MARSH & MCLENNAN COMPANIES, INC.
ent_019e2419f61ff6796c942508a4f42a6a
Disclosures
16
State AG · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
6,709
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MARSH & MCLENNAN COMPANIES, INC.
- Normalized
- marsh mclennan companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XMP3KDCKJXIU47
- SEC EDGAR CIK
- 0000062709
- Domain
- None on record
Disclosure history (16)newest first
- Maine State AGas victim2021-12-30
A vulnerability in a third-party vendor's software allowed unauthorized actors to exfiltrate data. The breach affected 367 Maine residents, exposing their names and driver's license or non-driver identification card numbers. The incident occurred between April 17 and April 30, 2021, and was discovered on April 26, 2021.
- Massachusetts State AGas victim2021-07-06
Marsh McLennan reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-06. 6,709 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2021-07-01
Marsh McLennan reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-01. The breach occurred during 4/22/2021 - 4/30/2021. The breach was discovered on 4/26/2021. Notice was sent on 6/30/2021.
- Washington State AGas victim2021-06-30
Marsh McLennan notified Washington AG of a cyberattack where an unauthorized actor exploited a third-party software vulnerability between April 22-30, 2021. Discovered April 26, 2021. Affected 2,550 WA residents, exposing names, SSNs, IDs, passports, and health insurance data. Marsh McLennan engaged FBI, reset admin rights, and offered 2 years of credit monitoring.
- Indiana State AGas victim2021-06-30
Marsh McLennan reported a data breach to the Indiana Attorney General. The breach occurred on 2021-04-22 and was reported on 2021-06-30. 943 Indiana residents were affected.
- New Hampshire State AGas victim2021-06-30
Marsh McLennan notified the New Hampshire Attorney General on June 30, 2021, regarding a breach discovered on April 26, 2021. An unauthorized actor exploited a vulnerability in third-party software between April 22 and April 30, 2021, to access personal information of 485 New Hampshire residents. Affected data included names, SSNs, driver's license numbers, and passport information. Marsh McLennan notified the FBI, reset access rights, and is offering two years of credit monitoring via Experian.
- Montana State AGas victim2021-06-30
Marsh McLennan notified individuals of a data breach where an unauthorized actor exploited a vulnerability in third-party software between April 22 and April 30, 2021. The incident involved personal information including names. Marsh McLennan notified law enforcement, restricted access, and offered credit monitoring.
- South Carolina State AGas victim2021-06-30
Marsh McLennan notified individuals of a data breach discovered on April 26, 2021, involving unauthorized access to a limited set of data via a third-party software vulnerability. Access occurred between April 22 and April 30, 2021. The incident involved names and other personal information. Marsh McLennan notified law enforcement, terminated access, reset IT admin rights, and offered two years of credit monitoring through Experian. Rhode Island residents (532) were explicitly counted.
- California State AGas victim2021-06-30
Marsh McLennan notified individuals that an unauthorized actor exploited a vulnerability in a third-party software provider's system to access a limited set of data in Marsh McLennan's environment. The unauthorized access occurred between April 22 and April 30, 2021, and was discovered on April 26, 2021. Affected data included names and other personal information. Marsh McLennan terminated the actor's access, reset administrator rights, and offered two years of complimentary credit monitoring through Experian.
- Illinois State AGas victim2021-01-01
MARSH MCLENNAN filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-242). The register records the breach as discovered on April 26, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas reporting2019-01-15
Marsh & McLennan Agency LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-01-15. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-03-16
Marsh & McLennan Companies Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-03-16. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-02-02
Marsh & McLennan Companies reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-02-02. 2 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2013-11-27
Marsh & McLennan Companies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-11-27. 2,541 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas reporting2013-11-26
Kroll Background Screening Services experienced a third-party cyber intrusion between June and September 2013. Marsh & McLennan Companies notified the NH AG that personal data (SSN, name, address, employment history) of 86 NH residents may have been accessed. Kroll is under federal criminal investigation. Affected individuals were offered 2 years of credit monitoring via AllClear ID.
- California State AGas victim2013-11-26
Marsh & McLennan Companies notified California residents that Kroll Background Screening Services, a third-party vendor, experienced a data intrusion from June to September 2013. Personal information including SSNs, names, addresses, employment, and academic histories may have been accessed. Kroll notified MMC on September 25, 2013. MMC offered two years of identity protection via AllClear ID and notified regulators and credit bureaus. Investigation was ongoing.