CSIDB logo
Incident

Arthur J. Gallagher & Co.

Incident posture

Attack window
Sep 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
Arthur J. Gallagher & Co.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Arthur J. Gallagher & Co., an international insurance brokerage firm, experienced a ransomware attack affecting a limited portion of its internal systems. The company confirmed the incident and stated that no material operational or financial impacts were anticipated, maintaining confidence in its overall business continuity despite the compromise.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 26, 2020, international insurance brokerage firm Arthur J. Gallagher & Co. experienced a ransomware attack targeting its internal systems. The company publicly confirmed the cybersecurity incident, identifying it as a ransomware operation that disrupted a subset of its infrastructure. The attack prompted an immediate response from the firm’s internal teams to contain the breach and assess its scope. Arthur J. Gallagher characterized the compromised systems as a “limited portion” of its overall network infrastructure, indicating that core business operations remained largely unaffected. No specific details were disclosed regarding the ransomware variant used, the initial attack vector, or whether data exfiltration occurred prior to encryption. The company did not report any immediate service disruptions to clients or external partners resulting from the incident.

Arthur J. Gallagher stated the attack did not materially impact its business operations or financial condition, suggesting effective containment measures limited systemic damage. The firm did not disclose whether it engaged with threat actors, paid a ransom, or relied solely on internal recovery processes. No customer data breaches or third-party system compromises were reported in connection with the incident. The company’s public communications emphasized operational continuity while acknowledging ongoing remediation efforts for affected internal systems. No regulatory filings or subsequent updates elaborated on forensic findings, threat actor attribution, or specific recovery timelines beyond the initial confirmation. The incident marked a confirmed cybersecurity event for the global insurance broker but did not trigger significant financial disclosures or operational restructuring announcements.

Sources

Sources available to members: 1 source.

CSIDB