CSIDB logo
Incident

Ardonagh Group

Incident posture

Attack window
Oct 2020
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-01-09 19:51

Linked entities

Victim
Ardonagh Group
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Ardonagh Group experienced a ransomware incident that prompted the immediate disabling of 200 administrative accounts and the takedown of impacted systems to contain the infection. The insurance firm activated business continuity plans to minimize customer disruption while engaging third-party forensic and IT experts for remediation efforts. Internal IT access became inconsistent during the response, with operational challenges compounded by ongoing financial losses reported prior to the attack. The company confirmed the incident was detected through routine monitoring but did not disclose specifics about the ransomware or potential attackers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late September or early October 2020, Ardonagh Group, a Jersey-headquartered insurance brokerage and the UK’s second-largest privately owned insurance broker, experienced a significant cyber incident identified through routine monitoring systems. The company promptly classified the event as a potential ransomware infection, though official confirmation of ransomware specifics was withheld. Internal response teams disabled approximately 200 administrative accounts across its IT estate to contain credential compromise and limit attacker movement. Systems directly impacted by the incident were taken offline to prevent further propagation, causing intermittent IT access and operational disruptions across business units. The timing coincided with recent financial disclosures revealing a £94 million loss for the period, though no direct link between the financial results and the attack was established. Third-party forensic investigators and IT specialists were engaged immediately to assist with containment and analysis.

Ardonagh implemented pre-established business continuity plans for affected units to maintain customer operations while remediation efforts progressed. Crisis teams worked with external responders to isolate infected systems and halt ransomware execution, though the specific ransomware variant, initial attack vector, and data exfiltration details were not publicly confirmed. Company spokeswoman Kelly-Ann Knight emphasized proactive detection via existing monitoring tools but declined to elaborate on technical specifics or attribution. The incident remained under active investigation with remedial actions ongoing at the time of reporting. No customer data breaches or extortion demands were disclosed. The attack occurred amid a broader trend of ransomware targeting financially substantial organizations, following a separate ransomware incident at another major insurance broker weeks earlier.

Sources

Sources available to members: 1 source.

CSIDB