Clustered 7 filings across 5 jurisdictions · filing window May 26, 2022 → Jul 3, 2022. View entity profile → Other incidents for this victim →
incident inc_a0be743bccfb4eae · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Materiality delta · SEC filing delay — no SEC 8-K in this cluster.
Identity (basic) · Government ID
CA ME OR WA
Leak Site · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Dec 29, 2020 → Mar 1, 2022
When the intrusion reportedly occurred, per the linked filings
Feb 25, 2022
Reported by MAINE AG, OREGON AG, CALIFORNIA AG, WASHINGTON AG filings
aon.com
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Aon Plc reported a data breach to the Oregon Attorney General. The breach was reported on 2022-05-26. The breach occurred during 12/29/2020 - 3/1/2022. The breach was discovered on 2/25/2022. 31,799 individuals were affected. Notice was sent on 5/27/2022.
Affected (this filing): 31,799
Aon Plc reported a cybersecurity incident to the California Attorney General's Office. An unauthorized third party accessed Aon systems between December 29, 2020, and February 26, 2022. The incident involved the exfiltration of personal information, including names, Social Security numbers, and driver's license numbers. Aon retained cybersecurity firms and notified law enforcement (FBI). Remediation included enhanced security measures and 24 months of complimentary credit monitoring via Experian IdentityWorks. The notification was sent on May 27, 2022.
Aon Plc, a financial services company, reported an external system breach that affected 31,799 individuals. The incident occurred between December 29, 2020, and March 1, 2022, and was discovered on February 25, 2022. The compromised data included names combined with driver's license or non-driver identification card numbers. Aon provided affected individuals with written notification and offered 24 months of complimentary identity theft protection and credit monitoring services.
Affected (this filing): 31,799
Aon Plc, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2022-02-25 and filed notice on 2022-05-26. 6,889 Washington residents were affected. 90 days elapsed between awareness and notification. 423 days to identify the breach. 4 days to contain the breach.
Affected (this filing): 6,889
Aon Plc, a professional services firm, reported an external system breach that occurred on December 29, 2020, but was not discovered until February 25, 2022. The incident, described as hacking, affected 145,889 individuals and compromised names along with driver's license or non-driver ID numbers. The company began notifying affected individuals on May 27, 2022, and offered 24 months of complimentary credit monitoring and identity theft protection services through Experian.
Affected (this filing): 145,889
Aon Plc experienced a prolonged external system breach, lasting from December 29, 2020, to March 1, 2022. The incident was discovered on February 25, 2022. It affected 153,784 individuals, compromising names combined with driver's license or non-driver identification card numbers. In response, Aon offered 24 months of identity theft protection and credit monitoring services from Experian.
Affected (this filing): 153,784