MARSH & MCLENNAN COMPANIES, INC.
ent_019e2419f61ff6796c942508a4f42a6a
Disclosures
8
SEC 10-K Item 1C · State AG · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
2,550
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MARSH & MCLENNAN COMPANIES, INC.
- Normalized
- marsh mclennan companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XMP3KDCKJXIU47
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- FEDERALSEC 10-K Item 1Cas victim2024-02-12
10-K Item 1C cybersecurity risk management disclosure from an unnamed professional services firm. The filer describes its NIST CSF / ISO 27001-aligned cybersecurity program, board and audit committee oversight, CISO/CIO governance, third-party vendor risk procedures, MFA, VPN controls, phishing training, and penetration testing. The filer explicitly states that in 2023 it did not identify any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect the Company. No breach is disclosed.
- 🦞Maine State AGas victim2021-12-30
A vulnerability in a third-party vendor's software allowed unauthorized actors to exfiltrate data. The breach affected 367 Maine residents, exposing their names and driver's license or non-driver identification card numbers. The incident occurred between April 17 and April 30, 2021, and was discovered on April 26, 2021.
- 🦫Oregon State AGas victim2021-07-01
Marsh McLennan reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-01. The breach occurred during 4/22/2021 - 4/30/2021. The breach was discovered on 4/26/2021. Notice was sent on 6/30/2021.
- 🌲Washington State AGas victim2021-06-30
Marsh McLennan, a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2021-04-26 and filed notice on 2021-06-30. 2,550 Washington residents were affected. 65 days elapsed between awareness and notification. 4 days to identify the breach. 4 days to contain the breach.
- 🦬Montana State AGas victim2021-06-30
Marsh McLennan reported a data breach to the Montana Attorney General. The breach was reported on 2021-06-30. The breach occurred from 4/22/2021 to 4/30/2021. 256 Montana residents were affected.
- 🌴South Carolina State AGas victim2021-06-30
Marsh McLennan notified individuals of a data breach discovered on April 26, 2021, involving unauthorized access to a limited set of data via a third-party software vulnerability. Access occurred between April 22 and April 30, 2021. The incident involved names and other personal information. Marsh McLennan notified law enforcement, terminated access, reset IT admin rights, and offered two years of credit monitoring through Experian. Rhode Island residents (532) were explicitly counted.
- 🐻California State AGas victim2021-06-30
Marsh McLennan reported a data breach affecting Rhode Island residents (532 individuals) where an unauthorized actor exploited a third-party software vulnerability between April 22 and April 30, 2021, to access personal information including names. Marsh McLennan notified law enforcement, restricted access, and offered two years of credit monitoring via Experian.
- 🐻California State AGas reporting2013-11-26
Kroll Background Screening Services experienced a data incident in 2013 where third parties targeted its systems to obtain background check information. The intrusion occurred between June and September 2013. Marsh & McLennan Companies, Inc. notified affected individuals, whose personal information (including SSN, address, and employment history) may have been on Kroll servers. No evidence was found that data was taken, but credit protection services were offered.