Gallagher NAC
ent_fddd6260337e082b9666a14c
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
178,498
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Gallagher NAC
- Normalized
- gallagher nac— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Oregon State AGas victim2017-11-13
Gallagher NAC reported a data breach to the Oregon Attorney General. The breach was reported on 2017-11-13. The breach occurred during 6/18/2017 - 9/19/2017. The breach was discovered on 9/21/2017. 178,498 individuals were affected. Notice was sent on 11/13/2017.
- New Hampshire State AGas victim2017-11-13
Gallagher NAC notified the NH AG of a data event affecting 138 NH residents. Unusual activity was detected on Sept 21, 2017, involving a database tied to a web application. Data left the system between June 18 and Sept 19, 2017. Affected data likely included names and SSNs. GNAC disabled the app, engaged forensic investigators, notified law enforcement, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2017-11-13
Gallagher NAC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-11-13. 466 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2017-11-13
Gallagher NAC notified Washington AG of a data event affecting 579 residents. Unusual activity was detected on Sept 21, 2017, involving a database tied to a web application. Data left the system between June 18 and Sept 19, 2017. Affected data likely included names and SSNs. GNAC disabled the app, engaged forensic investigators, and offered 12 months of credit monitoring.
- California State AGas victim2017-11-13
Gallagher NAC reported that unusual activity was detected on September 21, 2017, relating to a database tied to a customer web application. Investigation determined that a small amount of data left the system between June 18, 2017, and September 19, 2017. The data potentially included names and Social Security numbers of individuals affiliated with client organizations. The web application was disabled, and a third-party forensic firm was retained. Affected individuals were offered credit monitoring and identity theft protection services.