← Blog

Aon Data Breaches: Full Timeline Through 2026

Share on X

People search Aon data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 1 Aon-linked incident, with headline counts up to 145K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Aon breach history matters

Aon operates in Technology (India). Across indexed rows, recurring themes include third-party and supply-chain exposure. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2022 — prolonged SharePoint/Outlook-side unauthorized access; North America PII notifications

Cataloged incident. Broker Aon plc filed an SEC 8-K after detecting activity on February 25, 2022, later characterizing a lengthy window in which an intruder accessed unstructured data from SharePoint sites and Outlook mailboxes before containment. State regulatory samples and trade reporting summarized Social Security numbers, driver's license data, and benefits-enrollment context for roughly 145,000 North Americans in court-facing summaries, with Aon emphasizing it did not classify the event as ransomware or operational takeover. Exposed categories include Names, government IDs, and benefits-adjacent enrollment fields per U.S. state notice mirrors and insurer trade press. BreachHistory cites approximately 145K+ affected records in this row. See the aon-sharepoint2022 and canonical BreachHistory entry.

Patterns and analysis

  • Third-party and supply-chain exposure — appears across multiple Aon catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the Aon company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/aon · Latest: aon-sharepoint2022.

Sources: BreachHistory catalog (1 row for Aon), company and regulator disclosures cited in individual breach records.