Data leak

Southeast Series of Lockton Companies Data Breach - 1.1M Individuals

πŸ“… 2024-11-20
Primary Source β†—

Incident Details

On November 20, 2024, an unauthorized party gained access to a single employee account and computer within the Southeast Series of Lockton Companies’ network β€” one of the largest insurance brokerage firms in the US. Despite the limited initial access point, the attacker accessed files containing the protected health and personal information of 1,124,727 individuals. Affected individuals were notified in March 2025. Compromised data includes names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and financial information. Southeast Series of Lockton Companies agreed to a $9.9 million class action settlement. Class members with documented losses are eligible for up to $5,000; others receive a pro-rata share. The settlement claims deadline was April 7, 2026, with a final approval hearing scheduled for May 7, 2026.

Technical Details

Initial Attack Vector
Unauthorized party accessed a single individual employee account and associated computer within Lockton's network, then accessed files containing protected health and personal information

Timeline

  1. 2024-11-20 Breach occurred
  2. 2025-03-01 Publicly disclosed
  3. 2025-03-01 Customers notified