Clustered 21 filings across 6 jurisdictions · filing window Jun 30, 2021 → Sep 30, 2021. View entity profile → Other incidents for this victim →
incident inc_ba33c28c2f334065 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account · Financial credentials
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE HI NH SC WA
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
21 filings across 6 jurisdictions · Jun 30, 2021 – Sep 30, 2021 · 2 milestones
Jun 3, 2020 → Sep 26, 2020
When the intrusion reportedly occurred, per the linked filings
Sep 26, 2020
Reported by DELAWARE AG, CALIFORNIA AG, WASHINGTON AG, SOUTH CAROLINA AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems. The breach window spanned from June 3, 2020, to September 26, 2020. An unknown actor accessed or acquired data, including SSNs, driver's licenses, financial account info, PHI, and credentials. Gallagher took systems offline, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring via Kroll. The notice was filed with the California AG on June 30, 2021.
Arthur J. Gallagher & Co. disclosed a ransomware incident affecting internal systems between June 3, 2020, and September 26, 2020. The company took systems offline, engaged forensic specialists, and confirmed the exposure of personal information (PII) belonging to certain individuals. The breach was discovered on September 26, 2020, and notifications were sent in July 2021. Affected data included names and other personal identifiers. The company provided 24 months of credit monitoring via Kroll.
Arthur J. Gallagher & Co. reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2021/07.08. Breach type: Hackers/Unauthorized Access. 2,345 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attack impacted internal systems between June 3 and September 26, 2020. While the specific data accessed was initially uncertain, the investigation confirmed that personal information of certain individuals was compromised. The company engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring.
Arthur J. Gallagher & Co. filed a supplemental data event correction with the Delaware Department of Justice on July 12, 2021. The filing corrects the intrusion timeline for an incident involving an unknown individual accessing Gallagher's network. The corrected access period is June 3, 2020, to September 26, 2020. Client notification is ongoing.
Arthur J. Gallagher & Co., a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2020-09-26 and filed notice on 2021-07-13. 72,378 Washington residents were affected. 290 days elapsed between awareness and notification. 115 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 72,378
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. This filing supplements prior notifications to residents in multiple states.
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems between June 3 and September 26, 2020. The breach compromised sensitive data including SSNs, driver's licenses, financial account info, medical records, and biometric data. The company engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring.
Arthur J. Gallagher & Co. notified South Carolina and other jurisdictions of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of internal systems. Gallagher took systems offline, engaged forensic specialists, and reported to law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification was sent on May 24, 2021.
Arthur J. Gallagher & Co. issued a supplemental data breach notification to Delaware residents regarding a ransomware incident detected on September 26, 2020. The breach impacted systems between June 3 and September 26, 2020, resulting in the unauthorized access of personal information. Gallagher engaged forensic specialists, notified law enforcement, and provided 24 months of credit monitoring to affected individuals.
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Impacted data included personal information. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No actual misuse was confirmed.
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems and potentially exposing customer and employee data, including names and government IDs. Gallagher took systems offline, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice.
Arthur J. Gallagher & Co. filed a supplemental data breach notification with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. This is the 5th supplemental notice.
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting systems accessed between June 3 and September 26, 2020. The breach impacted PII including government IDs. Gallagher engaged forensic specialists, took systems offline, and provided 24 months of credit monitoring. No specific victim count was disclosed in this notice.
Arthur J. Gallagher & Co. filed a supplemental notice with the Delaware Attorney General regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020, impacting internal systems. The company took systems offline, engaged forensic specialists, and notified law enforcement. The breach affected individuals' personal information, including names and government IDs. The company offered 24 months of credit monitoring via Kroll. This is the 6th supplemental notice, indicating ongoing identification of affected residents.
Arthur J. Gallagher & Co. notified South Carolina and other state attorneys general of a ransomware incident detected on September 26, 2020. The attack occurred between June 3 and September 26, 2020, resulting in the encryption of systems and unauthorized access to certain network segments. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. The breach impacted individuals' personal information, for which 24 months of credit monitoring via Kroll was provided. Notification letters were issued starting May 24, 2021.
Arthur J. Gallagher & Co. reported a ransomware incident detected on September 26, 2020, affecting internal systems between June 3 and September 26, 2020. The breach impacted customer/partner data including names and contact information. Gallagher took systems offline, engaged forensic specialists, and notified law enforcement. Affected individuals received 24 months of credit monitoring via Kroll. The filing was submitted to the South Carolina Office of the Attorney General.
Arthur J. Gallagher & Co. filed a supplemental notice to Delaware residents regarding a ransomware incident detected on September 26, 2020. The attack occurred between June 3, 2020, and September 26, 2020. The company took systems offline, engaged forensic specialists, and reported to law enforcement. Impacted data includes personal information of certain individuals. Affected individuals were offered 24 months of credit monitoring via Kroll. The specific number of affected individuals is not explicitly stated in this supplemental notice text.
State of New Hampshire Attorney General breach notification filed by Arthur J. Gallagher & Co. on September 7, 2021. The attached PDF document contains only page separators and no substantive breach details, incident dates, data types, or response actions. Extraction is limited to the filing metadata provided in the trusted lead-in tags.
Arthur J. Gallagher & Co. notified individuals of a ransomware incident detected on September 26, 2020. The attacker accessed data between June 3 and September 26, 2020. Gallagher engaged forensic specialists, took systems offline, and reported to law enforcement. Affected data included personal information. The company provided 24 months of credit monitoring via Kroll.
Arthur J. Gallagher & Co. notified South Carolina residents of a ransomware incident detected on September 26, 2020. The attack impacted internal systems between June 3 and September 26, 2020. Gallagher took systems offline, engaged forensic specialists, and reported to law enforcement. The breach affected individual data (PII). Affected individuals received 24 months of credit monitoring via Kroll. The incident status is contained.