Arthur J. Gallagher & Co. detected a ransomware attack on Saturday, Sept. 26, 2020, and reported it to the Securities and Exchange Commission two days later as an incident affecting a limited number of internal systems. The variant was identified as RagnarLocker. The broker said the attacker was unknown and declined to say whether it paid.
The notice sent to individuals the following summer told a longer story. The attackers had been in the network from June 3, 2020. Data in scope included Social Security and tax identification numbers, driver’s license and passport numbers, dates of birth, account credentials, financial account and card numbers, electronic signatures, medical records and biometric information.
Three Numbers, None From The Company
Gallagher never published a total. A Maine attorney general filing in July 2021 listed 7,376 residents. Litigation reporting put the figure at about 3 million. The settlement administrator later estimated roughly 3.49 million notice recipients across Gallagher and its claims-management subsidiary, Gallagher Bassett Services. The count in this file is the class estimate, and it is labelled as such.
A Broker Holds The Client’s File
An insurance broker is not a carrier, but it holds what the carrier needs: the employee census for a group health plan, the claims file for a workers’ compensation case, the identity documents behind a policy. Gallagher Bassett administers claims for employers, which is why medical records and biometrics appear in a broker’s breach notice. The people affected were mostly employees of Gallagher’s clients, with no relationship to Gallagher at all.
What Was Never Confirmed
A researcher noted before the attack that two of the company’s F5 BIG-IP devices were unpatched against CVE-2020-5902, a flaw under active exploitation that summer. Gallagher has not said how the attackers got in, and the observation is not confirmed as the vector. The class action, In re Arthur J. Gallagher Data Breach Litigation in the Northern District of Illinois, settled for $21 million with preliminary approval in September 2024 and a final hearing on Feb. 27, 2025. No regulator penalty was found.
Compiled from Gallagher’s SEC filings, its 2021 notification as reported, and settlement coverage, listed below. The compromise window is the company’s; the 3.49 million figure is the settlement administrator’s estimate; the F5 observation is a researcher’s and is not confirmed as the entry point. Graded high on the facts stated. Corrections: corrections@forensicpost.com.
- US insurance giant AJG reports data breach after ransomware attackBleepingComputer
- Insurance Broker A.J. Gallagher Reports on Investigation Into 2020 Ransomware AttackInsurance Journal
- Arthur J. Gallagher & Co., Form 10-Q for the quarter ended Sept. 30, 2020U.S. Securities and Exchange Commission
- Gallagher settles cyber breach suit for $21 millionBusiness Insurance