Keenan & Associates
ent_a00cf49696dcaa0e0da70592
Disclosures
19
State AG · HHS OCR · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,651,124
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Keenan & Associates
- Normalized
- keenan associates— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- ARTHUR J. GALLAGHER & CO.— per SEC Exhibit 21 filing
Disclosure history (19)newest first
- California State AGas victim2024-10-15
Keenan & Associates, an insurance brokerage, experienced a cybersecurity incident between August 21 and August 27, 2023. An unauthorized party gained access to internal systems and exfiltrated personal information including names, SSNs, driver's license numbers, passport numbers, and health insurance information. The incident was discovered on August 27, 2023. Keenan engaged forensic experts, contained the incident, and notified law enforcement. Affected individuals are offered 24 months of identity protection.
- California State AGas victim2024-04-11
Keenan & Associates reported a data breach to the California Attorney General. The incident occurred between August 21, 2023, and August 27, 2023. The filing provides only the organization name and breach dates; no details regarding the nature of the breach, data types affected, or number of individuals impacted are disclosed in the available record.
- Maine State AGas victim2024-04-02
Keenan & Associates, a financial services firm, experienced an external system breach between August 21, 2023, and August 27, 2023, discovered on the end date. The incident impacted 1,573,844 individuals, compromising their names and driver's license or non-driver identification card numbers. Affected individuals were notified starting on February 5, 2024. The company offered 24 months of complimentary credit monitoring and fraud protection services as a response.
- New Hampshire State AGas victim2024-03-29
Keenan & Associates, an insurance brokerage, reported a ransomware incident to the New Hampshire Attorney General in a supplemental notice dated March 29, 2024. The breach involved unauthorized access to internal systems between August 21 and 27, 2023. The incident affected 108 New Hampshire residents, including current and former employees, their dependents, and client-associated individuals. Personal information, including names and government IDs, was exfiltrated. Keenan contained the breach, engaged forensic experts, notified law enforcement, and offered credit monitoring services.
- California State AGas victim2024-03-22
Keenan & Associates, an insurance brokerage, experienced a cybersecurity incident between August 21-27, 2023. An unauthorized party accessed internal systems and exfiltrated data including names, SSNs, health info, and government IDs. The incident was discovered on August 27, 2023. 612 Rhode Island residents were affected. Keenan engaged forensic experts, contained the breach, notified law enforcement, and offered 24 months of identity monitoring.
- Massachusetts State AGas victim2024-01-26
Keenan & Associates (“Keenan”) reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-01-26. 1,294 Massachusetts residents were affected.
- Washington State AGas victim2024-01-26
Keenan & Associates, an insurance brokerage, reported a ransomware incident affecting 5,873 Washington residents. Unauthorized access occurred Aug 21-27, 2023. Data included names, SSNs, DOBs, driver's licenses, and health info. Keenan engaged forensic experts, contained the breach, and notified law enforcement. Notices were sent in Jan 2024 with 24-month credit monitoring offered.
- New Hampshire State AGas victim2024-01-26
Keenan & Associates reported a ransomware incident affecting 108 New Hampshire residents. Unauthorized access occurred between August 21-27, 2023. The attacker obtained personal information including names. Keenan recovered the data and believes it was not further copied. Notifications began January 26, 2024, offering credit monitoring.
- Maine State AGas victim2024-01-26
Keenan & Associates reported an external system breach (hacking) occurring on 08/21/2023, discovered on 08/27/2023. The incident affected 1,509,616 individuals, including 141 Maine residents. Personal information acquired included names and Social Security Numbers. Keenan provided 24 months of Experian IdentifyWorks identity protection services to affected individuals.
- Oregon State AGas victim2024-01-26
Keenan & Associates reported a data breach to the Oregon Attorney General. The breach was reported on 2024-01-26. The breach occurred during 8/21/2023 - 8/27/2023. The breach was discovered on 8/27/2023. 1,509,616 individuals were affected. Notice was sent on 1/26/2024.
- California State AGas victim2024-01-26
Keenan & Associates, an insurance brokerage, experienced a cybersecurity incident where an unauthorized party accessed internal systems between August 21-27, 2023. The breach affected 612 Rhode Island residents, exposing names, SSNs, driver's license numbers, passport numbers, and health information. Keenan engaged forensic experts, contained the incident, notified law enforcement, and offered 24 months of identity protection.
- Vermont State AGas victim2024-01-26
Keenan & Associates, an insurance brokerage, disclosed a cybersecurity incident occurring between August 21-27, 2023. Unauthorized parties accessed internal systems, obtaining personal information including names, SSNs, DOBs, driver's licenses, and health data. Keenan engaged forensic experts, notified law enforcement, and offered 24 months of Experian IdentityWorks. The notice was filed with the Vermont AG on January 26, 2024.
- Illinois State AGas victim2024-01-01
KEENAN & ASSOCIATES filed a data-breach notice with the Illinois Attorney General in January 2024 (case 24-01-048). The register records the breach as discovered on August 21, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2023-12-11
Keenan & Associates notified Montana residents of a ransomware incident discovered on August 27, 2023. Unauthorized access occurred between August 21-27, 2023, resulting in the exfiltration of personal information including names, SSNs, driver's licenses, passport numbers, health information, and employment data. Keenan engaged forensic experts, contained the incident, and notified law enforcement. Affected individuals were offered 24 months of Experian IdentityWorks.
- CALIFORNIAHHS OCRas victim2023-12-11
Keenan & Associates reported to HHS on 2023-12-11 a Hacking/IT Incident affecting 1,651,124 individuals. Breached information located on Network Server.
- California State AGas victim2023-12-11
Keenan & Associates reported a data breach occurring between August 21 and 27, 2023. The notification letter offers 24 months of Experian IdentityWorks and identity restoration services, indicating personal information was compromised. No specific attack vector or individual count is detailed in the provided text.
- Massachusetts State AGas victim2015-12-02
Keenan & Associates reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-12-02. 39 Massachusetts residents were affected. The report records the breach type as electronic.
- CALIFORNIAHHS OCRas victim2015-12-01
HHS OCR 'Wall of Shame' entry: Keenan & Associates (CA), a Business Associate, reported an Unauthorized Access/Disclosure breach affecting 35,404 individuals, with PHI located on a Network Server. Submitted to OCR on 2015-12-01. The OCR row contains no narrative on attack vector, threat actor, root cause, or remediation.
- California State AGas victim2015-12-01
Keenan & Associates, a third-party health insurance administrator, discovered on October 9, 2015, that documents containing employee and dependent information (names, addresses, phone numbers, birth dates, plan identifiers, and some SSNs) were potentially searchable on the Internet due to a vendor's misconfiguration of security settings on a portal. The documents did not contain medical claims or diagnostic codes. Keenan reconfigured the portal, engaged Kroll for two years of identity monitoring, and instructed vendors to stop using the responsible software tool.