Desk live·
ForensicPost
Insurance/Identity/File 22-0228

Aon Found an Intruder With 14 Months of Intermittent Access and Notified 145,889 People

The broker’s Form 8-K described a cyber incident affecting a limited number of systems. Its letters three months later described unauthorised access at various times between Dec. 29, 2020, and Feb. 26, 2022, with Social Security and license numbers taken. How the attacker got in was never said.

Constructed geometry · not a chart of case data
JurisdictionUSAChicagothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAon plc
ActorUnattributed
D. Kennedy8 min readConfidence: high3 sources reviewed

Aon plc reported to the Securities and Exchange Commission on Feb. 28, 2022, that it had identified a cyber incident on Feb. 25 affecting a limited number of systems, and that it did not expect a material impact. Letters to individuals dated May 27, 2022, said an unauthorised party had accessed systems at various times between Dec. 29, 2020, and Feb. 26, 2022. The data taken included names with Social Security numbers, driver’s license numbers and, for a small number, benefits enrolment information.

The count grew as filings arrived. An early figure of about 28,700 appeared in June 2022. By July the Maine attorney general’s filing, as reported, put it at 145,889, described as North American customers.

What Aon Said It Was Not

The broker’s spokesperson told trade press that Aon was not a ransomware victim, had not lost control of its systems and had not paid anyone to restore anything. The attacker no longer had access, the company said, and there was no indication the data had been further copied or shared. What the intrusion was, if not ransomware, and how it began were not described. A 14-month window with access at various times describes a foothold that was used repeatedly rather than a single event, and the file records that without knowing more.

A Broker’s Clients Are In The File

Aon arranges insurance and benefits for employers. The people it notified were largely employees of client companies whose data passed through Aon’s systems for enrolment and claims. As at Gallagher, filed at 20-0928, the affected population had no relationship with the organisation that lost their data. The letter came from a company most of them had never heard of, about a benefit plan their employer had chosen.

Class actions followed in Illinois in June and July 2022. An appeals court revived one in September 2023 after a standing dismissal. No regulatory penalty was found, and no vector was ever disclosed.

How we reported this

Compiled from Aon’s Form 8-K, its notification letters as reported and contemporaneous trade coverage, listed below. The 145,889 figure is attributed to a Maine filing that could not be fetched directly and is stated as reported. The earlier 28,700 figure is noted as partial. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Aon plc, Form 8-K, Feb. 28, 2022U.S. Securities and Exchange Commission
  2. Aon Hack Exposed Sensitive Information of 146,000 CustomersInfosecurity Magazine
  3. Aon faces lawsuits over cyberattackBusiness Insurance
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary