00eccc0fd86177207
Disclosures
25+
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
111,317
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ARTHUR J. GALLAGHER & CO.
- Normalized
- arthur j gallagher— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930049QLLMPART6V29
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- 🦞Maine State AGas victim2021-12-06
Arthur J. Gallagher & Co. reported a data breach resulting from an external system breach (hacking) that occurred between June 3, 2020, and September 26, 2020. The breach was discovered on June 23, 2021. The compromised information included names and Social Security numbers. The incident affected 281 individuals in total, including 2 Maine residents. Affected individuals were notified on November 30, 2021, and offered 24 months of identity theft protection services through Kroll.
- 🌴South Carolina State AGas victim2021-09-30
Arthur J. Gallagher & Co. notified South Carolina residents of a ransomware incident detected on September 26, 2020. The attack impacted internal systems between June 3 and September 26, 2020. Gallagher took systems offline, engaged forensic specialists, and reported to law enforcement. The breach affected individual data (PII). Affected individuals received 24 months of credit monitoring via Kroll. The incident status is contained.
- 🦞Maine State AGas victim2021-09-29
An external system breach at Arthur J. Gallagher & Co. that occurred on June 3, 2020, was discovered on June 23, 2021. The breach affected 497 Maine residents, and the compromised information included names in combination with financial account numbers or credit/debit card numbers and their security codes. The company offered 24 months of identity theft protection services through Kroll.
- 🦞Maine State AGas victim2021-09-13
Arthur J. Gallagher & Co. experienced an external system breach between June 3, 2020, and September 26, 2020. The incident, discovered on June 23, 2021, resulted in the compromise of names and Social Security numbers. The company notified the 36 affected Maine residents on September 13, 2021, and offered 24 months of identity protection services through Kroll.
- 🦞Maine State AGas victim2021-09-08
Arthur J. Gallagher & Co. reported an external system breach (hacking) occurring between June 3, 2020, and September 26, 2020, discovered on June 23, 2021. The incident affected 5,577 individuals, including 2 Maine residents. Acquired data included names and Social Security Numbers. The company provided written notification and offered 24 months of identity theft protection services via Kroll.
- 🌴South Carolina State AGas victim2021-09-08
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Gallagher engaged forensic specialists, took systems offline, and reported to law enforcement. Affected data included personal information. The company provided 24 months of credit monitoring via Kroll.
- ⛰️New Hampshire State AGas victim2021-09-07
State of New Hampshire Attorney General breach notification filed by Arthur J. Gallagher & Co. on September 7, 2021. The attached PDF document contains only page separators and no substantive breach details, incident dates, data types, or response actions. Extraction is limited to the filing metadata provided in the trusted lead-in tags.
- 🦞Maine State AGas victim2021-09-01
Arthur J. Gallagher & Co. reported an external system breach (hacking) occurring on June 3, 2020, discovered on June 23, 2021. The incident affected 111,317 individuals, including 322 in Maine. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). The company provided written notification on September 1, 2021, and offered 24 months of identity theft protection services via Kroll.
- 💎Delaware State AGas victim2021-08-19
Arthur J. Gallagher & Co. filed a supplemental notice to Delaware residents regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020. The company took systems offline, engaged forensic specialists, and reported to law enforcement. Impacted data includes personal information of certain individuals. Affected individuals were offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice text.
- 🦞Maine State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a data breach affecting 882 Maine residents. The breach, which was discovered on June 23, 2021, occurred on June 3, 2020. The incident was described as an external system breach (hacking), and the compromised information included names in combination with financial account numbers or credit/debit card numbers along with their security codes. Affected individuals were notified on August 17, 2021, and offered 24 months of credit monitoring services from Kroll.
- 🌴South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting systems accessed between June 3 and September 26, 2020. The breach impacted PII including government IDs. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No specific victim count was disclosed in this notice.
- 💎Delaware State AGas victim2021-08-17
Arthur J. Gallagher & Co. filed a supplemental notice with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, including names and government IDs. The company offered 24 months of credit monitoring via Kroll. This is the 6th supplemental notice, indicating ongoing identification of affected residents.
- 🌴South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. notified South Carolina and other state attorneys general of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of systems and unauthorized access to certain network segments. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification letters were issued starting May 24, 2021.
- 🌴South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems between June 3 and September 26, 2020. The breach impacted customer/partner data including names and contact information. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. Affected individuals received 24 months of credit monitoring via Kroll. The filing was submitted to the South Carolina Office of the Attorney General.
- 🦞Maine State AGas victim2021-08-12
Arthur J. Gallagher & Co. experienced an external system breach on June 3, 2020, which was discovered on June 23, 2021. The breach affected 738 Maine residents, and the compromised information included financial account numbers or credit/debit card numbers along with their security codes or PINs. The company notified the affected individuals on July 29, 2021, and offered 24 months of identity theft protection services through Kroll.
- 💎Delaware State AGas victim2021-08-12
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. This is the 5th supplemental notice.
- 🦞Maine State AGas victim2021-08-04
Arthur J. Gallagher & Co. reported an external system breach (hacking) that occurred on June 3, 2020, and was discovered on June 23, 2021. The breach affected 6,823 individuals, including one resident of Maine. The compromised information included names and Social Security numbers. Affected individuals were notified on August 5, 2021, and offered 24 months of identity theft protection services from Kroll.
- 🌴South Carolina State AGas victim2021-08-04
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Impacted data included personal information. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No actual misuse was confirmed.
- 💎Delaware State AGas victim2021-08-04
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems and potentially exposing customer and employee data, including names and government IDs. Gallagher took systems offline, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice.
- 🦞Maine State AGas victim2021-07-21
Arthur J. Gallagher & Co. reported a data breach affecting 664 Maine residents. The breach, which was discovered on June 23, 2021, occurred on June 3, 2020. The compromised information includes names and financial account numbers or credit/debit card numbers. The company offered 24 months of identity theft protection services through Kroll.
- 🌴South Carolina State AGas victim2021-07-21
Arthur J. Gallagher & Co. notified South Carolina and other jurisdictions of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of internal systems. Gallagher took systems offline, engaged forensic specialists, and reported to law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification was sent on May 24, 2021.
- 💎Delaware State AGas victim2021-07-21
Arthur J. Gallagher & Co. issued a supplemental data breach notification to Delaware residents regarding a ransomware incident detected on September 26, 2020. The breach impacted systems between June 3 and September 26, 2020, resulting in the unauthorized access of personal information. Gallagher engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring to affected individuals.
- 🦬Montana State AGas victim2021-07-21
Arthur J. Gallagher & Co. reported a data breach to the Montana Attorney General. The breach was reported on 2021-07-21. The breach occurred on 3/15/2019. 1,770 Montana residents were affected.
- 🌴South Carolina State AGas victim2021-07-19
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems between June 3 and September 26, 2020. The breach compromised sensitive data including SSNs, driver's licenses, financial account info, medical records, and biometric data. The company engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring.
- 💎Delaware State AGas victim2021-07-16
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. This filing supplements prior notifications to residents in multiple states.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of ARTHUR J. GALLAGHER & CO. — not by ARTHUR J. GALLAGHER & CO. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🏎️Indiana State AGvia The Boon Group Inc2025-05-06
The Boon Group Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-29 and was reported on 2025-05-06. 4 Indiana residents were affected. 31 individuals affected in total.
- 🐻California State AGvia Keenan & Associates2024-10-15
Keenan & Associates, an insurance brokerage, experienced a cybersecurity incident between August 21 and August 27, 2023. An unauthorized party gained access to internal systems and exfiltrated personal information including names, SSNs, driver's license numbers, passport numbers, and health insurance information. The incident was discovered on August 27, 2023. Keenan engaged forensic experts, contained the incident, and notified law enforcement. Affected individuals are offered 24 months of identity protection.
- 🐻California State AGvia Woodruff Sawyer & Co.2024-06-28
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged cybersecurity experts, notified the FBI, and amended security controls. Affected individuals are offered 24 months of Experian IdentityWorks.
- 🐻California State AGvia Keenan & Associates2024-04-11
Keenan & Associates reported a data breach to the California Attorney General. The incident occurred between August 21, 2023, and August 27, 2023. The filing provides only the organization name and breach dates; no details regarding the nature of the breach, data types affected, or number of individuals impacted are disclosed in the available record.
- 🦞Maine State AGvia Keenan & Associates2024-04-02
Keenan & Associates, a financial services firm, experienced an external system breach between August 21, 2023, and August 27, 2023, discovered on the end date. The incident impacted 1,573,844 individuals, compromising their names and driver's license or non-driver identification card numbers. Affected individuals were notified starting on February 5, 2024. The company offered 24 months of complimentary credit monitoring and fraud protection services as a response.
- ⛰️New Hampshire State AGvia Keenan & Associates2024-03-29
Keenan & Associates, an insurance brokerage, reported a ransomware incident to the New Hampshire Attorney General in a supplemental notice dated March 29, 2024. The breach involved unauthorized access to internal systems between August 21 and 27, 2023. The incident affected 108 New Hampshire residents, including current and former employees, their dependents, and client-associated individuals. Personal information, including names and government IDs, was exfiltrated. Keenan contained the breach, engaged forensic experts, notified law enforcement, and offered credit monitoring services.
- 🐻California State AGvia Woodruff Sawyer & Co.2024-03-20
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged forensic experts, notified the FBI, and amended security controls to prevent SIM swapping. Affected individuals are offered 24 months of Experian IdentityWorks.
- ⛰️New Hampshire State AGvia Woodruff Sawyer & Co.2024-03-18
State AG filing for Woodruff-Sawyer & Co. in New Hampshire. The attachment content was empty; no breach details, dates, or data types could be extracted from the provided source.
- 🦞Maine State AGvia Woodruff Sawyer & Co.2024-03-04
Woodruff-Sawyer & Co., an insurance brokerage and risk consulting firm based in San Francisco, reported a cybersecurity incident to the Maine Attorney General. On January 20, 2024, an executive was targeted by a SIM-swapping attack, allowing an unauthorized actor to reset work passwords and access cloud systems. The actor downloaded a subset of files containing client data, specifically names and driver's license numbers. The breach affected 3,087 individuals, including 25 Maine residents. Notification was sent on March 4, 2024, offering 24 months of credit monitoring and identity restoration services.
- 🦬Montana State AGvia Woodruff Sawyer & Co.2024-03-04
Woodruff-Sawyer & Co. reported a data breach to the Montana Attorney General. The breach was reported on 2024-03-04. The breach occurred on 1/20/2024. 4 Montana residents were affected.