Insurance giant AON victim of cyberattack

Insurance giant AON victim of cyberattack

AON, a British-American multinational that sells financial risk mitigation solutions, revealed that it had been the victim of a ransomware attack, or better said, it had been ignored, given that the attack would not have left a significant impact on the business.

The company filed a Form 8-K with the Securities and Exchange Commission (SEC) in which it said it was the target of a ransomware attack on February 25, 2022.

Other than that, he did not provide any further details. We don't know if social engineering or malware was used in the attack.

Limited number of affected systems

“On February 25, 2022, Aon identified a cyber incident that affected a limited number of systems. As soon as the incident was identified, the company launched an investigation and engaged the services of outside consultants, incident response professionals and attorneys. The incident did not have a significant impact on the company's operations," the document says.

"While the company is in the early stages of evaluating the incident, based on currently available information, the company does not expect the incident to have a material impact on its business, operations or financial condition," it added.

Among the services AON offers are insurance and reinsurance, making it a major target for ransomware operators. Knowing which businesses are insured against ransomware attacks makes it easier for threat actors to decide where to strike next, as insured businesses are more likely to pay the ransom and go about their day.

The last time an insurance company was attacked was in 2021, when Evil Corp hit CNA, allegedly demanding $40 million in cryptocurrency in exchange for a master decryption key for its terminals and not revealing stolen data online.

AON was formed when Ryan Insurance Group merged with Combined Insurance Company of America in 1982 and changed its name five years later in 1987. It is incorporated in Ireland but is based (and publicly traded) in the United States. As of 2021, it has offices in 120 countries around the world, employing approximately 50.000 people.

Via: BleepingComputer