Woodruff Sawyer & Co.
ent_684d2a0a6252c0c67b0f2367
Disclosures
10
State AG · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
4,903
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Woodruff Sawyer & Co.
- Normalized
- woodruff sawyer— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- woodruffsawyer.com
- Corporate parent
- ARTHUR J. GALLAGHER & CO.— per SEC Exhibit 21 filing
Disclosure history (10)newest first
- 🐻California State AGas victim2024-06-28
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged cybersecurity experts, notified the FBI, and amended security controls. Affected individuals are offered 24 months of Experian IdentityWorks.
- 🐻California State AGas victim2024-03-20
Woodruff-Sawyer & Co. experienced a data breach on January 20, 2024, when an unauthorized third party gained access to computer systems via SIM swapping of an executive's phone number. The attacker reset the executive's password and downloaded a small subset of files containing personal information. The company engaged forensic experts, notified the FBI, and amended security controls to prevent SIM swapping. Affected individuals are offered 24 months of Experian IdentityWorks.
- ⛰️New Hampshire State AGas victim2024-03-18
State AG filing for Woodruff-Sawyer & Co. in New Hampshire. The attachment content was empty; no breach details, dates, or data types could be extracted from the provided source.
- 🦞Maine State AGas victim2024-03-04
Woodruff-Sawyer & Co., an insurance brokerage and risk consulting firm based in San Francisco, reported a cybersecurity incident to the Maine Attorney General. On January 20, 2024, an executive was targeted by a SIM-swapping attack, allowing an unauthorized actor to reset work passwords and access cloud systems. The actor downloaded a subset of files containing client data, specifically names and driver's license numbers. The breach affected 3,087 individuals, including 25 Maine residents. Notification was sent on March 4, 2024, offering 24 months of credit monitoring and identity restoration services.
- 🦬Montana State AGas victim2024-03-04
Woodruff-Sawyer & Co. reported a data breach to the Montana Attorney General. The breach was reported on 2024-03-04. The breach occurred on 1/20/2024. 4 Montana residents were affected.
- 🏎️Indiana State AGas victim2024-03-04
Woodruff-Sawyer & Co reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-20 and was reported on 2024-03-04. 244 Indiana residents were affected. 3,087 individuals affected in total.
- 🐻California State AGas victim2020-12-08
Woodruff Sawyer & Co. disclosed unauthorized access to employee email accounts between March 2 and April 30, 2020. The incident involved potential exposure of personal information for clients and employees. The company engaged forensic investigators, reset passwords, and is offering credit monitoring services.
- 🦫Oregon State AGas victim2020-11-12
Woodruff Sawyer & Co. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-11-12. The breach occurred during 3/2/2020 - 3/3/2020. The breach was discovered on 9/1/2020. 4,903 individuals were affected. Notice was sent on 11/9/2020.
- 🌲Washington State AGas victim2020-11-10
Woodruff Sawyer & Co., a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2020-05-01 and filed notice on 2020-11-10. 2,393 Washington residents were affected. 193 days elapsed between awareness and notification. 60 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2020-11-09
Woodruff Sawyer & Co. reported a data breach to the Montana Attorney General. The breach was reported on 2020-11-09. The breach occurred from 3/2/2020 to 3/3/2020. 23 Montana residents were affected.