Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, financial-services, ransomware] · confidence: medium · severity: medium · affected_sectors: [financial-services] · au_impact: true

Aon plc, the global insurance and risk-management broker, was listed on the Termite ransomware group's data-leak site, detected at 01:07 UTC on 7 October according to threat-monitoring service Kalir Pulse. The claim remains entirely unverified: Aon has issued no breach statement, no regulator filing or CERT advisory names the company, and there is no proof-of-compromise sample, stolen-data volume, intrusion date, encryption evidence or ransom deadline. It is also unclear which Aon entity or geography the claim refers to. If genuine, exposure at a major broker could ripple to clients, since underwriting submissions may reveal clients' cyber-insurance arrangements and security postures. Termite's best-known prior claim is the November 2024 Blue Yonder attack that disrupted downstream customers including Starbucks. Treat as an extortion allegation pending confirmation.

Attribute Detail
Sector Financial Services
Date 2026-10-08
Source The420.in
Reliability Tier 3