Woodruff Sawyer & Co.
ent_684d2a0a6252c0c67b0f2367
Disclosures
16
State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
8,725
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Woodruff Sawyer & Co.
- Normalized
- woodruff sawyer— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- woodruffsawyer.com
- Corporate parent
- ARTHUR J. GALLAGHER & CO.— per SEC Exhibit 21 filing
Disclosure history (16)newest first
- New Hampshire State AGas victim2024-07-22
Woodruff-Sawyer & Co. filed a supplemental notice with the New Hampshire Attorney General regarding a March 4, 2024 e-sim swap attack. The incident affected 14 New Hampshire residents. Notifications were sent starting March 4, 2024. The investigation is complete.
- California State AGas victim2024-06-28
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged cybersecurity experts, notified the FBI, and amended security controls. Affected individuals are offered 24 months of Experian IdentityWorks.
- California State AGas victim2024-03-20
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged forensic experts, notified the FBI, and amended security controls to prevent SIM swapping. Affected individuals are offered 24 months of Experian IdentityWorks.
- New Hampshire State AGas victim2024-03-18
Woodruff-Sawyer & Co. reported a SIM swapping attack on Jan 20, 2024, where an attacker compromised an executive's credentials to access cloud systems and download files containing PII. 13 New Hampshire residents were affected. The company engaged forensic investigators, notified the FBI, and offered credit monitoring.
- Massachusetts State AGas victim2024-03-05
Woodruff-Sawyer & Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-03-05. 63 Massachusetts residents were affected.
- Maine State AGas victim2024-03-04
Woodruff-Sawyer & Co., an insurance brokerage and risk consulting firm based in San Francisco, reported a cybersecurity incident to the Maine Attorney General. On January 20, 2024, an executive was targeted by a SIM-swapping attack, allowing an unauthorized actor to reset work passwords and access cloud systems. The actor downloaded a subset of files containing client data, specifically names and driver's license numbers. The breach affected 3,087 individuals, including 25 Maine residents. Notification was sent on March 4, 2024, offering 24 months of credit monitoring and identity restoration services.
- Montana State AGas victim2024-03-04
Woodruff-Sawyer & Co. disclosed that on January 20, 2024, an unauthorized third party gained access to its systems via SIM swapping, compromising an executive's credentials. The attacker downloaded files containing names, dates of birth, and driver's license numbers. The company engaged forensic experts, notified the FBI, enhanced security controls, and offered 24 months of Experian IdentityWorks.
- Indiana State AGas victim2024-03-04
Woodruff-Sawyer & Co reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-20 and was reported on 2024-03-04. 244 Indiana residents were affected. 3,087 individuals affected in total.
- Indiana State AGas victim2021-03-09
Woodruff Sawyer & Co reported a data breach to the Indiana Attorney General. The breach occurred on 2020-03-02 and was reported on 2021-03-09. 1 Indiana residents were affected. 8,725 individuals affected in total.
- Massachusetts State AGas victim2021-02-26
Woodruff Sawyer & Co reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-02-26. 1 Massachusetts residents were affected. The report records the breach type as paper.
- New Hampshire State AGas victim2021-02-18
Woodruff Sawyer & Co., an insurance consulting brokerage, reported unauthorized access to employee email accounts between March 2, 2020, and April 30, 2020. An unknown actor used valid credentials to access emails, potentially exposing names and Social Security numbers of approximately one New Hampshire resident. The company engaged forensic investigators, reset credentials, implemented MFA, and offered 12 months of credit monitoring. The investigation is ongoing.
- California State AGas victim2020-12-08
Woodruff Sawyer & Co. disclosed unauthorized access to employee email accounts between March 2 and April 30, 2020. The incident involved potential exposure of personal information for clients and employees. The company engaged forensic investigators, reset passwords, and is offering credit monitoring services.
- Oregon State AGas victim2020-11-12
Woodruff Sawyer & Co. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-11-12. The breach occurred during 3/2/2020 - 3/3/2020. The breach was discovered on 9/1/2020. 4,903 individuals were affected. Notice was sent on 11/9/2020.
- Washington State AGas victim2020-11-10
Woodruff Sawyer & Co. notified the Washington AG of unauthorized access to employee email accounts between March 2-3, 2020. The incident affected 2,393 Washington residents, primarily involving names, DOBs, and health/claims data. Access was gained via compromised credentials. Remediation included MFA implementation and credit monitoring offers.
- Montana State AGas victim2020-11-09
Woodruff Sawyer & Co. notified Montana residents of unauthorized access to an employee email account between March 2-3, 2020. The incident involved the use of stolen credentials and resulted in potential exposure of personal information belonging to clients. The company engaged forensic investigators, reset passwords, and offered one year of credit monitoring services.
- Massachusetts State AGas victim2020-08-05
Woodruff Sawyer & Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-08-05. 9 Massachusetts residents were affected. The report records the breach type as electronic.