2022 Aon — prolonged SharePoint/Outlook-side unauthorized access; North America PII notifications
Data compromised
Names, government IDs, and benefits-adjacent enrollment fields per U.S. state notice mirrors and insurer trade press
Technical writeup
Broker Aon plc filed an SEC 8-K after detecting activity on February 25, 2022, later characterizing a lengthy window in which an intruder accessed unstructured data from SharePoint sites and Outlook mailboxes before containment. State regulatory samples and trade reporting summarized Social Security numbers, driver's license data, and benefits-enrollment context for roughly 145,000 North Americans in court-facing summaries, with Aon emphasizing it did not classify the event as ransomware or operational takeover.
Root cause
External attack chain against collaboration endpoints (vendor disclosures and AG-filed consumer notices cited CVE-2021-27852 class issues in litigation summaries)