ARTHUR J. GALLAGHER & CO.
ent_019e221b72cd00a00eccc0fd86177207
Disclosures
25+
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,140,520
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ARTHUR J. GALLAGHER & CO.
- Normalized
- arthur j gallagher— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930049QLLMPART6V29
- SEC EDGAR CIK
- 0000354190
- Domain
- None on record
Disclosure history (newest 25)newest first
- New Hampshire State AGas victim2021-12-10
Arthur J. Gallagher & Co. filed a supplemental notice with the New Hampshire AG regarding a ransomware incident detected on September 26, 2020. Unauthorized access occurred between June 3 and September 26, 2020. The notice covers approximately 1 New Hampshire resident. Data types included PII. The company engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring.
- Maine State AGas victim2021-12-06
Arthur J. Gallagher & Co. reported a data breach resulting from an external system breach (hacking) that occurred between June 3, 2020, and September 26, 2020. The breach was discovered on June 23, 2021. The compromised information included names and Social Security numbers. The incident affected 281 individuals in total, including 2 Maine residents. Affected individuals were notified on November 30, 2021, and offered 24 months of identity theft protection services through Kroll.
- New Hampshire State AGas victim2021-10-04
Arthur J. Gallagher & Co. filed a supplemental notice with the New Hampshire AG regarding a ransomware incident detected on September 26, 2020. Unauthorized access occurred between June 3 and September 26, 2020. The breach affected approximately 511 New Hampshire residents, including individuals from Gallagher's clients (Finish Line, Sterling Jewelers, Zale). Data accessed included PII. Response included system isolation, forensic investigation, and 24 months of credit monitoring.
- South Carolina State AGas victim2021-09-30
Arthur J. Gallagher & Co. notified South Carolina residents of a ransomware incident detected on September 26, 2020. The attack impacted internal systems between June 3 and September 26, 2020. Gallagher took systems offline, engaged forensic specialists, and reported to law enforcement. The breach affected individual data (PII). Affected individuals received 24 months of credit monitoring via Kroll. The incident status is contained.
- Maine State AGas victim2021-09-29
An external system breach at Arthur J. Gallagher & Co. that occurred on June 3, 2020, was discovered on June 23, 2021. The breach affected 497 Maine residents, and the compromised information included names in combination with financial account numbers or credit/debit card numbers and their security codes. The company offered 24 months of identity theft protection services through Kroll.
- New Hampshire State AGas victim2021-09-13
Arthur J. Gallagher & Co. filed a supplemental notice with the NH AG regarding a ransomware incident detected on Sept 26, 2020. Unauthorized access occurred between June 3 and Sept 26, 2020. The notice covers 2 New Hampshire residents. The company engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring.
- Maine State AGas victim2021-09-13
Arthur J. Gallagher & Co. experienced an external system breach between June 3, 2020, and September 26, 2020. The incident, discovered on June 23, 2021, resulted in the compromise of names and Social Security numbers. The company notified the 36 affected Maine residents on September 13, 2021, and offered 24 months of identity protection services through Kroll.
- Maine State AGas victim2021-09-08
Arthur J. Gallagher & Co. reported an external system breach (hacking) occurring between June 3, 2020, and September 26, 2020, discovered on June 23, 2021. The incident affected 5,577 individuals, including 2 Maine residents. Acquired data included names and Social Security Numbers. The company provided written notification and offered 24 months of identity theft protection services via Kroll.
- South Carolina State AGas victim2021-09-08
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Gallagher engaged forensic specialists, took systems offline, and reported to law enforcement. Affected data included personal information. The company provided 24 months of credit monitoring via Kroll.
- New Hampshire State AGas victim2021-09-07
Arthur J. Gallagher & Co. filed a supplemental notice to the NH AG regarding a September 2020 ransomware event. Unauthorized access occurred between June 3 and September 26, 2020. The company notified approximately 690 NH residents and offered 24 months of credit monitoring.
- Maine State AGas victim2021-09-01
Arthur J. Gallagher & Co. reported an external system breach (hacking) occurring on June 3, 2020, discovered on June 23, 2021. The incident affected 111,317 individuals, including 322 in Maine. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). The company provided written notification on September 1, 2021, and offered 24 months of identity theft protection services via Kroll.
- New Hampshire State AGas victim2021-08-23
Arthur J. Gallagher & Co. filed a supplemental data event notice with the New Hampshire Attorney General on August 23, 2021. The notice covers approximately 1,222 New Hampshire residents affected by a data incident involving multiple insurance clients. Notification was mailed on August 17, 2021, offering credit monitoring services.
- Delaware State AGas victim2021-08-19
Arthur J. Gallagher & Co. filed a supplemental notice to Delaware residents regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020. The company took systems offline, engaged forensic specialists, and reported to law enforcement. Impacted data includes personal information of certain individuals. Affected individuals were offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice text.
- Maine State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a data breach affecting 882 Maine residents. The breach, which was discovered on June 23, 2021, occurred on June 3, 2020. The incident was described as an external system breach (hacking), and the compromised information included names in combination with financial account numbers or credit/debit card numbers along with their security codes. Affected individuals were notified on August 17, 2021, and offered 24 months of credit monitoring services from Kroll.
- South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting systems accessed between June 3 and September 26, 2020. The breach impacted PII including government IDs. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No specific victim count was disclosed in this notice.
- Delaware State AGas victim2021-08-17
Arthur J. Gallagher & Co. filed a supplemental notice with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, including names and government IDs. The company offered 24 months of credit monitoring via Kroll. This is the 6th supplemental notice, indicating ongoing identification of affected residents.
- South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. notified South Carolina and other state attorneys general of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of systems and unauthorized access to certain network segments. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification letters were issued starting May 24, 2021.
- South Carolina State AGas victim2021-08-17
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems between June 3 and September 26, 2020. The breach impacted customer/partner data including names and contact information. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. Affected individuals received 24 months of credit monitoring via Kroll. The filing was submitted to the South Carolina Office of the Attorney General.
- New Hampshire State AGas victim2021-08-16
Arthur J. Gallagher & Co. filed a supplemental notice with the New Hampshire Attorney General regarding a ransomware incident. The breach occurred between June 3 and September 26, 2020, and was detected on September 26, 2020. The incident affected approximately 1,189 New Hampshire residents, involving access to personal information. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring.
- Maine State AGas victim2021-08-12
Arthur J. Gallagher & Co. experienced an external system breach on June 3, 2020, which was discovered on June 23, 2021. The breach affected 738 Maine residents, and the compromised information included financial account numbers or credit/debit card numbers along with their security codes or PINs. The company notified the affected individuals on July 29, 2021, and offered 24 months of identity theft protection services through Kroll.
- Delaware State AGas victim2021-08-12
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. This is the 5th supplemental notice.
- New Hampshire State AGas victim2021-08-04
Supplemental notice to NH AG regarding Arthur J. Gallagher & Co. ransomware incident. Unauthorized access occurred June 3-Sept 26, 2020. Discovered Sept 26, 2020. 4 NH residents affected. Data included PII. Response included forensic investigation, system isolation, and 24-month credit monitoring via Kroll.
- Maine State AGas victim2021-08-04
Arthur J. Gallagher & Co. reported an external system breach (hacking) that occurred on June 3, 2020, and was discovered on June 23, 2021. The breach affected 6,823 individuals, including one resident of Maine. The compromised information included names and Social Security numbers. Affected individuals were notified on August 5, 2021, and offered 24 months of identity theft protection services from Kroll.
- South Carolina State AGas victim2021-08-04
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Impacted data included personal information. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No actual misuse was confirmed.
- Delaware State AGas victim2021-08-04
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems and potentially exposing customer and employee data, including names and government IDs. Gallagher took systems offline, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of ARTHUR J. GALLAGHER & CO. — not by ARTHUR J. GALLAGHER & CO. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Illinois State AGvia Risk Program Administrators LLC2026-08-01
RISK PROGRAM ADMINISTRATORS LLC filed a data-breach notice with the Illinois Attorney General in August 2026 (case 26-08-1392). The register records the breach as discovered on June 26, 2026. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Nebraska State AGvia Risk Program Administrators LLC2026-07-23
Risk Program Administrators LLC (RPA) notified Nebraska AG of a phishing incident affecting 7 Nebraska residents. An unknown actor accessed employee email accounts between May 27, 2025, and June 16, 2025, potentially exposing names and Social Security numbers. RPA secured the account, engaged third-party cybersecurity specialists, and provided 12 months of credit monitoring to affected individuals. Notices were sent on July 23, 2026.
- CALIFORNIAHHS OCRvia Risk Program Administrators LLC2026-07-23
Risk Program Administrators LLC reported to HHS on 2026-07-23 a Hacking/IT Incident affecting 8309 individuals. Breached information located on Email.
- Indiana State AGvia The Boon Group Inc2025-05-06
The Boon Group Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-29 and was reported on 2025-05-06. 4 Indiana residents were affected. 31 individuals affected in total.
- California State AGvia Keenan & Associates2024-10-15
Keenan & Associates, an insurance brokerage, experienced a cybersecurity incident between August 21 and August 27, 2023. An unauthorized party gained access to internal systems and exfiltrated personal information including names, SSNs, driver's license numbers, passport numbers, and health insurance information. The incident was discovered on August 27, 2023. Keenan engaged forensic experts, contained the incident, and notified law enforcement. Affected individuals are offered 24 months of identity protection.
- Massachusetts State AGvia Gallagher Bassett Services, Inc.2024-08-30
Gallagher Bassett Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-30. 1 Massachusetts residents were affected.
- New Hampshire State AGvia Woodruff Sawyer & Co.2024-07-22
Woodruff-Sawyer & Co. filed a supplemental notice with the New Hampshire Attorney General regarding a March 4, 2024 e-sim swap attack. The incident affected 14 New Hampshire residents. Notifications were sent starting March 4, 2024. The investigation is complete.
- California State AGvia Woodruff Sawyer & Co.2024-06-28
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged cybersecurity experts, notified the FBI, and amended security controls. Affected individuals are offered 24 months of Experian IdentityWorks.
- California State AGvia Keenan & Associates2024-04-11
Keenan & Associates reported a data breach to the California Attorney General. The incident occurred between August 21, 2023, and August 27, 2023. The filing provides only the organization name and breach dates; no details regarding the nature of the breach, data types affected, or number of individuals impacted are disclosed in the available record.
- Maine State AGvia Keenan & Associates2024-04-02
Keenan & Associates, a financial services firm, experienced an external system breach between August 21, 2023, and August 27, 2023, discovered on the end date. The incident impacted 1,573,844 individuals, compromising their names and driver's license or non-driver identification card numbers. Affected individuals were notified starting on February 5, 2024. The company offered 24 months of complimentary credit monitoring and fraud protection services as a response.