[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fagmb7iboikkt":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":26,"affectedCount":26,"affectedCountStatus":27,"affectedCountLowerBound":13,"affectedCountUnit":28,"hasEnglishDescription":4,"contentLocale":29,"availableLocales":30,"translations":32,"severity":35,"dataClasses":36,"description":47,"seoTitle":8,"seoDescription":48,"logoUrl":49,"isVerified":4,"isSensitive":4,"isSpamList":50,"isMalware":50,"company":51},"6a4f8fdefd772fed72ce5f47","Southeast Series of Lockton Companies 2024","Southeast Series of Lockton Companies 2024 Data Breach","southeast-series-of-lockton-companies-2024","global.lockton.com","2024-11-20T00:00:00.000Z","2026-07-09T12:11:10.400Z",null,"2026-07-19T00:11:04.900Z","Official substitute notice; South Carolina notice sample; HHS OCR; healthcare security reporting; settlement website; official website logo","https:\u002F\u002Flockton-us.foleon.com\u002Fsubstitute-notice\u002Fdata-incident\u002F",[16,18,19,20,21,22,23,24,25],"https:\u002F\u002Fconsumer.sc.gov\u002Fsites\u002Fconsumer\u002Ffiles\u002FDocuments\u002FSecurity%20Breach%20Notices\u002F2025\u002FSoutheastSeriesofLocktonCompaniesLLC.pdf","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report_hip.jsf","https:\u002F\u002Fwww.hipaajournal.com\u002Fsoutheast-series-of-lockton-companies-data-breach-litigation\u002F","https:\u002F\u002Fwww.hipaaguide.net\u002Fbiggest-healthcare-data-breaches-h1-2025\u002F","https:\u002F\u002Fwww.techtarget.com\u002Fhealthtechsecurity\u002Ffeature\u002FBiggest-healthcare-data-breaches-reported-in-2025-so-far","https:\u002F\u002Fthelocktondatasettlement.com\u002F","https:\u002F\u002Fglobal.lockton.com\u002Fus\u002Fen","https:\u002F\u002Flockbox.lockton.com\u002Fm\u002F72e67bf1bb84a31d\u002Foriginal\u002FUI-Lockton-logo.jpg",1124727,"known","unknown","en",[29,31],"tr",{"en":33,"tr":34},{"slug":9},{"slug":9},"Critical",[37,38,39,40,41,42,43,44,45,46],"Names","Physical addresses","Phone numbers","Email addresses","Dates of birth","Social security numbers","Financial information","Medical information","Health insurance information","Protected health information","\u003Cp>The Southeast Series of Lockton Companies 2024 data breach is an incident involving single account and single computer access related to the unit providing insurance brokerage and employee benefits services under the Lockton umbrella. The organization reported that on November 20, 2024, it noticed suspicious activity on a Lockton computer, immediately initiated an investigation, and worked with third-party cybersecurity experts. The investigation revealed that an unauthorized party accessed a single individual account and computer in the Lockton environment on the same day and obtained certain files.\u003C\u002Fp>\n\u003Cp>Although the initial technical access to the incident was brief, the scope has expanded because the affected files contained sensitive information of a very large group of people. The current impact is evaluated as 1,124,727 people. This number is not the count of online accounts proven to have been leaked, but the number used for notifications and impact regarding individuals who may have been included in files protected under the incident, containing health information or personal data. Since the types of data may vary from person to person, this record does not claim that all fields are present for each individual.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Among the types of data that may be at risk in the context of the Lockton incident are first and last name, physical address, phone number, email address, date of birth, Social Security number, financial information, medical information, health insurance information, and protected health information. In the official incident report, name, date of birth, Social Security number, medical information, and health insurance information were explicitly stated; in current impact assessments, address, phone, email, and financial information categories have also been associated with the incident. Therefore, the data classes pose identity, health, and financial risks.\u003C\u002Fp>\n\u003Cp>When a social security number and date of birth are found together, the risk of fraudulent credit applications, tax fraud, job application fraud, and identity theft increases. Health insurance information and medical data can be used for fraudulent healthcare claims or insurance abuse. For individuals with financial information, the risks concerning bank, credit, payment, and account openings are higher. Email and phone information can make targeted phishing messages more convincing; these messages may come under the pretense of employee benefits, insurance, credit monitoring, or compensation.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In this record, the date of the violation is used as November 20, 2024, because it was reported that unauthorized access and file acquisition occurred on the same day. The date the organization became aware of the incident is also considered as November 20, 2024. The subsequent file review was used to determine which individuals and types of data were involved in the incident. The affected records may include personal data associated with clients for whom Lockton provides insurance and employee benefits services.\u003C\u002Fp>\n\u003Cp>The record should not be confused with incidents from different years or different regional units bearing the Lockton name. This page has been created only for the Southeast Series of Lockton Companies incident dated November 20, 2024. Separate Lockton-titled notifications seen in 2026 are not included in this record. Additionally, since the official incident statement refers to single account and single computer access, this record does not imply long-term and unrestricted network access across the institution. The impact arises from the data content obtained in the files.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group includes individuals whose data is processed within the scope of Lockton’s employee benefits, insurance brokerage, or employer-supported benefit services. A person may not be directly aware that they are a Lockton customer; an indirect relationship with Lockton may have been established through their employer, insurance plan, health plan, or benefits service. Therefore, individuals receiving the notification should consider not only the company name they recognize but also information that may have been shared through their employer or insurance services.\u003C\u002Fp>\n\u003Cp>Individuals whose Social Security numbers and birth dates are compromised face a higher long-term risk of identity theft. Those whose health insurance or medical information is affected may experience fraudulent medical service claims, incorrect insurance transactions, or unfamiliar medical bills. Individuals with financial information should also monitor their bank and credit accounts. For those whose phone and email information is compromised, there is a high risk of targeted messages; attackers may request personal information under the pretext of support related to the event, credit monitoring, payment, or benefits updates.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Individuals who may have been affected by this incident should first check which types of data are included in their own notifications. If there is a Social Security number, date of birth, or financial information, credit reports should be reviewed, and options such as credit freezing or fraud alerts should be considered. People with bank or credit account information should monitor automatic payments, new account openings, credit applications, and unfamiliar transaction activity. If a suspicious transaction is observed, the relevant financial institution should be contacted promptly.\u003C\u002Fp>\n\u003Cp>Individuals with health insurance or medical information should check insurance explanation documents, health service claims, and employer benefit portals. If an unrecognized service, unexpected bill, or incorrect record is noticed, written communication should be established with the relevant insurance or health service provider. Users should not click on unexpected links presented under the pretext of credit monitoring or support services, and should use the communication channels indicated in official notifications or independently verified for contacting the institution.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Long-term risk should be considered in breaches involving Social Security numbers, health, and financial data, such as the Lockton 2024 incident. Changing passwords alone is not sufficient, as the incident may involve permanent identity records and insurance data. Users should periodically review their credit reports, be cautious of fraudulent applications before the tax period, check health insurance service statements, and raise objections early to any unknown health claims.\u003C\u002Fp>\n\u003Cp>Unique passwords should be used on employer fringe benefits and insurance portals, and multi-factor login should be enabled wherever possible. Benefit plan, insurance renewal, credit monitoring, or payment messages received via email and phone should be carefully evaluated. Users should keep records related to the incident, notification letters, dates of suspicious transactions, and institutional correspondence. If the same information is used for authentication in other services, additional security settings should be enabled for those services.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The record check on this page allows the user to view personal data records that may be associated with the Southeast Series of Lockton Companies 2024 data breach. A match does not mean that all types of data listed were exposed for the same individual. The data fields applicable to each person should be evaluated according to the details in the notification sent to them. Even if a direct relationship with Lockton is not observed, an indirect relationship may have been established through an employer or insurance service.\u003C\u002Fp>\n\u003Cp>After users see the impact status, actions should be prioritized according to the type of data. For identity data, credit and official application checks should be prioritized; for health and insurance data, healthcare service and insurance disclosure checks; for financial information, bank and credit account checks should be prioritized. The Southeast Series of Lockton Companies 2024 data breach is a significant employee benefits and health data security incident demonstrating that even limited technical access can turn into a very large impact area due to the density of sensitive data in files.\u003C\u002Fp>","Southeast Series of Lockton Companies 2024 Data Breach. 1.1 Million reported records are reported. Reported data: Names, Physical addresses, Phone numbers…","\u002Fuploads\u002Flogo\u002Fsoutheast-series-of-lockton-companies-2024.jpg",false,{"name":52,"sector":53,"country":54,"website":10,"websiteArchiveUrl":55,"websiteStatus":55,"websiteCheckedAt":13},"Lockton","Insurance","United States",""]