BROWN & BROWN, INC.
ent_019e5b57fc3b0db09e49e0bfeceb1502
Disclosures
2
SEC 10-K Item 1C · Leak Site · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- BROWN & BROWN, INC.
- Normalized
- brown brown— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300PC8KTJ71XKFY89
- SEC EDGAR CIK
- 0000079282
- Domain
- brown-brown-pc.com
Disclosure history (2)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-12
Brown & Brown, Inc. discloses in its 10-K Item 1C that it has experienced cybersecurity incidents including malware infections, phishing campaigns, ransomware, and vulnerability exploit attempts. The company states these incidents have not had a material impact on its business, results of operations, or financial condition. The filing details its cybersecurity governance, risk management, and incident response programs.
- GLOBALLeak Siteas victim2025-06-23
(Including data of several thousand customers) Brown & Brown, P.C., provides the comprehensive legal service and personal, life-long attention of a general practitioner while ensuring that our clients receive the experienced, specialized attention required in todays complex legal environment.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of BROWN & BROWN, INC. — not by BROWN & BROWN, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🏎️Indiana State AGvia RSC Insurance Brokerage, Inc.2026-06-23
RSC Insurance Brokerage Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-01-15 and was reported on 2026-06-23. 50 Indiana residents were affected. 15,055 individuals affected in total.
- ⛰️New Hampshire State AGvia RSC Insurance Brokerage, Inc.2026-06-23
RSC Insurance Brokerage, Inc. notified the New Hampshire Attorney General of a security incident involving unauthorized access to an employee's Microsoft 365 account. The unauthorized access occurred between January 15-16, 2026. The breach exposed the names and Social Security numbers of 17 New Hampshire residents, along with some medical and insurance information. Notifications were mailed on June 23, 2026, offering one year of credit monitoring.
- 🏛️Massachusetts State AGvia RSC Insurance Brokerage, Inc.2026-06-01
RSC Insurance Brokerage, Inc notified Massachusetts residents of a data incident involving names, Social Security numbers, and health/insurance information. The company offered 24 months of complimentary credit monitoring via Epiq and stated it strengthened security measures. No specific attack vector or dates were provided in the notice.
- GLOBALLeak Sitevia Capstone Insurance Brokers Ltd2025-02-04
Capstone Insurance Brokers Ltd, based in Canada, provides wide-ranging insurance services covering personal, business, and life and health insurance. They aim to offer unmatched professional service, guaranteeing customers top-rate policies. With their expertise, Capstone ensures personalized solutions that cater to individual and business needs with maximum value and protection. Their team is dedicated with a commitment to delivering superior customer service.
- 🐻California State AGvia Allocation Services, Inc.2024-11-08
Allocation Services, Inc. dba IMPAXX notified the California AG of a data breach involving a former employee who retained personal information after employment ended. The company became aware of the incident in April 2024 and confirmed the retention on May 30, 2024. Affected data includes names, addresses, dates of birth, and Social Security numbers related to workers' compensation and liability claims. IMPAXX is offering 12 months of complimentary credit monitoring and identity theft protection to affected individuals.
- 🍁Vermont State AGvia Selman & Company, LLC2024-11-04
Selman & Company, LLC notified Vermont AG of a data breach involving its third-party hosting provider, PAS-SG/PAS Hosting. On August 15, 2024, an unauthorized third party accessed files containing plan participants' personal information, including names, SSNs, and financial account numbers. Selman is offering 24 months of Equifax credit monitoring. The incident is contained; no misuse is currently known.
- 🏎️Indiana State AGvia Selman & Company, LLC2024-11-04
Selman & Company LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-08-15 and was reported on 2024-11-04. 2 Indiana residents were affected. 199 individuals affected in total.
- 🦞Maine State AGvia Selman & Company, LLC2024-11-04
Selman & Company, LLC reported a data breach to the Maine Attorney General's office following an external system breach (hacking) that occurred on August 15, 2024. The breach was discovered on October 17, 2024, and affected 2 Maine residents. The company began notifying affected individuals on November 4, 2024, and offered 24 months of credit monitoring services through Equifax Credit Watch Gold.
- 🐻California State AGvia Academic HealthPlans, Inc.2021-08-13
Academic HealthPlans, Inc. notified California regulators of a phishing incident targeting employee email accounts between August 6, 2020, and October 2, 2020. The breach involved unauthorized access to Microsoft Office 365 accounts, potentially exposing customer PHI and basic identity information. No evidence of data exfiltration was found, but the company engaged Kroll to provide one year of complimentary identity monitoring to affected individuals.
- 🦫Oregon State AGvia Academic HealthPlans, Inc.2021-08-02
Academic HealthPlans, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2021-08-02. The breach occurred during 8/2/2020 - 10/2/2020. The breach was discovered on 6/4/2021. 15,189 individuals were affected. Notice was sent on 8/2/2021.